Skip to content
Topic Contested in court

Privacy Shield

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Former EU-US data transfer framework (invalidated)

185 linked items 5 Laws22 Case Law65 Guidance14 Enforcement61 News

Overview

21 sources · Jul 23, 2026

Legal Framework

Transfers of personal data to third countries operate under a tiered structure within the GDPR. Article 45 establishes the primary mechanism: an adequacy decision by the European Commission confirming that a third country ensures a level of protection essentially equivalent to that within the EU. Where such a decision exists, transfers may proceed without further authorisation.

"Such a transfer shall not require any specific authorisation."
— GDPR Art. 45

The Privacy Shield was adopted as just such an adequacy decision, designed to legitimise EU-to-US data transfers. Its assessment under Article 45(2) required the Commission to evaluate the rule of law, relevant legislation — including national security and surveillance — and the existence of effective supervisory authorities and enforceable data subject rights.

Where no adequacy decision applies, controllers must rely on Article 49 derogations or Article 46 safeguards. Under Article 49(1)(a), for instance:

"the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards"
— GDPR Art. 49(1)(a)

Articles 13 and 14 GDPR additionally require controllers to inform data subjects about intended third-country transfers and the existence or absence of an adequacy decision.

Key Developments

The Privacy Shield's downfall came in Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems (Case C-311/18, "Schrems II"), where the Court of Justice invalidated the Commission's adequacy decision. The core deficiency was the absence of enforceable rights for EU data subjects against US surveillance authorities. The Court found that, while Presidential Policy Directive 28 imposed certain requirements on US intelligence programmes, it fell short of the equivalence standard:

"the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities."
— Schrems II ¶181

The Court also confirmed that supervisory authorities are obliged to examine complaints independently, even where an adequacy decision is in force:

"that authority must examine, with complete independence, whether the transfer of personal data at issue complies with the requirements laid down by the GDPR"
— Schrems II ¶157

This means controllers cannot rely mechanically on an adequacy decision; they must conduct their own assessment of whether the destination country's legal framework — particularly government access powers — undermines the safeguards provided.

Status of the Debate

The invalidation of the Privacy Shield is settled law. However, the broader question of how to achieve lawful EU-US transfers remains contested and actively litigated. The EU-US Data Privacy Framework adopted in 2023 purports to address the deficiencies identified in Schrems II, but its durability is uncertain — a third Schrems challenge is widely anticipated. The doctrinal fault line centres on whether the new framework's redress mechanism genuinely provides data subjects with actionable rights against US surveillance, the precise deficiency that doomed its predecessor. Until the CJEU rules on the new framework, controllers must treat its adequacy status as provisional.

Practical Guidance

  • Do not rely solely on the adequacy decision. Even where the Data Privacy Framework applies, document a transfer impact assessment examining US government access powers, consistent with the Schrems II obligation to verify essential equivalence.

  • Map your transfer routes. Identify which transfers depend on the adequacy decision, Standard Contractual Clauses, or Article 49 derogations, and ensure each route is independently justified.

  • Supplement SCCs where necessary. Where US surveillance laws create risks that SCCs alone cannot mitigate, adopt additional technical measures (encryption, pseudonymisation, split processing) to bring the protection level to essential equivalence.

  • Update privacy notices. Articles 13(1)(f) and 14(1)(f) require disclosure of third-country transfers and the existence or absence of an adequacy decision — ensure notices reflect the current framework status.

  • Prepare for re-litigation. Given the contested status of the successor framework, maintain contingency plans for alternative transfer mechanisms in case of future invalidation.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems Schrems II CJEU Case Law CJEU Jul 2020 invalidity of Privacy Shield
why this is here
the Privacy Shield Decision cannot ensure a level of protection essentially equivalent to that arising from the Charter

The document is the CJEU judgment invalidating the Privacy Shield, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Data Protection Commissioner v. Schrems and Facebook Schrems I CJEU Case Law CJEU Oct 2015 invalid safe harbor decision
why this is here
the Commission found that the United States authorities were able to access the personal data transferred from the Member States to the United States

This is Schrems I, the foundational case invalidating the Safe Harbor framework, which Privacy Shield replaced and later suffered a similar fate.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Data Protection Commissioner v. Schrems and Facebook Schrems I CJEU Case Law CJEU Oct 2015 Invalidation of Safe Harbour and basis for Privacy Shield
why this is here
Decision 2000/520 does not contain sufficient findings regarding US measures which ensure adequacy

The case is a direct precursor to the Privacy Shield invalidation, discussing the adequacy of the Safe Harbour decision.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Data Protection Commissioner v. Schrems and Facebook Schrems I CJEU Case Law CJEU Oct 2015 EU-US data transfer framework
why this is here
the fourth paragraph of Annex I to Decision 2000/520

The document explicitly refers to Decision 2000/520, which is the Privacy Shield framework, and discusses its implications for data transfers.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems Schrems II CJEU Case Law CJEU Jul 2020 adequacy decision validity challenge
why this is here
challenging the validity of an adequacy decision are well founded, bring an action before the national courts

The case relates to the Schrems II lineage and the mechanism for challenging adequacy decisions like Privacy Shield, though it does not name it.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems Schrems II CJEU Case Law CJEU Jul 2020 Schrems II invalidation context
why this is here
such a standard clauses decision incorporates effective mechanisms that make it possible, in practice, to ensure compliance with the level of protection required by EU law

This is Schrems II, which invalidated Privacy Shield and set conditions for SCCs; the ruling is a key reference for the former framework's invalidation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

art 45 Transfers on the basis of an adequacy decision Laws GDPR Apr 2016 Adequacy decision framework
why this is here
may decide, by means of implementing act, that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection within the meaning of paragraph 2 of this Article.

While the article defines the general adequacy procedure, it does not specifically address the Privacy Shield or its invalidation; it only provides the framework that such decisions are made under.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… AP Enforcement Autoriteit Persoonsgegevens Jul 2024 invalidated Privacy Shield and successor
why this is here
Since the European Court of Justice declared the EU-US Privacy Shield invalid, the transfer of personal data to the USA is only permitted under certain conditions

The document directly applies the Privacy Shield invalidation and notes the later Data Privacy Framework as successor.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Data Protection Commissioner v. Schrems and Facebook Schrems I CJEU Case Law CJEU Oct 2015 Transfer to third countries framework
why this is here
transfers of personal data to third countries may be effected only in full compliance with the provisions adopted by the Member States pursuant to the directive

The document predates the Privacy Shield but is foundational to the Schrems line of cases that invalidated it.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

CJEU annuls PNR data transfer decision as ultra vires under Art. 95 EC Transfers: Where the transfers of personal data are authorized under an agreement that was adopted ultra vires, the authorization is void. Case Law CJEU May 2006 invalidated transfer framework
why this is here
Decision 2004/496 cannot have been validly adopted on the basis of Article 95 EC.

The annulment of an EU-US PNR transfer decision echoes the invalidation of Privacy Shield, though the document predates Privacy Shield.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€200,000 Bocconi University: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use… ITALY ·Garante ·Art. 2, 5, 6 +6 Enforcement Italian Data Protection Authority (Garante) Sep 2021 Invalidity of Privacy Shield as transfer basis
why this is here
The processing agreement between the University and Respondus was based on the data protection agreement between the EU and the USA, known as the Privacy Shield, although it had been declared invalid by the Schrems II ruling.

This directly addresses the Privacy Shield's invalidation and its use as a transfer mechanism, which is the specific focus of this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€25,000 CDON AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Enforcement Data Protection Authority of Sweden Jun 2023 Post-Schrems II context
why this is here
The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment

The case is triggered by the Schrems II judgment which invalidated Privacy Shield, though the document does not discuss that framework in detail.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€1,200M Meta Platforms Ireland Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had… DPC ·Art. 46 Enforcement Data Protection Authority of Ireland May 2023 Invalidated framework
why this is here
after the Schrems II ruling

The decision is a direct consequence of the Schrems II ruling that invalidated the Privacy Shield, but the document does not discuss the Privacy Shield itself.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

EU-US Privacy Framework needs a long hard look The Commission has endorsed enthusiastically a recent US order to implement a new framework to protect the privacy of personal data shared between the US and Europe. Dick Roche… News EURactiv Oct 2022 Privacy Shield invalidation and successor
why this is here
the EU-US Privacy Shield arrangements could ensure a level of protection essentially equivalent to that guaranteed by the EU General Data Protection Regulation

The document extensively discusses the Schrems II invalidation of Privacy Shield and the new framework intended to replace it, making it central to this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

The EU-US Data Privacy Framework: A new era for data transfers? > Legally, until an adequacy determination is granted, companies should continue to follow the European Data Protection Board’s recommendations on measures that supplement… News IAPP Oct 2022 Successor to Privacy Shield
why this is here
The EU-US Data Privacy Framework: A new era for data transfers?

The title suggests it addresses the framework replacing Privacy Shield, but the document only provides the title and navigation without substantive content.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 65 Guidance · all 61 News