The long-awaited decision by the European Court of Justice (ECJ) on the EU-U.S. Privacy Shield has turned out as expected: The EU-U.S. Privacy Shield agreement does not provide an adequate level of data protection. We have been advising in this direction since the EU-U.S. Privacy Shield was established and have advised our clients against basing their data processing on the EU-U.S. Privacy Shield.
Background
The GDPR considers a uniform level of data protection to be guaranteed only within the EU. If personal data is to leave the EU—for example, because the cloud service being used is hosted on U.S. servers—a level of data protection corresponding to EU GDPR standards must be ensured there.
Under the GDPR, the European Commission has the authority to determine whether the legal framework of another country meets these standards. However, the Court of Justice of the European Union (CJEU) has the authority to review this adequacy decision.
EU-U.S. Privacy Shield
The EU concluded the EU-U.S. Privacy Shield Agreement with the United States, and the European Commission had determined that if U.S. companies complied with the terms of this agreement, data could be processed in the United States. U.S. companies were required to register specifically for this purpose.
No further contractual agreements between the U.S. company and the EU company were required. The system was therefore particularly easy to administer.
From the outset, there was criticism that the EU-U.S. Privacy Shield Agreement did not effectively protect data from access by U.S. authorities, that there were insufficient legal remedies, and that, in general, the agreement was far too complex, meaning that EU citizens could not, in practice, obtain legal protection in the United States. This criticism built on the predecessor to the EU-U.S. Privacy Shield Agreement, the Safe Harbor Agreement between the EU and the U.S., which had already been declared invalid by the CJEU several years earlier.
CJEU Ruling
In its judgment of July 16, 2020, the CJEU has now addressed these criticisms. The full reasoning behind the judgment has not yet been made public, but the press release already provides insight into the key grounds for the decision.
The CJEU bases its criticism primarily on the fact that U.S. laws governing surveillance programs are not limited to what is strictly necessary. They therefore do not meet the EU’s standards of proportionality. The relevant U.S. regulations concerning certain surveillance programs do not in any way indicate that the authorization contained therein to carry out these programs is subject to restrictions or that they include safeguards for EU data.
The Court adds that even where the regulations contain requirements, they do not confer on the data subjects any rights that could be enforced in court against the U.S. authorities. The ombudsman mechanism provided for in the EU-U.S. Privacy Shield does not provide data subjects in the United States with a legal remedy through which they could enforce safeguards equivalent to those in the EU. There is a lack of both guarantees regarding the ombudsman’s independence and U.S. mechanisms that would allow the ombudsman to issue binding decisions against U.S. intelligence agencies.
The adequacy decision regarding the EU-U.S. Privacy Shield was therefore declared invalid. Consequently, the EU-U.S. Privacy Shield cannot serve as a legal basis for the transfer of data from the EU to the U.S. No transition period has been granted, meaning that such data transfers without a sufficient legal basis must cease immediately, unless another legal basis can be found.
What happens next?
The CJEU also had to rule on the so-called standard contractual clauses.
The EU had begun publishing model contracts years ago. These models provide for written contracts between EU companies and non-EU companies regarding the non-EU company’s data processing. The contracts may only be filled in at certain points but may not otherwise be amended, and they are quite lengthy. Through the standard contractual clauses, the EU company instructs the non-EU company to carry out data processing in a specific manner, thereby ensuring that the European level of data protection is maintained even when data is processed outside the EU.
The adequacy of the level of data protection achieved through the Standard Contractual Clauses has been endorsed by the European Court of Justice. Many companies that have their data processed in the United States will now want to rely on this.
However,
The CJEU has also emphasized that the Standard Contractual Clauses must be taken seriously. The clauses stipulate that EU and non-EU companies must verify in advance whether the required level of protection is maintained in the third country in question, and that the recipient must, if necessary, notify the EU company if it cannot comply with the standard contractual clauses, whereupon the data exporter must suspend the data transfer and/or withdraw from the contract with the recipient.
It seems questionable how, in light of U.S. legislation—with its insufficiently restricted intelligence agency powers, which led to the invalidity of the EU-U.S. Privacy Shield—the companies involved can determine that an adequate level of protection exists in the United States.
Thus, the only options left to justify data processing in the United States are likely those provided under Article 49 of the GDPR, as long as the United States of America does not amend its data protection laws.
Addendum
The ruling is now available.
Addendum 2:
In the years following the ruling, the EU has initiated a new agreement with the U.S. This is now called the EU–U.S. Data Privacy Framework (DPF). This legal framework has been controversial since its entry into force and has been increasingly unstable since June 2026, as the U.S. Supreme Court issued a ruling that can be interpreted to mean that the President must always retain executive oversight. The fully independent supervisory authority provided for by the DPF could thus be missing as a cornerstone of the DPF.
The statements represent initial information that was current for the law applicable in Germany at the time of initial publication. The legal situation may have changed since then. Furthermore, the information provided cannot replace individual advice on a specific matter. Please contact us for this purpose.