Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Privacy Shield Invalidated: EU Data Transfers to the U.S. under Siege (again…)

By Jeffrey L. Poston, Frederik Van Remoortel, Jarno Vanto & Lee Matheson CIPP/US, CIPP/E, CIPP/A, CIPM on July 17, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

At 9:30 a.m. Central European Time, privacy professionals around the world were refreshing their browsers to read the long-awaited judgment of the Court of Justice of the European Union (CJEU) principally addressing the viability of Standard Contractual Clauses (SCCs) and the EU-U.S. Privacy Shield (Privacy Shield) as means to transfer personal data from the European Union (EU) to the United States (U.S.).

When the judgment arrived, it landed with a bang: though the CJEU upheld the use of SCCs, it invalidated the Privacy Shield, the well-known mechanism to transfer personal data from the EU to the U.S.  The decision also cast doubt on the viability of other options, including SCCs, for making transatlantic transfers.

The foundation of this decision and previous decisions affirming challenges to U.S. privacy practices is that the protection of personal data is a fundamental right in the EU, akin to a constitutional right in the U.S.  The General Data Protection Regulation (GDPR) enshrined these fundamental rights and established uniform data protection standards across the EU designed to protect the personal data of EU-based individuals.

Protecting these fundamental rights when data is transferred abroad falls to the European Commission (EC). The EC can decide that certain countries provide an “adequate” level of protection for personal data thereby permitting the transfer of personal data to those countries.

In 2000, the EC put in place an adequacy mechanism known as the “Safe Harbour” for personal data transfers to the U.S. It was invalidated by the CJEU in 2015 (Schrems I, case C‑362/14) due in large part to U.S. surveillance practices that arose in the wake of 9/11. It was replaced in 2016 by the Privacy Shield, which aimed to address the concerns that the CJEU outlined in its Schrems I judgment.

The CJEU has now also invalidated the Privacy Shield (Schrems II, case C-311/18) based on ongoing concerns regarding certain U.S. surveillance programs and their effect on the guaranteed privacy rights of EU-based individuals under the GDPR.

The CJEU came to this conclusion despite the fact that the U.S. “[…] participated actively in the case with the aim of providing the court with a full understanding of U.S. national security data access laws and practices and how such measures meet, and in most cases exceed, the rules governing such access in foreign jurisdictions, including in Europe,” as underlined in today’s statement of U.S. Secretary of Commerce Wilbur Ross.

The Court also looked at SCCs for processors, a mechanism that was created by the EC to facilitate international data transfer from the EU to non-EU vendors. While the CJEU did not invalidate this mechanism, it did underline that it is up to the exporting and importing organizations to verify that the legal system of the country where the recipient organization resides provides sufficient safeguards.

The Court’s decision places EU transferring companies and recipient U.S. companies in a bind. U.S. companies can no longer rely on the Privacy Shield to receive data from the EU. While the CJEU upheld the legality of the SSCs, it now leaves it up to each EU exporting company to make its own decision regarding the integrity of U.S. privacy practices before deciding whether to transfer EU data to a U.S. company. And given that the CJEU has itself now invalidated the Privacy Shield based on its finding that the privacy practices of the U.S. government are deficient, an EU company contemplating entering into SCCs with a U.S. company will be faced with a difficult decision.

The Irish Data Protection Commission, the authority that passed this case to the CJEU, raises similar concerns in its statement: “[…] it is clear that, in practice, the application of the SCCs transfer mechanism to transfers of personal data to the United States is now questionable.” It adds that the issue “will require further and careful examination, not least because assessments will need to be made on a case by case basis.”

Today’s judgment is expected to significantly disrupt cross-Atlantic personal data transfers and the business models that rely on them in the short term. It remains to be seen what position European data protection authorities will take with regard to companies that rely on existing Privacy Shield certifications. A pragmatic approach with a de facto grace period (which, for the avoidance of doubt, is not foreseen in the CJEU’s judgement), at least until there is a solid data transfer solution, seems to make the most sense.

Until these issues are resolved, affected businesses would likely benefit from ensuring that all data transfers and the corresponding data transfer mechanisms are duly mapped. Organizations relying on Privacy Shield certifications should also consider implementing other data transfer mechanisms such as SCCs while they remain an option or assessing whether derogations such as consent or contractual necessity can be relied upon.

Binding Corporate Rules that are approved by EU data protection authorities, may provide another solution to affected businesses recognizing that they can be used only for companies of the same corporate group or companies engaged in a joint economic activity.

Photo of Jeffrey L. Poston Jeffrey L. Poston

Jeff Poston is a partner in Crowell & Moring’s Washington, D.C. office, where he serves as co-chair of the firm’s Chambers USA-ranked Privacy & Cybersecurity Group and is a member of the Litigation Group. A seasoned trial lawyer with more than 25 years…

Jeff Poston is a partner in Crowell & Moring’s Washington, D.C. office, where he serves as co-chair of the firm’s Chambers USA-ranked Privacy & Cybersecurity Group and is a member of the Litigation Group. A seasoned trial lawyer with more than 25 years of experience leading investigations and litigation for corporate clients, Jeff counsels and defends clients in complex data protection matters involving class-actions and regulatory enforcement actions, as well as commercial disputes. Jeff also counsels businesses on both domestic and international privacy compliance matters, including the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

Read more about Jeffrey L. PostonEmail
Show more Show less
Photo of Frederik Van Remoortel Frederik Van Remoortel
Read more about Frederik Van RemoortelEmail
Photo of Jarno Vanto Jarno Vanto

Jarno Vanto (CIPP/E, CIPP/US) is a partner in the Privacy & Cybersecurity Group in Crowell & Moring’s New York office. With an extensive understanding of the complex international regulatory environment and cross-industry technologies, he provides a differentiated global perspective to clients on personal…

Jarno Vanto (CIPP/E, CIPP/US) is a partner in the Privacy & Cybersecurity Group in Crowell & Moring’s New York office. With an extensive understanding of the complex international regulatory environment and cross-industry technologies, he provides a differentiated global perspective to clients on personal information privacy, cybersecurity, technology transactions, and corporate matters.

With a keen understanding of client risk level and risk tolerance, he partners with clients to help them achieve their business goals and provides a range of legal services, including privacy and cybersecurity compliance counseling, complex cross-border and domestic technology and data transactions, data and software licensing, other technology and data transfer agreements, as well as regulatory investigations involving personal information.

Read more about Jarno VantoEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Retail & Consumer Products Law Observer
  • Organization:
    Crowell & Moring LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo