London Daily

Focus on the big picture.
Monday, Jul 20, 2026

Despite EU court rulings, Facebook says US is safe to receive Europeans’ data

Despite EU court rulings, Facebook says US is safe to receive Europeans’ data

Internal documents say EU judges’ ruling ‘should not be relied on’ in data transfer assessments.
Europe's top court says Washington plays fast and loose with European data. Facebook disagrees.

Despite the European Union's highest court twice declaring that the United States does not offer sufficient protection for Europeans' data from American national security agencies, the social media giant's lawyers continue to disagree, according to internal documents seen by POLITICO.

Their conclusion that the U.S. is safe for EU data is part of Facebook's legal argument for it to be able to continue shipping data across the Atlantic.

"The conclusion of the Equivalence Assessment is, in summary, that relevant U.S. law and practice provides protection of personal data that is essentially equivalent to the level of protection required by EU law," says one of the Facebook internal documents, dated 2021. Equivalence Assessments are made by companies to judge how privacy protections in non-EU countries compare to Europe's.

In July 2020, the Court of Justice of the European Union (CJEU) struck down a U.S.-EU data transfer instrument called Privacy Shield. The court concluded Washington did not offer adequate protection for EU data shipped overseas because U.S. surveillance law was too intrusive for European standards.

In the same landmark ruling, the Luxembourg-based court upheld the legality of another instrument used to export data out of Europe called Standard Contractual Clauses (SCCs). But it cast doubt on whether these complex legal instruments could be used to shuttle data to countries where EU standards cannot be met, including the U.S.

The CJEU reached a similar conclusion in 2015, striking down the predecessor agreement to Privacy Shield because of U.S. surveillance law and practices. In both rulings, Europe's top judges categorically stated Washington did not have sufficiently high privacy standards.

Still, Facebook — the company at the heart of both cases — thinks it shouldn't follow the court's reasoning.

The company's lawyers argue in the documents that the EU court ruling "should not be relied on" for the social media company's own assessment of data transfers to the U.S., because the judges' findings relate to Privacy Shield data pact, and not the Standard Contractual Clauses which Facebook uses to transfer data to the U.S.

"The assessment of U.S. law (and practice) under Article 45 GDPR is materially different to the assessment of law and practice required under Article 46 GDPR," the document reads. That refers to the two different types of legal data transfer instruments under the EU's General Data Protection Regulation and indicates that assessment under SCCs is different to assessment under Privacy Shield.

The company also says that changes to U.S. law and practices since the July 2020 ruling should be taken into account. As an example, it cites the U.S. Federal Trade Commission, a watchdog, "carrying out its role as a data protection agency with unprecedented force and vigour." Those arguments have been central to Washington's pitch during ongoing transatlantic negotiations over a new EU-U.S. data agreement.

Though companies have to take the EU court ruling into account when making their own assessments of third party country regimes, they can, in theory, diverge from the court's findings if they believe it is justified in a particular situation. This means that companies like Facebook can, in theory, continue to ship data out of Europe if they can prove its sufficiently protected.

"A transfer impact assessment conducted under EU law should take [the court's findings] into account for transfers to the U.S., but it is still an assessment that each company makes for their specific transfers under SCCs, which they are responsible for if the legality of that transfer is or will be challenged," said Gabriela Zanfir-Fortuna of the Future of Privacy Forum think tank.

Even so, several legal experts contacted by POLITICO said they could not see how Facebook would be able to conclude the U.S. protections are essentially equivalent to the EU's in light of the court ruling. One said that this was especially true for Facebook, since the company's own data transfers were at the heart of the case.

The revelations heap fresh pressure on the Irish Data Protection Commission (DPC), which first received a complaint against Facebook's data transfers in 2013 from Austrian campaigner Max Schrems. That complaint led to the CJEU's so-called Schrems I and Schrems II rulings that concluded that U.S. protections fall short of EU standards.

In a preliminary decision in September 2020, the Irish DPC suggested Facebook would have to stop transferring data to the U.S. following last July's ruling, but has yet to finalize the decision despite overturning Facebook's challenge to the agency's investigation in May. Dublin now holds the power to stop Facebook from moving EU data to the U.S.

If the Irish watchdog follows through with that decision, it would mark a serious blow to Facebook's efforts to keep the data taps flowing amid the ongoing EU-U.S. discussions on a new data-transfer pact.

The Irish DPC said it could not comment since it has an open inquiry into the matter.

A Facebook spokesperson said: “Like other companies, we have followed the rules and relied on international transfer mechanisms to transfer data in a safe and secure way. Businesses need clear, global rules, underpinned by the strong rule of law, to protect transatlantic data flows over the long term.”

The company's internal document also points to the EU's data flows deal with the United Kingdom, which Brussels approved in June, to back up its favorable assessment of the U.S.

"It is clear that in some important respects, the U.K. regime, which the Commission has assessed to be adequate under Article 45 GDPR, takes a similar approach to the U.S. in relation to limitations on data protection rights in the context of interception of communications," the document reads.

In a separate document listing factors relevant to its data transfers, Facebook seeks to downplay the risk that data is accessed by U.S. authorities.

It notes the 234,998 data requests it received from U.S. authorities in 2020 "represents a tiny fraction" of the total number of users, which Facebook estimates at around 3.30 billion.
Newsletter

Related Articles

0:00
0:00
Close
Jingye Demands Full Compensation After Britain illegally Nationalized British Steel
Brilliant move: Péter Magyar Moves to Nominate Chess Grandmaster Judit Polgár as Hungary’s President
Spain Defeats Argentina in Extra Time to Win Second World Cup
Police Block Cockroach Janta Party’s March to Parliament as Education Protests Intensify
Current AI Seeks to Build an Open Global AI Infrastructure Outside Big Tech Control
Turkey Explores S-400 Transfer to UAE in Bid to Rejoin F-35 Program
Josh Kerr Breaks Twenty-Seven-Year World Mile Record at London Diamond League
Thames Water Crisis Deepens as South East Water Outages Hit Thousands in Kent
EU Ban on Destroying Unsold Clothing Forces British Fashion Brands to Change Operations
UK Government Confirms Existing North Sea Oil and Gas Licences Will Be Honoured
UK Covid Inquiry Finds Nearly Ten Billion Pounds Lost in Pandemic Protective Equipment Procurement
Thames Water Moves Toward Possible Temporary Nationalisation Amid Rescue Plan Dispute
Andy Burnham Cancels One Point Eight Billion Pound Digital ID Programme After Taking Office
UK Government Takes British Steel Into Full Public Ownership to Protect Jobs and Supply Chains
Andy Burnham Becomes UK Prime Minister and Pledges Focus on Living Costs and Public Services
Germany’s Economic Malaise Reopens the Sunday Shopping Debate
Singapore Considers Lower Taxes for Fund Managers as Hong Kong Intensifies Talent Contest
US Retaliates Against Iran After Two American Troops Killed in Jordan
Bank of Asia BVI Enters Court-Supervised Liquidation After Regulators Find It Insolvent
Proposed U.S.-Saudi Nuclear Pact Could Permit Limited Uranium Enrichment Under International Safeguards
Netherlands Declares Water Shortage Emergency After Drought Pushes Rivers to Historic Lows
Why Kentucky Fried Chicken Became KFC—and Why the False Explanations Persist
Iran Claims It Destroyed Bahrain’s Main Artificial Intelligence Center in Missile and Drone Strike
Ukrainian Drones Strike Wildberries Warehouses Deep Inside Russia
Brothers Andrew and Tristan Tate Who Turned "Toxic Masculinity" Into a Brand Arrested in Miami as Britain Seeks Their Extradition
Reported CIA Mission Helped Clear the UAE’s Path to Advanced US AI Chips
Artificial Intelligence Capital Fuels Markets While Governments and Regulators Face Mounting Strategic Tests
China’s Moonshot’s Kimi K3 Narrows the Gap With Anthropic Through Scale, Openness and Lower Cost
Gold and Cash Seizure Puts Indonesia’s Senior Anti-Corruption Prosecutor Under Investigation
The Ledger Will Not Trust on Faith
Bank of England Warns Climate Shocks Could Trigger Sudden Asset Repricing
UK Treasury Places Microsoft, Google, AWS and Oracle Under New Financial Resilience Rules
Scottish Government Faces Pressure Over Delays in Vulnerable Group Background Checks
Crown Prosecution Service Authorises Additional Charges Against Andrew and Tristan Tate
NHS Approves At-Home Cancer Treatments for Rare Blood Disorders
Bank of England Gains Oversight of Major Cloud Providers Supporting UK Financial System
UK Government Plans Major Overhaul of English Local Councils Through New Unitary Authorities
British Steel Nationalisation Dispute Escalates as Chinese Owner Jingye Seeks Compensation
Bank of England Signals Interest Rates Will Stay High as It Warns of Financial Risks From Climate and AI
Trump Administration Pressures Banks to Restrict Financial Access for Undocumented Immigrants
Passenger Bound for Germany Refused to Sit Beside a Woman on a Plane — Then Slapped a Flight Attendant
Ukraine’s Leadership Rift Spills Into the Streets as Protesters Target Army Chief
Ukrainian Drone Barrage Kills Eight and Strikes Russian Logistics Network
Key Trends to Watch
Financial Conduct Authority Warns Cloud and Digital Risks Are Becoming a Financial Priority
Jeffrey Donaldson Appeals Sexual Abuse Conviction as Democratic Unionist Party Opens Review
Welsh Health Authorities Launch Emergency Meningitis Vaccination Programme for Students
Scottish Business Activity Falls for Third Month as Companies Face Rising Costs
Bank of England Regulators Demand Better Access to Digital Banking Services
United Kingdom Cuts Bilateral Aid to Several African Countries by Up to Ninety Per Cent
×