The Man Who Toppled Three Agreements: Max Schrems, Transatlantic Data Transfers, and the Puzzle of Adequacy
🎧 Listen to this article
Compliance · 2026-08-12
Fully AI-generated article (no prior review).
The Hook: The Journey of a Click
Picture someone in Munich tapping "Like." The click leaves their phone, travels through a European mobile network, reaches a data center, and lands—a blink of an eye later—on a server somewhere in Oregon or Virginia. Between the finger on the screen and the hard drive in the United States lies an ocean, but above all lies something else: a legal order that treats this click differently from the European one. Because the moment a piece of personal data leaves the soil of the European Union, it also leaves the protective sphere of the General Data Protection Regulation—and enters a world where, under certain laws, intelligence agencies are permitted to access precisely this data.
This is not a hypothetical scenario. It is the everyday reality of every cloud service, every newsletter tool, every analytics platform, every AI model that runs through a US provider. And it is the heart of a legal drama that has been playing out for over a decade between Brussels, Luxembourg, and Washington. The lead role belongs to a single Austrian jurist, Max Schrems, who has managed to bring down not one but two international data agreements between the EU and the US before Europe's highest court—and whose shadow already falls clearly over the third, the one in force today.
For someone like Sven—a Senior AI Engineer with one foot in cloud architecture and one in IT security—this drama is anything but academic. Almost every modern software stack touches US infrastructure: hyperscaler clouds, SaaS tools, LLM APIs, telemetry, authentication services. The question of whether and on what legal basis personal data may flow there is not a footnote for the legal department but an architectural decision. This article takes you the whole way: from the basic mechanics of the GDPR through both Schrems rulings and the deeper clash of values to today's Data Privacy Framework and the cracks that have been appearing in it since 2025.
Part 1: Why a Piece of Data Cannot Simply Leave the EU
The Territoriality Problem of Data Protection
The General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) grants every person in the EU a high, fundamentally rights-anchored level of protection for their personal data. But this level of protection is tied to a territory and a legal order. As soon as data is exported to a third country, that protection could be hollowed out by a mere change of location: one would only have to process the data outside the EU to escape European rules.
That is exactly what the GDPR seeks to prevent. Chapter V (Articles 44 to 49) therefore governs the "transfer of personal data to third countries or international organisations." The guiding principle appears in Article 44: any such transfer is permissible only if the level of protection afforded in the third country is not undermined by the transfer. This is the principle of continuity of protection—the protection is meant to follow the data, so to speak, even across the border. A European fundamental right is not supposed to end at the customs barrier.
The Three Routes Across the Border
The GDPR recognizes three mechanisms on which a transfer to a third country can rest.
The first and most convenient is the adequacy decision (Article 45). The European Commission can determine that a third country—or a particular sector or framework within it—offers a level of protection that is "essentially equivalent" to the European one (the famous formula). Where such a decision exists, data may flow as freely as within the EU, without additional guarantees. Countries such as Switzerland, Canada (in part), Japan, or the United Kingdom hold such decisions. The US is a special case, and this entire article converges on it.
The second route is appropriate safeguards (Article 46). In the absence of an adequacy decision, exporter and importer can establish protection contractually themselves—most commonly through the Commission's Standard Contractual Clauses (SCCs), and additionally through Binding Corporate Rules or approved codes of conduct.
The third route is the derogations of Article 49—for instance the data subject's explicit consent or necessity for the performance of a contract. These derogations are to be interpreted narrowly and are unsuited as a permanent basis for systematic mass transfers.
The crucial point for understanding the whole Schrems saga: all three routes must achieve the same goal—an essentially equivalent level of protection. An adequacy decision is not a political favor but a legal assertion of fact about the state of the law in the destination country. And because it is an assertion of fact, a court can review it and declare it wrong. That is exactly what has happened twice.
Part 2: Safe Harbor and Schrems I (2015)
A Student, a Data Export, and a Whistleblower
The story begins long before the GDPR, under its predecessor, the 1995 Data Protection Directive. In 2000 the European Commission, in the Safe Harbor decision (2000/520/EC), had determined that US companies which voluntarily committed to a set of data protection principles and registered with the Federal Trade Commission offered an adequate level of protection. More than 4,000 companies used this "safe harbor" to process data from Europe—including Facebook, which transferred the data of its European users from its Irish subsidiary to the parent company in California.
Max Schrems, then an Austrian law student, became aware of the discrepancy between European aspiration and American practice—fueled by Edward Snowden's revelations in 2013. Snowden had disclosed that US intelligence agencies could, under programs such as PRISM, systematically access the data of major technology companies. Schrems complained to the Irish Data Protection Commissioner and argued that, in light of this access, US law could not guarantee an adequate level of protection. The Irish authority initially rejected the complaint—after all, the Commission's Safe Harbor decision existed. The case worked its way through the Irish courts to the Court of Justice of the European Union (CJEU).
The Judgment
On 6 October 2015, in Case C-362/14 (Schrems I), the CJEU declared the Safe Harbor decision invalid. The reasoning set the yardstick for everything that followed. The Court established two things. First, a national supervisory authority may examine a complaint even where a Commission adequacy decision exists—the decision does not remove fundamental rights from judicial review. Second, Safe Harbor did not meet the standard of "essentially equivalent" protection, because US law allowed national security authorities far-reaching access to the transferred data without the affected individuals having effective legal remedies. A regime that permitted authorities to access, on a general basis, the content of electronic communications violated the essence of the fundamental right to respect for private life.
With that, the first agreement had fallen. Thousands of companies had to move their transfers overnight onto other bases—mostly Standard Contractual Clauses. And the EU and the US began negotiating to replace Safe Harbor.
Part 3: Privacy Shield and Schrems II (2020)
The Second Attempt
The successor agreement was called the EU-US Privacy Shield and entered into force in July 2016 through a Commission adequacy decision (2016/1250). It was meant to remedy Safe Harbor's weaknesses: stricter obligations for companies, more oversight by the US Department of Commerce and the FTC, and—in answer to the fundamental-rights concerns—an Ombudsperson mechanism at the US State Department, to which Europeans could bring complaints about intelligence access.
Schrems did not let up. His complaint was now directed not against Safe Harbor but against the Standard Contractual Clauses to which Facebook had switched after Schrems I—arguing that even contractual clauses are useless if US law compels the data importer to grant the authorities access anyway. The case landed in Luxembourg once more.
The Judgment and Its Double Message
On 16 July 2020, in Case C-311/18 (Schrems II), a two-faced judgment was handed down.
The first face: the CJEU declared the Privacy Shield invalid as well. The reasoning deepened the critique from Schrems I and named the specific US surveillance laws. Two legal bases stood at the center. Section 702 of the Foreign Intelligence Surveillance Act (FISA 702) allows US agencies to compel American providers to hand over the targeted communications of non-US persons located outside the US—the statutory basis for the PRISM and Upstream programs. Executive Order 12333, dating from 1981, governs broader foreign intelligence gathering, such as tapping data in transit. The Court objected that these programs were not limited to what is "strictly necessary" (no proportionality in the European sense) and that Europeans had no effective, court-like remedy. The Ombudsperson mechanism did not suffice, because the Ombudsperson was neither sufficiently independent of the executive nor able to make binding decisions against the intelligence agencies. The Privacy Shield thereby violated Articles 7 (private life), 8 (data protection), and 47 (effective remedy) of the EU Charter of Fundamental Rights.
The second face: the Standard Contractual Clauses remained valid—but with a heavy condition. The CJEU stressed that SCCs, as mere contracts between two private parties, cannot bind the authorities of the third country. One must therefore not rely on them blindly. Exporter and importer must assess, in each individual case, whether the law and practice in the destination country actually afford the transferred data an equivalent level of protection—and, if not, adopt supplementary measures to close the gap. From this requirement grew the practice of the Transfer Impact Assessment (TIA): a documented risk analysis for every third-country transfer. Where supplementary measures cannot close the gap, the transfer must be suspended.
The practical consequence was a bind. For transfers to the US, companies now had neither an agreement nor reliable standard clauses—because the very laws (FISA 702, EO 12333) that had brought down the Privacy Shield applied equally to transfers on an SCC basis. In many cases the only effective "supplementary measure" was strong encryption, in which the US importer never sees the data in the clear and the keys remain in Europe. Yet this is technically impossible for many cloud processing operations, because the provider must decrypt the data in order to process it.
Part 4: The Core of the Conflict—Two Legal Orders, One Unsolvable Contradiction?
Before we reach the third agreement, it is worth exposing the real nerve of the dispute. It is not about sloppy contract wording but about a structural collision of two constitutional cultures.
On the European side stands the Charter of Fundamental Rights. The CJEU reads it to mean that any interference with private life and data protection must, first, rest on a clear legal basis; second, be proportionate (limited to what is strictly necessary); and third, be reviewable through an effective, independent remedy. Mass, suspicionless access to the content of communications is, on this reading, incompatible with the essence of the fundamental rights.
On the American side stands a different tradition. The constitutional protection of the Fourth Amendment against unreasonable searches historically protects, above all, US persons and people on US soil; foreigners abroad largely do not enjoy this protection. Foreign intelligence gathering is regarded as a legitimate instrument of national security and is subject to its own, largely secret, logic of oversight (such as the FISA Court). For a European whose data sits in the US, a gap opens from this: they are precisely the kind of "non-US person abroad" who enjoys the least protection.
The conflict can be summed up in a single sentence: the EU demands, for foreign data subjects, a level of protection that the US historically does not even grant to its own foreigners. Every transatlantic data agreement is an attempt to bridge this gulf not through a constitutional amendment—which is politically unrealistic—but through executive commitments and new complaint mechanisms. I am of the opinion that this is precisely where the structural fragility of all three agreements lies: as long as the bridge is built from administrative orders rather than statutes, it is only as stable as the political will that carries it.
Part 5: The Data Privacy Framework (2023)—The Third Attempt
The American Answer: Executive Order 14086
After Schrems II it was clear that mere relabeling would not do. This time the US side had to address the substance. On 7 October 2022, President Biden signed Executive Order 14086 on "Enhancing Safeguards for United States Signals Intelligence Activities." It sought to heal precisely the two wounds the CJEU had named.
First, it introduced, for the first time, the standards "necessary and proportionate" for US foreign intelligence gathering. This conceptually imported the European proportionality principle into a US administrative order: signals intelligence is to be conducted only for an exhaustively enumerated set of legitimate purposes and only to the extent required.
Second, it created a two-tier redress mechanism for individuals from qualifying states (which include the EU). At the first tier, the Civil Liberties Protection Officer (CLPO) in the Office of the Director of National Intelligence reviews a complaint. At the second tier, the individual can request a review by the newly created Data Protection Review Court (DPRC)—established by an Attorney General regulation (28 CFR Part 201). Despite the name, the DPRC is not a court of the judiciary but an adjudicative body within the executive branch (in the Department of Justice); its judges, however, enjoy special protections against removal, may decide independently, and can order binding remedial measures.
The Adequacy Decision
On this foundation, on 10 July 2023, the European Commission issued its third adequacy decision—this time for the EU-US Data Privacy Framework (DPF). US companies can self-certify with the Department of Commerce and thereby commit to a set of data protection principles; a certified company counts as a recipient to which European data may flow without further guarantees. At the same time, SCC-based transfers benefit too: the commitments from EO 14086 (proportionality, DPRC) improve the legal situation in the destination country and thus ease the case-by-case assessment required after Schrems II.
For practice, the DPF brought a noticeable relaxation. Anyone working with a DPF-certified US provider can once again transfer data on a clear legal basis. But from the outset one question hovered over the framework, the very one that had already brought down Safe Harbor and Privacy Shield: will it withstand renewed scrutiny by the CJEU?
Part 6: The New Cracks (2025–2026)
First Crack: The Firing of the Watchdogs
The DPF rests on a chain of US institutions whose independence the Commission cited as evidence of adequacy. One of them is the Privacy and Civil Liberties Oversight Board (PCLOB)—a bipartisan oversight body that supervises the intelligence agencies and whose reports fed into the European assessment.
On 27 January 2025, President Trump dismissed the three Democratic members of the five-member board without stating reasons. This dropped the PCLOB below its quorum, rendering it effectively unable to act. A federal court in Washington (District Court for the District of Columbia) found, on 21 May 2025, that the firings were unlawful with respect to at least two members—but the episode nourished the suspicion in Europe that the independent oversight the DPF presupposes is politically vulnerable. If a government can recall the watchdogs overnight, how sturdy is the commitment that those watchdogs were supposed to secure? This question strikes at the core of the European logic of adequacy.
Second Crack: The Latombe Case
The DPF's first judicial test came not from Schrems but from Philippe Latombe, a French member of parliament who challenged the adequacy decision before the General Court of the European Union (the first instance of the CJEU). On 3 September 2025, in Case T-553/23 (Latombe v Commission), the Court dismissed the action and confirmed the validity of the DPF. It found the DPRC sufficiently independent and impartial, US law adequately limiting bulk data collection, and the safeguards essentially equivalent.
For providers this was a relief—but only a provisional one. Latombe filed an appeal with the Court of Justice itself on 31 October 2025 (Case C-703/25 P). This appeal is limited to points of law and was still pending in mid-2026, with no hearing date set. And here lies the real tension: historically, the Court of Justice (the upper instance) has shown itself considerably more skeptical on data protection questions than the General Court (the lower instance)—the same upper instance that toppled Safe Harbor and Privacy Shield. In parallel, noyb—Schrems' organization, whose name stands for "None of Your Business"—keeps up the political pressure and continues to argue that the US commitments do not cure the underlying deficiencies.
Why the "Third Time" Might Be Different—or Not
There are good arguments that the DPF is more stable than its predecessors: for the first time the proportionality principle is anchored in the US order itself, and with the DPRC there exists a remedy with real decision-making power rather than a toothless ombudsperson. At the same time the basic weakness persists: the foundation is an Executive Order, which a future president could amend or repeal with a stroke of the pen, and the overseeing institutions showed in 2025 how quickly their independence can come under pressure. I am of the opinion that the decisive question is not whether the DPF is legally cleanly constructed—it is more carefully built than its predecessors—but whether a bridge built on administrative orders can withstand the political weather. As long as the underlying gulf between US surveillance law and EU fundamental rights does not close, every adequacy decision remains a decision on probation.
Part 7: What This Means in Practice
From a bird's-eye view, the whole saga condenses into three maxims that apply to anyone who builds or operates systems with US exposure.
First: the legal basis is an architectural decision, not an afterthought checkbox. Wherever personal data leaves the EU, it needs a documented basis—DPF certification of the recipient, Standard Contractual Clauses plus a Transfer Impact Assessment, or a narrow derogation under Article 49. Anyone who makes this decision only at the end is building on sand. The wise move is to check, already when choosing a provider, whether it is DPF-certified and where exactly it processes.
Second: data residency and encryption are the most resilient technical measures. Because any agreement can topple politically, the sturdiest precaution is not to let the dependency arise in the first place: EU regions of the hyperscalers, European sovereign-cloud offerings, and above all encryption in which the keys remain in European hands and the US provider never sees the data in the clear. Where this is possible, the legal dispute over surveillance access becomes technically moot.
Third: build for changeability, not for the eternity of an agreement. History teaches that transatlantic data frameworks have a limited half-life. An architecture that permits a change of provider or region without a total rebuild is inoculated against the next Schrems decision. This is the same underlying idea behind portability, open formats, and loosely coupled interfaces.
The common thread through all of this is an old engineering principle: do not rely on a single commitment whose continued existence you do not control. An adequacy decision is such a commitment—useful while it holds, but no foundation to build on without a fallback.
Cross-References in the Vault
- NIS2 and What It Really Means for Mid-Market IT Consulting Firms in Germany – the organization-focused cybersecurity regulation whose compliance logic data transfer complements.
- When IT Is Not Allowed to Fail: DORA and Digital Operational Resilience in Finance – why third-party risk and exit strategies in finance carry the same "don't-depend-on-one-commitment" logic.
- Security by Default: The EU Cyber Resilience Act and the End of the Insecure Product – another building block of European digital regulation with the same fundamental-rights root.
- The Pyramid of Risk: How the EU AI Act Tames Artificial Intelligence – and Why It Concerns the Whole World – the Brussels effect and the risk-based regulatory philosophy that shows through here as well.
- The Key That Dies After Every Message: The Signal Protocol, the Double Ratchet, and the Art of End-to-End Encryption – the technical answer to state access: encryption in which no one but the endpoints can read along.
- Harvest Now, Decrypt Later: Post-Quantum Cryptography and the Race Against the Quantum Computer – the same "harvest now, decrypt later" logic that also threatens intercepted transatlantic data in the long run.
The Central Takeaway
If you take one single thing from this article, let it be this: a data transfer to the US is not a purely technical connection but a legal decision resting on a politically vulnerable foundation. Twice the CJEU has let the foundation collapse—Safe Harbor in 2015, Privacy Shield in 2020—and over today's Data Privacy Framework the Latombe appeal already hangs. The deeper cause is not a legal formality but a genuine clash of values: the EU demands proportionality and effective legal protection for foreigners too, while US surveillance law traditionally does not grant either to that extent.
For daily practice this means: treat the legal basis of a third-country transfer as a first-class architectural decision, not a downstream compliance checkbox. For every US service, clarify whether it is DPF-certified, where it processes, and whether you can encrypt the data such that the provider never sees it in the clear. And build your systems so that a change of region or provider is not a total rebuild. Whoever heeds this is not immune to the next Schrems decision—but prepared. Because a commitment whose continued existence you do not control yourself is good comfort, but a poor foundation.
A Question to Reflect On
Think of a service you or your team is currently using that transfers personal data to the US—a cloud platform, an analytics tool, an LLM API. Do you know off the top of your head on what legal basis this transfer rests, and what would happen to your processing if the Court of Justice declared the Data Privacy Framework invalid tomorrow—would you have a fallback, or would operations grind to a halt?
Sources
- Judgment of the CJEU of 6 October 2015, C-362/14 (Schrems I) – InfoCuria
- Judgment of the CJEU of 16 July 2020, C-311/18 (Schrems II) – InfoCuria
- Commission Implementing Decision (EU) 2023/1795 – adequacy of the EU-US Data Privacy Framework (10 July 2023) – EUR-Lex
- Executive Order 14086 – Enhancing Safeguards for United States Signals Intelligence Activities – U.S. Department of Justice, Office of Privacy and Civil Liberties
- European General Court dismisses Latombe challenge, upholds EU-US Data Privacy Framework – IAPP
- European Court of Justice to Review Challenge to EU-U.S. Data Privacy Framework (C-703/25 P) – WilmerHale
- D.C. Federal Court Rules Termination of Democrat PCLOB Members Is Unlawful – Hunton Privacy & Cybersecurity Law Blog