Data Sovereignty / Source date:

Privacy Shield Invalidated (Schrems II, July 2020): The Day Data Transfers Broke

The July 2020 Schrems II ruling invalidated Privacy Shield with immediate effect — leaving thousands of organizations without a legal basis for EU-US data transfers and triggering a compliance emergency.

Illustration of payroll, cloud storage, support and backup cards being reassessed beside a transfer register and key-custody note.

Last Thursday the Court of Justice of the European Union struck down the EU-US Privacy Shield framework, with immediate effect and no transition period. If your organisation transfers personal data from Europe to the United States on the basis of a supplier's Privacy Shield certification, that transfer became unlawful on the sixteenth of July. There is no grace period, no wind-down window and no pending appeal. The judgment in Case C-311/18, already known everywhere as Schrems II, also did something more consequential and much less widely reported. It upheld standard contractual clauses, and in doing so it changed what signing them means. The paperwork is no longer the compliance step. It is the beginning of an assessment you are now required to perform yourself.

What the court actually decided

Three holdings matter, and they should be read narrowly rather than dramatically. First, the Commission's adequacy decision underpinning Privacy Shield is invalid. The court's reasoning centred on United States surveillance authorities, the absence of proportionality limits that European law requires, and the fact that the Ombudsperson mechanism did not give European data subjects an effective remedy before an independent body. This is substantially the same reasoning that ended Safe Harbor in 2015, addressed to a framework built specifically to answer it. Second, standard contractual clauses remain valid as a transfer mechanism. They survive because they are a contract between two private parties and do not depend on any assessment of the destination country's law. That is also their weakness, which the court spelled out: a contract cannot bind a public authority that is not party to it. Third, and this is the operative part, the exporter and the importer must verify, before transferring, whether the law of the destination country allows compliance with the clauses, taking account of the circumstances of the transfer. Where it does not, they must adopt supplementary measures capable of bringing protection up to the European standard, or not transfer. And supervisory authorities are obliged to suspend or prohibit transfers where those conditions are not met. That last obligation is the part organisations are underestimating. The exposure created by this judgment is not primarily a fine. It is an order to stop a data flow that your business depends on.

Why signing new clauses does not close the question

The instinct this week has been to chase paper: replace Privacy Shield references in vendor agreements with standard contractual clauses and consider the matter handled. That work is necessary and it is not sufficient, for a reason worth stating plainly. The problem the court identified is that certain United States surveillance authorities reach providers of electronic communications services regardless of what those providers have promised contractually. A clause obliging your processor to resist unlawful access does not remove it from the scope of a statute. So the honest position, four days after the judgment, is that a large number of transfers to major American service providers now rest on clauses whose central premise the court has publicly questioned. This does not make those transfers automatically unlawful. It makes them transfers that require an assessment and, in many cases, additional measures. The assessment is specific: which importer, under which authorities, holding what categories of data, accessible by whom, with what technical protections in place.

The four measures that change the analysis

Most supplementary measures being discussed this week are cosmetic. Four are not, and they are engineering decisions rather than legal ones. Hold the keys somewhere the importer cannot reach. Encryption is only a supplementary measure if the importer has no access to plaintext and no access to key material. If the service processes, indexes, searches or renders your data, it holds plaintext, and encryption at rest is a control against theft of a disk rather than against a lawful demand. Keep the identifiers at home. Pseudonymisation is genuinely powerful where the mapping table never leaves your jurisdiction and cannot be reconstructed by the importer. It is worthless where the dataset is re-identifiable from its own contents, which is usually true of anything containing an email address. Constrain the access path. Support access from the destination country, standing administrative privileges and remote session rights are transfers in themselves. Time-boxed, approved, logged, jurisdiction-restricted access materially changes the risk picture and is often achievable within weeks. Change where the data rests. Regional storage with local processing is now worth paying for, on the strict condition that you understand what remains global: telemetry, backups, identity directories, support tooling and the vendor's own analytics.

A technical control has a defined boundaryArticle-derived engineering questions, not a lawful-transfer finding. Legal adequacy needs qualified assessment.
ControlBoundary to test
Key custodyCan the importer obtain plaintext or key material?
PseudonymisationCan the remaining data or recipient reconstruct identity?
Restricted accessDo support, administrators and sub-processors still cross borders?
Regional deploymentWhere do processing, telemetry and backups actually occur?

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Practical Guidance for Post-Schrems II Compliance Planning

  • Find every transfer that relied on Privacy Shield this week. Search contracts and data protection addenda for the term. Each hit is a mechanism that no longer exists and needs replacing now, not at renewal.
  • Replace the mechanism first, then assess. Execute standard contractual clauses immediately so the transfer has a legal basis while you carry out the harder analysis.
  • Tier your transfers before assessing them. Volume, sensitivity, whether data subjects are employees or customers, whether special categories are involved. Most organisations have between five and fifteen transfers that genuinely warrant a full assessment.
  • Write the assessment down, with a date and an author. The judgment creates a documentation duty in substance. An undocumented assessment is indistinguishable from no assessment when a regulator asks.
  • Send your significant vendors a short, specific questionnaire. Are you subject to surveillance authorities applicable to electronic communications service providers, have you received orders, what is your challenge practice, where are your support staff located, and what regional processing options exist. Vague reassurance is not evidence.
  • Treat support access and sub-processors as first-class transfers. These are the flows organisations miss, and they are frequently the only place where data actually crosses a border in a way that matters.
  • Do not rely on consent or contractual-necessity derogations for routine flows. The narrow derogations in Chapter V exist for occasional, specific transfers. Building a payroll platform on them will not survive scrutiny.
  • Give the board a two-page honest summary. What is affected, what has been remediated, what remains exposed, and the realistic cost of the alternatives. The worst position is a board that learns about this from a customer.

The Regional Angle

Four consequences are specific to organisations operating from the Gulf, and only one of them is about Europe. The first is that the judgment's method will be turned on this region almost immediately. The test the court applied asks whether a destination country's law permits access by public authorities beyond what is necessary and proportionate, and whether foreign data subjects have an effective remedy before an independent body. Applied to most jurisdictions in the region, that analysis is uncomfortable, and it is now a question European counterparties are contractually obliged to ask. Gulf entities receiving personal data from Europe, including group companies receiving employee data from a European parent, should expect a transfer questionnaire within the next few months and should prepare a factual description of local access powers, lawful interception requirements and available redress. Nobody will be able to point to a published transparency record, so the description will have to be authored rather than cited. The second is that the regional regulatory picture changed this month too. The Dubai International Financial Centre enacted a new data protection law in June with effect from the first of July and an enforcement runway into the autumn, and its transfer provisions sit on top of, not instead of, the European question. An entity in one of the region's financial free zones can now be simultaneously an importer under European rules and an exporter under its own, for the same dataset, with two different sets of documentation to maintain. Consolidate that into one transfer register organised by jurisdiction rather than running parallel exercises. The third is a marketing risk. The new in-country cloud regions opened in the Gulf over the last two years will be positioned as the answer to this judgment, and they are not. They are an excellent answer to latency, to local supervisory expectations and to sector cloud frameworks. They do not change the fact that the operator is a United States company subject to United States legal process, which is the specific issue the court addressed. Local region plus local key custody plus restricted support paths is a serious proposition. Local region alone is a procurement story. The fourth is the flow nobody governs: human resources. Regional groups with a European parent or European subsidiaries move candidate data, employee records, performance information and payroll detail into Gulf-based shared services routinely, usually with no transfer mechanism at all because it feels internal. It is not internal in law, and it is the category most likely to be raised by a European works council or employee representative body, which is a faster route to a supervisory complaint than any customer contract. If you do one piece of work this quarter, it should be the intra-group agreement covering people data.

The objection worth taking seriously

The strongest criticism of this judgment is that it is legally coherent and operationally impossible. It requires private organisations, including small ones with no legal department, to evaluate the surveillance law of foreign states and to decide whether a superpower's intelligence framework meets European proportionality standards. That is not a judgement a mid-sized distributor in Sharjah or a software company in Tallinn can make. In practice the burden will be discharged by boilerplate produced by law firms and signed by people who have not read it, which protects nobody. The second objection is about distribution of harm. Large technology companies will build regional infrastructure, contractual frameworks and dedicated compliance teams; the outcome for them is cost. Smaller organisations, and non-European ones, will simply be excluded from flows they depend on, or will proceed in ignorance until somebody complains. Localisation achieved through litigation lands hardest on the least resourced, and it does so without any legislature having debated it. Both criticisms are sound, and neither changes what a responsible organisation should do in the next sixty days. The practical standard that will emerge is not perfection; it is proportionate, documented, honest assessment with visible remediation where risk is highest. The organisations that will struggle are not the ones whose analysis turns out to be imperfect. They are the ones with nothing written down, no idea where their data goes, and a contract that still cites a framework the court abolished last Thursday.

Common Questions

Can we keep using our American cloud provider?

In most cases yes, with standard contractual clauses in place, a documented assessment, and supplementary measures proportionate to the data involved. Whether that position is comfortable depends entirely on the sensitivity of what you are transferring.

Is there any grace period at all?

Not from the court. Privacy Shield ceased to be a valid basis on the day of the judgment. How supervisory authorities exercise enforcement discretion in the coming months is a separate question, and not one to build a plan on.

Does this affect transfers to countries other than the United States?

Yes. The assessment obligation applies to every transfer to a country without an adequacy decision, including the Gulf, India, and, depending on how the year ends, the United Kingdom.

What should we expect over the next twelve months?

Expect the European Data Protection Board to publish guidance on supplementary measures within weeks, and expect it to be stricter than industry hopes. Expect the Commission to accelerate its modernised standard contractual clauses, which were already in preparation, and expect a fresh contract-repapering exercise when they arrive. Expect complaints against named companies and their European customers rather than test cases in the abstract. And expect no third framework to appear quickly: two have now been annulled on the same reasoning, and nothing in United States surveillance law has changed to support a third.


Post-Schrems II Compliance Planning — we find the transfers that just lost their legal basis, tier the ones that need real assessment, and put the engineering measures in place that make the answer defensible.

Continue reading

Talk to OPS

Start with the operating problem.