Schrems II
What is Schrems II?
The 2020 ruling by the Court of Justice of the European Union that invalidated the EU-US Privacy Shield and imposed additional obligations on organisations using Standard Contractual Clauses for international data transfers.
Terms that appear alongside schrems ii
Each of these is named in at least one of the same controls as schrems ii. The number is how many controls name both.
- impact assessment 24 shared controls
- transfer impact assessment 24 shared controls
- gdpr 23 shared controls
- consent 19 shared controls
- privacy framework 18 shared controls
- binding corporate rules 17 shared controls
- data privacy framework 16 shared controls
- standard contractual clauses 16 shared controls
Frameworks that govern schrems ii
What the standards actually require on schrems ii
Requirements naming schrems ii across 6 standards, quoted from the control text.
Provides for the Datatilsynet's role where no adequacy decision exists, supporting the assessment of transfers consistent with CJEU case law (Schrems II) and the GDPR transfer rules.
DK-502-§31 · Third-country transfer determinations (post Schrems II) →Cross-border transfer of personal data from Italy is governed by GDPR Chapter V + Italian Codice + Italian Garante guidance. (1) GDPR Chapter V Transfer Mechanisms: (a) Adequacy decisions per Commission - Andorra + Argentina + Canada (commercial organisations)...
ItalyCodice-CrossBorder-Transfer-Adequacy-SCCs-BCRs-Retention-ItalianSectorRules-EUDataAct · Italy Codice Cross-Border Transfer + EU Adequacy + Standard Contractual Clauses + Binding Corporate Rules + EU Data Act + Italian Sector Retention Rules + Schrems II + Transfer Impact Assessment →Greece Law 4624/2019 operational provisions covering Data Subject Rights + Breach + DPIA + Transfers + Children. DATA SUBJECT RIGHTS (per GDPR Art.
GR-DPA-DataSubjectRights-Breach-DPIA-Transfers-Children · Greece Law 4624/2019 Data Subject Rights, Breach Notification, DPIA, International Transfers and Children's Data →Infotv operates in parallel with EU GDPR (Regulation (EU) 2016/679) since May 2018 with Hungarian specifics: criminal data treatment + 25-day SLA + 16-year age + works council + Hungarian-language privacy notices + NAIH-Hungarian-specific DPIA triggers.
HU-INFOTV-Coord-GDPR-International-Transfers-NIS2-Hungary · HU Infotv Coordination with GDPR + International Transfers + Hungarian Cybersecurity Act XXIII of 2023 (NIS2) + 2024-2025 Pipeline →Chapter V (Articles 27-30) Transfer of Personal Data Abroad. Articles 27 + 28 + 29 + 30 govern cross-border transfers per GDPR Articles 44-49 transposition.
ICELAND-Act90-Chap5-CrossBorder-EEA-AdequacyDecisions-SCC-BCR · Iceland Act 90/2018 - Chapter V Cross-Border Transfer of Personal Data + EEA + Adequacy + SCCs + BCRs + Article 30 Privacy Policy →Standard 8 per Section 27 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall not be transferred outside Jamaica unless adequate protection is provided.
JM-DPA2020-Standard8-Transfers-Outside-Jamaica-Sec27-Adequacy-Decisions-Standard-Contractual-Clauses-BCR-Derogations · Jamaica DPA 2020 Standard 8 - Transfers Outside Jamaica + Section 27 + Adequacy Decisions + Standard Contractual Clauses + Binding Corporate Rules + Derogations + Cross-Border Data Flows + Caribbean Community + International Data Privacy →Questions people ask about schrems ii
What is Schrems II?
Why is Schrems II important for compliance?
Which compliance frameworks address Schrems II?
Where can I learn more about Schrems II?
See how Schrems II applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.