Privacy Shield
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Former EU-US data transfer framework (invalidated)
Overview
21 sources · Jul 23, 2026Legal Framework
Transfers of personal data to third countries operate under a tiered structure within the GDPR. Article 45 establishes the primary mechanism: an adequacy decision by the European Commission confirming that a third country ensures a level of protection essentially equivalent to that within the EU. Where such a decision exists, transfers may proceed without further authorisation.
"Such a transfer shall not require any specific authorisation."
— GDPR Art. 45
The Privacy Shield was adopted as just such an adequacy decision, designed to legitimise EU-to-US data transfers. Its assessment under Article 45(2) required the Commission to evaluate the rule of law, relevant legislation — including national security and surveillance — and the existence of effective supervisory authorities and enforceable data subject rights.
Where no adequacy decision applies, controllers must rely on Article 49 derogations or Article 46 safeguards. Under Article 49(1)(a), for instance:
"the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards"
— GDPR Art. 49(1)(a)
Articles 13 and 14 GDPR additionally require controllers to inform data subjects about intended third-country transfers and the existence or absence of an adequacy decision.
Key Developments
The Privacy Shield's downfall came in Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems (Case C-311/18, "Schrems II"), where the Court of Justice invalidated the Commission's adequacy decision. The core deficiency was the absence of enforceable rights for EU data subjects against US surveillance authorities. The Court found that, while Presidential Policy Directive 28 imposed certain requirements on US intelligence programmes, it fell short of the equivalence standard:
"the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities."
— Schrems II ¶181
The Court also confirmed that supervisory authorities are obliged to examine complaints independently, even where an adequacy decision is in force:
"that authority must examine, with complete independence, whether the transfer of personal data at issue complies with the requirements laid down by the GDPR"
— Schrems II ¶157
This means controllers cannot rely mechanically on an adequacy decision; they must conduct their own assessment of whether the destination country's legal framework — particularly government access powers — undermines the safeguards provided.
Status of the Debate
The invalidation of the Privacy Shield is settled law. However, the broader question of how to achieve lawful EU-US transfers remains contested and actively litigated. The EU-US Data Privacy Framework adopted in 2023 purports to address the deficiencies identified in Schrems II, but its durability is uncertain — a third Schrems challenge is widely anticipated. The doctrinal fault line centres on whether the new framework's redress mechanism genuinely provides data subjects with actionable rights against US surveillance, the precise deficiency that doomed its predecessor. Until the CJEU rules on the new framework, controllers must treat its adequacy status as provisional.
Practical Guidance
Do not rely solely on the adequacy decision. Even where the Data Privacy Framework applies, document a transfer impact assessment examining US government access powers, consistent with the Schrems II obligation to verify essential equivalence.
Map your transfer routes. Identify which transfers depend on the adequacy decision, Standard Contractual Clauses, or Article 49 derogations, and ensure each route is independently justified.
Supplement SCCs where necessary. Where US surveillance laws create risks that SCCs alone cannot mitigate, adopt additional technical measures (encryption, pseudonymisation, split processing) to bring the protection level to essential equivalence.
Update privacy notices. Articles 13(1)(f) and 14(1)(f) require disclosure of third-country transfers and the existence or absence of an adequacy decision — ensure notices reflect the current framework status.
Prepare for re-litigation. Given the contested status of the successor framework, maintain contingency plans for alternative transfer mechanisms in case of future invalidation.
why this is here
the Privacy Shield Decision cannot ensure a level of protection essentially equivalent to that arising from the Charter
The document is the CJEU judgment invalidating the Privacy Shield, making it a primary source for this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the Commission found that the United States authorities were able to access the personal data transferred from the Member States to the United States
This is Schrems I, the foundational case invalidating the Safe Harbor framework, which Privacy Shield replaced and later suffered a similar fate.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Decision 2000/520 does not contain sufficient findings regarding US measures which ensure adequacy
The case is a direct precursor to the Privacy Shield invalidation, discussing the adequacy of the Safe Harbour decision.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the fourth paragraph of Annex I to Decision 2000/520
The document explicitly refers to Decision 2000/520, which is the Privacy Shield framework, and discusses its implications for data transfers.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
challenging the validity of an adequacy decision are well founded, bring an action before the national courts
The case relates to the Schrems II lineage and the mechanism for challenging adequacy decisions like Privacy Shield, though it does not name it.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
such a standard clauses decision incorporates effective mechanisms that make it possible, in practice, to ensure compliance with the level of protection required by EU law
This is Schrems II, which invalidated Privacy Shield and set conditions for SCCs; the ruling is a key reference for the former framework's invalidation.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
may decide, by means of implementing act, that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection within the meaning of paragraph 2 of this Article.
While the article defines the general adequacy procedure, it does not specifically address the Privacy Shield or its invalidation; it only provides the framework that such decisions are made under.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Since the European Court of Justice declared the EU-US Privacy Shield invalid, the transfer of personal data to the USA is only permitted under certain conditions
The document directly applies the Privacy Shield invalidation and notes the later Data Privacy Framework as successor.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
transfers of personal data to third countries may be effected only in full compliance with the provisions adopted by the Member States pursuant to the directive
The document predates the Privacy Shield but is foundational to the Schrems line of cases that invalidated it.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Decision 2004/496 cannot have been validly adopted on the basis of Article 95 EC.
The annulment of an EU-US PNR transfer decision echoes the invalidation of Privacy Shield, though the document predates Privacy Shield.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The processing agreement between the University and Respondus was based on the data protection agreement between the EU and the USA, known as the Privacy Shield, although it had been declared invalid by the Schrems II ruling.
This directly addresses the Privacy Shield's invalidation and its use as a transfer mechanism, which is the specific focus of this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
in light of the Schrems II judgment
The document references the Schrems II judgment, which invalidated Privacy Shield, but does not discuss Privacy Shield directly here.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment
The case is triggered by the Schrems II judgment which invalidated Privacy Shield, though the document does not discuss that framework in detail.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
after the Schrems II ruling
The decision is a direct consequence of the Schrems II ruling that invalidated the Privacy Shield, but the document does not discuss the Privacy Shield itself.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the EU-US Privacy Shield arrangements could ensure a level of protection essentially equivalent to that guaranteed by the EU General Data Protection Regulation
The document extensively discusses the Schrems II invalidation of Privacy Shield and the new framework intended to replace it, making it central to this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
The EU-US Data Privacy Framework: A new era for data transfers?
The title suggests it addresses the framework replacing Privacy Shield, but the document only provides the title and navigation without substantive content.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Nothing of this type on this topic.
This is the top of each pile — all 65 Guidance · all 61 News