[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLayeFpnBs3VfAoatGW9oVpX9ZDpNqHUL1SYUbtRx6Qc":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"9135b2ce-af81-46ec-a243-263b4d1c495e","CJEU - C-311\u002F18 - Facebook Ireland and Schrems","cjeu-c-311-18-facebook-ireland-and-schrems-2f7a32","Fixed categorisation ← Older revision Revision as of 07:42, 16 September 2026 Line 51: Line 51: ==Further Resources== ==Further Resources== ''Share blogs or news articles here!'' ''Share blogs or news articles here!'' [[index.php?title=Category:Featured decisions]] [[Category:Featured decisions]]","The Court of Justice of the European Union (CJEU) invalidated Commission Decision 2016\u002F1250, commonly known as the EU-US Privacy Shield. However, the court affirmed the validity of Standard Contractual Clauses (SCCs) for data transfers, provided they include effective mechanisms to ensure compliance with the GDPR's level of protection for EU citizens.","CJEU invalidates EU-US Privacy Shield, upholds SCCs with conditions.","Help CJEU - C-311\u002F18 - Facebook Ireland and Schrems: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:40, 17 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 editsm Tag: Visual edit← Older edit Latest revision as of 07:42, 16 September 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators567 editsm Line 51: Line 51: ==Further Resources====Further Resources== ''Share blogs or news articles here!''''Share blogs or news articles here!'' [[index.php?title=Category:Featured decisions]][[Category:Featured decisions]] Latest revision as of 07:42, 16 September 2026 CJEU - C-311\u002F18 Facebook Ireland and Schrems Court: CJEU Jurisdiction: European Union Relevant Law: Article 2(2) GDPR Article 45 GDPR Article 46 GDPR Article 58 GDPR 7 CFRDecision 2010\u002F87\u002FEUDecision (EU) 2016\u002F12508 CFR47 CFR Decided: 16.07.2020 Parties: Data Protection Commission Facebook Ireland Maximillian Schrems Case Number\u002FName: C-311\u002F18 Facebook Ireland and Schrems European Case Law Identifier: ECLI:EU:C:2020:559 Reference from: High Court (Ireland) Language: 24 EU Languages Original Source: AG OpinionJudgement Initial Contributor: Isabel Hahn The Court of Justice of the European Union (CJEU) invalidated Commission Decision 2016\u002F1250 (the EU-US Privacy Shield), but affirmed the validity of standard contractual clauses (SCCs), providing that they include effective mechanisms to ensure compliance in practice with the “essentially equivalent” level of protection guaranteed by the GDPR to EU citizens. Contents 1 English Summary 1.1 Facts 1.2 Dispute 1.3 Holding 2 Comment 3 Further Resources English Summary Facts Maximillian Schrems, an Austrian citizen, had been a Facebook user since 2008. As is the case with users residing in the European Union, some of the data belonging to Mr. Schrems had been transferred by Facebook Ireland to its servers belonging to Facebook Inc., located in the United States. In 2013, Mr. Schrems complained to the Irish Data Protection Commissioner (DPC) seeking to prohibit these transfers. When this complaint was rejected, he brought an action against the decision before the Irish High Court, which in turn referred a number of questions to the CJEU, the most prominent of which was whether the EU-US adequacy decision, the so-called “Safe Harbor\", was valid. In its judgment on October 6th 2015 (Case C-362\u002F14, “Schrems I”), the CJEU invalidated the Safe Harbor and stated that, in order to be \"adequate\", the level of data protection offered by the third country should be “essentially equivalent” to that being offered in the EU. As a result, the High Court annulled the decision rejecting Mr. Schrems’ complaint, and referred the case back to the DPC. In the remittal “judgment” before the DPC, Facebook Ireland explained that the invalidated adequacy decision was not relevant as a large part of personal data was transferred to Facebook Inc. pursuant to Standard Contractual Clauses (SCCs). On this basis, the DPC asked Mr. Schrems to reformulate his complaint. In his reformulated complaint lodged on December 1st 2015, Mr. Schrems alleged that US law required Facebook Inc. to disclose his personal data to certain United States authorities in the context of various monitoring programs (in particular, the FISA 702 and the Executive Order 12.333). In Mr Schrems’ view, these programs contravened different data protection principles as well as Article 7 CFR, Article 8 CFR, and Article 47 CFR. After investigating the allegations made by Mr. Schrems, the DPC argued that it could not adjudicate on them until the CJEU had examined the validity of the SCCs, and so it brought proceedings before the High Court. On May 4th 2018 the High Court made the reference for a (second) preliminary ruling to the CJEU. In its reference to the CJEU, the High Court specified that Section 702 of the FISA permitted the Attorney General and the Director of National Intelligence to authorize jointly, following FISA approval, the surveillance of individuals who are not US citizens and who are located outside of the US in order to obtain foreign intelligence information. It was also affirmed that Section 702 of the FISA provided the basis for the PRISM and UPSTREAM surveillance programs. PRISM in particular, requires Internet Service Providers (ISPs) to supply the NSA with all communications to and from a ‘selector’. UPSTREAM on the other hand, permitted the NSA to copy and filter Internet traffic flows from the ‘backbone’ of the internet, granting it access to both the content of communications and their metadata. Furthermore, the High Court had found that Executive Order 12.333 (E.O. 12333) allowed the NSA to access data in transit by accessing underwater cables on the floor of the Atlantic. The High Court stated that the only limit on US surveillance activities was found in the Presidential Policy Directive (PPD-28), and even this only stated that intelligence activities should be ‘tailored as feasible’. On the basis of these findings, the High Court considered that the US carried out mass processing of personal data without ensuring a level of protection that was essentially equivalent to that which was guaranteed by Article 7 CFR and Article 8 CFR. The High Court also highlighted that EU citizens did not have the same remedies available to them as US citizens with regards to the processing of their personal data, since the Fourth Amendment to the Constitution of the United States did not apply to non-US citizens. This meant that it was particularly difficult for EU citizens to establish standing before a US court. Moreover, activities based on E.O. 12333 were not subject to judicial oversight and were not justiciable. Given the considerable effects of US surveillance law on the rights of Europeans, the High Court raised the question of whether the SCCs are valid, given that they may not be binding on the State authority of the third country. If they did not bind the third country State authority, then they are not capable of remedying a possible lack of an adequate level of protection of personal data. Dispute The request for a preliminary ruling referred eleven questions to the Court of Justice. The topics covered in these questions were as follows: the applicability of EU law to data transfers made for commercial purposes, but further processed for national security and law enforcement purposes the relevant legislation for determining whether there has been a violation of individual rights how to assess the level of protection in a third country whether data transfers to the US violate the Charter whether the level of protection offered in the US respects or limits an individual’s right to a judicial remedy what level of protection is required to be afforded to personal data that is transferred under SCCs whether the SCCs can even be adequate as safeguards given they do not bind national authorities whether there is an obligation to suspend data flows if a data importer is subject to surveillance law what the relevance of the Privacy Shield decision is with regards to assessing safeguards whether the presence of an ombudsperson can ensure that the US provides an effective remedy to data subjects whether the SCCs violate the Charter Holding The Court began by clarifying that the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State, to another economic operator established in a third country, even if in that country the data would be processed by the national authorities for public security, defense, and state security purposes. In particular, the Court stressed that a transfer of data is not excluded from the scope of the GDPR for the reason that it may be processed by the national authorities of a third country. Regarding the level of protecti","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-311\u002F18_-_Facebook_Ireland_and_Schrems&diff=53080&oldid=52401","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F8\u002F87\u002FCjeulogo.png","2026-09-16T07:42:49+00:00","2026-09-16T08:00:14.726099+00:00",9,[18,21,24],{"name":19,"type":20},"Facebook","vendor",{"name":22,"type":23},"EU-US Privacy Shield","product",{"name":25,"type":23},"Standard Contractual Clauses","d95477d7-eb04-4fad-a2dc-be1428040ce7",{"id":26,"icon":28,"name":29,"slug":30},null,"Privacy Fines","privacy-fines",[32,37,42,47],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":38},{"id":39,"icon":28,"name":40,"slug":41},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":43},{"id":44,"icon":28,"name":45,"slug":46},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":48},{"id":26,"icon":28,"name":29,"slug":30},[]]