? Back to Blog

Schrems II implications (high level)

Brendan G · 2026-04-22

The Schrems II Ruling: Background and Key Findings

The Schrems II case, also known as Data Protection Commissioner v. Facebook Ireland Limited, was brought by the Irish Data Protection Commission (DPC) in response to the Facebook and Instagram data processing practices. The ECJ's ruling on July 16, 2020, declared the EU-US Privacy Shield framework invalid and emphasized the importance of companies taking responsibility for ensuring the protection of personal data transferred outside the EEA. The key findings of the Schrems II ruling include: * The EU-US Privacy Shield framework is invalid, and companies relying on this framework to transfer personal data from the EEA to the US must find alternative means. * The General Data Protection Regulation (GDPR) applies to data transfers outside the EEA, and companies must ensure that these transfers comply with GDPR requirements. * Companies are responsible for ensuring the protection of personal data transferred outside the EEA and must take steps to mitigate risks associated with these transfers.

Data Transfer Mechanisms Post-Schrems II

The Schrems II ruling has significant implications for data transfer mechanisms, particularly those relying on the EU-US Privacy Shield framework. In the absence of this framework, companies must explore alternative means for data transfers, such as: * Standard Contractual Clauses (SCCs): The EU has adopted new SCCs, which provide a standardized framework for data transfers between the EEA and third-party countries. Companies can rely on these SCCs to ensure compliance. * Binding Corporate Rules (BCRs): Companies can establish BCRs, which are binding agreements that set out the rules for data protection within a group of companies. * Ad-hoc transfers: Companies can make individual transfers of data, which must be carefully assessed to ensure compliance with GDPR requirements. When implementing SCCs, it's essential to note that the EU has introduced new SCCs in 2021, which provide a more robust framework for data transfers. These SCCs include additional requirements, such as: * **Onward transfers:** SCCs now require companies to implement additional safeguards for onward transfers of data to third-party countries. * **Data subject rights:** SCCs now require companies to implement additional procedures for data subject rights, such as the right to erasure. * **Audits and inspections:** SCCs now require companies to cooperate with audits and inspections by the European Data Protection Board (EDPB). When establishing BCRs, companies must ensure that these agreements meet the requirements of the GDPR and the EU Data Protection Directive. BCRs must include provisions for: * **Data protection principles:** BCRs must include principles for the protection of personal data, such as the principle of transparency. * **Data subject rights:** BCRs must include procedures for data subject rights, such as the right to erasure. * **Data protection officer (DPO):** BCRs must include provisions for the appointment of a DPO.

Challenges and Opportunities in the Post-Schrems II Era

The Schrems II ruling presents challenges for companies, particularly those relying on the EU-US Privacy Shield framework. However, it also creates opportunities for companies to enhance their data protection practices and ensure compliance with GDPR requirements. Some of the key challenges and opportunities include: * **Challenge:** Companies must find alternative means for data transfers, which can be time-consuming and resource-intensive. * **Opportunity:** Companies can take this opportunity to review and enhance their data protection practices, ensuring that they are better equipped to handle data transfers and protect personal data. * **Challenge:** Companies must ensure that data transfers comply with GDPR requirements, which can be complex and nuanced. * **Opportunity:** Companies can leverage this opportunity to develop more robust data protection measures, ensuring that they are better positioned to handle data transfers and protect personal data.

Steps to Ensure Compliance with the Schrems II Ruling

To ensure compliance with the Schrems II ruling, companies must take the following steps: * **Conduct a data transfer impact assessment (DTIA):** Companies must conduct a DTIA to identify and assess the risks associated with data transfers. * **Implement SCCs or BCRs:** Companies must implement SCCs or BCRs to ensure compliance with GDPR requirements. * **Develop a data protection policy:** Companies must develop a data protection policy that outlines the rules for data protection within the organization. * **Train staff:** Companies must train staff on data protection practices and ensure that they understand their roles and responsibilities. When conducting a DTIA, companies must consider factors such as: * **Data categories:** Companies must identify the categories of personal data being transferred. * **Recipient countries:** Companies must identify the countries to which the data is being transferred. * **Data processing activities:** Companies must identify the data processing activities being performed on the data. When implementing SCCs or BCRs, companies must ensure that these agreements meet the requirements of the GDPR and the EU Data Protection Directive. SCCs or BCRs must include provisions for: * **Data protection principles:** SCCs or BCRs must include principles for the protection of personal data, such as the principle of transparency. * **Data subject rights:** SCCs or BCRs must include procedures for data subject rights, such as the right to erasure. * **Data protection officer (DPO):** SCCs or BCRs must include provisions for the appointment of a DPO.

Conclusion

The Schrems II ruling has significant implications for companies transferring personal data from the EEA to the US and other third-party countries. By understanding the key takeaways and steps companies can take to ensure compliance, organizations can mitigate risks and ensure the protection of personal data.

Join the affiliate program and earn 50%. No approvals, no waitlists.