Skip to main content
Category: Data Transfers

EU-US Privacy Shield

Also known as: EU-U.S. Privacy Shield, EU-U.S. Privacy Shield Framework, Privacy Shield
Simply put

The EU-US Privacy Shield was a legal framework designed by the U.S. Department of Commerce and the European Commission to allow companies to transfer personal data from the European Union to the United States for commercial purposes while providing protections for individuals. It is no longer valid: the Court of Justice of the European Union struck it down in 2020, so it can no longer be relied on to lawfully transfer personal data out of the EU. Organizations that once used it have generally had to move to other transfer tools, and readers should verify the current mechanisms, including the more recent EU-US Data Privacy Framework, against official sources.

Formal definition

The EU-US Privacy Shield was a self-certification framework administered by the U.S. Department of Commerce and recognized by the European Commission through Commission Implementing Decision (EU) 2016/1250, which constituted an adequacy decision for transfers of personal data from the EU/EEA to certified U.S. organizations. It was originally adopted under Directive 95/46/EC (the predecessor to the GDPR); under the GDPR, adequacy decisions are made pursuant to Article 45. The Court of Justice of the European Union invalidated the Privacy Shield adequacy decision in its judgment of 16 July 2020 in Schrems II (Case C-311/18), meaning that as of that date it can no longer be relied upon as a valid transfer mechanism by either controllers or processors transferring personal data from the EEA. A parallel Swiss-U.S. Privacy Shield existed separately. Following invalidation, the EU and the U.S. developed the EU-US Data Privacy Framework (adopted in 2023), and a related UK extension has been established; practitioners should confirm the current status, scope, and any supplementary measures against the up-to-date official texts, as transfer tools and adequacy positions continue to evolve.

Why it matters

The EU-US Privacy Shield matters because for several years it was a primary mechanism that allowed thousands of organizations to transfer personal data from the EU/EEA to the United States for commercial purposes without negotiating bespoke transfer arrangements. Its recognition rested on Commission Implementing Decision (EU) 2016/1250, which constituted an adequacy decision (the relevant legal basis for such decisions under the GDPR is Article 45). Because so many transatlantic data flows depended on it, its status became a central compliance question for any business handling EU personal data with a U.S. dimension.

Its significance today is largely cautionary. The Court of Justice of the European Union invalidated the Privacy Shield adequacy decision in its judgment of 16 July 2020 in Schrems II (Case C-311/18). As of that date the framework can no longer be relied upon as a valid transfer mechanism by either controllers or processors moving personal data from the EEA. Organizations that had built their transfer strategy around Privacy Shield generally had to pivot to other tools and reassess their transfers, in many cases applying supplementary measures. This history illustrates how transfer mechanisms and adequacy positions can change through litigation and are not permanent.

The episode also frames the current landscape. Following invalidation, the EU and the U.S. developed the EU-US Data Privacy Framework, adopted in 2023, and a related UK extension has been established. Practitioners should not treat Privacy Shield certification as sufficient today and should verify the current status, scope, and any required supplementary measures against up-to-date official sources, as transfer tools continue to evolve.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify any legacy reliance on Privacy Shield in transfer records and vendor documentation. Since the framework has been invalid for EEA transfers since 16 July 2020, continued reliance on it would not provide a lawful basis, and organizations should reassess transfers and confirm whether a current mechanism such as the EU-US Data Privacy Framework or another Article 46 tool applies.
Privacy and Technology Lawyers
Lawyers advising on cross-border transfers should understand that Privacy Shield was a formal adequacy decision (Commission Implementing Decision (EU) 2016/1250), not merely an informal arrangement, and that it was struck down in Schrems II (Case C-311/18). This history informs advice on how transfer mechanisms and adequacy decisions can be challenged and change over time.
U.S. Organizations Serving EU Customers
U.S. businesses that previously self-certified under Privacy Shield can no longer rely on that certification for EEA data imports. They should verify their current transfer basis, which may include the EU-US Data Privacy Framework adopted in 2023, and consider any UK extension separately, confirming scope against official sources.
Engineers and Data Architects
Engineers designing systems that route EU personal data to the United States should not treat a historical Privacy Shield reference in system documentation as a valid transfer safeguard. Data flow mapping should reflect the currently applicable mechanism and any supplementary measures required following the Schrems II judgment.

Inside EU-US Privacy Shield

Adequacy Decision Basis
The EU-US Privacy Shield was given legal effect by the European Commission through Commission Implementing Decision (EU) 2016/1250, which constituted an official adequacy decision. This decision was originally adopted under Directive 95/46/EC (the predecessor to the GDPR); adequacy decisions are now made under Article 45 GDPR. It was not merely an informal or adequacy-style arrangement but a formal adequacy determination for participating US organizations.
Self-Certification Mechanism
Privacy Shield operated as a voluntary self-certification framework administered on the US side, under which eligible US-based organizations committed to a set of privacy principles. Certification was intended to allow transfers of personal data from the EEA to certified US recipients without a separate transfer tool, for the period the framework remained valid.
Schrems II Invalidation
The Court of Justice of the European Union invalidated the Privacy Shield adequacy decision on 16 July 2020 in the Schrems II judgment (Case C-311/18). As a result, the Privacy Shield can no longer be relied upon as a valid transfer mechanism under the EU GDPR, and this applies to both controllers and processors transferring personal data out of the EEA.
Successor Framework Context
Following invalidation, the EU-US Data Privacy Framework was adopted in 2023 as a successor mechanism, supported by a new adequacy decision, and a UK extension was established to cover transfers from the UK. Practitioners should verify the current status and scope of these instruments against official sources, as adequacy decisions and their supplementary conditions can evolve or be subject to legal challenge.

Common questions

Answers to the questions practitioners most commonly ask about EU-US Privacy Shield.

Can we still rely on the EU-US Privacy Shield to transfer personal data to the United States?
No. The Court of Justice of the European Union invalidated the EU-US Privacy Shield in its judgment of 16 July 2020 in Schrems II (Case C-311/18). Since that date, the Privacy Shield can no longer be relied on as a valid transfer mechanism under the EU GDPR, and this applies to both controllers and processors transferring personal data from the EEA. Organisations that had relied on it needed to identify an alternative lawful basis for transfer. You should verify the current position against official sources, as the transfer landscape continues to evolve.
Was the Privacy Shield an official adequacy decision, or something less formal?
It was an official adequacy decision, not merely an adequacy-style arrangement. The Privacy Shield was given effect by Commission Implementing Decision (EU) 2016/1250, adopted under the framework of Directive 95/46/EC (the predecessor to the GDPR). Adequacy decisions are the mechanism by which the European Commission determines that a third country ensures an adequate level of protection; under the current GDPR, the relevant legal basis for such decisions is Article 45. The Privacy Shield decision was subsequently invalidated in Schrems II.
What replaced the Privacy Shield for EU-US data transfers?
Following the invalidation of the Privacy Shield, the European Commission adopted a new adequacy decision for the EU-US Data Privacy Framework in 2023. Organisations wishing to rely on it should confirm the certification status of the US recipient and monitor for any legal challenges, as adequacy decisions and their supporting arrangements can be subject to review and change over time. Readers should verify the current status against the official text and Commission announcements.
If our organisation was self-certified under the Privacy Shield, what should we consider now?
Because the Privacy Shield can no longer support transfers under the EU GDPR, prior self-certification does not by itself provide a lawful transfer basis. Organisations generally need to reassess their transfers, identify an appropriate current mechanism, and document the assessment. Where relevant, this may involve considering the EU-US Data Privacy Framework or other transfer tools. The specific steps depend on your role and circumstances, so this should be assessed case by case.
Does the position on the Privacy Shield differ under the UK regime?
The UK GDPR operates as a separate regime, and transfer arrangements for the UK are determined under UK law and by UK authorities rather than by EU adequacy decisions directly. A UK extension to the EU-US Data Privacy Framework was established to address UK-to-US transfers. The precise scope and current status should be verified against official UK guidance, as the UK and EU positions can diverge.
Where does the boundary of the Privacy Shield's relevance lie for our current compliance program?
The Privacy Shield is now primarily of historical and contextual relevance for EU GDPR transfers, given its invalidation on 16 July 2020. Its continued value in a compliance program is mainly in understanding the reasoning of Schrems II, which informs the assessment of subsequent transfer tools and supplementary measures. For live transfer decisions, you should rely on currently valid mechanisms and confirm their status against the up-to-date official text and regulatory guidance.

Common misconceptions

The Privacy Shield is still a valid basis for transferring personal data from the EEA to the US.
It is not. Since the CJEU's Schrems II judgment on 16 July 2020 (Case C-311/18), the Privacy Shield adequacy decision has been invalid and cannot be used to lawfully transfer personal data from the EEA under the EU GDPR. Organizations relying on it needed to move to another transfer mechanism.
The Privacy Shield and the EU-US Data Privacy Framework are the same thing.
They are distinct instruments. The Privacy Shield was invalidated in 2020, whereas the EU-US Data Privacy Framework is a separate, later arrangement adopted in 2023 with its own adequacy decision. Certification or reliance on one does not automatically equate to coverage under the other; the current framework's status should be verified against official sources.
The Privacy Shield was an informal or unofficial arrangement rather than a formal legal determination.
It was an official adequacy decision, given effect by Commission Implementing Decision (EU) 2016/1250, originally adopted under Directive 95/46/EC. Adequacy is a defined legal mechanism, now governed by Article 45 GDPR, and not merely an informal or adequacy-style understanding.

Best practices

Do not rely on the Privacy Shield for any EEA-to-US transfer; treat it as invalid since 16 July 2020 for both controller and processor transfers and identify a currently valid transfer mechanism.
Review contracts, privacy notices, and transfer documentation to remove outdated references to the Privacy Shield as a transfer basis and update them to reflect the mechanism actually in use.
Verify whether the EU-US Data Privacy Framework (2023) and its UK extension apply to your specific transfers, and confirm the current status of the relevant adequacy decisions against official EU and UK sources rather than assuming permanence.
For UK-originating transfers, distinguish EU GDPR positions from UK GDPR positions and confirm which instrument or extension governs, as the mechanisms and their coverage can differ.
Assess whether supplementary measures or an alternative transfer tool are needed for a given data flow, consistent with the risk-based approach emphasized in Schrems II.
Monitor for regulatory guidance and potential legal challenges to successor frameworks, and re-verify your transfer basis periodically as adequacy decisions and transfer tools can evolve.