Home Reviews About
Twenty of Time

What the Schrems II Ruling Means for Data Transfers to the US

In July 2020, the Court of Justice of the European Union delivered a judgment that reshaped how organisations think about moving personal data across the Atlantic. The Schrems II decision invalidated the EU-US Privacy Shield and placed strict conditions on the use of standard contractual clauses, citing concerns that American surveillance law offered insufficient protection for European citizens.

For Australian organisations, the ruling may seem geographically distant, yet it has practical reach. Many Sydney and Melbourne-based firms rely on US-hosted platforms for email, customer relationship management, payroll, and analytics. When those platforms process the personal data of European residents, Schrems II applies regardless of where the service provider or the Australian customer is headquartered.

The legal mechanics behind the decision

The case originated with Maximilian Schrems, an Austrian privacy advocate who challenged Facebook's transfer of his data to Ireland and onward to the United States. The Irish Data Protection Commissioner referred questions to the Court of Justice, and the resulting decision dismantled the Privacy Shield while leaving standard contractual clauses technically usable.

The court's reasoning rested on two pillars. First, it found that US surveillance practices, particularly under Section 702 of the Foreign Intelligence Surveillance Act and Executive Order 12333, allowed authorities to access data without the equivalent protections found in EU law. Second, it held that the data subjects affected by such access did not have meaningful redress, undermining the essence of the right to privacy.

Australian readers familiar with the Telecommunications (Interception and Access) Act might recognise a parallel tension between national security frameworks and individual rights. The differences in legal safeguards are central to why a transatlantic data transfer carries risk, even when both countries claim democratic oversight.

Why US surveillance law triggered concern

Section 702 authorises the US intelligence community to target non-US persons located abroad, with companies like Google, Microsoft, and Amazon often receiving directives to provide access to communications. Executive Order 12333 governs signals intelligence more broadly and, unlike 702, is not subject to statutory oversight or judicial review in the same way. Together, these instruments created what the court described as a disproportionate interference with the privacy of EU residents.

The decision was not a blanket accusation against American technology. Rather, it asked whether the legal framework offered protections substantively equivalent to EU standards. The answer, for the court, was no, and that conclusion forced businesses across the world to reconsider their data architecture.

For Australian businesses using services like Microsoft 365, Salesforce, or Workday, this meant reassessing whether standard contracts alone could satisfy European regulators. The cloud privacy trade-offs examined elsewhere on this blog illustrate why these reassessments often surface uncomfortable choices between cost, convenience, and compliance.

Impact on Australian organisations

Australian companies rarely think of themselves as caught in European regulatory disputes, but the territorial scope of the General Data Protection Regulation is broad. Any processing of data belonging to someone in the EU, whether a customer, employee, or website visitor, brings GDPR obligations into play. Add cross-border transfers to US-based processors, and Schrems II enters the picture.

Consider a Brisbane-based SaaS provider whose clients include a German retailer. Customer names, addresses, and payment details flow through a US hyperscaler for hosting. Pre-Schrems II, the Privacy Shield provided a relatively simple compliance pathway. Post-Schrems II, that pathway collapsed, and the company must now rely on contractual clauses plus a documented transfer impact assessment.

The Australian Privacy Principles, administered by the Office of the Australian Information Commissioner, do not require such assessments, but the Notifiable Data Breaches scheme does demand prompt reporting when serious harm is likely. A business that mishandles EU data may therefore face parallel exposure: regulatory fines from European authorities and reputational damage closer to home. Telstra's 2022 breach and the subsequent Optus incident showed how quickly public trust can erode when data handling goes wrong.

The successor framework and its limits

In July 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework, designed to address Schrems II's criticisms through new US safeguards, including a redress mechanism through the Data Protection Review Court. The framework allows certified US companies to receive EU personal data without additional contractual measures.

However, the framework has its own vulnerabilities. Privacy advocates have already signalled intent to challenge it, citing concerns that the new safeguards remain insufficient. Some Australian firms have nonetheless resumed transfers to certified US providers, betting that the framework will hold long enough to justify the operational simplicity. Others have continued building out European data centres, preferring structural separation over legal risk.

Practical compliance steps

For Australian organisations, the path forward rarely follows a single template. A useful starting point is mapping every data flow that crosses the EU-US boundary, including backup systems, support tools, and analytics pipelines that quietly route through American services. Once the map exists, the next decisions become more concrete.

Transfer impact assessments should document the specific surveillance laws that apply to the recipient, the categories of data transferred, and the supplementary measures in place. Encryption with keys held by the data exporter is one such measure, though regulators have questioned whether US authorities can compel access to keys held by US-headquartered providers. Pseudonymisation, anonymisation where feasible, and contractual transparency clauses each add a layer of protection.

For businesses whose entire operating model depends on US platforms, the compliance habits of organisations that navigate regulatory complexity often include proactive engagement with regulators rather than reactive scrambling. Building a relationship with European data protection authorities before a complaint arises can transform the compliance function from a cost centre into a strategic asset.

Australian parallels and broader lessons

Australia's own privacy regime has trended toward stronger protections, particularly through amendments to the Privacy Act and the strengthening of the Notifiable Data Breaches scheme. The Australian Prudential Regulation Authority's CPS 234 standard forces banks in Sydney and Melbourne to demonstrate cyber resilience, an obligation that pushes financial institutions toward more sophisticated data governance than many other sectors.

Yet Australian law still permits extensive data collection by both government agencies and private firms. The My Health Record opt-out period in 2018 sparked debate about consent and centralised databases, and similar concerns surface whenever federal proposals touch on expanded data sharing. Schrems II offers a useful comparator: a jurisdiction that decided certain surveillance powers were simply incompatible with baseline privacy expectations.

For Australians reading about European decisions, the lesson is not that Europe got it right and the US got it wrong. It is that legal frameworks encode choices about how much intrusion a society tolerates, and those choices have commercial consequences. Businesses that ignore those consequences risk regulatory action, contractual disputes, and erosion of customer trust.

Looking ahead for cloud and SaaS

The structural response to Schrems II has been a wave of regional cloud infrastructure investment. Microsoft, AWS, and Google have expanded their European regions to give customers technical options for keeping data on European soil. Australian firms have sometimes piggy-backed on these regions, routing EU-resident data through Frankfurt or Dublin while retaining Australian data in Sydney.

For software-as-a-service vendors, the picture is more complex. Multi-tenant platforms often process data across regions by default, and contractual commitments to data residency can be harder to enforce than marketing suggests. Customers should ask providers for explicit documentation of where each data category resides, who has access, and under what legal regime. The consent form tricks that designers deploy often obscure precisely the kind of information needed for these assessments, leaving buyers to discover residency limits only after contracts are signed.

Looking ahead, expect further litigation over the EU-US Data Privacy Framework, continued investment in regional infrastructure, and growing pressure on Australian policymakers to clarify how cross-border transfers involving local companies should be governed. The transatlantic dispute is not a temporary disruption; it is the new operating environment for anyone handling personal data across borders.

The practical takeaway is straightforward: any Australian organisation that processes the data of European residents should treat Schrems II as a structural design constraint, not a paperwork exercise. Map your transfers, assess the legal exposure of your recipients, and build technical and contractual safeguards that would survive scrutiny if challenged by a European regulator. The cost of getting it right now is invariably less than the cost of getting it wrong later.