Vai al contenuto principale
Torna al wiki
Privacy & Compliance

What Is Schrems II?

Ultimo aggiornamento il 21 luglio 2026

Schrems II is the common name for the July 2020 judgment of the Court of Justice of the European Union (case C-311/18) that invalidated the EU–US Privacy Shield, the framework thousands of companies relied on to transfer personal data across the Atlantic. Brought by Austrian privacy advocate Max Schrems — whose earlier case had already toppled the Safe Harbor arrangement in 2015 — the ruling held that US surveillance law prevented the framework from guaranteeing EU citizens the level of protection the GDPR demands. Overnight, a legal foundation of transatlantic data flows disappeared, and the case became shorthand for the fragility of cross-border transfer mechanisms.

What the Court Decided

Two holdings define the judgment. First, the Privacy Shield fell because US intelligence programs allowed access to transferred data beyond what EU law considers proportionate, and EU citizens lacked effective judicial redress against it. Second, standard contractual clauses (SCCs) — the main alternative mechanism — survived, but with a demanding condition: the exporting controller must assess, transfer by transfer, whether the destination country's law undermines the clauses in practice, and add supplementary measures where it does. A contract cannot bind a foreign intelligence agency, so for data accessible in plaintext by a US provider, the assessment frequently has no comfortable answer.

The Aftermath for Websites and Cloud Services

The ruling's reach extended far beyond data centers, because transfers happen wherever a US-controlled service touches EU visitor data — and European regulators applied that logic to the everyday web. Decisions in several member states found routine website embeds transmitting visitor data to US endpoints unlawful, with fonts, analytics, and other third-party scripts among the casualties. A successor framework, the EU–US Data Privacy Framework, received an adequacy decision in 2023, restoring a legal basis for certified companies — but it rests on the same tension the court has now struck down twice, faces challenges of its own, and history sets the pattern: architectures built on a transfer mechanism inherit that mechanism's lifespan.

Engineering Around the Problem

The durable response to Schrems II is architectural rather than contractual: where processing stays inside the EU, the entire transfer question — adequacy decisions, SCCs, supplementary measures, and their periodic invalidation — never arises. That shifts vendor selection toward data residency as a primary criterion, especially for components that touch every visitor. Verification is a case in point: a CAPTCHA runs on logins and checkouts across the whole site, so its data flows matter disproportionately, and EU-hosted services such as CaptchaFox keep that processing within European jurisdiction while collecting no persistent identifiers in the first place. The lesson the case keeps teaching is the same one data minimization starts from: data that is never collected, or never leaves, needs no transfer mechanism at all.

Informazioni su CaptchaFox

CaptchaFox è una soluzione conforme al GDPR con sede in Germania che protegge siti web e applicazioni da abusi automatizzati, come bot e spam. Il suo approccio distintivo e multilivello utilizza segnali di rischio e sfide crittografiche per facilitare un processo di verifica robusto. CaptchaFox consente ai clienti di essere operativi in pochi minuti, non richiede gestione continua e offre alle aziende una protezione duratura.

Per saperne di più su CaptchaFox, contattaci o inizia a integrare la nostra soluzione con una prova gratuita.

Termini correlati

What Is the GDPR?

The GDPR is the EU's General Data Protection Regulation — the law governing how personal data of people in the EU may be collected, processed and shared.

Continua a leggere
What Is Email Scraping?

Email scraping is the automated harvesting of email addresses from websites and public sources to build spam, phishing, and resale lists.

Continua a leggere
What Is Price Scraping?

Price scraping is the automated bulk extraction of prices from a competitor's site — fueling undercutting strategies and a constant crawler load.

Continua a leggere
What Is Web Scraping?

Web scraping is the automated extraction of data from websites. It powers search engines and price comparison — and content theft and competitive abuse.

Continua a leggere

Combatti i bot e proteggi i dati dei tuoi utenti.

Non dare ai truffatori e agli spammer alcuna possibilità e proteggi il tuo sito web con CaptchaFox oggi.

CaptchaFox protegge i siti web su desktop e dispositivi mobili