LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:courts:cjeu_schrems2

This is an old revision of the document!


Court of Justice of the European Union, Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems ("Schrems II")

Draft – editorial review pending. As of 27 September 2026.

Type Judgment (preliminary ruling, Grand Chamber)
Adopted by Court of Justice of the European Union
Adopted 16 July 2020
Legal status Final judgment, ECLI:EU:C:2020:559; binding interpretation of EU law
Official text CURIA
Subject area Data and surveillance

Overview

On a reference from the Irish High Court, the Court of Justice examined transfers of personal data from the EU to the United States under the General Data Protection Regulation (GDPR). It declared invalid Commission Implementing Decision (EU) 2016/1250 on the adequacy of the EU-US Privacy Shield, and held Commission Decision 2010/87/EU on standard contractual clauses to be valid, subject to case-by-case verification by data exporters and oversight by supervisory authorities. The judgment assessed the limits of foreign-intelligence surveillance under the EU Charter of Fundamental Rights. It is referred to in debates on State surveillance, transatlantic data flows and digital sovereignty.

Provisions relevant to the cyber and information sphere

  • Arts. 7, 8, 47 and 52(1) of the Charter – The Court assessed US surveillance programmes (based on Section 702 FISA and Executive Order 12333) against the rights to privacy and data protection, the right to an effective remedy and the requirement of proportionality.
  • Art. 45 GDPR – Adequacy requires a level of protection “essentially equivalent” to that guaranteed in the EU; the Court found that the Privacy Shield did not meet this standard, as the surveillance programmes were not limited to what is strictly necessary and the Ombudsperson mechanism did not provide a remedy before a body offering guarantees equivalent to Art. 47 of the Charter.
  • Art. 46 GDPR – Transfers under standard contractual clauses require appropriate safeguards; exporters must suspend or end transfers where equivalent protection cannot be ensured, and supervisory authorities are required to suspend or prohibit such transfers in that case.
  • The Court held that the GDPR applies to transfers for commercial purposes even if the data may be processed by public authorities of the third country for national security purposes.

Application to cyber and information operations

The judgment concerns the compatibility of signals-intelligence access to transferred data with EU fundamental rights. Following the judgment, the United States issued Executive Order 14086 (7 October 2022) on safeguards for signals intelligence activities, and the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework on 10 July 2023. An action for annulment of that decision (Case T-553/23, Latombe v Commission) was dismissed by the General Court on 3 September 2025; an appeal was lodged on 31 October 2025 [to be verified: appeal case number and status].

Recent developments

  • 2023-07-10: Commission adequacy decision for the EU-US Data Privacy Framework.
  • 2025-09-03: General Court dismisses Case T-553/23 (Latombe v Commission).
  • 2025-10-31: Appeal lodged against the General Court judgment (Official Journal C/2025/6610) [to be verified].

Sources

Change log

  • 2026-09-27: Entry created (draft).
law/courts/cjeu_schrems2.1790536042.txt.gz · Last modified: by lfpo