· Openers · Digital Sovereignty · 4 min read
The Uncertain Bridge Across the Atlantic – Part 2: Privacy Shield – The Patch That Didn't Hold
After Safe Harbor came Privacy Shield. More principles, an ombudsperson and promises of better protection. In 2020 the Court of Justice of the EU invalidated this agreement too. The same fundamental problems remained.
After the Safe Harbor ruling in 2015, politicians and companies promised that “this time we will fix it properly”.
In 2016 they presented Privacy Shield – the privacy shield. A new, improved agreement between the EU and the US.
It looked better on paper. More principles. More information for individuals. A special ombudsperson who would receive complaints from Europeans.
Unfortunately, it was mostly a patch on the same old bridge.
What was new in Privacy Shield?
Compared with Safe Harbor, Privacy Shield included:
- Clearer obligations for companies on how they could use and onward-transfer data.
- An ombudsperson on the US side to handle complaints related to intelligence activities.
- Promises that US surveillance would be “necessary and proportionate”.
It sounded reassuring. Thousands of companies certified under the new framework.
But one person kept asking uncomfortable questions: Max Schrems.
Schrems II – the same core problems
In 2020 the Court of Justice of the EU delivered its next ruling (Schrems II).
It invalidated Privacy Shield.
The Court saw that the fundamental problems had not been solved:
- US law (including FISA 702 and certain executive orders) still permits broad collection of data, not only when there is suspicion against specific individuals.
- Surveillance is not sufficiently limited to what is “strictly necessary” under the EU view of fundamental rights.
- The ombudsperson lacked sufficient power and independence to give Europeans a real remedy. It was more of a diplomatic function than a court.
The result was the same as five years earlier: the agreement did not hold.
What did it mean this time?
This was no longer just a theoretical problem.
Many organisations had moved large parts of their operations to US cloud platforms during the Privacy Shield years. Suddenly they had to look at Standard Contractual Clauses (SCCs) and perform Transfer Impact Assessments (TIAs) — formal assessments of whether it was still legal to transfer the data.
For many it became a paperwork exercise. Templates were filled in, but the underlying reality had not changed: the data was still subject to US jurisdiction.
Public sector organisations noticed it clearly in procurement. Questions about “where is the data stored?” and “which law applies in case of conflict?” became more common and sharper.
An analogy that sticks
Imagine the bridge from Part 1 has collapsed. You build a new one on the old foundations.
You paint it nicer. You put up signs saying “now it is safe”. You hire a guard to receive complaints from anyone who still falls through.
But the foundations — the US laws that allow broad access — have not moved one millimetre.
When the next storm comes (another court ruling), the bridge collapses again.
Why does the pattern repeat?
The problem is not a lack of good intentions. It is that the two legal systems rest on different core values when it comes to privacy and state power.
The EU treats data protection as a fundamental right. The US prioritises national security in ways that give authorities significantly more leeway.
As long as this does not change at the root, every new agreement will be vulnerable to the next court challenge.
What did we learn?
That “more detailed agreements” do not solve a structural problem.
That it is expensive and risky to constantly have to patch and repair legal foundations.
That the only stable solution is to not need the bridge at all — at least not for what really matters.
In Part 3 we look at the third attempt: the Data Privacy Framework from 2023. And why even that one fell — this time after only three years.
Ready to stop patching bridges and start building on solid ground?
Openers helps organisations map where their data actually goes and replace risky dependencies with solutions under Swedish or European control.
Book a meeting or learn more about our technical platform and digital tools.