Search
Contact
31.07.2020 | KPMG Law Insights

Data transfer following the ECJ ruling of July 16, 2020 C-311/18 (“Schrems II”).

On July 16, 2020, the ECJ issued a ruling in the Schrems II case that has far-reaching consequences for international data transfers:

  • The EU – U.S. Privacy Shield is ineffective and can no longer be used for data transfer to the U.S.. There is no grace period.
  • While the EU Standard Contractual Clauses (“SCC”) continue to be effective, the contracting parties must examine whether there are legal regulations in the recipient country that restrict compliance with the SCC and whether, if necessary, an adequate level of data protection can be ensured through supplementary regulations. The same applies to already approved Binding Corporate Rules (“BCR”).
  • The supervisory authorities have the right to prohibit data transfers also on the basis of the SCC, insofar as the regulations made with the SCC are not (or cannot be) complied with in individual cases.

The European Data Protection Board “EDPD/EDSA” announces in its FAQs, as of July 23, 2020, that it will provide guidance on the complementary measures for SCC. These could be legal, technical or organizational measures. For the USA, according to the ECJ’s findings, only measures that technically prevent access by the US authorities without a legality check in accordance with the principles of the GDPR or that give the data subjects the opportunity to seek effective legal protection in the USA should be considered.

Following the EDPD/EDSA, the following recommendation currently exists for dealing with data transfers to third countries:

  1. Data transfer to the U.S. on the basis of the EU-U.S. Privacy Shield will not continue. Check whether the data transfer can be switched to another legal basis, e.g. the SCC, or whether there is an exceptional circumstance pursuant to Art. 49 GDPR.
  2. When transferring data to the U.S. and other third countries based on SCCs, data recipients in the third countries must check whether they can comply with SCCs in their country and inform the data exporters in the EU. The same is true for BCR. All data exporters in the EU should therefore immediately write to their data recipients in third countries and ask for appropriate information. No more information needs to be obtained for the USA, as the ECJ ruling already contains all the information.
  3. If the data recipient in the third country declares that it cannot comply with the SCC or does not provide information, both (data exporter and data importer) must check whether the security gap can be closed by supplementary legal, technical or organizational measures and agree on these measures in an amendment agreement to the concluded SCC.
  4. If the data recipient in the third country cannot comply with the SCC, the security gap cannot be closed by supplementary measures and Art. 49 GDPR does not apply, the data must be moved to the EU. If this is not possible, the responsible supervisory authority must be informed.

We are happy to support you, e.g. with the

  • Analysis of your service relationships with data recipients in third countries with regard to any need for adaptation
  • additions to the SCC required as a result
  • Analysis of the legal situation in third countries, as well as for
  • Responding to requests or orders from data protection authorities

We will provide you with further information on the implementation of the ECJ ruling “Schrems II” in third countries, in particular in the USA, in our 2 webinar series, in German together with the experts from KPMG AG Wirtschaftsprüfungsgesellschaft and in English together with our lawyer colleagues from Nelson Mullins Riley & Scarborough LLP in the USA, as well as with our lawyer colleagues from other countries, planned for the end of August 2020.

Explore #more

03.09.2025 | In the media

Guest article in the insurance industry: Embedded Insurance – More than just a new sales channel

The insurance industry is facing a paradigm shift. Traditional sales models are increasingly being supplemented by innovative approaches aimed at facilitating access to insurance policies…

03.09.2025 | KPMG Law Insights

Supply Chain Act: reporting obligation no longer applies, sanctions reduced

In the coalition agreement, the coalition partners agreed to abolish the Supply Chain Due Diligence Act (LkSG) as part of the implementation of the European…

29.08.2025 | In the media

Statement by Ulrich Keunecke on the special infrastructure fund in Politico

KPMG Law financial expert Ulrich Keunecke explains how the infrastructure special fund can be leveraged with capital from private investors. You can find the article…

25.08.2025 | Deal Notifications

KPMG Law is advising APELOS on the refinancing and acquisition of a practice group with around 50 practice locations.

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised APELOS Therapie GmbH, a leading therapy practice group in Germany, on the refinancing…

15.08.2025 | In the media

KPMG Law Statement in Die-Stiftung.de on the topic of foundation registers – The long road to digital order

The entry into force of the foundation law reform on July 1, 2023 marks a turning point in the German foundation system. The list of…

14.08.2025 | KPMG Law Insights

Electromobility in logistics – legal challenges

In order to reduce its CO2 emissions, the logistics industry is increasingly turning to electromobility. This is not only due to ESG regulations such as…

07.08.2025 | KPMG Law Insights

NIS2: How energy suppliers must protect themselves against cyber attacks

In July 2025, the Military Counterintelligence Service reported a significant increase in spying attempts and disruptive measures by the Russian secret service, according to media…

06.08.2025 | KPMG Law Insights

Tax havens: When business relationships trigger criminal proceedings

A German tech company had been paying license fees to a contractual partner in Panama for years without ever having any problems. However, few people

06.08.2025 | Deal Notifications

KPMG Law, KPMG in Germany and KPMG in Switzerland advised Bureau Veritas on the acquisition of Dornier Hinneburg and its Swiss subsidiary Hinneburg Swiss

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) together with KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) and KPMG AG Switzerland advised Bureau Veritas Group (Bureau Veritas) on the acquisition…

05.08.2025 | Deal Notifications

KPMG Law advises Athagoras Holding GmbH on the acquisition of IGES Group

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) provided legal advice to Athagoras Holding GmbH, a platform of the Munich-based PE firm Greenpeak Partners, on the acquisition…

Contact

Dr. Konstantin von Busekist

Managing Partner
Head of Global Compliance Practice
KPMG Law EMA Leader

Tersteegenstraße 19-23
40474 Düsseldorf

Tel.: +49 211 4155597123
kvonbusekist@kpmg-law.com

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

Maik Ringel

Senior Manager

Münzgasse 2
04107 Leipzig

Tel.: +49 341 22572563
mringel@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll