6.1 Schrems Decisions and Transfer Requirements

Key Takeaways

  • GDPR Chapter V (Articles 44–50) requires an adequacy decision, an Article 46 appropriate safeguard, or a narrow Article 49 derogation before personal data leaves the EEA
  • Schrems I (C-362/14, 6 October 2015) invalidated the EU–U.S. Safe Harbor adequacy decision; it did not rewrite U.S. surveillance law
  • Schrems II (C-311/18, 16 July 2020) invalidated the EU–U.S. Privacy Shield adequacy decision and left Standard Contractual Clauses valid
  • After Schrems II, an exporter using SCCs or another Article 46 tool must complete a Transfer Impact Assessment and add supplementary measures if destination-country law undermines the clauses
  • A TIA examines the specific transfer, foreign law and practice (especially public-authority access), and whether data subjects have effective redress — not a generic SOC 2 stamp
Last updated: August 2026

Schrems Decisions and Transfer Requirements

Domain I.C asks a U.S. privacy professional to explain why personal data cannot simply ride a transatlantic circuit because a vendor is convenient. The General Data Protection Regulation (GDPR) treats a disclosure from the European Economic Area (EEA) to a third country as a restricted transfer. Chapter V (Articles 44–50) is the lock on that door. The Court of Justice of the European Union (CJEU) then decided, twice, that the European Commission's first two U.S. adequacy deals did not turn the key.

Why an EU-to-U.S. transfer needs a Chapter V mechanism

Article 44 states the principle: a transfer, including onward transfer, may take place only if the Chapter V conditions are met. Three lawful paths exist:

  1. Adequacy (Article 45) — the Commission has decided that the destination country, territory, or specified sector ensures an essentially equivalent level of protection. Transfers to an adequate destination do not need a separate contract tool for the Chapter V step.
  2. Appropriate safeguards (Article 46) — no adequacy, but the exporter uses Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), an approved code or certification, or another listed tool, and data subjects have enforceable rights and effective remedies.
  3. Derogations (Article 49) — narrow, case-specific exceptions (explicit consent after being informed of the risks, a contract with or in the interest of the data subject, important public-interest reasons, legal claims, vital interests, and a tightly limited compelling-legitimate-interest residual). Derogations are not a standing export program for a U.S. SaaS stack.

The United States is not the subject of a general Article 45 decision that covers every U.S. organization. The current EU-U.S. adequacy path — the EU-U.S. Data Privacy Framework (DPF), taught in the next section — covers only participating, self-certified organizations. Every other U.S. importer still needs an Article 46 tool or a true Article 49 derogation. "We have a privacy notice" and "the customer clicked accept" are not Chapter V mechanisms.

Chapter V pathWhen it works for a U.S. importerWhat it is not
Article 45 adequacyThe importer is on the DPF list (or another specified adequate sector, if one exists)A blanket blessing of all U.S. companies
Article 46 safeguardsSCCs, BCRs, or another listed tool, plus Schrems II homeworkA paper signature with no assessment of U.S. law
Article 49 derogationsA specific, usually occasional, transfer that fits a listed exceptionThe default architecture for ongoing HR, CRM, or cloud processing

Schrems I: Safe Harbor falls (2015)

Schrems I is Case C-362/14, Maximilian Schrems v Data Protection Commissioner, judgment of 6 October 2015. An Austrian Facebook user complained that EU personal data sent to the United States under the Safe Harbor scheme was exposed to U.S. intelligence collection. The CJEU invalidated Commission Decision 2000/520/EC, the Safe Harbor adequacy decision.

Two holdings still drive exam answers. First, an adequacy decision must reflect essential equivalence with EU fundamental rights, not a loose "adequate enough for commerce" slogan. Second, a national supervisory authority must be able to examine a complaint even when a Commission adequacy decision is in force; the Commission cannot silence that review. Safe Harbor died. U.S. surveillance statutes did not. Companies that had treated the Safe Harbor certification mark as a complete transfer theory had to move to another Chapter V path.

Schrems II: Privacy Shield falls; SCCs survive with homework (2020)

Schrems II is Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximilian Schrems, judgment of 16 July 2020. The CJEU invalidated Commission Implementing Decision (EU) 2016/1250 — the EU–U.S. Privacy Shield adequacy decision. The Court held that U.S. law, in particular section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333, did not contain sufficient limitations and that EU persons lacked effective judicial redress against intelligence access.

This is the exam's most-missed sentence: Schrems II did not invalidate SCCs. The then-current controller-to-processor clauses (Decision 2010/87) remained a valid Article 46 tool. What the Court added is the homework. The exporter — with the importer — must verify, in the specific circumstances of the transfer, whether the law and practice of the destination country prevent the importer from complying with the clauses. If public-authority access or the absence of redress would undermine the contractual protections, the parties must adopt supplementary measures. If no combination of clauses plus measures can achieve essentially equivalent protection, the transfer must not proceed.

The European Data Protection Board (EDPB) Recommendations 01/2020 (version 2.0, June 2021) translate that holding into an operational sequence: map the transfer; identify the Article 46 tool; assess the third country; identify and adopt supplementary measures; complete procedural steps; and re-evaluate. That documented exercise is the Transfer Impact Assessment (TIA) (also called a transfer-impact or data-transfer impact assessment). The term is not a defined GDPR article heading; it is the Schrems II due-diligence file.

What a TIA actually examines

A TIA is not a vendor security questionnaire with a European title. It asks whether this transfer of these data, in this format, to this importer, in this country, will still enjoy essentially equivalent protection after it leaves the EEA.

Examine at least:

  • The transfer itself. Categories of personal data (including special-category data), volume, format (identifiable, encrypted, pseudonymized), purposes, number of actors, and whether the importer will make onward transfers.
  • Foreign law and practice. Not the statute book in the abstract, but how public authorities can compel access to the imported data — for the United States, FISA 702, Executive Order 12333, and the Stored Communications Act / National Security Letter practice that actually reaches the importer's service.
  • Surveillance and access in practice. Does the importer provide electronic communications services that are realistic 702 selectors? Is the data at rest in the United States in a form intelligence services can read? EDPB guidance looks at both law on the books and practice.
  • Redress. Can the data subject obtain an effective remedy against unlawful access, or is there only a political Ombudsperson with no power to bind the intelligence community? Schrems II treated the Privacy Shield Ombudsperson as inadequate. The later DPF package answered that criticism with Executive Order 14086 and the Data Protection Review Court (DPRC) — facts for the next section, not a reason to skip a TIA for an uncertified importer.
  • Supplementary measures. Technical measures (end-to-end or robust encryption with keys remaining under EEA control, pseudonymization that the importer cannot reverse, split processing) are stronger than purely contractual promises to "challenge overbroad requests," because a U.S. company cannot contract out of a valid FISA directive. Organizational measures (access minimization, transparency reports, notice-and-challenge procedures) support the technical layer; they rarely replace it for bulk, readable HR or messaging data.

Scenario. An Irish controller sends identifiable EU employee performance files to an uncertified U.S. HR-cloud vendor under 2021 SCCs. The TIA cannot stop at "we signed Module 2." It must ask whether the vendor is the kind of electronic-communications or cloud provider U.S. authorities can compel, whether the files are stored in the clear in the United States, and whether any encryption key sits solely with the Irish exporter. If the files are readable in the United States and no supplementary measure closes that gap, Schrems II says the transfer does not go.

Exam traps

  • Do not say Schrems II invalidated SCCs. Privacy Shield fell; SCCs stayed and grew extra conditions.
  • Do not treat a U.S. privacy notice, a SOC 2 report, or "the employee consented in the handbook" as a Chapter V mechanism for ongoing EU-to-U.S. HR or customer transfers.
  • Do not confuse the DPF's later adequacy decision with a general finding that all U.S. law is adequate. Uncertified importers still need Article 46 plus a TIA.
  • Do not write a TIA that assesses only encryption marketing copy and never the destination country's access and redress regime.
Loading diagram...
Chapter V Paths After Schrems II
Test Your Knowledge

What did the Court of Justice of the European Union do to Standard Contractual Clauses in Schrems II (C-311/18)?

A
B
C
D
Test Your Knowledge

What must a Transfer Impact Assessment examine before an EEA exporter relies on Standard Contractual Clauses for a transfer to an uncertified U.S. importer?

A
B
C
D
Test Your Knowledge

Why does a routine EU-to-U.S. transfer of customer or employee personal data need a GDPR Chapter V mechanism?

A
B
C
D