This is an old revision of the document!
Table of Contents
CJEU, Schrems II (2020)
As of 30 September 2026.
| Full title | Court of Justice of the European Union, Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (“Schrems II”) |
|---|---|
| Type | Judgment (preliminary ruling, Grand Chamber) |
| Adopted by | Court of Justice of the European Union |
| Adopted | 16 July 2020 |
| Legal status | Final judgment, ECLI:EU:C:2020:559; binding interpretation of EU law |
| Official text | CURIA |
| Subject area | Data and surveillance |
Overview
On a reference from the Irish High Court, the Court of Justice examined transfers of personal data from the EU to the United States under the General Data Protection Regulation (GDPR). It declared invalid Commission Implementing Decision (EU) 2016/1250 on the adequacy of the EU-US Privacy Shield, and held Commission Decision 2010/87/EU on standard contractual clauses to be valid, subject to case-by-case verification by data exporters and oversight by supervisory authorities. The judgment assessed the limits of foreign-intelligence surveillance under the EU Charter of Fundamental Rights. It is referred to in debates on State surveillance, transatlantic data flows and digital sovereignty.
Provisions relevant to the cyber and information sphere
- Arts. 7, 8, 47 and 52(1) of the Charter – The Court assessed US surveillance programmes (based on Section 702 FISA and Executive Order 12333) against the rights to privacy and data protection, the right to an effective remedy and the requirement of proportionality.
- Art. 45 GDPR – Adequacy requires a level of protection “essentially equivalent” to that guaranteed in the EU; the Court found that the Privacy Shield did not meet this standard, as the surveillance programmes were not limited to what is strictly necessary and the Ombudsperson mechanism did not provide a remedy before a body offering guarantees equivalent to Art. 47 of the Charter.
- Art. 46 GDPR – Transfers under standard contractual clauses require appropriate safeguards; exporters must suspend or end transfers where equivalent protection cannot be ensured, and supervisory authorities are required to suspend or prohibit such transfers in that case.
- The Court held that the GDPR applies to transfers for commercial purposes even if the data may be processed by public authorities of the third country for national security purposes.
Application to cyber and information operations
The judgment concerns the compatibility of signals-intelligence access to transferred data with EU fundamental rights. Following the judgment, the United States issued Executive Order 14086 (7 October 2022) on safeguards for signals intelligence activities, and the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework on 10 July 2023. An action for annulment of that decision (Case T-553/23, Latombe v Commission) was dismissed by the General Court on 3 September 2025; Mr Latombe lodged an appeal on 31 October 2025 (Case C-703/25 P, Latombe v Commission); no judgment on the appeal had been identified as of the date above.
Recent developments
- 2023-07-10: Commission adequacy decision for the EU-US Data Privacy Framework.
- 2025-09-03: General Court dismisses Case T-553/23 (Latombe v Commission).
- 2025-10-31: Appeal lodged against the General Court judgment, Case C-703/25 P (Official Journal C/2025/6610).
Related entries
Sources
- CURIA: Case C-311/18, accessed 2026-09-27
- CURIA: Case T-553/23 Latombe v Commission, accessed 2026-09-27
Change log
- 2026-09-27: Entry created (draft).
- 2026-09-30: Entry reviewed and finalised.
