Regulatory Watch  /  European Union  /  Guidance
Moderate impactGuidancePublished

noyb releases guidance for EU companies on Schrems II data‑transfer obligations

The guidance explains steps EU controllers should take after the CJEU Schrems II judgment, including reviewing data flows, stopping transfers that rely on the invalidated Privacy Shield, and notifying DPAs when using SCCs after a negative assessment. It also outlines potential GDPR fines of €20 million or 4% of global turnover for non‑compliant transfers.

Why it matters: It helps EU controllers avoid hefty GDPR penalties by complying with the CJEU’s Schrems II ruling on trans‑Atlantic data transfers.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Next Steps for EU companies & FAQs
noyb · primary source · Jul 20, 2020
Details
JurisdictionEuropean Union
RegulatorEDPB
CourtCJEU
LawGeneral Data Protection Regulation
StatusPublished
PublishedJuly 20, 2020
Effectivenot stated
PenaltyUnder the GDPR there is a penalty of € 20 Mio or 4% of the global turnover if you continue to transfer data without a valid legal instrument (Article 83(5)(c) GDPR).
Topicscross border transfer, security, privacy
Datapersonal