· Openers · Digital Sovereignty  · 3 min read

The Uncertain Bridge Across the Atlantic – Part 1: Safe Harbor Collapsed in 2015

A simple 2000 agreement was supposed to make it legal to send personal data to the US. In 2015 the Court of Justice of the EU ruled the bridge was unsafe. That was the start of a pattern we are still living with.

Imagine building your entire digital operation on a bridge across the Atlantic.

Every day you send customer data, citizen records, emails, documents and analytics across that bridge to American cloud services. It feels normal. Everyone does it. There is even an official agreement saying it is fine.

Then one day in 2015 the trust in the bridge collapses.

What was Safe Harbor?

Safe Harbor was an agreement between the EU and the US that came into force in 2000.

The idea was simple: American companies could self-certify that they followed a set of privacy principles. European organisations could then send personal data to them without extra hassle.

It was convenient. It made it possible to use US email services, CRM systems, analytics tools and cloud storage at scale.

But there was a big problem that few spoke openly about.

Snowden, Schrems and the wake-up call

In 2013 Edward Snowden revealed how US intelligence agencies were collecting vast amounts of internet data — including from Europeans.

A young Austrian law student named Max Schrems read the agreements and asked a simple question:

If US law allows authorities to access my data pretty much as they please, how can a self-certification agreement actually protect me?

He filed a complaint about Facebook transferring data from Ireland to the US. The case reached the Court of Justice of the European Union.

In October 2015 the Court ruled. It invalidated Safe Harbor.

Why did the ruling happen?

The Court essentially said:

  • US law gives authorities too broad access to personal data.
  • There are insufficient limitations and safeguards.
  • Europeans have no effective way to seek redress when their data ends up with US authorities.

In short: the protection was not “essentially equivalent” to what the EU demands of itself.

What did it mean in practice?

Suddenly thousands of organisations no longer had a valid basis for sending data to common American services.

Many carried on anyway — what else were they supposed to do? But the legal uncertainty was real.

Public procurement started asking where data was stored. Lawyers wrote long memos. IT leaders had to explain to management why “everyone else” might suddenly be a problem.

It was the first time many realised that digital sovereignty is not just a technical issue. It is about who decides what happens to your data when the rules change.

A simple analogy

Imagine you rent premises for your operations.

The landlord promises “we have security under control”. But the landlord’s country can change the law at any time and say: “We have the right to enter and look at everything in the premises, without telling you why.”

Would you feel secure?

That is roughly what Safe Harbor meant.

What happens next?

They promised a better, stronger bridge. It was called Privacy Shield.

But the story repeated itself.

In the next part we look at why the second bridge also collapsed — and what it tells us about relying on agreements that never change the underlying foundations.


Want to understand where your data flows today and which tools can realistically be replaced with sovereign alternatives?

Book a no-obligation meeting with Openers. We help public sector, businesses and organisations map risks and take practical steps towards real digital sovereignty.

Learn more about our compliance and security offerings or book a meeting directly.

Back to Blog

Related Posts

View All Posts »