# Privacy Shield — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/privacy-shield
> Sources are cited per item. Verify against the official texts before relying on them.

Former EU-US data transfer framework (invalidated)

## Overview

## Legal Framework

Transfers of personal data to third countries operate under a tiered structure within the GDPR. [Article 45](/laws/gdpr/art-45) establishes the primary mechanism: an adequacy decision by the European Commission confirming that a third country ensures a level of protection essentially equivalent to that within the EU. Where such a decision exists, transfers may proceed without further authorisation.

> "Such a transfer shall not require any specific authorisation."
> — [GDPR Art. 45](/laws/gdpr/art-45)

The Privacy Shield was adopted as just such an adequacy decision, designed to legitimise EU-to-US data transfers. Its assessment under Article 45(2) required the Commission to evaluate the rule of law, relevant legislation — including national security and surveillance — and the existence of effective supervisory authorities and enforceable data subject rights.

Where no adequacy decision applies, controllers must rely on [Article 49](/laws/gdpr/art-49) derogations or Article 46 safeguards. Under Article 49(1)(a), for instance:

> "the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards"
> — [GDPR Art. 49(1)(a)](/laws/gdpr/art-49#par-1-pnt-a)

Articles [13](/laws/gdpr/art-13#par-1-pnt-f) and [14](/laws/gdpr/art-14#par-1-pnt-f) GDPR additionally require controllers to inform data subjects about intended third-country transfers and the existence or absence of an adequacy decision.

## Key Developments

The Privacy Shield's downfall came in *Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems* (Case C-311/18, "Schrems II"), where the Court of Justice invalidated the Commission's adequacy decision. The core deficiency was the absence of enforceable rights for EU data subjects against US surveillance authorities. The Court found that, while Presidential Policy Directive 28 imposed certain requirements on US intelligence programmes, it fell short of the equivalence standard:

> "the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities."
> — [Schrems II ¶181](/posts/6121#seg-181)

The Court also confirmed that supervisory authorities are obliged to examine complaints independently, even where an adequacy decision is in force:

> "that authority must examine, with complete independence, whether the transfer of personal data at issue complies with the requirements laid down by the GDPR"
> — [Schrems II ¶157](/posts/5945#seg-157)

This means controllers cannot rely mechanically on an adequacy decision; they must conduct their own assessment of whether the destination country's legal framework — particularly government access powers — undermines the safeguards provided.

## Status of the Debate

The invalidation of the Privacy Shield is settled law. However, the broader question of how to achieve lawful EU-US transfers remains contested and actively litigated. The EU-US Data Privacy Framework adopted in 2023 purports to address the deficiencies identified in Schrems II, but its durability is uncertain — a third Schrems challenge is widely anticipated. The doctrinal fault line centres on whether the new framework's redress mechanism genuinely provides data subjects with actionable rights against US surveillance, the precise deficiency that doomed its predecessor. Until the CJEU rules on the new framework, controllers must treat its adequacy status as provisional.

## Practical Guidance

- **Do not rely solely on the adequacy decision.** Even where the Data Privacy Framework applies, document a transfer impact assessment examining US government access powers, consistent with the Schrems II obligation to verify essential equivalence.

- **Map your transfer routes.** Identify which transfers depend on the adequacy decision, Standard Contractual Clauses, or Article 49 derogations, and ensure each route is independently justified.

- **Supplement SCCs where necessary.** Where US surveillance laws create risks that SCCs alone cannot mitigate, adopt additional technical measures (encryption, pseudonymisation, split processing) to bring the protection level to essential equivalence.

- **Update privacy notices.** Articles 13(1)(f) and 14(1)(f) require disclosure of third-country transfers and the existence or absence of an adequacy decision — ensure notices reflect the current framework status.

- **Prepare for re-litigation.** Given the contested status of the successor framework, maintain contingency plans for alternative transfer mechanisms in case of future invalidation.

## Legislation (full text of key provisions)

### Transfers on the basis of an adequacy decision

*Source: GDPR, gdpr-art-45-en, 2016-04-27 — https://overview.legal/posts/90855*

### Recital 114 — Data transfer safeguards absent adequacy decision

*Source: GDPR, gdpr-rec-114-en, 2016-04-27 — https://overview.legal/posts/91743*

In any case, where the Commission has taken no decision on the adequate level of data protection in a third country, the controller or processor should make use of solutions that provide data subjects with enforceable and effective rights as regards the processing of their data in the Union once those data have been transferred so that that they will continue to benefit from fundamental rights and safeguards.

### Recital 112 — Public interest vital interests data transfer derogations

*Source: GDPR, gdpr-rec-112-en, 2016-04-27 — https://overview.legal/posts/91739*

Those derogations should in particular apply to data transfers required and necessary for important reasons of public interest, for example in cases of international data exchange between competition authorities, tax or customs administrations, between financial supervisory authorities, between services competent for social security matters, or for public health, for example in the case of contact tracing for contagious diseases or in order to reduce and/or eliminate doping in sport. A transfer of personal data should also be regarded as lawful where it is necessary to protect an interest which is essential for the data subject's or another person's vital interests, including physical integrity or life, if the data subject is incapable of giving consent. In the absence of an adequacy decision, Union or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of data to a third country or an international organisation. Member States should notify such provisions to the Commission. Any transfer to an international humanitarian organisation of personal data of a data subject who is physically or legally incapable of giving consent, with a view to accomplishing a task incumbent under the Geneva Conventions or to complying with international humanitarian law applicable in armed conflicts, could be considered to be necessary for an important reason of public interest or because it is in the vital interest of the data subject.

### Recital 104 — human rights in third country adequacy assessment

*Source: GDPR, gdpr-rec-104-en, 2016-04-27 — https://overview.legal/posts/91723*

In line with the fundamental values on which the Union is founded, in particular the protection of human rights, the Commission should, in its assessment of the third country, or of a territory or specified sector within a third country, take into account how a particular third country respects the rule of law, access to justice as well as international human rights norms and standards and its general and sectoral law, including legislation concerning public security, defence and national security as well as public order and criminal law. The adoption of an adequacy decision with regard to a territory or a specified sector in a third country should take into account clear and objective criteria, such as specific processing activities and the scope of applicable legal standards and legislation in force in the third country. The third country should offer guarantees ensuring an adequate level of protection essentially equivalent to that ensured within the Union, in particular where personal data are processed in one or several specific sectors. In particular, the third country should ensure effective independent data protection supervision and should provide for cooperation mechanisms with the Member States' data protection authorities, and the data subjects should be provided with effective and enforceable rights and effective administrative and judicial redress.

### Recital 108 — appropriate safeguards for international data transfers

*Source: GDPR, gdpr-rec-108-en, 2016-04-27 — https://overview.legal/posts/91731*

In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third country by way of appropriate safeguards for the data subject. Such appropriate safeguards may consist of making use of binding corporate rules, standard data protection clauses adopted by the Commission, standard data protection clauses adopted by a supervisory authority or contractual clauses authorised by a supervisory authority. Those safeguards should ensure compliance with data protection requirements and the rights of the data subjects appropriate to processing within the Union, including the availability of enforceable data subject rights and of effective legal remedies, including to obtain effective administrative or judicial redress and to claim compensation, in the Union or in a third country. They should relate in particular to compliance with the general principles relating to personal data processing, the principles of data protection by design and by default. Transfers may also be carried out by public authorities or bodies with public authorities or bodies in third countries or with international organisations with corresponding duties or functions, including on the basis of provisions to be inserted into administrative arrangements, such as a memorandum of understanding, providing for enforceable and effective rights for data subjects. Authorisation by the competent supervisory authority should be obtained when the safeguards are provided for in administrative arrangements that are not legally binding.

## Case law

### Cour Administrative - 49701C

*Source: Administrative Court of the Grand-Duchy of Luxembourg, 2024-12-12 — https://overview.legal/posts/158440 — original: https://gdprhub.eu/index.php?title=Cour_Administrative_-_49701C*

Facts — On 19 May 2020, a Luxembourg bank informed the complainant that, by 30 June 2020, they would transmit the complainant's bank account information to the Luxembourg fiscal authorities. Afterwards, by latest the 30th September 2020, the Luxembourg fiscal authorities will share this information with the US fiscal authorities. The complainant, a French and American citizen connected to the association for the protection of civil rights ASBL, turned to the Luxembourg direct Tax Office (hereinafter: ACD), explaining that the data to be transferred on the basis of the FATCA concern identification, financial and economic data, i.e. personal data as defined in the GDPR. Thus, the complainant requested the ACD to erase the personal data and immediately discontinue the exchange of information between the ACD and the American fiscal authorities. The director of the ACD rejected this request, stating that the ASBL is not a data subject and the processing of the personal data of the complainant was necessary to respect the Luxembourg FATCA Agreement law to which the ACD is subject, Thus, in their view the request to restrict processing is not justified. The complainant turned to the Luxembourg Administrative Tribunal, which rejected the injunctive request to suspend the information sharing with the US fiscal authorities. The Tribunal also declared itself entitled neither to decide on the decision of the ACD, nor to invalidate it. As to the merit, the Tribunal found the request for invalidation unfounded, rejecting the request for a reimbursement and ordering the complainant to pay the costs. The ACD challenged the receivability of appeal. Holding — In relation to the GDPR-related questions, the court held the following. Whether the GDPR was applicable to the data transfer With regards to the applicability of the GDPR and the law of the 1st August 2018 about the organisation of the Commission Nationale pour la Protection des Données (CNPD, the Luxembourg data protection supervisory authority) and the implementation of Regulation (EU) 2016/679 replacing Directive 95/46 EC and the law of the 2nd August 2002 about the implementation of said directive. The subject of the case is neither direct prevention, detection and prosecution of criminal activities (when Directive (EU) 2016/680 would apply), nor is it within the area of the Common Foreign and Security Policy (which is exempt from the application of the GDPR), therefore the GDPR applies. In respect of the prevention, detection and prosecution of criminal activities, Directive (EU) 2016/680 would only apply if the data controller were a competent authority. These authorities are only authorities of law enforcement, and the tax office is not one of them. The processing in question in the case at hand concerns the exercise of the rights of Member States in the area of taxation, in particular the mutual cooperation in tax matters through the automatic exchange of information. Whether the FATCA Agreement was valid in the light of the GDPR In interpreting the GDPR related to the case, the court found furthermore, that Article 96 GDPR applies, i.e. as an existing international treaty, the FATCA Agreement is valid even if it contradicts the GDPR. As the FATCA Agreement was signed the 28th March 2014 and enacted by the law of the 24th July 2015, it was concluded before the GDPR entered into force and is thus covered by Article 96 of the GDPR. There is also no stipulation which would require – contrary to what the appellants state – to modify the FATCA Agreement in view of the GDPR. The primacy of international law over the national law, which is enshrined in Luxembourg law, in case when there is a conflict between rules of an international treaty and those in national law, even a posteriori (i.e. when the rules of national law are adopted after the entry in force of the international treaty), the international norm has precedence over the national norm. Thus, in case of a hypothetical contradiction with the law of the 2nd August 2002, the FATCA Agreement would prevail. Whether the transfer of personal data to the US should have been preceded by a Transfer Impact Assessment and whether the transfer to the US was lawful Concerning the further two questions proposed to be asked from the CJEU, the court was of the opinion that these were not necessary to decide the present case. Given that Article 96 GDPR applies, the legality the decision of the director of ACD of the 22nd March 2021, having refused to stop the transfer of the personal data provided by the Luxembourg financial institutions through the automatic exchange of information to the fiscal administration of the United States in the framework of the FATCA Agreement has thus to be examined exclusively in the light of the Directive 95/46 EC, as this directive remains in force (due to Article 96 GDPR) as the only legal reference to judge the lawfulness of the measure, as no withdrawal or modification of FATCA Agreement was necessary. Articles 25 and 26 of Directive 95/46 EC are the rules to be taken into account as specific rules as the automatic exchange of information according to FATCA Agreement is a transfer of personal data to third countries, and these rules are part of chapter IV of Directive 95/46 EC, entitled “transfer of personal data to third countries”. The appellants claim that in this respect, ACD should have investigated the adequate level of protection in the US. However, in Mémorial (the Luxembourg official journal), series A n° 156 of the 10th August 2015 (p. 3796) establishes that "the conditions of entry into force of the agreement about the exchange of notes indicated above (i.e. the exchange of notes regarding FATCA Agreement, signed the 31st March and 1st April 2015) being fulfilled the 29th July 2015, the said acts entered into force between the Contracting Parties the 28th July 2015, according to Article 10 of the Agreement. Thus, the State had sufficient elements of information to conclude that the exchanged data remain confidential, will be used for fiscal purposes and will be processed by infrastructures which ensure such confidentiality. Thus, the State did not find any elements to doubt in this regard at that point. Article 26 (1), point d Directive 95/46 authorises Member States to foresee or authorise transfers of personal data to a third country also when the legal system of this latter does not ensure an adequate level of protection, namely in the case when this transfer is necessary for the concerned Member State to preserve an important public interest. This stipulation has to be understood as giving Member States a certain freedom of manoeuvre concerning the content of the notion of important public interest which they consider justifying the transfer of personal data to third countries which do not guarantee an adequate level of protection, given that the interests which merit protection are not entirely the same in the different Member States. In general, the State rightly argues that the CJEU recognised the fight against aggressive tax planning and the prevention of risk of tax avoidance and tax fraud as objectives in the general interest recognised by the Union which can justify the restriction of rights guaranteed in the Charter of Fundamental Rights (judgment of the 8th December 2022, case C-694/20, Orde van Vlaamse Balies e.a. and of the 29th July 2024, case. C-623/22, Belgian Association of Tax Lawyers). The transfer of information serves this objective. The appellants contest nevertheless this analysis, referring to the Guidelines 2/2020 the EDPB according to which the derogations should be interpreted narrowly and concern mainly occasional and on-repetitive transfers but cannot justify transfers on a large scale, as foreseen in the FATCA Agreement. This restriction does not, however, stem from Article 26 (1), point d of Directive 95/46 EC, neither from the relevant Recitals of Directive 95/46 EC. Even if the EDPB has a certain role in the harmonised application of the Directive 95/46 EC and afterwards of the GDPR by all member States, its analysis in its guidelines is not binding. The appellants also claim that there should be a similar provision of information from the US fiscal authorities to the European authorities. Nevertheless, such a requirement of reciprocity is not required neither from Article 26 (1), point d), nor from the recitals of Directive 95/46 EC. Even when such a reciprocity corresponds a certain logic of cooperation, such a logic is in political domain but does not influence the interpretation of a rule of Union law. Based on the above considerations, the court considers that the execution of the FATCA Agreement and of the law of the 24th July 2015 by the ACD is lawful based on Article 26 (1) point d), of Directive 95/46 EC, even when the US does not guarantee and adequate protection of personal data pursuant to Article 25 (1), of Directive 95/46 EC. Therefore, the arguments of the appellants to the contrary have to be rejected. This analysis is also sufficient to support that there is no need to request a preliminary ruling from the CJEU. Therefore, the Administrative Court of Luxembourg rejected the appeal.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### CJEU - C-311/18 - Facebook Ireland and Schrems

*Source: GDPRhub, 2026-07-17 — https://overview.legal/posts/125639 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-311/18_-_Facebook_Ireland_and_Schrems*

Facts — Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor", was valid. In its judgment on October 6th 2015 (Case C-362/14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be "adequate", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC. In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1st 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Article 7 CFR, Article 8 CFR, and Article 47 CFR. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4th 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU. In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISA approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data without ensuring a level of protection that was essentially equivalent to that which was guaranteed by Article 7 CFR and Article 8 CFR. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable. Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data. Dispute — The request for a preliminary ruling referred eleven questions to the Court of Justice. The topics covered in these questions were as follows: the applicability of EU law to data transfers made for commercial purposes, but further processed for national security and law enforcement purposes the relevant legislation for determining whether there has been a violation of individual rights how to assess the level of protection in a third country whether data transfers to the US violate the Charter whether the level of protection offered in the US respects or limits an individual’s right to a judicial remedy what level of protection is required to be afforded to personal data that is transferred under SCCs whether the SCCs can even be adequate as safeguards given they do not bind national authorities whether there is an obligation to suspend data flows if a data importer is subject to surveillance law what the relevance of the Privacy Shield decision is with regards to assessing safeguards whether the presence of an ombudsperson can ensure that the US provides an effective remedy to data subjects whether the SCCs violate the Charter Holding — The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes. In particular, the Court stressed that a transfer of data is not excluded from the scope of the GDPR for the reason that it may be processed by the national authorities of a third country. Regarding the level of protection required in such an instance, the Court held that the requirements presented by the GDPR regarding safeguards, enforceable rights, and legal remedies must continue to be applied. In other words, when their data is transferred abroad, a data subject must be afforded a level of protection essentially equivalent to that which they would receive in EU. In such circumstances, in order to assess the level of protection, both existing contractual clauses between the data importer and exporter, and the potential access by public authorities in a third country must be taken into account, along with the relevant aspects of the legal system in the third country. The Court then analyzed Decision 2016/1250 (the “Privacy Shield”), which was the self-certification scheme in place for controllers based in the US. Examining the decision in light of the provisions of the Charter, the Court held that the requirements of US national security, public interest, and law enforcement do in fact interfere with the fundamental rights of persons whose data is transferred there. These limitations on the protection of personal data were not circumscribed in a way that satisfied requirements that are essentially equivalent to those required under EU law. The principle of proportionality was also not satisfied, in so far as US surveillance programs are not limited to what is ‘strictly necessary’. It was noted that the provisions in the US surveillance programs neither limited the power they conferred onto national authorities, nor granted data subjects actionable rights before the courts against the US authorities. The Court proceeded to scrutinize the Ombudsperson mechanism that had been in place under the Privacy Shield, stating that it too did not provide data subjects with a cause of action before a body which was fully independent, and that this body was limited in so far as it could not impose rules that were binding on US intelligence services. Taking all of this into account, the Court declared the Privacy Shield Decision to therefore be invalid. The Court also clarified that in the absence of an adequacy decision, the competent supervisory authorities are required to suspend or prohibit a transfer of personal data to a third country where they consider that the standard data protection clauses are not or cannot be complied with in the third country, and that the protection of the data transferred cannot be ensured by other means. Following this, the Court then examined the validity of the SCCs (Decision 2010/87). First, the Court held that the validity of the Decision was not called into question by the mere fact that the SCCs do not bind national authorities in a third country. After establishing this, the Court emphasized that the validity of the SCCs, however, did depend on whether there were effective mechanisms in place that make it possible to ensure compliance with the level of protection required by EU law. Important to note is that here the Court held that the SCCs in themselves did provide for such mechanisms. However, it went on to stress that where these mechanisms cannot be complied with, the transfers of personal data pursuant to these clauses is to be suspended or prohibited. Furthermore, there is an obligation on the data exporter and the recipient of the data to verify prior to a transfer, what the level of protection in a third country is, and whether it will be possible to comply with the requirements of the SCCs.

### Judgment of the General Court (Tenth Chamber, Extended Composition) of 3 September 2025.#Philippe Latombe v European Commission.#Transfer of personal data to the United States – Commission Implementing Decision on the adequate level of protection of personal data ensured by the United States – Right to an effective remedy – Right to private and family life – Decisions based solely on the automated processing of personal data – Security of the processing of personal data.#Case T-553/23.

*Source: General Court, T-553/23, 2025-09-03 — https://overview.legal/posts/132137 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0553*

In Case T-553/23, French citizen Philippe Latombe sought annulment of the European Commission's Implementing Decision (EU) 2023/1795, which found that the United States ensures an adequate level of personal data protection under the EU-US Data Privacy Framework. Latombe challenged the adequacy decision on grounds including infringement of Articles 7 and 8 of the EU Charter, the right to an effective remedy, protections against solely automated decisions, and data security, arguing the framework failed to provide essentially equivalent protection to EU law. The General Court dismissed the action as unfounded, upholding the Commission's adequacy decision.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### CJEU - C-362/14 - Schrems I

*Source: GDPRhub, 2015-06-10 — https://overview.legal/posts/122860 — original: https://gdprhub.eu/index.php?title=CJEU_-_C-362/14_-_Schrems_I*

Facts — Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. Some of Mr. Schrems personal data had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the US. Personal data transferred by undertakings such as Facebook Ireland to their parent company established in the US can be accessed by the NSA and other US security agencies in the course of a mass and indiscriminate surveillance. EU citizens have no effective rights to be heard on question of surveillance and interception of their data by the NSA and other US security agencies. The Commission had declared data transfers to the US legal under Article 25(6) of the Data Protection Directive 95/46 (Directive 95/46) when complying with safe-harbor regime by Decision 2000/520 (the Adequacy Decision), finding the US's protection of personal data adequate in Article 1 of the decision, if the recipients adhered to so called safe harbor privacy principles. These included derogations from data protection principles for US national interests. In Article 3 of the decision the Commission heightened the threshold for DPAs to take action within the scope of Article Article 25 of Directive 95/46. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers, claiming that the US did not have an adequate level of protection. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, asking in essence whether Article 25(6) of Directive 95/46, read in the light of Articles 7, 8 and 47 CFR, must be interpreted to mean that an Adequacy Decision prevents a DPA from examining the claim of a data subject regarding transfer of personal data to that third country when it contends that the law and practices in force in the third country do not ensure an adequate level of protection. The Advocate General's Opinion — The AG opined, that the derogations provided for in the Adequacy Decision enabling access by US authorities to data transferred to US organisations within the safe harbor regime are too general and not limited to what strictly necessary to adequately protect data from EU based persons. Thus, the AG found the US intelligence services’ access to the transferred data interfering with fundamental rights. The AG considered, that EU citizens using Facebook are not informed that their personal data will be generally accessible to US security agencies and EU citizens have no effective right to be heard on the surveillance and interception of their data. While the AG found that there is an oversight of the US Foreign Intelligence Surveillance Court, the proceedings before it are secret and ex parte, which, in the AG’s opinion, is an interference with the rights of citizens to an effective remedy protected by Article 47 CFR. The AG found it “extremely doubtful” that the limitations at issue may be regarded as respecting the essence of Article 7 or 8 EUCFR as they do not define grounds for the derogations by sufficient precision. Thus, the AG opined that Decision 2000/520 must be declared invalid. The AG stated, that neither private dispute resolution mechanisms or the Federal Trade Commission can challenge access by the US intelligence services to personal data transferred from the EU and that there is no independent authority capable of verifying that the implementation of the derogations is limited to what strictly necessary. Therefore the AG found, that the Commission exceeds the limits imposed by compliance with the principle of proportionality in light of Articles 7, 8 and 52(1) EUCFR. The Adequacy Decision, according to the AG, must therefore be declared invalid since it does not ensure an adequate level of protection of the personal data transferred from the EU to the US under that scheme. The Courts Decision — The CJEU held that the Commission's Safe Harbour decision did not prevent the DPC from examining whether the transfer of user data to the USA by Facebook should be suspended. The court found that DPAs do not have powers on the basis of Article 28 Directive 95/46 regarding processing carried out in a third country. However, the court held, that having personal data transferred from a Member State to a third country constitutes, in itself, processing of personal data and thus found the DPAs vested with the power to check whether a data transfer to a third country complies with the requirements laid down by Directive 95/46. The court found that until a Commission's decision is declared invalid by the it, DPAs cannot adopt measures contrary to that decision as it is in principle presumed to be lawful until withdrawn, annulled or declared invalid. However the court found that Decision 2000/520 cannot prevent persons whose personal data has been or could be transferred to a third country from lodging with the DPA a claim concerning the protection of their rights and freedoms. If, the court reasoned, the DPA rejects it, the complainant must, in the light of Article 47 CFR, have access to judicial remedies. If however the DPA considers the complaint well founded, the court held, it must in accordance with Article 28(3) of Directive 95/46, read in the light in particular of Article 8(3) CFR, be able to engage in legal proceedings. Thus, according to the court, the national legislature must provide for legal remedies enabling the concerned DPA to put forward the objections before the national courts which may make a reference for a preliminary ruling. Thus the court held that Article 25(6) of Directive 95/46, read in the light of Articles 7, 8 and 47 CFR, must be interpreted as meaning that an Adequacy Decision, does not prevent a DPA from examining the claim of a data subject that the law and practices in force in the third country do not ensure an adequate level of protection. Furthermore, the court found that Article 25(6) of Directive 95/46 required for the level of data protection offered a third country to be considered "adequate" it should be “essentially equivalent” to that of the EU as otherwise circumvention of Directive 95/46 would be too easy. The court held, that the Commission is obliged to assess whether a third country's domestic law or international commitments and its compliance practice afford an essentially equivalent protection and check periodically if this assessment is still correct. The court found that the Adequacy Decision in stating that ‘national security, public interest, or law enforcement requirements’ have primacy over the safe harbor principles enables interference with the fundamental rights of the persons whose personal data is or could be transferred to the US. Regarding the derogations and limitations within the Adequacy Decision the court stated - drawing on C‑293/12 and C‑594/12 - that they must apply only in so far as is strictly necessary, which is not the case where legislation generally authorises storage of all the personal data transferred from the EU to the US without any differentiation, limitation or exception. In particular, the court found that legislation permitting the public authorities' access on a generalised basis to the content of electronic communications compromises the essence of the fundamental right to respect for private life, as guaranteed by Article 7 CFR. Likewise, the court held, that legislation not providing for an individual to pursue legal remedies to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 CFR. Consequently, the court held that in including such derogations within its decision the Commission could not state that the US ‘ensures’ an adequate level of protection. Thus the court invalidated Article 1 of the Adequacy Decision, declaring the level of protection in the US adequate. Additionally, the court found, that Article 25(6) of Directive 95/46 does not empower the Commission to eliminate or restrict the powers of the DPAs, thus Article 3 of the Adequacy Decision in restricting the DPAs to act where a data subject calls into question whether an Adequacy Decision is compatible with the protection of the privacy and of the fundamental rights and freedoms of individuals was exceeding the Commissions powers. Therefore the court invalidated Article 3 of the decision. In conclusion, the court held, that as Article 1 and 3 of the decision are inseperably linked it invalidates the decision as a whole.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/6121 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=6121*

“although not requiring a third country to ensure a level of protection identical to that guaranteed in the EU legal order, the term ‘adequate level of protection’ must […] be understood as requiring the third country in fact to ensure, by reason of its domestic law or its international commitments, a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union by virtue of the regulation, read in the light of the Charter.

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6146 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6146*

Safe harbour: US public authorities are not required to comply with safe harbor principles. Decision 2000/520 specifies that safe harbor principles may be limited to the extent necessary to meet national security, public interest or law enforcement requirements, or statute, regulation or caselaw. Self-certified US organizations receiving personal data from the EU are thus bound to disregard safe harbor principles when they conflict with US legal requirements. Decision 2000/520 does not contain s

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6145*

Necessity/proportionality: The Decision does not contain any finding regarding US rules intended to limit the interference when they pursue legitimate objectives such as national security, nor refer to effective legal protection against such interference. FTC procedures and private dispute resolution mechanisms concern compliance with safe harbor principles (against US organizations) and cannot be applied with respect to measures originating from the State. Moreover, the Commission found that if

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/5945 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311*

“the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation” / “The exercise of that responsibility is of particular importance where personal data is tra

## Guidance

### Statement 01/2022 on the announcement of an agreement in principle on a new Trans-Atlantic Data Privacy Framework

*Source: EDPB, statement-012022-on-the-announcement-of-an-agreement-in-principle-on-a-new-en, 2022-04-06 — https://overview.legal/posts/125955 — original: https://www.edpb.europa.eu/documents/statement/statement-012022-on-the-announcement-of-an-agreement-in-principle-on-a-new_en*

1 Adopted Statement 01/2022 on the announcement of an agreement in principle on a new Trans - Atlantic Data Privacy Framework Adopted on 6 April 2022 The European Data Protection Board has adopted the following statement: The EDPB welcomes the announcement of a political agreement in principle between the European Commission and the United States on 25 March on a new Trans - Atlantic Data Privacy Framework. This announcement is made at a time where transf ers from the E uropean Economic Area to…

### EDPB Report on the first review of the European Commission Implementing Decision on the adequate protection of personal data under the EU-US Data Privacy Framework

*Source: EDPB, edpb-report-on-the-first-review-of-the-european-commission-en, 2024-11-04 — https://overview.legal/posts/125708 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-report-on-the-first-review-of-the-european-commission_en*

Adopted EDPB Report on the first review of the European Commission Implementing Decision on the adequate protection of personal data under the EU - US Data Privacy Framework Version 1.1 Adopted on 4 November 2024 Adopted 2 Version 1.1 14 November 2024 Minor correction Version 1.0 4 November 2024 Adoption of the report Adopted 3 Adopted 4 EXECUTIVE SUMMARY On 10 July 2023, the European Commission adopted its adequacy decision for the EU - U.S. Data Privacy Framework . Article 3 of the adequacy…

### Information Note on the Data Privacy Framework redress mechanism for national security purposes

*Source: EDPB, information-note-on-the-data-privacy-framework-redress-mechanism-for-en, 2024-04-24 — https://overview.legal/posts/125754 — original: https://www.edpb.europa.eu/documents/other-guidance/information-note-on-the-data-privacy-framework-redress-mechanism-for_en*

1 Information Note on the redress mechanism for EU/EEA individuals in relation to alleged violations of U.S. law with respect to their data collected by U.S authorities competent for national security 2 Context about complaints on government access by U.S. intelligence authorities On 10 July 2023, the European Commission adopted its Implementing Decision C(2023) 4745 on the adequate level of protection of personal data under the EU-U.S. Data Privacy Framework ( ‘DPF Adequacy decision ’ ) 1 . An…

### Information note on data transfers under the GDPR to the United States after the adoption of the adequacy decision on 10 July 2023

*Source: EDPB, information-note-on-data-transfers-under-the-gdpr-to-the-united-states-en, 2023-07-18 — https://overview.legal/posts/125835 — original: https://www.edpb.europa.eu/documents/other-guidance/information-note-on-data-transfers-under-the-gdpr-to-the-united-states_en*

1 Adopted Information note on data transfers under the GDPR to the United States after the adoption of the adequacy decision on 10 July 2023 On 10 July 2023, the European Commission (‘the Commission’) adopted its Implementing Decision of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework (‘the Adequacy Decision’) 1 , which contains in its annex the EU-US Data…

### EU - U.S. Privacy Shield - Third Annual Joint Review report – 12/11/2019

*Source: EDPB, eu-us-privacy-shield-third-annual-joint-review-report-en, 2019-11-12 — https://overview.legal/posts/126199 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/eu-us-privacy-shield-third-annual-joint-review-report_en*

1 Adopted EU - U.S. Privacy Shield - Third Annual Joint Review Adopted on 12 November 2019 2 Adopted 4 Adopted The European Data Protection Board Having regard to Article 4 and Recitals 145 to 149 of the Commis sion Implementing Decision (EU) 2016/1250 of 12 July 2016 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the pro tection provided by the EU - U.S. Pri vacy Shield (“EU - U.S. Privacy Shield), HAS ADOPTED THE FOLL OWING REPORT: 1 EXECUTIVE…

### EU - U.S. Privacy Shield - Second Annual Joint Review report – 22/01/2019

*Source: EDPB, eu-us-privacy-shield-second-annual-joint-review-report-en, 2019-01-22 — https://overview.legal/posts/126256 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/eu-us-privacy-shield-second-annual-joint-review-report_en*

1 Adopted EU - U.S. Privacy Shield - Second Annual Joint Review Adopted on 22 January 2019 2 Adopted 4 Adopted The European Data Protection Board Having regard to Article 4 and Recitals 145 to 149 of the Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the EU - U.S. Privacy Shield (“EU - U.S. Privacy Shield), HAS ADOPTED THE FOLLOWING REPORT : 1 EXECUTIVE…

### EU-US Data Privacy Framework FAQ for European businesses

*Source: EDPB, eu-us-data-privacy-framework-faq-for-european-businesses-en, 2024-07-16 — https://overview.legal/posts/125734 — original: https://www.edpb.europa.eu/documents/other-guidance/eu-us-data-privacy-framework-faq-for-european-businesses_en*

Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN BUSINESSES 1 Adopted on 16 July 2024 1 In this context, European businesses refer to businesses in the EEA, which transfer or may transfer personal data to companies in the U.S. certified under the DPF. Adopted 2 Adopted 3 Q1. WHAT IS THE EU - U.S . DATA PRIVACY F RAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. Companies that have self - certified under the DPF must…

### EU-US Data Privacy Framework FAQ for European individuals

*Source: EDPB, eu-us-data-privacy-framework-faq-for-european-individuals-en, 2024-07-16 — https://overview.legal/posts/125730 — original: https://www.edpb.europa.eu/documents/other-guidance/eu-us-data-privacy-framework-faq-for-european-individuals_en*

Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN INDIVIDUALS 1 Adopted on 16 July 2024 1 In this context, European individuals means any natural person, regardless of their nationality, whose personal data have been transferred to a U . S . company under the EU - U . S . Data Privacy Framework . A dopted 2 A dopted 3 Q1. WHAT IS THE EU - U.S. DATA PRIVACY FRAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. The…

## Enforcement decisions

### EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft

*Source: EDPS, 2024-03-08 — https://overview.legal/posts/125645 — original: https://gdprhub.eu/index.php?title=EDPS_-_2021-0518*

Facts — Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA. The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by Microsoft include identity and contact data of users (when signing on to the service and when checking the licenses), data generated by the users while using the software and data generated by Microsoft based on the usage of the software. The EDPS found that the processing presents significant risks as it monitors the behaviour of users, combines datasets and uses artificial intelligence. Reference date is the 12th May 2021, the date when the investigation was launched. Some measures were taken meanwhile by the Commission, which were taken into account in the recommendations issued. Holding — The EDPS found infringements with regards to purpose limitation, transfers to a third country and further, unathorised disclosure of personal data. Purpose limitation: The EDPS found that it was not sufficiently defined in the International License Agreement (ILA) which types of personal data are to be processed for which purposes. Instead, there was only a list of purposes stating that Microsoft uses these data for: troubleshooting billing remunerating Microsoft staff, internal reporting and business modelling, financial reporting following the use of the system for own reasons (analytics) to improve the service security risk management protection of intellectual property These stated purposes were considered to be too vague and general pursuant to the Art 29 WP. The Commission and Microsoft could not demonstrate that all these data were necessary and that a less intrusive collection of data would be insufficient to achieve the purposes cited. In addition, some of these purposes were actually not in the interest of the Commission but for purposes of individual to Microsoft (like remuneration of their personnel). In this case, the processor acts as controller; thus, these purposes and the data used for this purposes should have been precisely defined. Also, if data were used for purposes other than for which they were collected, the compatibility of these new purposes with the original ones should have been assessed. As a processor, Microsoft should have processed the personal data on documented instructions by the Commission. This was not ensured as the Commission did not issue sufficiently clear documented instructions to Microsoft. For example, though the Commission gave instructions for analytics and improvement of the service, these instructions were not sufficiently detailed and precise and did not exclusively concern uses of data for the purposes of the controller. Some instructions were given orally, but this was not enabled by the ILA and the oral instructions were not documented. The Commission did not assess whether it is necessary and proportionate to transmit data to Microsoft Ireland and its sub-processors. Further details of this infringement are given under the part on further unauthorised disclosure or personal data. Transfer to third countries : The Commission transferred personal data to Microsoft, a company established in the US. This raises questions about adequacy for such transfers to a third country. After the reference date, the Commission adopted the Transatlantic Data Privacy Framework (TDPF), which is an adequacy decision in respect of recipients in the US who register under this framework. The EDPS found that even when the software and data storage is property of Microsoft, it is directly transferred to these subcontractors and cannot therefore be covered by the TDPF to Microsoft US and onward transfer from Microsoft US to other subcontractors under SCCs. The EDPS found that in was not clearly specified in the ILA what types of personal data can be transferred to which recipients in which third country. The Commission also did not appraise the transfers and therefore could not determine whether any supplementary measures are necessary. In addition, the Commission should have performed a data transfer impact assessment and (as there are no SCCs applicable by EUIs as exporters) should have submitted the DPAs with these processors or subprocessors in third countries to the EDPS for approval. Because it failed to do this, the Commission did not implement effective supplementary measures for these transfers. Another issue was that the “EU storage guarantee” offered by Microsoft did not cover all types of data. Some data may be accessible to recipients in third countries. The “EU Data Boundary” also has numerous exceptions and exclusions which cover customer data, service generated data, diagnostic data and professional services data. Further unauthorised disclosure or personal data: A specific reference was made to Article 9 Regulation (EU) 2018/1725, which concerns transmission of personal data by EU institutions to recipients established in the EU. According to the EDPS, this article is also applicable to transmission of personal data to processors of EUIs. Therefore all transmission of personal data should be in the public interest and if the data subject’s legitimate interests may be prejudiced, the controller has to weigh the competing interests and establish that it is proportionate to transmit the personal data. The purpose of management and functioning of the Commission, use of products the staff is familiar with etc. was not found to be the purpose of processing of the personal data by MS. As long as the purposes are not specified, specific and explicit, it is not possible to do this balancing. In addition, the EDPS found that the Commission did not ensure that transfers take place “solely to allow tasks within the competence of the controller to be carried out”. The EDPS determined that organisational and contractual measures to restrict/prevent access of third country authorities were not sufficient, and that further technical measures are thus necessary. The EDPS also found that the organisational measures applied are only limiting transfers but does not ensure that transfers are protected. Further, the encryption is only found to be an adequate measure if the controller is in control of the encryption key. In this case, customers control the keys, but Microsoft has access to the encryption key, and thus, even when law does not oblige it to decrypt the data on an authority request, it may do it voluntarily. Also, the ILA does not detail encryption of data other than “customer data”, i.e. diagnostic data, service generated data or professional services data. The contract also enabled the processor not to notify the Commission about a request of disclosure also when EU or Member State law did not prohibit this notification and enabled recipients in third countries not to notify requests for disclosure also when the law prohibiting it did not constitute a necessary and proportionate measure in a democratic society respecting the essence of the fundamental rights and freedoms recognised by the Charter.

### Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Sweden, 2023-06-30 — https://overview.legal/posts/48052 — original: https://www.enforcementtracker.com/ETid-1937*

The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment, stating that the company was unlawfully transferring personal data to the US. The company had used Google Analytics for visitor statistics and based the data processing by the statistics tool on the EU standard contractual clauses, as no adequacy decision had been issued by the EU Com

### CDON AB: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Sweden, 2023-06-30 — https://overview.legal/posts/48053 — original: https://www.enforcementtracker.com/ETid-1938*

The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the Schrems II judgment, stating that the company was unlawfully transferring personal data to the US. The company had used Google Analytics for visitor statistics and based the data processing by the statistics tool on the EU standard contractual clauses in the absence of an EU Commission adequacy decision for the USA. In the c

### Portuguese National Statistical Institute: Non-compliance with general data processing principles

*Source: Portuguese Data Protection Authority (CNPD), 2022-11-02 — https://overview.legal/posts/47639 — original: https://www.enforcementtracker.com/ETid-1524*

The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in Portugal. The DPA first found that the controller had failed to inform the data subjects that the provision of religious and health data was purely voluntary. The DPA considered this to be an interference with the data subjects' ability to freely express their will regarding data processing. In addition, the DPA found that

### NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations

*Source: NAIH (Hungary), 2026-05-12 — https://overview.legal/posts/184727 — original: https://gdprhub.eu/index.php?title=NAIH_(Hungary)_-_NAIH-450-7-2026*

Facts — The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding — The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.

### Meta Platforms Ireland Limited: Insufficient legal basis for data processing

*Source: Data Protection Authority of Ireland, 2023-05-12 — https://overview.legal/posts/47959 — original: https://www.enforcementtracker.com/ETid-1844*

The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had violated Art. 46 GDPR by continuing to transfer personal data to the U.S. after the Schrems II ruling of the CJEU. According to the Schrems II ruling, U.S. law does not provide a level of protection for personal data substantially equivalent to that provided by EU law and that the standard contractual clauses (SCCs) al

### Belgian DPA rules on competence in cross-border cookie consent complaint involving

*Source: APD/GBA (Belgium), 2022-01-21 — https://overview.legal/posts/122841 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_11/2022*

Facts — The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they can control which non-essential (e.g. for advertising purposes) cookies they accept or refuse. If they choose to turn off interest-based advertising, they still see advertisements on the internet, but these are not adapted to their suspected interests or preferences. The Belgian DPA received a complaint via the Internal Market Information (IMI) system from the Berlin DPA regarding the illegitimate use of cookies on a website. More specifically, the complainant stated that (i) the tool for selecting advertising preferences did not work (cookie opt-out option for third parties does not work) and that consent was therefore not freely given; (ii) the website forced users to accept cookies in order to be able to select their advertising preferences. Holding — On cross-border processing - competence of the Belgian DPA The DPA first had to determine whether it was competent. According to Article 56 GDPR "the supervisory authority of the main establishment[...] of the controller shall be competent to at as lead supervisory authority for cross-border processing[...]". The Belgian DPA was found to be competent because the defendant had its sole place of business in Belgium, although its activities were deemed to substantially affect or be likely to affect data subjects in several Member States, including Germany. Obligation to set cookies in order to select advertising preferences on the website & "Cookie wall" practice (violation of Article 7 GDPR) - Complaint not upheld Second, the DPA had to determine whether the operator of the website lawfully placed a cookie on the complainant's device. The complainant argued that their consent was not freely given because they could not have used the website without giving it. Indeed, in its recent guidelines, the EDPB condemned the practice of making the provision of a service or access to a website conditional on accepting the placement of non-necessary cookies on the user's device. However, in this case the cookie in question was strictly necessary for the functioning of the website. The respondent indeed showed that the fact that the cookie needed to be placed in order to use certain parts of the website (namely the homepage / terms and conditions / Protecting your privacy-page) and thus the legal basis in order to process this personal data and place this cookie was not consent, but legitimate interest of the data controller (Article 6(1)(f) GDPR) Use of cookies without prior information given to the user (violation of the transparency principle - Article 5 GDPR) - Complaint upheld Third, the DPA assessed whether it was lawful to place the aforementioned cookie without providing certain information about such processing. The DPA restated that the purpose of the transparency principle is that the data subject should be able to determine what the scope and consequences of the processing encompass before it occurs. Thus, controllers are required to at least provide information on (i) the duration of the operation of cookies and (ii) whether the cookie is a first or third party one. When viewing the website, the DPA's investigation showed that even before any information could be delivered to the user, a cookie was loaded in the browser because it was otherwise technically impossible to display the necessary information in the user's language. The DPA held that due to the absence of language selection by the user, it would have been appropriate to display the information regarding the use of cookies in English, a widespread language commonly used by other websites. Thus, the Belgian DPA issued a reprimand to the operator of 'YourOnlineChoices.com' for violating Article 12 GDPR and Article 13 GDPR and ordered them to comply with their processing register - specifically to mention the third party countries personal data was sent to. Additionally, the Belgian DPA also shares some interesting insights regarding the processing of cookies: definition of 'trackers'; different types of cookies; valid consent under GDPR and ePrivacy Directive - transparency obligations

### EDPS - 2020-1013

*Source: EDPS, 2022-01-05 — https://overview.legal/posts/122849 — original: https://gdprhub.eu/index.php?title=EDPS_-_2020-1013*

Facts — In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The issues raised were: confusing and unclear cookie banners, vague and unclear data protection notices, and the illegal transfer of data to the US. Holding — On data controllership — According to the EDPS, the processor may enjoy a considerable degree of autonomy in providing its services and may identify the ‘non-essential’ elements of the processing operation. Furthermore, the processor may advise or propose certain measures in this respect, but it is up to the controller to decide whether to accept such advice or proposals. The analysis of the EDPS shows that the European Parliament (EP) delegated some aspects on the setting up and functioning of the website to Ecolog. The EDPS considers the EP acts as the sole data controller for the processing in question (i.e. the operation of the Parliament’s dedicated website) whereas Ecolog acts as a processor. After having assessed the instructions given by the EP to the processor, the EDPS concluded that the EP did not show the necessary diligence required from a data controller and, ultimately, failed to comply with the Regulation on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data 2018/1725 (hereafter Regulation 2018/1725), in particular with Articles 26(1) and 29(1). Moreover, the EDPS considered that the EP failed to provide the necessary detailed instructions to Ecolog for the setting up of the website, including the drafting of the data protection notice. The absence of documented instructions is therefore in violation of Article 29(3) Regulation 2018/1725. Transparency and information requirements — The EDPS confirmed that the data protection notice published at the time of the complaint did not reflect the processing done by the EP, since it merely consisted of a copy of the testing center of Zaventem's airport. Moreover, the reference made in the document to Article 6(1)(f) GDPR was wrong since it stems from the same error. The EDPS confirmed that the EP did not meet its transparency requirements. The EDPS also analysed the updated version of the data protection notice during the procedure and raised several remaining -and even new- inconsistencies and issues. Among other things, the following problems persisted after the data protection notice was updated: a mere reference to Article 15 and 16 Regulation 2018/1725 is misleading as it should apply in its entirety; the reference to the processing of health data is not correct since no such data are processed in the case at hand; the retention period mentioned is not precise enough; the sections of the data protection notices relating to the recipients of the personal data fail to make any reference to the processor; inconsistencies between the different linguistic versions of the data protection notices were still observed: The English and German versions refer to Ecolog and the Laboratory van Poucke as processors under Article 29 Regulation 2018/1725, whereas the French version refers to them as controllers (‘responsables du traitement’). Moreover, the DPO’s contact details on the website refer to Ecolog in all three linguistic versions of the website, when they should be referring to the Parliament Cookies and transfers of personal data to the US — The EDPS confirmed that tracking cookies, such as the Stripe and the Google analytics cookies, are considered personal data, even if the traditional identity parameters of the tracked users are unknown or have been deleted by the tracker after collection. In the same vein, the EDPS rejected the EP's argument and confirmed that upon installation on a device, a cookie cannot be considered ‘inactive’. Every time a user visited Ecolog’s website, personal data was transferred to Stripe through the Stripe cookie, which contained an identifier. The EDPS reached the conclusion that a transfer of data was taking place to the US, via the use of Google and Stripe cookies, since Google Analytics is hosted in the US and the data protection notice referred to a Standard Contractual Clause (SCC) for the transfer of data outside of the EU. However, the Parliament provided no documentation, evidence or other information regarding the contractual, technical or organisational measures in place to ensure an essentially equivalent level of protection to the personal data transferred to the US in the context of the use of cookies on the website. Cookie banner on the Parliament’s dedicated website — The EDPS reminded that: before setting cookies or any other technology falling within the scope of Article 5(3) ePrivacy Directive 2002/58/EC (hereafter ePrivacy Directive), the EU institution must provide the user with adequate information on what is accessed or stored on the user’s terminal equipment, on the purposes of this action and the means for expressing their consent; no action may be performed before the consent is collected. In addition, users must be enabled to withdraw their consent at any time; ‘cookie walls’ are not in line with Regulation 2018/1725, meaning that for consent to be freely given, access to the website’s service and functionalities should not depend on the users’ consent for cookies that are not strictly necessary in the sense described above; in case personal data collected through the cookies are shared with third parties such as analytics partners, the cookie banner should draw the user's attention to it. The EDPS reached the conclusion that the cookie banners in all three languages were not in line with the definition of consent under Article 3(15) Regulation 2018/1725, nor did they meet the requirements of Article 37 Regulation 2018/1725 and Article 5(3) ePrivacy Directive. The cookie banner further failed to provide transparent information regarding the processing of personal data in relation to the cookies on the website. Request for access to personal data — The Parliament was aware that the complainants’ personal data had been processed through the cookies, which were present on the website for the period between 30 September to 4 November 2020, since transfers of personal data had taken place. Consequently, and especially following the EDPS’ inquiry on the matter, the Parliament should have replied to the complainants’ access to personal data request. The Parliament should have provided the relevant information even if it was aware that the processing of the personal data in question was unlawful, as the main purpose of the right of access under Article 15 GDPR is precisely to enable data subjects to become aware of the processing and verify the lawfulness thereof, or exercise other data subject rights. Conclusion — The EDPS concludes that the Parliament has infringed the following articles of Regulation 2018/1725: Articles 26(1) and 29(1) due to its failure to fulfil its responsibilities as controller and use a processor providing sufficient guarantees to implement appropriate technical and organisational measures; Article 29(3) due to its failure to provide documentation relating to the detailed instructions given to the processor for the setting up and functioning of the website; Articles 4(1)(a) and 14, 4(2), and 15 due to its failure to respect the principle of transparency, accountability and the data subjects’ right to information because of the inaccurate data protection notice and cookie banner on the dedicated website; Article 46 and Article 48(2)(b) of the Regulation, due to its reliance on the Standard Contractual Clauses in the absence of a demonstration that data subjects’ personal data transferred to the US were provided an essential equivalent level of protection; Article 37 read in the light of Article 5(3) of the ePrivacy Directive, due to its failure to protect information (the cookies) transmitted to, stored in, related to, processed by and collected from the users’ terminal equipment; Articles 17 and 14(4) due to its failure to reply to the data subjects’ request for access to their personal data. On the basis of the above, the EDPS decides: to issue a reprimand to the Parliament in accordance with Article 58(2)(b) Regulation 2018/1725 for the above infringements; to order the Parliament, pursuant to Article 58(2)(b) Regulation 2018/1725:, to update its data protection notices in the dedicated website in order to provide all relevant information relating to the processing of personal data. The Parliament should address this order within one month from the date of the decision.

## Recent developments

### US Supreme Court just blew up EU-US Data Transfers

*Source: noyb - European Center for Digital Rights, 2026-06-29 — https://overview.legal/posts/53122 — original: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers*

Data Transfers On Monday, the US Supreme Court decided in Trump v. Slaughter that the US Federal Trade Commission (“FTC”) may not be independent anymore. Since 2000, the EU has relied on the “independent” FTC as the enforcer of EU-US deals on personal data. According to EU treaty law, such oversight must be independent. In the current EU-US deal, the European Commission relies on the independent FTC 259 (!) times. Max Schrems: “Given that there are no independent authorities in the US anymore, w

### EU-US Data Transfers: Time to prepare for more trouble to come

*Source: noyb - European Center for Digital Rights, 2025-12-10 — https://overview.legal/posts/49177 — original: https://noyb.eu/en/eu-us-data-transfers-time-prepare-more-trouble-come*

Data Transfers Most EU-US data transfers are based on the “Transatlantic Data Privacy Framework” (TAFPF) or so-called “Standard Contract Clauses” (SCCs). Both instruments rely on fragile US laws, non-binding regulations and case law that is under attack – and is likely blown up in the next months. As instability in the US legal system becomes undeniable and the US shows open signs of hostility towards the EU, it is time to reconsider where our data is flowing – and how long the legal “house of c

### EU-US Data Transfers: First Reaction on "Latombe" Case

*Source: noyb - European Center for Digital Rights, 2025-09-03 — https://overview.legal/posts/53141 — original: https://noyb.eu/en/eu-us-data-transfers-first-reaction-latombe-case*

Data Transfers Press Release by the General CourtBackground. Philippe Latombe, a French member of parliament, brought an action for annulment of the EU-US data transfer agreement (Transatlantic Data Protection Framework) before the General Court (the First Instance among the EU Courts). The CJEU (the second instance within the EU Courts) had previously ruled in “Schrems I” and “Schrems II” that the two prior agreements were illegal. Both were anulled. The new deal is structured almost identicall

### US Cloud soon illegal? Trump punches first hole in EU-US Data Deal

*Source: noyb - European Center for Digital Rights, 2025-01-23 — https://overview.legal/posts/53165 — original: https://noyb.eu/en/us-cloud-soon-illegal-trump-punches-first-hole-eu-us-data-deal*

Data Transfers Since the Snowden disclosures we know that the US engages in mass surveillance of EU users by scooping up personal data from US Big Tech. The "Privacy and Civil Liberties Oversight Board" (PCLOB) is the key US oversight authority for these laws. US media now reports, that Democratic members of the PCLOB got removed and their email accounts shut down. This brings the number of appointed Members below the threshold to have the PCLOB operate. The fact that the US President simply rem

### Austrian DSB: Meta Tracking Tools Illegal

*Source: noyb - European Center for Digital Rights, 2023-03-16 — https://overview.legal/posts/53248 — original: https://noyb.eu/en/austrian-dsb-meta-tracking-tools-illegal*

Data Transfers Austrian DSB: Meta Tracking Tools Illegal In a groundbreaking decision in one of noybs 101 complaints, the Austrian Data Protection Authority (DSB) has decided that the use of Facebook’s tracking pixel directly violates the GDPR and the so-called “Schrems II” decision on transatlantic data flows. In 2020, the Court of Justice (CJEU) decided that the use of US providers violates the GDPR, as US surveillance laws require US companies, like Facebook, to provide user’s personal inform

## Literature

### A Commercial Ceasefire: Why the EU-US Data Privacy Framework Cannot Survive Schrems III

*Source: Zenodo (CERN European Organization for Nuclear Research), 2026-07-01 — https://overview.legal/posts/53821 — original: https://doi.org/10.5281/zenodo.21094258*

The adequacy mechanism under GDPR Article 45 is structurally incapable of delivering legal certainty across divergent constitutional orders without a binding international treaty. Despite representing the most sophisticated transatlantic data transfer arrangement to date, the EU-US Data Privacy Framework remains a 'commercial ceasefire' built on executive discretion rather than structural reform and is likely to face invalidation in a future 'Schrems III'before the CJEU Grand Chamber. The paper

### Regulatory border effects in digital trade: Estimating the GDPR’s asymmetric impact on EU enterprises’ cross-border e-commerce through a triple difference-in-differences design

*Source: International Review of Economics & Finance, 2026-07-10 — https://overview.legal/posts/132114 — original: https://doi.org/10.1016/j.iref.2026.105587*

The General Data Protection Regulation (Regulation (EU) 2016/679; GDPR) created a structural asymmetry between intra-EEA and extra-EEA digital transactions, since Articles 44 to 49 imposed compliance burdens on transfers to third countries that have no analogue within the European Economic Area. This paper introduces and operationalises the regulatory border effect (RBE), the wedge between intra-EU and extra-EEA digital sales attributable to the differential cost structure of GDPR Chapter V, and

### Implications of GDPR and EU Adequacy Decision for Regulation of Profiling and Automated Decision-making in Korea

*Source: Chungnam Law Review, 2022-11-30 — https://overview.legal/posts/132602 — original: https://doi.org/10.33982/clr.2022.11.30.4.189*

### Unprotected Processing by Default vs Data Protection by Design and by Default Under the GDPR for Schrems II and GDPR

*Source: SSRN Electronic Journal, 2022-01-01 — https://overview.legal/posts/132477 — original: https://doi.org/10.2139/ssrn.4018408*

### International personal data transfer: An analysis of Brazil’s legal system and new LGPD under the adequacy standard of the EU GDPR

*Source: Journal of Data Protection Privacy, 2021-06-01 — https://overview.legal/posts/132549 — original: https://doi.org/10.69554/msqx9692*

The international transfer of personal data is an issue of fundamental importance in data protection. The General Data Protection Regulation (GDPR) has conditioned all data flow to third countries to stringent alternative requirements, the most important of which being the existence of an adequacy decision made by the European Commission finding the level of data protection afforded by that third country to be equivalent to the one provided by the GDPR. This study aims to apply the adequacy stan

## Tools

### European Commission adequacy decisions

*Source: European Commission, 2026-07-17 — https://overview.legal/posts/125629 — original: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en*

The authoritative list of third countries the European Commission has recognised as providing adequate protection under Article 45 GDPR (and its LED equivalent), with links to each adequacy decision and its review status — the first stop for any transfer analysis.

### Data Privacy Framework program — participant list

*Source: US Department of Commerce, 2026-07-17 — https://overview.legal/posts/125630 — original: https://www.dataprivacyframework.gov/list*

The official searchable list of US organisations self-certified under the EU-US Data Privacy Framework (the adequacy basis for EU→US transfers since 2023). Checking a recipient's active DPF status is the required first step before relying on the framework.

### ICO transfer risk assessment (TRA) tool

*Source: ICO, 2026-07-17 — https://overview.legal/posts/125622 — original: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/transfer-risk-assessments/*

The UK regulator's transfer risk assessment guidance and template — the post-Schrems II supplementary assessment for restricted transfers, offered as an alternative to the EDPB's six-step approach. Useful comparative material for Article 46 transfer assessments.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **International Transfer** — https://overview.legal/topics/internationale-doorgifte
  Transfer of personal data outside the EU/EEA
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/privacy-shield · 2026-08-22
