What is Schrems II?
EU ruling from 2020 that invalidated Privacy Shield. Affects all data transfers to the US. Address with SCC or DPF.
Schrems II is the name of a ruling from the Court of Justice of the European Union in 2020 that had major consequences for how data may be sent between Europe and the US. The case is named after Austrian lawyer Max Schrems, who brought the challenge. The core is simple to understand: the court found that US authorities can access Europeans' data in ways that are not compatible with GDPR.
The result was that the previous framework "Privacy Shield", which made it easy to move data to the US, was suddenly invalidated. Imagine a bridge between two countries unexpectedly closing — all traffic that went over it had to find a new route. In the same way, every business storing data with US cloud providers had to find new lawful solutions.
The most common routes today are so-called SCC (Standard Contractual Clauses — ready-made contract templates from the EU) or the newer DPF (Data Privacy Framework).
Why is Schrems II important for your business?
Very many businesses use US services without thinking about it — cloud storage, email, analytics tools. Schrems II means you need to know where your data actually ends up and that transfers to the US happen lawfully.
Miss this and you risk breaching GDPR, with fines and lost customer trust as a consequence. Handled correctly, it becomes a reassurance you can demonstrate.
Schrems II in practice
A business storing customer data with a US cloud provider must, after Schrems II, ensure the transfer rests on a valid basis — for example SCC or the provider being certified under DPF.
At ZORC, we help you map where your data is stored and set up solutions that hold up even after Schrems II.
Common questions about Schrems II
What does Schrems II mean?
Schrems II is an EU ruling from 2020 that invalidated Privacy Shield and tightened the rules for transferring personal data to the US. It is named after lawyer Max Schrems.
How does Schrems II affect my business?
If you use US cloud services or tools, you must ensure data transfers to the US happen lawfully — for example via SCC or DPF. Otherwise you risk breaching GDPR.
How do you address Schrems II?
The most common solutions are Standard Contractual Clauses (SCC) or the provider being certified under the EU-US Data Privacy Framework (DPF). Extra safeguards are often needed too.
Related terms
Consent Mode
Google's standard for passing consent to its services. Consent Mode v2 has been required since March 2024.
GDPR
The EU's data protection regulation. Governs how businesses may process personal data. Break it and fines can reach millions.
DPA
Data Processing Agreement. Required when someone else processes personal data on your behalf — e.g. cloud providers.
DPF
EU-US Data Privacy Framework. The replacement for Privacy Shield. Allows data transfers to certified US companies.
DPIA
Data Protection Impact Assessment. A required impact assessment for high-risk processing under GDPR Article 35.
IMY
Sweden's data protection authority — the regulator for GDPR. Handles complaints and can issue fines.