Schrems II is the Court of Justice judgment of 16 July 2020 that struck down the EU-US Privacy Shield. It made every exporter of personal data check the law of the destination country. For AI, it applies each time a prompt containing personal data reaches a model run by a US company.

Summary

  1. Transfers to the US are lawful today, with an open question. The Data Privacy Framework has applied since 10 July 2023 and the General Court upheld it in September 2025. An appeal is pending, and in July 2026 the EDPB asked the Commission to reassess it.11
  2. An EU endpoint helps only if nobody outside the EU has access. Global routing, remote support and US access requests can still create a transfer.15
  3. Encryption does not fix inference. A model needs the prompt in the clear. For that case the EDPB found no effective technical safeguard. The controls left are less personal data, EU-only processing, zero retention or self-hosting.3

What is Schrems II?

Austrian activist Maximilian Schrems complained that Facebook sent his data to US servers, where US intelligence agencies could reach it. In case C-311/18 the Court of Justice declared the Privacy Shield decision invalid. US surveillance programmes were "not limited to what is strictly necessary", and Europeans had no remedy before an independent body.1

The Court kept standard contractual clauses (SCCs) alive, with a condition. Exporter and importer must verify, before any transfer, that the destination country's law lets the clauses work. If they cannot, the exporter must suspend the transfer. A supervisory authority must step in if the exporter does not.1 That duty to check is the part of Schrems II that still binds every AI project.

How did EU-US data transfers get here? A timeline from 2015 to 2026

Three frameworks, two annulments and one pending appeal. The table lists the dates that changed what an exporter must do.

EU-US data transfer rules, key dates

Date Event Effect
6 Oct 2015 Schrems I, case C-362/14 Safe Harbour invalid
12 Jul 2016 Privacy Shield, Decision 2016/1250 Replaces Safe Harbour
16 Jul 2020 Schrems II, case C-311/18 Privacy Shield invalid; SCCs survive
10 Nov 2020 EDPB Recommendations 01/2020 Six-step roadmap, for consultation
4 Jun 2021 New SCCs, Decision 2021/914 Exporters must assess local law
18 Jun 2021 EDPB Recommendations, version 2.0 Final roadmap and use cases
7 Oct 2022 US Executive Order 14086 Limits on US signals intelligence
10 Jul 2023 DPF adequacy, Decision 2023/1795 Free flow to certified US firms
9 Oct 2024 First DPF review Works; next review in three years
3 Sep 2025 Latombe, case T-553/23 General Court upholds the DPF
31 Oct 2025 Appeal C-703/25 P lodged Court of Justice to decide
12 Jun 2026 FISA Section 702 statute lapses Certifications run to March 2027
29 Jun 2026 Trump v. Slaughter FTC members removable at will
31 Jul 2026 EDPB letter to the Commission Asks for a DPF reassessment

Sources: CJEU press release 91/20; General Court press release 106/25; EDPB Recommendations 01/2020; Decisions 2021/914 and 2023/1795; Commission review report of 9 October 2024; Official Journal notice of C-703/25 P; Supreme Court No. 25-332; EDPB letter of 31 July 2026; EFF and NBC News on Section 702. Accessed 1 October 2026.

The Court of Justice has struck down both earlier frameworks on the same ground: US surveillance law. The current one has survived the General Court; the Court of Justice has yet to rule.

Safe Harbour lasted fifteen years, Privacy Shield four

Both fell at the Court of Justice. The current framework is three years old and under appeal.

Safe Harbour lasted 15 years, Privacy Shield 4; the Data Privacy Framework is 3 years in.

Time from adoption to invalidation, or to 1 October 2026, years

Invalidated by the Court of Justice In force, appeal pending
0 4 8 12 16 15.2 4.0 3.2 Safe Harbour 2000 to 2015 Privacy Shield 2016 to 2020 Data Privacy Framework, 2023¹

1 Counted to 1 October 2026; appeal C-703/25 P pending at the Court of Justice.

Source: Lindstead calculation from decision and judgment dates in General Court press release 106/25 (3 September 2025) and CJEU press release 91/20 (16 July 2020)

A design that works only under the Data Privacy Framework depends on the outcome of the pending appeal. The fallback is SCCs, and they come with the assessment duty Schrems II created.

Is the EU-US Data Privacy Framework still valid in 2026?

Yes. The Commission adopted it on 10 July 2023, after US Executive Order 14086 limited signals intelligence to what is necessary and proportionate and set up a Data Protection Review Court.5 Its first review, on 9 October 2024, found the framework working and set the next review three years later.7 On 3 September 2025 the General Court rejected French MP Philippe Latombe's challenge. It found the review court independent, and held that bulk collection needs no prior authorisation if a court can review it afterwards.2

Four developments in 2026 keep the question open:

  • The appeal. Latombe appealed on 31 October 2025, as case C-703/25 P.8 In June 2026 Microsoft confirmed it had intervened on the Commission's side.9 Lindstead found no hearing date, Advocate General opinion or judgment as of 1 October 2026.
  • FTC independence. On 29 June 2026 the US Supreme Court held in Trump v. Slaughter that the President may remove FTC commissioners at will.10 The FTC enforces company commitments under the framework. On 31 July 2026 the EDPB asked the Commission to assess whether the ruling affects the adequacy decision, which cites the FTC's for-cause protection.11
  • Oversight. Three members of the Privacy and Civil Liberties Oversight Board were removed in January 2025. Two sued; the D.C. Circuit hears the case on 17 November 2026.12
  • Section 702. The statute lapsed on 12 June 2026.13 Collection continues under a yearlong court certification that runs to March 2027.14

None of this suspends the framework. A transfer to a certified US company is lawful today. The Commission has said the US safeguards apply to all transfers, whatever the tool, which also supports SCC assessments.6 The US CLOUD Act is a separate question: the framework makes a transfer lawful, but does not limit what US law can compel. The guide The US CLOUD Act and your AI data covers it.

Is sending prompts to an AI API a data transfer to the USA?

The EDPB applies three cumulative tests. The exporter is subject to the GDPR. It discloses or makes personal data available to another controller or processor. That importer is in a third country.15 A prompt with a customer name, a patient note or an employee record sent to a US endpoint meets all three. Remote access from a third country, for example for support, counts as a transfer too.3

Inference adds a specific problem. The EDPB's Use Case 6 covers processors that need data in the clear. Where the destination's law allows access beyond what is necessary and proportionate, the EDPB could not envisage an effective technical measure. Encryption in transit and at rest does not help when the importer holds the keys.3 A language model reads every prompt in the clear.

Five ways to run a model, and where Schrems II bites

Set-up Transfer? Residual risk Main control
US provider, US or global endpoint Yes US access to prompts DPF or SCCs plus TIA
US provider, EU region, routed Yes, when routed out Inference in any geography Pin EU or EU data zone
US provider, EU-only processing No, if no outside access Support access, US orders Contract, zero retention
EU-owned provider, EU endpoint No Its own sub-processors Article 28 contract
Self-hosted model in the EU No Own security and logs Article 32 measures

No transfer, EU law only No transfer on paper, third-country access possible Transfer, needs a Chapter V tool

Sources: EDPB Guidelines 05/2021 (version 2.0) and Recommendations 01/2020 (version 2.0); GDPR Articles 28, 32 and 44 to 49; Lindstead classification. Accessed 1 October 2026.

When does an EU endpoint of a US provider still carry transfer risk?

The EDPB answers with Example 12 of its Guidelines 05/2021. An EU processor owned by a third-country parent, with processing only in the EU and no access from outside, does not make a transfer. If it obeys an access request from third-country authorities, that disclosure is a transfer. The controller must weigh that risk before choosing the processor, under Article 28.15 Four gaps recur in AI contracts:

  • Routing. At Microsoft, a "Global" deployment may process prompts in any geography where the model runs. An EU data zone keeps processing inside EU member states.16 Anthropic's own API offers only "global" and "us" inference and US-only workspace storage. On Amazon Bedrock and Google Cloud, the region follows the endpoint chosen.18
  • Side features. Microsoft runs batch jobs as a Global deployment type. Data rests in the chosen geography, but processing may happen wherever the model is deployed.16
  • Abuse monitoring. OpenAI keeps abuse-monitoring logs for up to 30 days by default. European residency requires zero data retention or a similar approved control.17 Microsoft stores flagged prompts for human review unless a customer is approved for modified abuse monitoring. For EEA deployments, its reviewers sit in the EEA.16
  • The contracting entity. A US parent that signs the contract and runs support is an importer, whatever the region of the endpoint.

An EU endpoint is still the right default for a US model. It narrows the question to one risk: a US order to the provider. Whether that risk is acceptable depends on the data. Health data is a special category under Article 9, so the bar is higher; the healthcare sector page covers the sector rules.

What happens when an organisation gets Schrems II wrong?

Three large fines show the cost. Meta relied on new SCCs with supplementary measures; the Irish regulator found they did not address the risks the Court identified.19 Uber stopped using SCCs for over two years and kept sending driver data to its US headquarters, in some cases including criminal and medical data.21

Three transfer decisions, almost €2 billion

Meta, TikTok and Uber were fined a combined €1.98 billion for unlawful transfers.

Three decisions on unlawful transfers since Schrems II total €1.98 billion in fines.

Fine for unlawful transfers of personal data, € million

Transfers to the United States Transfers to China
0 200 400 600 800 1,000 1,200 1,400 1,200 485 290 Meta Ireland, 2023 TikTok¹ Ireland, 2025 Uber Netherlands, 2024

1 €485 million for unlawful transfers (Article 46(1) GDPR) out of a €530 million total; €45 million was for transparency.

Source: Data Protection Commission (Ireland), 22 May 2023 and 2 May 2025; Autoriteit Persoonsgegevens, 26 August 2024

The TikTok case matters most for AI. It turned on remote access: staff in China could reach EEA user data stored elsewhere. The regulator found that TikTok had not shown this data was protected to EU standards, and that its assessment of Chinese law fell short.20 The same logic applies to support engineers who can open AI logs from outside the EU.

Checklist: sending personal data to an AI API under Schrems II

The EDPB's six-step roadmap, applied to a model API.3 Each step should leave a document that a regulator or auditor can read.

  1. Map every flow. Record the provider entity, endpoint, region, deployment type, retention, sub-processors and who can access logs. Include embeddings, files, fine-tuning data and evaluation sets.
  2. Keep personal data out of prompts. Remove or pseudonymise names and identifiers before the call, where the use case allows it. What is not sent is not transferred.
  3. Pick the transfer tool. For the Data Privacy Framework, check the contracting entity on the official list.23 Otherwise sign SCCs under Decision 2021/914: module two for controller to processor, module three for processor to processor.4
  4. Assess the destination's law. SCC transfers need a documented transfer impact assessment under clause 14. Cover Section 702, the 2026 changes above and the provider's record of government requests.
  5. Pin processing to the EU. Choose EU regions or an EU data zone, never global routing. Check caching, batch jobs and abuse-monitoring stores separately.
  6. Switch off retention. Apply for zero data retention or modified abuse monitoring, and confirm in writing what is still kept and where.
  7. Fix the contract. An Article 28 agreement with an EU contracting entity, a sub-processor list, and a duty to notify and challenge government access requests.22
  8. Self-host where the assessment fails. Special category data, privileged files and trade secrets usually belong on a model the organisation runs itself. Large-scale processing of such data needs a data protection impact assessment under Article 35.
  9. Set review triggers. Reassess on the Latombe appeal judgment, any Commission action on the EDPB letter, a Section 702 reauthorisation and every change to provider terms.

The GDPR is one layer. The AI Act adds its own duties for deployers and providers; dates are in the AI Act timeline. Lindstead's AI governance and compliance work covers the flow map, transfer impact assessment and contract review.

When is self-hosting the cleaner answer to Schrems II?

When the data cannot leave and the assessment cannot pass. An open-weight model on EU hardware, operated by the organisation or an EU-owned provider, involves no transfer to a model maker and no US importer. The GDPR still applies in full: lawful basis, access control, retention and security under Article 32. The self-hosted LLM guide covers models, hardware and cost. The European cloud GPU price index shows what EU-owned capacity costs.

Self-hosting is a trade, with its own risks. Many organisations split the work: US APIs for public or pseudonymised content, a self-hosted model for regulated data. Lindstead's model selection and AI deployment services build that split.

Frequently asked questions

  • Schrems II is the Court of Justice judgment of 16 July 2020 in case C-311/18. It struck down the EU-US Privacy Shield because US surveillance law went beyond what EU law allows. Standard contractual clauses stayed valid, but every exporter must now check that the destination country's law lets the clauses work.

  • Yes, as of 1 October 2026. The General Court upheld it on 3 September 2025 and an appeal, case C-703/25 P, is pending at the Court of Justice. On 31 July 2026 the EDPB asked the Commission to assess whether Trump v. Slaughter affects the framework.

  • Yes, when prompts with personal data reach a provider in the United States or are routed there. It is lawful under the Data Privacy Framework if the provider is certified, or under standard contractual clauses with a transfer impact assessment. EU data residency can avoid the transfer, if nobody outside the EU can access the data.

  • Partly. If processing stays in the EU and nobody outside the EU has access, the EDPB does not count it as a transfer. The provider can still receive US access requests, and complying would be a transfer. The EDPB expects controllers to weigh that risk before choosing the processor.

  • Not for the transfer itself: the adequacy decision covers transfers to certified US organisations. Check that the contracting entity appears on the Data Privacy Framework List. Many organisations still document a fallback, because both earlier frameworks fell at the Court of Justice.

Next step: The AI Sovereignty Scan maps which AI data flows leave the EU, which rest on the Data Privacy Framework alone, and what to move first.

Sources

  1. Court of Justice of the EU, Press release 91/20, judgment in case C-311/18 (Schrems II), 16 July 2020. curia.europa.eu/jcms/upload/docs/application/pdf/2020-07/cp200091en.pdf
  2. General Court of the EU, Press release 106/25, judgment in case T-553/23, Latombe v Commission, 3 September 2025. Footnotes list Schrems I (C-362/14, 6 October 2015), Decisions 2000/520/EC and 2016/1250 and Executive Order 14086. curia.europa.eu/site/upload/docs/application/pdf/2025-09/cp250106en.pdf
  3. EDPB, Recommendations 01/2020 on measures that supplement transfer tools, version 2.0, 18 June 2021. www.edpb.europa.eu/our-work-tools/our-documents/recommendations/recommendations-012020-measures-supplement-transfer_en
  4. Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses, EUR-Lex. eur-lex.europa.eu/eli/dec_impl/2021/914/oj
  5. Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the EU-US Data Privacy Framework, EUR-Lex. eur-lex.europa.eu/eli/dec_impl/2023/1795/oj
  6. European Commission, Questions and answers: EU-US Data Privacy Framework, 10 July 2023. ec.europa.eu/commission/presscorner/detail/en/qanda_23_3752
  7. European Commission, Report on the first periodic review of the EU-US Data Privacy Framework, 9 October 2024. commission.europa.eu/document/download/25695177-8073-4ce3-bf81-eb816dc6b468_en?filename=Report+on+the+first+periodic+review+of+the+functioning+of+the+adequacy+decision+on+the+EU-US+Data+Privacy+Framework.pdf
  8. Appeal in case C-703/25 P, Latombe v Commission, notice in the Official Journal, EUR-Lex. eur-lex.europa.eu/eli/C/2025/6610/oj/eng
  9. Solutions Numériques, Microsoft defends EU-US data transfers in the Latombe appeal, June 2026 (press report). www.solutions-numeriques.com/data-privacy-framework-microsoft-defend-les-transferts-de-donnees-ue-etats-unis/
  10. Supreme Court of the United States, Trump v. Slaughter, No. 25-332, 29 June 2026. www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf
  11. EDPB, Letter to Commissioner McGrath on Trump v. Slaughter, 31 July 2026. www.edpb.europa.eu/system/files/2026-08/edpb_letter_20260731_us_supremecourt_judgment_trump_v_slaughter_en.pdf
  12. Brennan Center for Justice, LeBlanc v. Privacy and Civil Liberties Oversight Board, case tracker, updated 21 September 2026. www.brennancenter.org/our-work/research-reports/leblanc-v-us-privacy-and-civil-liberties-oversight-board
  13. EFF, Section 702 has expired, 12 June 2026. www.eff.org/deeplinks/2026/06/victory-702-has-expired
  14. NBC News, A key US spying program expires: what does that mean?, June 2026. www.nbcnews.com/politics/trump-administration/fisa-section-702-warrantless-foreign-surveillance-expire-congress-rcna349798
  15. EDPB, Guidelines 05/2021 on the interplay between Article 3 and Chapter V of the GDPR, version 2.0, 14 February 2023. www.edpb.europa.eu/system/files/2023-02/edpb_guidelines_05-2021_interplay_between_the_application_of_art3-chapter_v_of_the_gdpr_v2_en_0.pdf
  16. Microsoft Learn, Data, privacy and security for Foundry Models sold by Azure, updated June 2026. learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy
  17. OpenAI, Data controls in the OpenAI platform (data residency and retention). developers.openai.com/api/docs/guides/your-data
  18. Anthropic, Claude Platform documentation, Data residency. platform.claude.com/docs/en/build-with-claude/data-residency
  19. Data Protection Commission (Ireland), Conclusion of inquiry into Meta Ireland, 22 May 2023. www.dataprotection.ie/en/news-media/press-releases/Data-Protection-Commission-announces-conclusion-of-inquiry-into-Meta-Ireland
  20. Data Protection Commission (Ireland), Fine of €530 million on TikTok over transfers to China, 2 May 2025. www.dataprotection.ie/en/news-media/latest-news/irish-data-protection-commission-fines-tiktok-eu530-million-and-orders-corrective-measures-following
  21. Autoriteit Persoonsgegevens, Fine of €290 million on Uber for transfers of drivers' data to the US, 26 August 2024. www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-of-290-million-euro-on-uber-because-of-transfers-of-drivers-data-to-the-us
  22. Regulation (EU) 2016/679 (GDPR), EUR-Lex. eur-lex.europa.eu/eli/reg/2016/679/oj
  23. US Department of Commerce, Data Privacy Framework List. www.dataprivacyframework.gov/list

Method: desk research of public primary sources, accessed 1 October 2026. Court, regulator and provider documents are quoted as published; press reports are labelled. This guide is not legal advice. Corrections: contact@lindstead.com.