{"id":1768,"date":"2020-07-21T10:19:09","date_gmt":"2020-07-21T09:19:09","guid":{"rendered":"https:\/\/www.calligo.io\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/"},"modified":"2024-01-18T14:40:19","modified_gmt":"2024-01-18T14:40:19","slug":"step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation","status":"publish","type":"post","link":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/","title":{"rendered":"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation"},"content":{"rendered":"<h2 style=\"font-size: 36px; text-align: center;\">Data Privacy News: Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation, and what it means for you<\/h2>\n<p>Last Thursday, the Court of Justice of the EU (CJEU), the European Union\u2019s top court, struck down the EU-US data sharing agreement, Privacy Shield, technically known as the EU-US Data Protection Shield.<\/p>\n<p>The case known as Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (also referred to as Schrems II)\u00a0ruled that the data sharing agreement between the EU and the US, Privacy Shield, is not suitable as it does not provide adequate protection for EU citizens\u2019 personal data when stored in the United States.<\/p>\n<p style=\"text-align: center;\"><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"width: 291px; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/Schrems-II.png\" alt=\"Schrems II\" width=\"291\" height=\"693\" \/><\/p>\n<blockquote>\n<p style=\"text-align: center;\"><span style=\"color: #00beea;\"><em>\u201cThe Court of Justice invalidates Decision 2016\/1250 on the adequacy of the protection provided by the EU-US Data Protection Shield\u201d<\/em><\/span><\/p>\n<\/blockquote>\n<p class=\"CalligoBody\" style=\"text-align: left;\" align=\"left\">The above quote is the opening statement of the official press release from the CJEU regarding the case. Whilst the sentence appears simple enough, its ramifications are far more serious, and essentially puts thousands of businesses at risk of breaching GDPR.<\/p>\n<p class=\"CalligoBody\" style=\"text-align: left;\" align=\"left\">\n<p class=\"BodyText\">Privacy Shield was one of the few mechanisms under GDPR where EU personal data could be transferred to the US, and with its immediate shut down, it leaves over 5,300 organizations who relied on this mechanism to find a new and safe way to transfer data.<\/p>\n<p class=\"BodyText\">\n<h2 style=\"font-size: 24px;\"><span style=\"color: #00beea;\">The history behind the Schrems II ruling<\/span><\/h2>\n<table style=\"border-color: #99acc2; border-collapse: collapse; table-layout: fixed; margin-left: auto; margin-right: auto; display: table; height: 843px; border-style: hidden;\" width=\"808\">\n<tbody>\n<tr style=\"height: 102px;\">\n<td style=\"width: 122px; height: 102px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>June 2013<\/strong><\/td>\n<td style=\"width: 645px; height: 102px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">In June 2013, National Security Agency (NSA) whistleblower, Edward Snowden, discloses information regarding PRISM, a US government surveillance programme that collected data from some of American\u2019s biggest tech companies which included Facebook, Google and Apple.<\/td>\n<\/tr>\n<tr style=\"height: 177px;\">\n<td style=\"width: 122px; height: 177px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>June 2013<\/strong><\/td>\n<td style=\"width: 645px; height: 177px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">In light of Edward Snowden\u2019s disclosures, Max Schrems files his complaint to the Irish Data Protection Commission regarding Safe Harbor, an agreement prior to Privacy Shield, that was used to transfer EU citizens\u2019 data to the US.<\/p>\n<p>Schrems argued that by collecting his personal data and transferring it to the US for processing, Facebook was exposing him to mass surveillance, which is illegal under the EU\u2019s Charter of Fundamental Rights.<\/td>\n<\/tr>\n<tr style=\"height: 58px;\">\n<td style=\"width: 122px; height: 58px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>June 2014<\/strong><\/td>\n<td style=\"width: 645px; height: 58px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">The following year, the Irish High Court refers the case, now referred to as the &#8220;Safe Habor decision&#8221; or \u201cSchrems I\u201d, to the CJEU (\u201cMax Schrems v. Data Protection Commissioner\u201d)<\/td>\n<\/tr>\n<tr style=\"height: 80px;\">\n<td style=\"width: 122px; height: 80px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>October 2015<\/strong><\/td>\n<td style=\"width: 645px; height: 80px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">The CJEU rules in Schrems\u2019 favour and invalidates Safe Harbor, as it does not offer EU citizens adequate protection of their personal data against mass surveillance programmes in the US.<\/td>\n<\/tr>\n<tr style=\"height: 124px;\">\n<td style=\"width: 122px; height: 124px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>October \u2013<br \/>\nDecember 2015<\/strong><\/td>\n<td style=\"width: 645px; height: 124px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">With the same motive as in 2013, i.e. resenting the potential exposure of his personal data to mass surveillance, Schrems files a second complaint to the Irish Data Protection Commission re the use of EU Standard Contractual Clauses, known as \u201cData Protection Commissioner v Facebook Ireland and Maximillian Schrems\u201d. The case will also be referred as \u201cSchrems II\u201d.<\/td>\n<\/tr>\n<tr style=\"height: 58px;\">\n<td style=\"width: 122px; height: 58px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>July 2016<\/strong><\/td>\n<td style=\"width: 645px; height: 58px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">EU-US Privacy Shield was adopted as a mechanism for EU data transfers to the US, replacing Safe Harbor.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"width: 122px; height: 36px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>October 2017<\/strong><\/td>\n<td style=\"width: 645px; height: 36px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">The Irish High Court refers the Schrems II case to the CJEU<\/td>\n<\/tr>\n<tr style=\"height: 59px;\">\n<td style=\"width: 122px; height: 59px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>May 2018<\/strong><\/td>\n<td style=\"width: 645px; height: 59px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">On the 25<sup>th<\/sup> May 2018, Europe enforces its new data protection framework, the General Data Protection Regulation (GDPR) .<\/td>\n<\/tr>\n<tr style=\"height: 37px;\">\n<td style=\"width: 122px; height: 37px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>July 2019<\/strong><\/td>\n<td style=\"width: 645px; height: 37px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">The first hearing on the case Schrems II takes place at the CJEU<\/td>\n<\/tr>\n<tr style=\"height: 53px;\">\n<td style=\"width: 122px; height: 53px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>December 2019<\/strong><\/td>\n<td style=\"width: 645px; height: 53px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">CJEU Advocate General publishes his opinion on the Schrems II case.<\/td>\n<\/tr>\n<tr style=\"height: 59px;\">\n<td style=\"width: 122px; height: 59px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\"><strong>16 July 2020<\/strong><\/td>\n<td style=\"width: 645px; vertical-align: middle; height: 59px; background-color: #fafafa; border: 1px dashed #666666; padding: 4px;\">CJEU announce their judgement on the case, with Privacy Shield being immediately invalidated, but upholding data transfer via SCCs.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"last\" style=\"font-size: 24px;\"><span style=\"color: #00beea;\">What did they say and why?<\/span><\/h2>\n<p>The important thing to note is that this decision was not based on business practices within the US, but in fact, on the surveillance and the regulatory climate within the USA.<\/p>\n<p>As the U.S. Chamber of Commerce Executive Vice President and Head of International Affairs states, \u201c<em>\u2026[the case] focuses not on commercial uses of data, but on concerns over potential government access.<\/em>\u201d<\/p>\n<p>There were two main rulings re Privacy Shield:<\/p>\n<table style=\"width: 100%; border-collapse: collapse; table-layout: fixed; display: inline-table; border: 0px none #99acc2;\">\n<tbody>\n<tr>\n<td style=\"width: 9.39394%; border-style: none; padding: 4px;\"><img decoding=\"async\" style=\"width: 54px;\" src=\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/interface-1.png\" alt=\"interface (1)\" width=\"54\" \/><\/td>\n<td style=\"width: 90.6061%; border-style: none; padding: 4px;\">US law enforcement agencies\u2019 surveillance is not \u201climited to what is strictly necessary\u201d \u2013 the EU standard. Therefore, any EU personal data transferred to the US under Privacy Shield is additionally \u2013 and unacceptably \u2013 exposed to surveillance. In fact, the judgement also revealed that strictly, US law states that surveillance on non-US citizens only needs to be \u201cas tailored as feasible\u201d.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 9.39394%; border-style: none; padding: 4px;\"><img decoding=\"async\" style=\"width: 54px;\" src=\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/interface-3.png\" alt=\"interface (3)\" width=\"54\" \/><\/td>\n<td style=\"width: 90.6061%; border-style: none; padding: 4px;\">Protection of EU citizens\u2019 privacy rights in the US is too weak. Neither EU member states, nor the US Ombudsman (set up to help EU citizens make any case) have either the authority or the practical ability to enforce GDPR in the US.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Considering these findings, it hardly comes as a surprise that the result came in as it did.<\/p>\n<blockquote>\n<p style=\"text-align: center;\"><span style=\"color: #00beea;\">\u201cIn the light of all of the foregoing considerations, it is to be concluded that the Privacy Shield Decision is invalid.\u201d<\/span><\/p>\n<\/blockquote>\n<p>There was then an additional key ruling on Standard Contractual Clauses:<\/p>\n<table style=\"width: 100%; border-collapse: collapse; table-layout: fixed; display: inline-table; border: 0px none #99acc2;\">\n<tbody>\n<tr>\n<td style=\"width: 9.39394%; border-style: none; padding: 4px;\"><img decoding=\"async\" style=\"width: 54px;\" src=\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/interface-4.png\" alt=\"interface (4)\" width=\"54\" \/><\/td>\n<td style=\"width: 90.6061%; border-style: none; padding: 4px;\">Standard Contractual Clauses remain valid, though with a caveat that both the data \u201cexporter\u201d and \u201cimporter\u201d must review whether the destination country offers a level of protection equivalent to that of the EU, and in particular what data access rights the country\u2019s authorities may have.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Given the surveillance and regulatory climate of the US, and the judgement also actively encouraging Supervisory Authorities to strike down any SCCs where the guarantees within them are not upheld or capable of being upheld, it is unclear for how long SCCs will survive as a recognised legitimate mechanism.<\/p>\n<p>Unsurprisingly, guidance is soon expected from the EU and Supervisory Authorities, though in the meantime, SCCs are an entirely legitimate data transfer mechanism.<\/p>\n<h2 style=\"font-size: 24px;\"><span style=\"color: #00beea;\">What does this mean in practice?<\/span><\/h2>\n<p>If your business transfers EU data subjects\u2019 data to the US, you may need to take certain steps to ensure continued compliance with the GDPR.<\/p>\n<p>Circumstances include:<\/p>\n<ul>\n<li><span style=\"background-color: transparent;\">US-based organizations receiving data from EU customers<\/span><\/li>\n<li>Moving data internally within your organisation, for example from EU regional office to US HQ<\/li>\n<li>Using US suppliers for EU service delivery<\/li>\n<li>\u2026and plenty more<\/li>\n<\/ul>\n<p>If any of these or similar circumstances apply to you, we have set out below some \u201cwhat if\u2026?\u201d scenarios to help guide your next steps.<\/p>\n<h2 style=\"font-size: 24px;\"><span style=\"color: #00beea;\">1. What if I am Privacy Shield-certified?<\/span><\/h2>\n<p>Privacy Shield may be insufficient, but it is still in operation. The US Chamber of Commerce has stated that it will<\/p>\n<blockquote>\n<p style=\"text-align: center;\"><span style=\"color: #00beea;\">\u201ccontinue to administer the Privacy Shield program\u2026[and] today\u2019s decision does not relieve participating organizations of their Privacy Shield obligations.\u201d<\/span><\/p>\n<\/blockquote>\n<p>Therefore, if you are Privacy Shield-certified, you must maintain this certification unless you formally withdraw from the scheme.<\/p>\n<p>However, on top of this certification, you will now have to implement another mechanism for the lawful transfer of EU Personal Data to the US.<\/p>\n<h2 style=\"font-size: 24px;\"><span style=\"color: #00beea;\">2. What if I only rely on Privacy Shield to transfer personal data from Europe to the US?<\/span><\/h2>\n<p>The Judgement has determined that Privacy Shield does not offer suitable protections for the transfer of EU Personal Data to the US. This means that you must put in place one of the following mechanisms with immediate effect, and then update your data sharing policies and documentation to reflect the change.<\/p>\n<h3 style=\"font-size: 18px;\"><strong>Standard Contractual Clauses<\/strong><\/h3>\n<p>This is likely to be the most common mechanism relied on for transferring personal data to the US.<\/p>\n<p>SCCs are contract articles pre-approved by the EC for use by organisations performing international transfers of EU personal data. They create the necessary obligations \u2013 beyond those of typical GDPR compliance clauses found in many supplier contracts \u2013 for how the data should be handled by the receiving party (in this case, based in the US).<\/p>\n<p>However, given the uncertainty over SCCs\u2019 future usefulness, this risk ought to be entered on your risk register.<\/p>\n<h3 style=\"font-size: 18px;\">Binding Corporate Rules<\/h3>\n<p>Binding Corporate Rules (legal mechanisms that allow multinational companies to transfer EU personal data to entities outside Europe) would likely be suitable for protecting EU Personal Data moving to the US. However, these require Supervisory Authority approval and take months if not years to finalise. These are therefore unlikely to be a viable option unless your business already has Binding Corporate Rules already in place.<\/p>\n<p>If you are in the process of putting in place Binding Corporate Rules that cover transfers to entities outside Europe, but these are not yet approved, then you will still have to utilise another mechanism pending their approval \u2013 most likely, Standard Contractual Clauses.<\/p>\n<h3 style=\"font-size: 18px;\">Derogations<\/h3>\n<p>There are limited situations in which transfers of personal data to the US may be permitted without any formal mechanism in place. You should obtain legal advice if you are intending to rely on a derogation, as their application is very limited.<\/p>\n<h3 style=\"font-size: 18px;\">Consent<\/h3>\n<p>If you do not believe you will be able to put Standard Contractual Clauses in place and none of the other mechanisms apply, you should obtain the consent of your European data subjects to any transfer of their personal data to the US.<\/p>\n<p>Please note that this consent must still comply with GDPR requirements \u2013 i.e. it must be freely given, specific, informed, and unambiguous.<\/p>\n<h2 style=\"font-size: 24px;\"><span style=\"color: #00beea;\">3. What if I already have Standard Contractual Clauses or Binding Corporate Rules in place?<\/span><\/h2>\n<p class=\"CalligoBody\">Standard Contractual Clauses and Binding Corporate Rules continue to be recognised as an appropriate safeguard for personal data transfers outside Europe.<\/p>\n<p class=\"CalligoBody\">\n<table style=\"width: 100%; border-collapse: collapse; table-layout: fixed; display: table; margin-left: auto; margin-right: auto; border: 0px none #99acc2;\">\n<tbody>\n<tr>\n<td style=\"width: 5%; text-align: center; border-width: 0px; border-style: none; padding: 4px;\"><\/td>\n<td style=\"width: 76.7272%; border-width: 0px; border-style: none; background-color: #00beea; padding: 4px;\">\n<h3 class=\"CalligoBody\" style=\"text-align: center; font-size: 20px;\"><span style=\"color: #f9f9f9;\"><strong><i>Note from our experts on SCCs<\/i><\/strong><\/span><\/h3>\n<p class=\"CalligoBody\"><span style=\"color: #f9f9f9;\">Technically, Standard Contractual Clauses only cover transfers from European controllers to non- European processors\/controllers, the general consensus has historically been that they will not be challenged if used in relation to transfers from European processors to non-European sub-processors \/ controllers, although that may change with the new judgement.<\/span><\/p>\n<p class=\"CalligoBody\"><span style=\"color: #f9f9f9;\">\u00a0<\/span><\/p>\n<p class=\"CalligoBody\"><span style=\"color: #f9f9f9;\">Note too that some Data Processing Agreements may even expressly require the non-European based processor to put Standard Contractual Clauses in place with their non-European sub-processors. You should, nonetheless, get legal advice on whether Standard Contractual Clauses would be enforceable in these circumstances.<\/span><\/p>\n<\/td>\n<td style=\"width: 5%; border-width: 0px; border-style: none; padding: 4px;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Calligo designs continuous safety, privacy, and protection into every business data use, ensuring that every action is legal, ethical, and meaningful.<\/p>\n<p>Find out more about our <a href=\"https:\/\/www.calligo.io\/services\/data-protection-officer-as-a-service\/\" target=\"_blank\" rel=\"noopener\">Data Privacy Services<\/a> and how our experts in data privacy, data security and technology can build and support your data privacy programme by clicking below, or alternatively, contact the team directly, <a href=\"\/contact\/\" rel=\" noopener\">here<\/a>.<\/p>\n<p><a href=\"https:\/\/www.calligo.io\/services\/data-protection-officer-as-a-service\/\" rel=\" noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"width: 1515px;\" src=\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/Data_Privacy_Regulation_Services.jpg\" alt=\"Data_Privacy_Regulation_Services\" width=\"1515\" height=\"522\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our VP of Data Privacy has written a step-by-step guide to Schrems II &#038; Privacy Shield\u2019s invalidation, and what it means for your privacy obligations<\/p>\n","protected":false},"author":33,"featured_media":1666,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[140,141,121],"tags":[],"post_format_type":[40],"class_list":["post-1768","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-privacy-glossary","category-data-protection","category-glossary"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation | Calligo<\/title>\n<meta name=\"description\" content=\"Our VP of Data Privacy has written a step-by-step guide to Schrems II &amp; Privacy Shield\u2019s invalidation, and what it means for your privacy obligations\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation | Calligo\" \/>\n<meta property=\"og:description\" content=\"Our VP of Data Privacy has written a step-by-step guide to Schrems II &amp; Privacy Shield\u2019s invalidation, and what it means for your privacy obligations\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/\" \/>\n<meta property=\"og:site_name\" content=\"Calligo\" \/>\n<meta property=\"article:published_time\" content=\"2020-07-21T09:19:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-18T14:40:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1256\" \/>\n\t<meta property=\"og:image:height\" content=\"912\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Brendan Walsh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@calligocloud\" \/>\n<meta name=\"twitter:site\" content=\"@calligocloud\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Brendan Walsh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/\"},\"author\":{\"name\":\"Brendan Walsh\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f\"},\"headline\":\"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation\",\"datePublished\":\"2020-07-21T09:19:09+00:00\",\"dateModified\":\"2024-01-18T14:40:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/\"},\"wordCount\":1653,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.calligo.io\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg\",\"articleSection\":[\"Data Privacy\",\"Data Protection\",\"Glossary\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/\",\"url\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/\",\"name\":\"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation | Calligo\",\"isPartOf\":{\"@id\":\"https:\/\/www.calligo.io\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg\",\"datePublished\":\"2020-07-21T09:19:09+00:00\",\"dateModified\":\"2024-01-18T14:40:19+00:00\",\"description\":\"Our VP of Data Privacy has written a step-by-step guide to Schrems II & Privacy Shield\u2019s invalidation, and what it means for your privacy obligations\",\"breadcrumb\":{\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage\",\"url\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg\",\"contentUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg\",\"width\":1256,\"height\":912},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.calligo.io\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.calligo.io\/#website\",\"url\":\"https:\/\/www.calligo.io\/\",\"name\":\"Calligo\",\"description\":\"Building value through data\",\"publisher\":{\"@id\":\"https:\/\/www.calligo.io\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.calligo.io\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.calligo.io\/#organization\",\"name\":\"Calligo\",\"url\":\"https:\/\/www.calligo.io\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg\",\"contentUrl\":\"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Calligo\"},\"image\":{\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/calligocloud\",\"https:\/\/www.linkedin.com\/company\/calligo-limited\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f\",\"name\":\"Brendan Walsh\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.calligo.io\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g\",\"caption\":\"Brendan Walsh\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation | Calligo","description":"Our VP of Data Privacy has written a step-by-step guide to Schrems II & Privacy Shield\u2019s invalidation, and what it means for your privacy obligations","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/","og_locale":"en_GB","og_type":"article","og_title":"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation | Calligo","og_description":"Our VP of Data Privacy has written a step-by-step guide to Schrems II & Privacy Shield\u2019s invalidation, and what it means for your privacy obligations","og_url":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/","og_site_name":"Calligo","article_published_time":"2020-07-21T09:19:09+00:00","article_modified_time":"2024-01-18T14:40:19+00:00","og_image":[{"width":1256,"height":912,"url":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg","type":"image\/jpeg"}],"author":"Brendan Walsh","twitter_card":"summary_large_image","twitter_creator":"@calligocloud","twitter_site":"@calligocloud","twitter_misc":{"Written by":"Brendan Walsh","Estimated reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#article","isPartOf":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/"},"author":{"name":"Brendan Walsh","@id":"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f"},"headline":"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation","datePublished":"2020-07-21T09:19:09+00:00","dateModified":"2024-01-18T14:40:19+00:00","mainEntityOfPage":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/"},"wordCount":1653,"commentCount":0,"publisher":{"@id":"https:\/\/www.calligo.io\/#organization"},"image":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg","articleSection":["Data Privacy","Data Protection","Glossary"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/","url":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/","name":"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation | Calligo","isPartOf":{"@id":"https:\/\/www.calligo.io\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage"},"image":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg","datePublished":"2020-07-21T09:19:09+00:00","dateModified":"2024-01-18T14:40:19+00:00","description":"Our VP of Data Privacy has written a step-by-step guide to Schrems II & Privacy Shield\u2019s invalidation, and what it means for your privacy obligations","breadcrumb":{"@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#primaryimage","url":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg","contentUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/group-9@2x.jpg","width":1256,"height":912},{"@type":"BreadcrumbList","@id":"https:\/\/www.calligo.io\/insights\/glossary\/step-by-step-guide-to-schrems-ii-and-privacy-shields-invalidation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.calligo.io\/"},{"@type":"ListItem","position":2,"name":"Step-by-step guide to Schrems II and Privacy Shield\u2019s invalidation"}]},{"@type":"WebSite","@id":"https:\/\/www.calligo.io\/#website","url":"https:\/\/www.calligo.io\/","name":"Calligo","description":"Building value through data","publisher":{"@id":"https:\/\/www.calligo.io\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.calligo.io\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.calligo.io\/#organization","name":"Calligo","url":"https:\/\/www.calligo.io\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/","url":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg","contentUrl":"https:\/\/www.calligo.io\/wp-content\/uploads\/2023\/04\/calligo-og.jpg","width":1200,"height":630,"caption":"Calligo"},"image":{"@id":"https:\/\/www.calligo.io\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/calligocloud","https:\/\/www.linkedin.com\/company\/calligo-limited\/"]},{"@type":"Person","@id":"https:\/\/www.calligo.io\/#\/schema\/person\/e2e0283a3e6c3a237a10e012c081755f","name":"Brendan Walsh","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.calligo.io\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/299d5b23f0682aabb1a2347ddf8b95df04b22cfec378aea17a8f7395c74b2bc8?s=96&d=mm&r=g","caption":"Brendan Walsh"}}]}},"_links":{"self":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/posts\/1768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/comments?post=1768"}],"version-history":[{"count":0,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/posts\/1768\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/media\/1666"}],"wp:attachment":[{"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/media?parent=1768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/categories?post=1768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/tags?post=1768"},{"taxonomy":"post_format_type","embeddable":true,"href":"https:\/\/www.calligo.io\/wp-json\/wp\/v2\/post_format_type?post=1768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}