Don’t do SECURITY. Do business SECURELY.

EU–US Safe Harbor invalidated by the Court of Justice

The CJEU has declared the EU–US Safe Harbor framework invalid, affecting transfers of personal data to the United States.

In a landmark ruling in the case brought by Maximillian Schrems (Case C-362/14), the Court of Justice of the European Union has today declared the European Commission’s Safe Harbor adequacy decision invalid.

Safe Harbor has been relied on by thousands of organisations to transfer personal data from the EU to self-certified US companies. The Court found that US law did not provide an essentially equivalent level of protection, particularly in relation to access by US public authorities.

What should you do now?

  • Identify all transfers of personal data to US organisations, including cloud services and suppliers.
  • Establish which relied on Safe Harbor.
  • Put alternative safeguards in place, such as EU Standard Contractual Clauses or Binding Corporate Rules.
  • Watch for guidance from the ICO and European regulators, and for a replacement framework.

Source: Case C-362/14 Schrems judgment (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights