Privacy Shield
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Former EU-US data transfer framework (invalidated)
Overview
21 sources · Jul 23, 2026Legal Framework
Transfers of personal data to third countries operate under a tiered structure within the GDPR. Article 45 establishes the primary mechanism: an adequacy decision by the European Commission confirming that a third country ensures a level of protection essentially equivalent to that within the EU. Where such a decision exists, transfers may proceed without further authorisation.
"Such a transfer shall not require any specific authorisation."
— GDPR Art. 45
The Privacy Shield was adopted as just such an adequacy decision, designed to legitimise EU-to-US data transfers. Its assessment under Article 45(2) required the Commission to evaluate the rule of law, relevant legislation — including national security and surveillance — and the existence of effective supervisory authorities and enforceable data subject rights.
Where no adequacy decision applies, controllers must rely on Article 49 derogations or Article 46 safeguards. Under Article 49(1)(a), for instance:
"the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards"
— GDPR Art. 49(1)(a)
Articles 13 and 14 GDPR additionally require controllers to inform data subjects about intended third-country transfers and the existence or absence of an adequacy decision.
Key Developments
The Privacy Shield's downfall came in Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems (Case C-311/18, "Schrems II"), where the Court of Justice invalidated the Commission's adequacy decision. The core deficiency was the absence of enforceable rights for EU data subjects against US surveillance authorities. The Court found that, while Presidential Policy Directive 28 imposed certain requirements on US intelligence programmes, it fell short of the equivalence standard:
"the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities."
— Schrems II ¶181
The Court also confirmed that supervisory authorities are obliged to examine complaints independently, even where an adequacy decision is in force:
"that authority must examine, with complete independence, whether the transfer of personal data at issue complies with the requirements laid down by the GDPR"
— Schrems II ¶157
This means controllers cannot rely mechanically on an adequacy decision; they must conduct their own assessment of whether the destination country's legal framework — particularly government access powers — undermines the safeguards provided.
Status of the Debate
The invalidation of the Privacy Shield is settled law. However, the broader question of how to achieve lawful EU-US transfers remains contested and actively litigated. The EU-US Data Privacy Framework adopted in 2023 purports to address the deficiencies identified in Schrems II, but its durability is uncertain — a third Schrems challenge is widely anticipated. The doctrinal fault line centres on whether the new framework's redress mechanism genuinely provides data subjects with actionable rights against US surveillance, the precise deficiency that doomed its predecessor. Until the CJEU rules on the new framework, controllers must treat its adequacy status as provisional.
Practical Guidance
Do not rely solely on the adequacy decision. Even where the Data Privacy Framework applies, document a transfer impact assessment examining US government access powers, consistent with the Schrems II obligation to verify essential equivalence.
Map your transfer routes. Identify which transfers depend on the adequacy decision, Standard Contractual Clauses, or Article 49 derogations, and ensure each route is independently justified.
Supplement SCCs where necessary. Where US surveillance laws create risks that SCCs alone cannot mitigate, adopt additional technical measures (encryption, pseudonymisation, split processing) to bring the protection level to essential equivalence.
Update privacy notices. Articles 13(1)(f) and 14(1)(f) require disclosure of third-country transfers and the existence or absence of an adequacy decision — ensure notices reflect the current framework status.
Prepare for re-litigation. Given the contested status of the successor framework, maintain contingency plans for alternative transfer mechanisms in case of future invalidation.