What Is Schrems II?
Schrems II is the common name for the July 2020 judgment of the Court of Justice of the European Union (case C-311/18) that invalidated the EU–US Privacy Shield, the framework thousands of companies relied on to transfer personal data across the Atlantic. Brought by Austrian privacy advocate Max Schrems — whose earlier case had already toppled the Safe Harbor arrangement in 2015 — the ruling held that US surveillance law prevented the framework from guaranteeing EU citizens the level of protection the GDPR demands. Overnight, a legal foundation of transatlantic data flows disappeared, and the case became shorthand for the fragility of cross-border transfer mechanisms.
What the Court Decided
Two holdings define the judgment. First, the Privacy Shield fell because US intelligence programs allowed access to transferred data beyond what EU law considers proportionate, and EU citizens lacked effective judicial redress against it. Second, standard contractual clauses (SCCs) — the main alternative mechanism — survived, but with a demanding condition: the exporting controller must assess, transfer by transfer, whether the destination country's law undermines the clauses in practice, and add supplementary measures where it does. A contract cannot bind a foreign intelligence agency, so for data accessible in plaintext by a US provider, the assessment frequently has no comfortable answer.
The Aftermath for Websites and Cloud Services
The ruling's reach extended far beyond data centers, because transfers happen wherever a US-controlled service touches EU visitor data — and European regulators applied that logic to the everyday web. Decisions in several member states found routine website embeds transmitting visitor data to US endpoints unlawful, with fonts, analytics, and other third-party scripts among the casualties. A successor framework, the EU–US Data Privacy Framework, received an adequacy decision in 2023, restoring a legal basis for certified companies — but it rests on the same tension the court has now struck down twice, faces challenges of its own, and history sets the pattern: architectures built on a transfer mechanism inherit that mechanism's lifespan.
Engineering Around the Problem
The durable response to Schrems II is architectural rather than contractual: where processing stays inside the EU, the entire transfer question — adequacy decisions, SCCs, supplementary measures, and their periodic invalidation — never arises. That shifts vendor selection toward data residency as a primary criterion, especially for components that touch every visitor. Verification is a case in point: a CAPTCHA runs on logins and checkouts across the whole site, so its data flows matter disproportionately, and EU-hosted services such as CaptchaFox keep that processing within European jurisdiction while collecting no persistent identifiers in the first place. The lesson the case keeps teaching is the same one data minimization starts from: data that is never collected, or never leaves, needs no transfer mechanism at all.
About CaptchaFox
CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.
To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.