The EU-US Privacy Shield declared invalid by the Court of Justice

News type
Legal news

On 16 July 2020, the Court of Justice of the European Union issued its long-awaited judgment (C-311/18) regarding data transfers to third countries (also referred to as the “Schrems II case”).

The transfer of personal data to countries outside the European Economic Area (so-called “third countries”) is only permitted when specific conditions are met. Articles 45 to 49 of the GDPR include multiple instruments to ensure that data transfers to third countries comply with EU data protection standards, such as adequacy decisions adopted by the European Commission. With the EU-US Privacy Shield Decision (and previously, the Safe Harbour Decision), the European Commission decided that the United States, as the data importer, ensured an adequate level of protection to the personal data transferred. However, after having already annulled the Safe Harbour decision (the “Schrems I case”), the Court of Justice has now also annulled the Commission’s Privacy Shield Decision with immediate effect in this recent judgment.

The Court of Justice annulled the Privacy Shield Decision after reviewing the nature and scope of specific US surveillance programmes. The Court concluded that the limitations on the protection of personal data arising from the domestic law of the United States on the access and use by US public authorities of data transferred from the EU to the US are not circumscribed in a way that satisfies EU data protection standards. Also, as regards the requirement of judicial protection, the Court holds that the Ombudsperson mechanism referred to in the Privacy Shield Decision does not provide any cause of action before a body which offers the persons whose data is transferred guarantees that are essentially equivalent to those required by EU law. The Privacy Shield therefore insufficiently addressed the Court’s previous concerns that led to the Schrems I decision.

On the question of maintaining the effects of the Privacy Shield Decision, the Court of Justice decided not to provide a transitional period. According to the Court, the annulment of the Privacy Shield is “not liable to create […] a legal vacuum”. The Court of Justice referred to Article 49 of the GDPR providing specific derogations such as the data subject’s consent or necessity for the performance of the contract. The question is, however, whether those legal bases - which should be interpreted restrictively - may apply to massive data transfers such as those previously undertaken on the basis of the Privacy Shield.

The Court of Justice also had to decide on the validity of Standard Contractual Clauses or “SCCs”, an instrument created by the European Commission to facilitate data transfers from EU controllers to non-EU controllers and processors. The Court of Justice ruled that SCCs can be a valid way to transfer personal data to third countries but do not automatically ensure an adequate level of protection. The EU controller and the recipient are required to verify, prior to any transfer and on a case-by-case basis, whether the level of protection required by EU law is respected in the third country and enables the recipient to comply with the SCCs. If this is not the case (which, in view of the Court’s decision on the Privacy Shield, it is likely not to be for transfers to the US), the controller should adopt additional measures to ensure an appropriate level of protection, or suspend or terminate the transfer of personal data. At present, however, there is only limited guidance about the nature of the additional measures that could be adopted to complete the SCCs.

It is clear that the Schrems II judgment has significant consequences for EU-US personal data transfers and impacts numerous businesses. Organisations should start reviewing and mapping out their international data transfer mechanisms and already implement alternative safeguards if data transfers are based on the Privacy Shield. However, that is easier said than done. The European Data Protection Board (EDPB) and the national supervisory authorities (including the Belgian Data Protection Authority) are currently assessing the Schrems II judgment in detail to provide further clarification to stakeholders as well as guidance on the use of adequate instruments for the transfer of personal data to third countries.

Please contact Karel Janssens for further information about this case and/or for general legal advice relating to privacy and data protection.

Practice areas