Regulatory Watch  /  European Union  /  Enforcement
Moderate impactEnforcementAnnounced

noyb reports companies' limited responses to GDPR data‑transfer inquiries after Schrems II

The non‑profit noyb contacted 33 firms in mid‑2020 asking for details on their international data transfers under Articles 12‑15 of the GDPR, following the CJEU Schrems II ruling. Many companies either did not reply or gave only generic policy references, while a few provided limited information such as copies of SCCs.

Why it matters: The report shows that many firms still lack transparent compliance mechanisms for cross‑border data transfers required by the Schrems II decision.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Companies can't say how they comply with CJEU ruling
noyb · primary source · Sep 25, 2020
Companies can't say how they comply with CJEU ruling
noyb · Sep 25, 2020
Details
JurisdictionEuropean Union
RegulatorEuropean Commission
CourtCourt of Justice of the European Union
LawStandard Contractual Clauses
CaseC‑311/18
StatusAnnounced
PublishedSeptember 25, 2020
Effectivenot stated
OrganisationsAirbnb, Netflix, WhatsApp, Slack, Microsoft, Virgin Media, Zoom
Topicscross border transfer, transparency, access, privacy
Datapersonal