EU sovereignty

Schrems II and the Data Privacy Framework: Why Transatlantic Data Transfer Is Still on Shaky Ground

Three times in a decade Europe's top court has torn up the legal basis for sending personal data to the US. Here is what Schrems II and the 2023 EU-US Data Privacy Framework really mean for your tools, your compliance, and why EU-hosted, EU-controlled services are the stable choice.

When a European company stores customer data in a US-operated cloud, or uses an American SaaS tool, it is making a cross-border data transfer under the GDPR - and the legal ground beneath that transfer has moved three times in a decade. The Court of Justice of the European Union (CJEU) struck down the Safe Harbor agreement in 2015 (Schrems I) and the Privacy Shield in 2020 (Schrems II). Its successor, the EU-US Data Privacy Framework of 2023, is already being litigated. For businesses and public bodies this is not an abstract debate. It determines whether your everyday tools are lawful, how much documentation you owe a supervisory authority, and how exposed you are the next time a court rules. This article explains what happened, why the conflict is structural rather than a paperwork gap, and what to do about it.

The ruling that redrew the map

On 16 July 2020, in Case C-311/18, the CJEU invalidated the EU-US Privacy Shield with immediate effect. The case grew out of a long-running complaint by the Austrian lawyer and activist Max Schrems (and his organisation noyb) against Facebook's transfers of European data to the United States.

The Court's reasoning was blunt. US surveillance programmes - notably Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333 - allow access to transferred data that is not limited to what is strictly necessary and proportionate. EU data subjects had no effective judicial redress against that access, and the Privacy Shield Ombudsperson was neither independent of the executive nor able to issue binding decisions. In short, US law did not offer protection 'essentially equivalent' to the GDPR read together with the EU Charter of Fundamental Rights. Thousands of companies that had relied on Privacy Shield lost their legal basis overnight.

Why US law is the real sticking point

The problem is not sloppy contracts; it is a genuine clash of legal orders. FISA Section 702 can compel US electronic-communications providers to assist government surveillance. The CLOUD Act lets US authorities demand data held by US-controlled companies regardless of where the servers physically sit. That is why the popular fix - 'we use the provider's EU data centre' - does not by itself solve the problem: a US parent company can still be reached.

On the European side stand Articles 7, 8 and 47 of the Charter: respect for private life, protection of personal data, and the right to an effective remedy. As long as a US provider can be lawfully compelled to hand over readable data with no equivalent redress for Europeans, every transfer framework built on top of that reality is inherently fragile. This is the reason each successive arrangement keeps failing in court.

SCCs survived - but the burden shifted to you

Schrems II did not outlaw all transfers. The CJEU upheld Standard Contractual Clauses (SCCs) as a valid transfer tool, and the Commission issued modernised, modular SCCs in June 2021. But the Court added a crucial condition: you cannot simply sign them and move on.

Before relying on SCCs, an exporter must carry out a Transfer Impact Assessment - examining the destination country's law and the specific transfer - and add 'supplementary measures' wherever that law falls short. The European Data Protection Board published recommendations on exactly this in 2021. Measures include strong encryption where the provider holds no key, or pseudonymisation. The uncomfortable reality is that for many US transfers, no technical measure fully cures FISA 702 exposure if the provider must be able to produce plaintext. The paperwork burden is real - and so is the residual risk.

The Data Privacy Framework: the current bridge

On 10 July 2023 the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (Decision 2023/1795). It rests on US Executive Order 14086 of October 2022, which for the first time wrote the concepts of 'necessity and proportionality' into US signals-intelligence practice and created a two-layer redress mechanism: a Civil Liberties Protection Officer in the intelligence community, and a new Data Protection Review Court (DPRC).

Under the Framework, US companies self-certify with the Department of Commerce; transfers to a certified organisation need no SCCs. The same EO 14086 safeguards can also be cited in a Transfer Impact Assessment to support ongoing SCC-based transfers. In practice, the DPF gave European businesses breathing room after three uncertain years - but it is a bridge, not bedrock.

Why the bridge is shaky: Schrems III looming

The Framework is not a treaty ratified by parliaments. It is an adequacy decision built on a US executive order - and both can change. A future US president can revoke or amend EO 14086, and the Commission's decision can be challenged in court.

It already has been. French MP Philippe Latombe sought annulment; on 3 September 2025 the EU General Court dismissed his challenge and upheld the DPF - but only on the facts as they stood in 2023 - and he appealed to the CJEU in October 2025. Max Schrems and noyb have signalled a further challenge, widely dubbed 'Schrems III'. The political ground is moving too: in early 2025 the US administration removed members of the Privacy and Civil Liberties Oversight Board (PCLOB), stripping the very body meant to oversee the redress system of its quorum. Given the CJEU's track record of scepticism, many observers expect it to look hard at these developments.

What this means when you choose a service

Treat the current calm as conditional. A few concrete takeaways. First, map your transfers: know which tools send personal data to the US and on what legal basis. Second, do not treat DPF certification as permanent - verify the company is actually on the Data Privacy Framework list, and keep a fallback plan for the day the decision is challenged.

Third, for genuinely sensitive data - health records, public-sector data, employee and minors' data - the most defensible posture is to keep it in the EU with a provider not subject to US jurisdiction. Fourth, remember that data residency alone is not sovereignty: a US-owned provider with EU servers remains reachable under the CLOUD Act, so look at ownership and control, not just the data-centre map. Fifth, document your reasoning; supervisory authorities increasingly expect to see it.

European alternatives are real - and maturing fast

The reassuring part is that avoiding this whole risk category is no longer a compromise. The market and the public sector have responded. Gaia-X is building federated standards for a sovereign European cloud. openDesk, developed by Germany's Centre for Digital Sovereignty (ZenDiS), bundles open-source collaboration into a sovereign digital workplace already being watched in France, Italy and the Netherlands.

The clearest signal is Schleswig-Holstein, which is migrating roughly 30,000 public-sector workstations off Microsoft to LibreOffice, Open-Xchange and Thunderbird - and eventually Linux - reportedly saving over 15 million euros a year while moving more than 40,000 accounts and over 100 million emails. Denmark's digital ministry is following a similar path. Regulatory tailwinds - the Data Act, NIS2, the DSA and DMA, and the debated EUCS cloud-certification scheme with its sovereignty tiers - all push in the same direction. The legal ground under transatlantic transfers will keep shifting. Choosing EU-hosted, EU-controlled services is how you stop rebuilding on it.

Ready to become more independent?

Explore European alternatives to the services you use every day.

Explore alternatives