Skip to main content

News story

July 29, 2020

Data transfers: EU/US Privacy Shield shattered

On 16 July 2020, the Court of Justice of the European Union (CJEU) struck down the European Union (EU)/United States (US) Privacy Shield, which served as the mechanism for which EU citizens’ personal data could be shared with the US. Instead, companies must now use standard contractual clauses (SCCs).

This will have far-reaching impacts on companies on both sides of the pond. Those who relied on the Privacy Shield to transfer personal data must find an alternative method or stop. This will be extremely problematic for companies that work across both jurisdictions, who must transfer personal data for their company to function.

What was the Privacy Shield?

Companies can transfer personal data to other countries where there is at least an equal measure of data protection as directed by EU law. Companies can legally transfer data when the EU has determined that a third country has adequate measures in place. Due to substandard data protection and privacy laws, the US has not passed this test. So, the EU and the US produced the Privacy Shield Framework. This framework carved out a legal path by which the personal data of EU citizens could be transferred between the EU and the US, so long as those US companies enrolled in the Privacy Shield Framework complied with the data protection obligations imposed upon them.

Why did the CJEU invalidate the Privacy Shield?

The CJEU determined that US National Security law does not sufficiently protect EU citizens’ personal data. US surveillance laws allow the government to access more personal data than is strictly necessary. In short, the US government can snoop to a degree that does not align well with EU law. Hence, the Privacy Shield Framework does not sufficiently protect the personal data transferred under it.

Standard Contractual Clauses – what are they?

SCCs are standard clauses published by the European Commission or by a member state Supervisory Authority. They offer sufficient safeguards on data protection to allow personal data to be transferred outside of the EU. Although the CJEU endorsed the use of SCCs, moving forward, it made clear that parties have an obligation to ensure that the laws in the recipient country are sufficient to protect EU personal data. If the guarantees of the SCCs are not upheld, then personal data transfers with that company must be suspended.

What should companies do now?

Companies that transfer personal data to the US must ensure they continue to do so lawfully. Where a company has previously relied on Privacy Shield certification, it must implement a new transfer mechanism as an SCC. Still, where required, it must consider additional supplemental contractual safeguards that go above the standard SCCs.

To avoid falling foul of the Information Commissioners Office (ICO), companies must assess whether their data privacy safeguards are sufficient and ensure those of any company outside of the EU with whom they have or intend to continue sharing EU citizens’ personal data affords an equivalent protection guaranteed within the EU under GDPR legislation.

This is a complicated area of cross-border data protection law. Companies should seek advice from a lawyer to ensure compliance with EU law.

Speak to Karen Cole today, who can review your existing contracts and practices to ensure your company complies.

Note: This is not legal advice; it provides information of general interest on a current legal issue.

Stay in touch

Subscribe to our newsletter

Stay in touch

By completing your details and submitting this form you confirm you are happy for us to send you marketing communications and that you agree to our Website Privacy Policy and Legal Notice and to us using Mailchimp to process your data.


Sending

News/Insight

  • Completion and post-completion steps in a sale: Final steps for sellers
    A guide to completion and post completion steps in a corporate sale including exchange, stamp duty, Companies House filings and key administrative requirements.


    Read more
  • How to protect your brand: A beginner’s guide
    Trademark protection for businesses explained, including how to register a trademark in England and Wales and the key steps to protect your brand.


    Read more
  • Inheritance Act claims and letters of wishes: Managing risk in estate planning
    This article explains who can bring a claim, the strict time limits involved, and the risks for executors and beneficiaries. It also explores how a carefully drafted Letter of Wishes can provide valuable context, demonstrate intention, and help reduc


    Read more
  • Confusion as Companies House rolls out identity checks for directors 
    Company directors are being urged to familiarise themselves with new identity verification requirements being introduced by Companies House, as confusion is reported around how and when the checks must be completed.


    Read more
  • Transactional documents in a corporate sale: What sellers should know
    Once due diligence is complete and terms are agreed, the focus turns to negotiating the transactional documents that underpin a share or asset sale. This guide explains the purpose of the key documents involved in business acquisitions and why carefu


    Read more

What they say...

  • Laura Kelly, February 2026
    Review of legal guidance received “I recently worked with Patrick Simpson on my settlement agreement. Patrick guided me through every stage with exceptional care and diligence. He kept the process moving efficiently, always updating me promptly

  • Prasanna Sooriakumaran, February 2026
    “Really good, especially at dealing with the company that tried to overplay their hand. I highly recommend.”

  • Sharla Munian, February 2026
    Outstanding Legal Support and a Brilliant Result “I cannot recommend RIAA Barker Gillette highly enough. My solicitor supported me throughout a very challenging property litigation matter, and thanks to her expertise, dedication, and strategic

  • Client, February 2026
    Very good service in disagreement with architect “RIAA assisted me in a conflict I had with my architect, who wanted to overcharge me. The end result was satisfactory, with invoices reasonable despite being slightly higher than expected!”

  • Sharla Munian, February 2026
    Outstanding Solicitor Who Delivered the Outcome I Hoped For “After a number of years navigating a complex financial settlement following my separation, my solicitor has been incredible from start to finish. Their professionalism, patience, and

Read more
Send this to a friend