Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Safe Harbour was a voluntary framework that let participating US companies receive personal data from the EU under a European Commission adequacy decision adopted in 2000. On 6 October 2015, the Court of Justice of the European Union (CJEU) declared that decision invalid in Schrems (Case C-362/14). The Court’s concerns included US government access to transferred data, inadequate limits and remedies, and the Commission decision’s restriction of independent review by national data-protection authorities.

“Revoked” is common shorthand, but the precise legal action was invalidation of the Commission’s decision. That ended Safe Harbour as a legal basis for transfers; it did not make every EU-to-US personal-data transfer impossible under every other mechanism.

What Safe Harbour was

The European Commission’s 2000 decision treated the Safe Harbour Privacy Principles, together with related US Department of Commerce FAQs, as providing adequate protection for EU personal-data transfers to participating US companies. Companies joined through voluntary self-certification and committed to follow the principles. US law could enforce those commitments, including through the Federal Trade Commission.

The framework addressed the practical problem of transferring EU personal data to US companies without a general US data-protection law equivalent to the EU regime. It provided a route for transfers to participating companies, rather than a blanket finding that every US recipient or every transfer was adequate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the CJEU invalidated Safe Harbour

The case began with Austrian Facebook user Maximillian Schrems’s complaint to Ireland’s data-protection authority. Some data provided by EU Facebook subscribers was transferred by Facebook’s Irish subsidiary to servers in the United States. Schrems argued that US law and practice did not adequately protect the data from public-authority surveillance. The CJEU considered whether the Commission’s decision could prevent supervisory review and whether the decision itself was valid.

The Commission had not established equivalent protection

The Court said the Commission needed to find that US law or international commitments ensured protection of fundamental rights essentially equivalent to that guaranteed in the EU. It had not made that necessary finding when adopting the Safe Harbour decision.

Company commitments did not bind public authorities

US national-security, public-interest, and law-enforcement requirements could take precedence over the voluntary Safe Harbour principles. The Court found that the decision did not establish adequate limits on that interference or effective legal protection against it.

Access and remedies were inadequate

The Court pointed to broad access to transferred data and the lack, in relevant circumstances, of administrative or judicial means for individuals to seek access to, correction of, or deletion of their data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

National authorities had to retain independent review

Individuals must be able to complain to national supervisory authorities, which must be able to examine complaints independently. The Commission’s decision could not remove those authorities’ power to investigate whether a transfer complied with EU law.

The CJEU’s press release put the outcome plainly: “For all those reasons, the Court declares the Safe Harbour Decision invalid.”

What the ruling changed—and what it did not

After the 6 October 2015 judgment, companies could no longer rely on the Safe Harbour adequacy decision for EU-to-US transfers. The ruling did not declare all transfers to the United States unlawful regardless of the legal route used. Other transfer mechanisms remained relevant, subject to their own requirements and scrutiny.

In 2020, the CJEU invalidated the later EU–US Privacy Shield adequacy decision in Schrems II. In the same judgment, it upheld the decision concerning standard contractual clauses, while requiring exporters and supervisory authorities to assess whether protection could be ensured in practice. Safe Harbour, Privacy Shield, and contractual clauses were distinct legal mechanisms; the 2015 judgment did not invalidate all of them.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What replaced Safe Harbour?

The EU–US Privacy Shield came after Safe Harbour, but it too was invalidated by the CJEU on 16 July 2020. The European Commission later adopted an adequacy decision for the EU–US Data Privacy Framework (DPF) on 10 July 2023. The Commission’s page lists the DPF for participating US commercial organisations, allowing personal data to flow to those organisations under that decision. The Commission reported its first periodic review on 9 October 2024.

The successor frameworks should not be treated as interchangeable: each has a different legal instrument and safeguards, and both the original framework and Privacy Shield were subject to court scrutiny. A CJEU appeal document records challenges to the DPF, including arguments about the Data Protection Review Court and bulk collection. That document sets out appeal grounds; it is not a judgment annulling the DPF. The Commission’s adequacy listing is the basis for describing the framework as listed here, checked on 4 October 2026.

Safe Harbour and its successors at a glance

Framework or route Legal instrument and date Participation or use Status described by the cited sources
Safe Harbour European Commission adequacy decision, 2000 Voluntary self-certification by participating US companies Declared invalid by the CJEU on 6 October 2015
EU–US Privacy Shield Later EU–US adequacy framework; invalidated on 16 July 2020 Company framework, distinct from Safe Harbour Its adequacy decision was invalidated in Schrems II
Standard contractual clauses Separate transfer mechanism considered in Schrems II Contractual transfer safeguards, with practical assessment duties The CJEU upheld the relevant decision, while requiring assessment of protection in practice
EU–US Data Privacy Framework European Commission adequacy decision, adopted 10 July 2023 Participating US commercial organisations Listed by the Commission; first periodic review reported 9 October 2024

Can EU personal data still be transferred to the US?

Yes, but the answer depends on the recipient and the transfer mechanism. The Commission’s DPF adequacy decision applies to participating US commercial organisations listed under the framework. Where that basis does not apply, another lawful transfer mechanism may be relevant; standard contractual clauses, for example, were not invalidated in Schrems II, but the parties must consider whether protection can be ensured in practice. Safe Harbour itself is no longer a valid basis.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.