Don’t do SECURITY. Do business SECURELY.

Schrems II: EU–US Privacy Shield invalidated

The CJEU has invalidated the EU–US Privacy Shield and set new expectations for Standard Contractual Clauses.

In its judgment in Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (C-311/18, “Schrems II”), the Court of Justice of the EU has today declared the EU–US Privacy Shield adequacy decision invalid, with immediate effect.

The Court upheld the validity of Standard Contractual Clauses (SCCs), but made clear that exporters must assess, case by case, whether the law of the destination country allows the importer to comply with them, and put supplementary measures in place where it does not.

What should you do?

  • Map all transfers of personal data to the US and other third countries.
  • Identify any that relied on Privacy Shield and move them to another transfer mechanism.
  • Carry out and document transfer impact assessments for transfers relying on SCCs.
  • Consider technical supplementary measures such as strong encryption with keys held outside the destination country.

The UK remains bound by EU data protection law during the Brexit transition period, so this ruling applies to UK exporters too.

Source: Case C-311/18 Schrems II judgment (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights