Historical and retrospective context. The original 19 February 2019 date is retained. The pending-case analysis and forecasts below describe 2019. On 16 July 2020 the Court invalidated Privacy Shield while upholding SCC validity subject to effective transfer safeguards. This is a later outcome, not a fact known on the original date.
Three and a half years after the Court of Justice struck down Safe Harbour, the same complainant, the same regulator and largely the same legal question are back before the same court. The case now working its way through Luxembourg as C-311/18, already universally known as Schrems II, asks whether standard contractual clauses provide adequate protection for personal data sent from the European Union to the United States. Whatever the Schrems II ruling eventually says, EU US data transfers are once again resting on an instrument whose validity is in front of a court. What makes this one different from the Safe Harbour case is the breadth of the exposure. Safe Harbour was a single mechanism used by a defined set of American companies. Standard contractual clauses are the default legal basis for transfers to every third country on earth, signed into tens of thousands of contracts by organisations that have never thought about surveillance law. If the clauses fall, or fall in part, the consequences are not confined to transatlantic traffic.
How the case got here, and what it actually asks
The procedural history is worth understanding because it explains why the outcome is hard to predict. The complainant did not set out to challenge the clauses. After the 2015 judgment, the complaint against a large social network's Irish establishment was reformulated to target transfers being made under contractual clauses instead. The Irish supervisory authority, rather than deciding the complaint, took the view that if the complaint had merit then the underlying Commission decisions approving the clauses were themselves in doubt, and only the Court of Justice can invalidate those. It went to the Irish High Court, which heard extensive evidence on United States surveillance law, made findings, and referred a long list of questions to Luxembourg in the middle of last year. The United States government, industry associations and privacy organisations have all intervened. A hearing is expected later this year, an Advocate General's opinion some months after that, and a judgment most likely in 2020. Pending litigation did not suspend existing processing or transfer obligations, and signing clauses did not make every transfer lawful. The substantive question is the one the court answered before in a different context. Do the protections available to a European data subject whose data sits in the United States, given surveillance authorities under national security law and the redress available to a non-citizen, meet the standard of essential equivalence that European law requires. Contractual clauses bind the two commercial parties. They do not bind a government, and that is the structural gap the case is about.
Why the clauses are harder to defend than they look
The defence of the clauses is essentially that they are not a guarantee of outcome but a framework with obligations, including a duty on the importer to tell the exporter if it cannot comply and a right for the exporter to suspend and terminate. The difficulty is that this machinery depends on knowing. An importer subject to a non-disclosure order cannot notify anyone, which means the clause that is supposed to protect the data subject cannot operate in precisely the circumstances that matter. A court that took that seriously in 2015 has no obvious reason to take it less seriously now, since the underlying American statutory position has not materially changed. There are outcomes short of outright invalidation. The court could uphold the clauses while making clear that exporters must assess the destination country's law and suspend transfers where the clauses cannot be honoured in practice, which would be an enormous operational burden rather than a legal cliff. It could confine itself to the questions about supervisory authority powers. It could also say something about the adequacy decision underpinning the current transatlantic framework, even though that decision is not formally the subject of the referral.
What breaks if the clauses go
The honest answer is that there is no adequate fallback at scale. Binding corporate rules work only for intra-group transfers, take a long time to approve and are not available to most organisations. Adequacy decisions cover a small number of countries. The derogations, consent, contractual necessity, important reasons of public interest, are explicitly for occasional and non-systematic transfers, and the guidance issued last year made clear that they cannot be used to underpin routine operational flows. An organisation running payroll, support, analytics or hosting across the Atlantic cannot solve the problem with a consent checkbox. Which means the realistic responses are architectural: keep the data in the region, hold the keys, or reduce what crosses. Those are slow and expensive, which is exactly why the preparation worth doing now is the cheap part of it.
Practical Guidance for a Schrems II Compliance Strategy
- Build the transfer inventory now. Every flow of personal data outside the European Economic Area, the mechanism relied on, the volume, the category of data and whether the flow is essential. This work is required by the record-keeping obligation anyway and is the prerequisite for any response.
- Identify the flows with no alternative. The ones where the recipient is the only viable provider, or where the data cannot be regionalised. Those are your genuine exposures; everything else is a project.
- Get an invalidation clause into new contracts. A right to require an alternative mechanism, a regional deployment or termination without penalty if the transfer basis becomes unlawful. Vendors sign this far more readily before a ruling than after one.
- Ask providers where regional deployment exists today. Not on the roadmap. Which services can run entirely within the European Union, at what price, and what functionality is lost.
- Separate the keys from the data wherever you can. Customer-held keys are not the only potentially relevant measure or an automatic answer. The EDPB's later guidance distinguishes strong encryption, qualifying pseudonymisation and processing that requires plaintext, each with specific conditions.
- Minimise what crosses. A surprising share of transatlantic flows are analytics, logs, telemetry and support access that could be reduced, pseudonymised or kept local with modest engineering effort.
- Do not tear anything up yet. The clauses are valid until a court says otherwise. Precipitate migration on the strength of a pending case is its own form of risk.
- Write the contingency down as a plan with owners and durations. Two pages. If the ruling lands badly, the difference between organisations will be whether somebody had already worked out what the first ninety days look like.
The Regional Angle
The reflex here is that this is a European argument about American companies. It is not, for two reasons that land directly on Gulf organisations. The first is contractual. The standard clauses are the instrument that regional service providers, back office centres, software firms and group entities sign when they receive personal data from European customers or European parents. If those clauses are invalidated or heavily qualified, the legal basis inside contracts you have already signed changes, and the remediation obligation flows down to you with a deadline set by somebody else's compliance department. Any regional business delivering services into Europe should know today which of its customer contracts contain the clauses, what the termination and suspension provisions say, and who is responsible for finding an alternative. That is a contract review, not a technology project, and it can be done this quarter. The second is more uncomfortable. The test the court is applying is not a test of the United States. It is a test of whether a third country provides protection essentially equivalent to European standards, including independent oversight of government access and effective redress for a European data subject. Apply that test here. That statement describes the historical 2019 discussion, not current law: later UAE and Saudi frameworks require their own current assessment. Telecommunications interception and lawful access powers sit with state authorities, and the avenue by which a European individual would seek redress against them is not obvious. On the court's own logic, a transfer to this region rests on the same fragile footing as a transfer to the United States, and its lawfulness cannot be inferred from an absence of litigation. That creates an opportunity as much as a risk. The financial free zones, the DIFC and ADGM, have their own data protection regimes with independent commissioners, and they are the only structures in the region with a plausible route to recognition in a European conversation. Groups with European data flows should be asking whether the entity receiving that data should sit inside one of those regimes rather than outside it, which is a corporate structuring question with a five-year horizon and a cost, and it is being asked far too rarely. There is also a timing point specific to the region. The announced Gulf cloud regions are not yet open, so an organisation that wanted to regionalise European data into a local facility today has limited options, and an organisation that wanted to keep European data in Europe usually can, cheaply. For the next year at least, the easier direction of travel is to leave European data in Europe rather than to pull it here, and roadmaps written this year should reflect that rather than the other way round.
The objection worth taking seriously
The objection is that we have seen this film. Safe Harbour was struck down, commerce did not stop, a replacement framework appeared within nine months, and the organisations that spent 2015 re-architecting looked foolish next to the ones that waited and signed new paperwork. Politics will not permit transatlantic data flows to be switched off, so the rational response to a pending case is to do nothing and keep the lawyers warm. The harder version of the objection accepts the risk but questions the response. Even if the clauses fall, the remedy will arrive with transition arrangements, regulators will be pragmatic, and the enforcement priority will be the very large platforms rather than a mid-sized business sending payroll data to a processor. Meanwhile regionalisation costs real money, loses functionality and concentrates risk in fewer providers. Spending that money on a hypothetical is difficult to defend to a board that has already funded a large compliance programme. Both arguments have force, and neither justifies doing nothing, because the preparation that matters is nearly free. A transfer inventory is already a legal requirement. A contract clause dealing with invalidation costs a negotiation, not a migration. Asking a provider where it can run in Europe is an email. Knowing which flows have no alternative is a day's work and is the only information that would let you respond quickly if the ruling is bad. The expensive decisions can and should wait for the judgment. The cheap ones should not, because their entire value is in having been made beforehand.
Common Questions
Are standard contractual clauses still valid?
The 2020 ruling upheld the SCC decision, but validity is not blanket transfer lawfulness. Assess destination law and effective safeguards; suspend or end the transfer where required protection cannot be ensured.
Does this affect transfers to countries other than the United States?
Potentially, and that is the underappreciated point. The clauses are used for every third country without an adequacy decision. A ruling that requires exporters to assess destination-country surveillance law would apply to India, the Philippines, the Gulf and everywhere else, not only to the United States.
Would moving to a European provider solve it?
It removes the transfer question and replaces it with different ones, including whether the provider is a subsidiary of a group subject to foreign disclosure laws, where support and administration are performed from, and whether the service is actually equivalent. Regionalisation is a real mitigation and not a complete one.
What should we expect over the next twelve months?
Expect a hearing in Luxembourg this year and an Advocate General's opinion towards the end of it, with a judgment most likely in 2020. Expect continued political pressure on the current transatlantic framework, including unresolved questions about the independent oversight role that the European Parliament has been complaining about. Expect major providers to accelerate European deployment options because they can read the same signals. And expect transfer questions to start appearing in ordinary commercial contracts rather than only in data protection annexes.
Schrems II Compliance Strategy — we inventory the transfers that would actually break, get invalidation language into your contracts while vendors will still sign it, and leave you with a ninety-day plan you hope not to use.
