Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

CJEU Issues Mixed Ruling for Schrems’ Class Action Against Facebook

By Philip N. Yannella & Taylor R. Steinbacher on January 29, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

The lawsuit by Austrian lawyer and serial plaintiff, Max Schrems, against Facebook suffered a setback in a ruling by the Court of Justice of the European Union (CJEU) last week. Schrems sought to bring class action-type claims on behalf of 25,000 participants worldwide in his home country of Austria, alleging that Facebook violated European Union privacy law when it assisted the United States National Security Agency’s PRISM surveillance program. Specifically, Schrems alleged that there is no adequate level of protection of European citizens’ Facebook data when it is transferred to the United States, because it could be accessed by US authorities without individualized suspicion. According to Schrems, Facebook’s collaboration with US authorities violated the Austrian data protection law of 2000, the Irish Data Protection Act of 1998, and Directive 95/46/EC of the European Parliament.

In a blow to Schrems, Europe’s highest court held that Schrems could not bring his action on behalf of the other 25,000 participants, who each sought damages of 500 euros per person. The court held that European Union law only allowed a consumer who is party to the contract to assert claims related to that contract and that courts lack jurisdiction to hear claims of other persons, whether they are located in that consumer’s country or are from elsewhere.

The ruling was not all bad for Schrems, however, as the CJEU held that he could continue to pursue the case as an individual in his home country of Austria and was not required to bring his suit in Ireland, the location of Facebook’s non-US headquarters.

Schrems is well-known for prosecuting a lawsuit that ultimately led the CJEU to hold in 2015 that the EU-US Safe Harbor framework for data transfers was inadequate and therefore invalid. The invalidation by the CJEU of this framework spurred the creation of the EU-U.S. Privacy Shield currently in effect. Schrems is also a party to another blockbuster lawsuit involving Facebook regarding the propriety of standard contractual clauses used by companies to enable data transfers between the US and the EU (Schrems II). That case is also currently pending before the CJEU after the Irish Data Protection Commissioner referred the case to the high court in October 2017. Insofar as nearly 88% of companies transferring data from the EU to US rely on standard contractual clauses, the CJEU’s decision in Schrems II could be momentous.

Philip N. Yannella

yannellap@ballardspahr.com | 215.864.8180 | view full bio

As Practice Leader of Ballard Spahr’s Privacy and Data Security Group, and Practice Leader of the firm’s E-Discovery and Data Management Group, Philip N. Yannella provides clients with 360-degree advice on the transfer, storage, and use…

yannellap@ballardspahr.com | 215.864.8180 | view full bio

As Practice Leader of Ballard Spahr’s Privacy and Data Security Group, and Practice Leader of the firm’s E-Discovery and Data Management Group, Philip N. Yannella provides clients with 360-degree advice on the transfer, storage, and use of digital information.

Phil regularly advises clients on the Stored Communications Act (SCA), Computer Fraud and Abuse Act (CFAA), EU-US Privacy Shield, General Data Protection Regulation (GDPR), Defense of Trade Secrets Act, PCI-DSS, Telephone Consumer Protection Act (TCPA), New York Department of Financial Services Cybersecurity Regulations, ISO 27001 compliance, HIPAA Security Rules, and FTC enforcement activity, as well as eDiscovery issues—leveraging his experience serving as National Discovery Counsel for more than two dozen companies in nationwide litigation. He harnesses his deep knowledge of privacy, data security, and information governance laws to help multinational companies develop global information governance programs to comply with overlapping, and sometimes conflicting, laws. Phil serves on the advisory board for the ACC Foundation’s Cybersecurity Survey, the largest survey of in-house counsel on cybersecurity issues.

Email
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    CyberAdviser
  • Organization:
    Ballard Spahr LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo