EU-US Privacy Shield
The EU-US Privacy Shield was a legal framework designed by the U.S. Department of Commerce and the European Commission to allow companies to transfer personal data from the European Union to the United States for commercial purposes while providing protections for individuals. It is no longer valid: the Court of Justice of the European Union struck it down in 2020, so it can no longer be relied on to lawfully transfer personal data out of the EU. Organizations that once used it have generally had to move to other transfer tools, and readers should verify the current mechanisms, including the more recent EU-US Data Privacy Framework, against official sources.
The EU-US Privacy Shield was a self-certification framework administered by the U.S. Department of Commerce and recognized by the European Commission through Commission Implementing Decision (EU) 2016/1250, which constituted an adequacy decision for transfers of personal data from the EU/EEA to certified U.S. organizations. It was originally adopted under Directive 95/46/EC (the predecessor to the GDPR); under the GDPR, adequacy decisions are made pursuant to Article 45. The Court of Justice of the European Union invalidated the Privacy Shield adequacy decision in its judgment of 16 July 2020 in Schrems II (Case C-311/18), meaning that as of that date it can no longer be relied upon as a valid transfer mechanism by either controllers or processors transferring personal data from the EEA. A parallel Swiss-U.S. Privacy Shield existed separately. Following invalidation, the EU and the U.S. developed the EU-US Data Privacy Framework (adopted in 2023), and a related UK extension has been established; practitioners should confirm the current status, scope, and any supplementary measures against the up-to-date official texts, as transfer tools and adequacy positions continue to evolve.
Why it matters
The EU-US Privacy Shield matters because for several years it was a primary mechanism that allowed thousands of organizations to transfer personal data from the EU/EEA to the United States for commercial purposes without negotiating bespoke transfer arrangements. Its recognition rested on Commission Implementing Decision (EU) 2016/1250, which constituted an adequacy decision (the relevant legal basis for such decisions under the GDPR is Article 45). Because so many transatlantic data flows depended on it, its status became a central compliance question for any business handling EU personal data with a U.S. dimension.
Its significance today is largely cautionary. The Court of Justice of the European Union invalidated the Privacy Shield adequacy decision in its judgment of 16 July 2020 in Schrems II (Case C-311/18). As of that date the framework can no longer be relied upon as a valid transfer mechanism by either controllers or processors moving personal data from the EEA. Organizations that had built their transfer strategy around Privacy Shield generally had to pivot to other tools and reassess their transfers, in many cases applying supplementary measures. This history illustrates how transfer mechanisms and adequacy positions can change through litigation and are not permanent.
The episode also frames the current landscape. Following invalidation, the EU and the U.S. developed the EU-US Data Privacy Framework, adopted in 2023, and a related UK extension has been established. Practitioners should not treat Privacy Shield certification as sufficient today and should verify the current status, scope, and any required supplementary measures against up-to-date official sources, as transfer tools continue to evolve.
Who it's relevant to
Inside EU-US Privacy Shield
Common questions
Answers to the questions practitioners most commonly ask about EU-US Privacy Shield.