Law and duties 3 minutes read

Data to the United States: where things stand after three attempts

Twice the Court of Justice struck down an arrangement; since 2023 the third one applies. What that means for embedded services, which assessment is still required – and why a tick box does not settle the question.

The GDPR permits transfers outside the EU only under conditions. The simplest route is an adequacy decision: the Commission finds that a country offers a comparable level of protection, and transfers there are treated like transfers within the EU. For the United States that route has an eventful history.

Three arrangements in ten years

  1. 2000Safe Harbor takes effect – a self-certification by US companies.
  2. 2015The Court of Justice strikes it down (Schrems I). Reason: disproportionate government access.
  3. 2016The successor, Privacy Shield, takes effect.
  4. 2020That one falls too (Schrems II) – for the same reason. Standard contractual clauses survive but require an additional assessment.
  5. 2023The Data Privacy Framework takes effect, resting on a US presidential order and a new redress court.
Both times the reasoning was the same: access powers of US intelligence services without effective legal redress for people in the EU. The third arrangement answers that with a review court – whether that suffices is once again before the courts.

What applies concretely today

A transfer to a US company is permitted where that company is certified under the Data Privacy Framework. The certification is publicly visible and has to be renewed annually – it is therefore not a permanent state but a status that can lapse.

The scope matters too: a certification can be limited to particular kinds of data. A company certified only for human-resources data does not thereby cover website data.

Where no certification exists

The remaining routes, in order of practicality

  • Standard contractual clauses plus assessmentThe usual route. Since Schrems II the clauses alone are not enough – a documented assessment of the legal situation in the destination country is added.
  • Supplementary measuresEncryption where the key stays in the EU, or processing exclusively in pseudonymised form.
  • Consent for the individual caseIntended only for occasional transfers and with a warning about the risks. Unsuitable for the continuous operation of a website.
  • Changing providerThe route that dissolves the question rather than administering it. For most kinds of service there are providers processing within the EU.

For practice this yields a simple stocktaking recommendation: every embedded service is examined for where it processes and whether a valid certification exists. The result belongs in the privacy notice – and the certifications belong in a diary, because they lapse annually.

Two struck-down arrangements in fifteen years is a pattern, not an exception. Anyone wanting the question gone for good moves the processing – anyone administering it plans for the next review.

Published 16 September 2026

This article explains general principles and does not replace legal advice on an individual case.

Back to the overview