Skip to main content
Back to the wiki
Privacy & Compliance

What Is Schrems II?

Last updated on July 21, 2026

Schrems II is the common name for the July 2020 judgment of the Court of Justice of the European Union (case C-311/18) that invalidated the EU–US Privacy Shield, the framework thousands of companies relied on to transfer personal data across the Atlantic. Brought by Austrian privacy advocate Max Schrems — whose earlier case had already toppled the Safe Harbor arrangement in 2015 — the ruling held that US surveillance law prevented the framework from guaranteeing EU citizens the level of protection the GDPR demands. Overnight, a legal foundation of transatlantic data flows disappeared, and the case became shorthand for the fragility of cross-border transfer mechanisms.

What the Court Decided

Two holdings define the judgment. First, the Privacy Shield fell because US intelligence programs allowed access to transferred data beyond what EU law considers proportionate, and EU citizens lacked effective judicial redress against it. Second, standard contractual clauses (SCCs) — the main alternative mechanism — survived, but with a demanding condition: the exporting controller must assess, transfer by transfer, whether the destination country's law undermines the clauses in practice, and add supplementary measures where it does. A contract cannot bind a foreign intelligence agency, so for data accessible in plaintext by a US provider, the assessment frequently has no comfortable answer.

The Aftermath for Websites and Cloud Services

The ruling's reach extended far beyond data centers, because transfers happen wherever a US-controlled service touches EU visitor data — and European regulators applied that logic to the everyday web. Decisions in several member states found routine website embeds transmitting visitor data to US endpoints unlawful, with fonts, analytics, and other third-party scripts among the casualties. A successor framework, the EU–US Data Privacy Framework, received an adequacy decision in 2023, restoring a legal basis for certified companies — but it rests on the same tension the court has now struck down twice, faces challenges of its own, and history sets the pattern: architectures built on a transfer mechanism inherit that mechanism's lifespan.

Engineering Around the Problem

The durable response to Schrems II is architectural rather than contractual: where processing stays inside the EU, the entire transfer question — adequacy decisions, SCCs, supplementary measures, and their periodic invalidation — never arises. That shifts vendor selection toward data residency as a primary criterion, especially for components that touch every visitor. Verification is a case in point: a CAPTCHA runs on logins and checkouts across the whole site, so its data flows matter disproportionately, and EU-hosted services such as CaptchaFox keep that processing within European jurisdiction while collecting no persistent identifiers in the first place. The lesson the case keeps teaching is the same one data minimization starts from: data that is never collected, or never leaves, needs no transfer mechanism at all.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is the GDPR?

The GDPR is the EU's General Data Protection Regulation — the law governing how personal data of people in the EU may be collected, processed and shared.

Read more
What Is Email Scraping?

Email scraping is the automated harvesting of email addresses from websites and public sources to build spam, phishing, and resale lists.

Read more
What Is Price Scraping?

Price scraping is the automated bulk extraction of prices from a competitor's site — fueling undercutting strategies and a constant crawler load.

Read more
What Is Web Scraping?

Web scraping is the automated extraction of data from websites. It powers search engines and price comparison — and content theft and competitive abuse.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices