Max Schrems
Max Schrems
Main page
516964

Max Schrems

logo
Community Hub0 subscribers
Read side by side
from Wikipedia

Maximilian Schrems (born 1987) is an Austrian activist, lawyer, and author who became known for campaigns against Facebook for its privacy violations, including violations of European privacy laws and the alleged transfer of personal data to the US National Security Agency (NSA) as part of the NSA's PRISM program. Schrems is the founder of NOYB – European Center for Digital Rights.

Key Information

[edit]

Complaints with the Irish Data Protection Commissioner (2011)

[edit]

While studying law during a semester abroad at Santa Clara University in Silicon Valley, Schrems decided to write his term paper on Facebook's lack of awareness of European privacy law, after being surprised by what the company's privacy lawyer, Ed Palmieri, said to his class on the subject.[1] He later made a request under the European Right of access to personal data provision for the company's records on him and received a CD containing over 1,200 pages of data, which he published at europe-v-facebook.org with personal information redacted. He filed a first round of complaints against the company with the Irish Data Protection Commissioner (DPC) in 2011. In February 2012 Richard Allan and another company executive flew to Vienna to debate these complaints with him that lasted six hours.[1] Facebook was audited under European law and had to delete some files and disable its facial recognition software.[2] In 2014 Schrems took back the complaints, claiming that he never received a fair procedure before the Irish Data Protection Commissioner. He has never received a formal decision by the DPC and was denied access to all submissions by Facebook and the files of the case. On europe-v-facebook.org, he commented about taking back his complaints:

This decision was based on the fact that the Irish DPC has refused a formal decision for years and has not even granted the most basic procedural rights (access to files, evidence or the counterarguments). The DPC has factually stopped all forms of communication and ignored all submissions made. Many observers assumed that this may be based on political and economic considerations in Ireland."[3]

Schrems I

[edit]
Max Schrems, 19 February 2012

In 2013 Schrems filed a complaint against Facebook Ireland Ltd with the Irish Data Protection Commissioner, Ireland being the country where Facebook has its European Headquarters.[4] The complaint was aimed at prohibiting Facebook from further transferring data from Ireland to the United States, given the alleged involvement of Facebook USA in the PRISM mass surveillance program. Schrems based his complaint on EU data protection law, which does not allow data transfers to non-EU countries unless a company can guarantee "adequate protection". The DPC rejected the complaint, saying that it was "frivolous and vexatious" and that there was no case to answer.[5] Schrems filed an application for judicial review in the Irish High Court over the inaction by the Irish DPC, which was granted.[4] On 18 June 2014, Mr. Justice Hogan adjourned the case pending a reference to the Court of Justice of the European Union (CJEU). He said that Irish law relating to privacy had effectively been pre-empted by European law and that the core issue was whether the relevant directives should be re-evaluated in the light of the subsequent entry into force of Article 8 (protection of personal data) of the Charter of Fundamental Rights of the European Union.[6][7][8]

The European Commission found in the executive decision 2000/520/EC that the so-called EU–US Safe Harbor Principles would provide "adequate protection" under Article 25 of Directive 95/46/EC (Data Protection Directive), when it comes to the transfer of personal information from the EU to the US. This executive decision by the European Commission was called into question by the 2013 Edward Snowden revelations. In essence Schrems therefore argued that the Safe Harbor system would violate his fundamental right to privacy, data protection and the right to a fair trial under the Charter of Fundamental Rights of the European Union.[9][10][11]

The oral hearing before the CJEU was held on 24 March 2015.[12][13] The court's Advocate General for the case was Yves Bot.[a] During the hearing, Bot asked the European Commission lawyer Bernhard Schima what advice he could give him if he was worried about his data being at the disposal of US authorities. Schima replied that he might consider closing down his Facebook account, if he had one.[14] He said the European Commission was unable to guarantee that "adequate" safeguards for the protection of data are met, a remark that Schrems said was the most striking thing he heard at the hearing.[15][16]

Bot delivered his opinion on 23 September 2015. He held the view that the Safe Harbor agreement was invalid and said that individual data protection authorities could suspend data transfers to third countries if they violated EU rights.[17][18][19][20]

On 6 October 2015, the Court of Justice of the European Union ruled that, (1) national supervisory authorities still have the power to examine EU–US data transfers in spite of an existing Commission decision (such as its Safe Harbor Decision in 2000 which determined that US companies complying with the principles were allowed to transfer data from the EU to the US), and (2) the Safe Harbor framework is invalid.[21] The Court found that the framework is invalid for several reasons: the scheme allows for government interference of the protections, it does not provide legal remedies for individuals who seek to access data related to them or have it erased or amended, and it prevents national supervisory authorities from exercising their powers. Under EU law, data-sharing with countries deemed to have lower privacy standards, including the US, are prohibited. Such activities will only be possible through more expensive and time-consuming methods.[22]

On 2 December 2015, Schrems resubmitted his original complaint against Facebook with the Irish Data Protection Commissioner. He also sent similar complaints to the Hamburg and Belgian Data Protection Authorities, which both claim jurisdiction over Facebook. The complaints are designed to enforce the CJEU judgement on Facebook, which presently does not rely on Safe Harbor for its data transfers. Instead Facebook relies on pre-approved contractual agreements called "model clauses". Schrems argues that these agreements also incorporate exceptions for cases of illegal mass surveillance, and thus that the CJEU ruling applies to these agreements as well.[23][24] The Irish Data Protection Commissioner took the view that Schrems had raised "well-founded" objections,[25] but that it needs further guidance from the CJEU to determine the complaint.

After the proceedings in February/March 2017,[26] Ms Justice Costello of the Irish High Court delivered the executive summary on 3 October 2017, referring the case to the CJEU.[27]

"Neither the introduction of the Privacy Shield Ombudsperson mechanism nor the provisions of Article 4 of the SCC decisions eliminate the well-founded concerns raised by the DPC in relation to the adequacy of the protection afforded to EU data subjects whose personal data is wrongfully interfered with by the intelligence services of the United States once their personal data has been transferred for processing to the United States."

— Ms Justice Costello

2014 Austrian class action

[edit]

On 1 August 2014 Schrems filed a lawsuit against Facebook at the local Viennese courts. He enabled other Facebook users to join his case, generating a "class action" style suit, dubbed by the press as a David and Goliath suit, estimated as likely to be the largest class action privacy suit ever brought in Europe. Any Facebook user was able to assign his claim to Schrems via the fbclaim.com webpage. Within six days the participation in the suit was limited to 25,000 Facebook users, due to too many registrations, although other users could still register an interest.[28] Schrems sued the Irish subsidiary of Facebook in the Vienna courts for a "token amount" of €500 in damages per participant.[29] The case was financed by the German litigation funder ROLAND ProzessFinanz [de].[30] According to the terms of fbclaim.com all awarded money would be forwarded to the individual participants. Schrems does not receive any financial benefit from the class action, but acts on a pro bono basis.[31]

The first hearing took place on 9 April 2015.[32] On 1 July 2015, the Vienna District Court dismissed the class-action, saying it had no jurisdiction. The Court's decision hinged on whether Schrems was merely a consumer of Facebook, since it was on that basis that Schrems was able to pursue a case in an Austrian civil court in his place of residence. Facebook accused Schrems in having a commercial interest in his numerous legal actions against Facebook. Judge Margot Slunsky-Jost said that Schrems could benefit off the enormous media interest in his future career. The Court ruled on procedural grounds that Schrems would consequently not qualify as a consumer and could not file at his home court in Vienna.

In October 2015, the Higher Regional Court of Vienna reversed the regional court ruling, finding that Schrems is a consumer and that he does not act in any commercial interest. The Higher Regional Court ruled that Schrems can bring his own claims against Facebook Ireland in Vienna, which constituted 20 of the 22 claims in the lawsuit, but is unable to form a class action for procedural reasons. This limited Schrems to bringing only a "model case".[33] The Oberlandesgericht allowed an appeal to the Austrian Supreme Court in the key matter of forming a class action under EU and Austrian law.[34] Schrems filed the appeal on 2 November 2015. Schrems won the battle, in the sense that Higher Regional Court of Vienna confirmed the judgment of the Regional Court for Civil Law Matters and Schrems received the EUR 500 token judgment from Facebook, but the war continues, since in Schrems' words, the regional courts "have not really dealt with many of the problems that this case raises." Specifically, while finding the Facebook violated DPD in this instance, they did not find against Facebook's assertion that it could use a contract of adhesion to define the limits of their data-handling obligations under the DPD. As of December 2020, Schrems referred the matter to the Austrian Supreme Court and hopes to take it onward to the European Court of Justice for a decisive judgment.[35]

Complaints filed under GDPR in 2018–19

[edit]

Shortly after its coming into effect on 25 May 2018, Schrems filed suit under the newly promulgated General Data Protection Regulation (GDPR) in Ireland against Google and Facebook for coercing their users into accepting their data collection policies. Three complaints totalling over €3.9 billion were filed.[36]

On 18 January 2019, Schrems filed further GDPR complaints against Amazon, Apple Music, DAZN, Filmmit, Netflix, SoundCloud, Spotify, and YouTube.[37][38] His non-profit, noyb.eu, alleged they failed to respond, did not include sufficient background information, or provided insufficient or unintelligible raw data.[39] noyb predicted a maximum total fine of €18.8 billion for the 8 companies.

Schrems II

[edit]

At the conclusion of Schrems I, the Irish High Court officially referred the case (now called Data Protection Commissioner v Facebook Ireland and Maximillian Schrems) to the CJEU, along with eleven questions to address related to the validity of the SCC[40] (standard contractual clauses).[41] Judgement was presented on 16 July 2020.[42]

"The CJEU ruled that the Privacy Shield does not provide adequate protection, and invalidated the agreement. The court also ruled that European data protection authorities must stop transfers of personal data made under the standard contractual clauses by companies, like Facebook, subject to overbroad surveillance. This decision has significant implications for U.S. Companies and for the U.S. Congress because it calls into question the adequacy of privacy protection in the United States."

— epic.org Press Release[43]

"This is another landmark ruling for privacy rights by the Court of Justice, and a clear signal that the United States needs to reform its surveillance laws or risk losing its position as a global technology leader. Congress should act quickly to bring U.S. law in line with international human rights standards."

— Alan Butler, EPIC Interim Executive Director and General Counsel, in response to the judgement[44]

In September 2020, Ireland's Data Protection Commission sent Facebook a preliminary order to stop transferring data from EU citizens to the US. A fine of 4% of annual revenue will be applied if the conditions are not met.[45] Facebook's blog published a response letter by Nick Clegg, VP of Global Affairs and Communications, on 9 September 2020.[46] Clegg acknowledged that the laws regarding data transfer are changing, yet still more legal clarity is needed for everyone involved, and advocated a revision to the Privacy Shield. Additionally, the response noted the seeming contradiction between the Privacy Shield, which applies to EU-US data transfers and the court invalidated, and the SCC, which apply to EU-3rd party countries and the court held still valid.

"A lack of safe, secure and legal international data transfers would damage the economy and hamper the growth of data-driven businesses in the EU, just as we seek a recovery from COVID-19. The impact would be felt by businesses large and small, across multiple sectors. In the worst case scenario, this could mean that a small tech start up in Germany would no longer be able to use a US-based cloud provider. A Spanish product development company could no longer be able to run an operation across multiple time zones. A French retailer may find they can no longer maintain a call centre in Morocco."

[...]

"The EU has led the way in establishing a framework for data protection that protects and empowers users. Privacy rules will continue to evolve, and global rules can ensure the consistent treatment of data wherever it is stored. Facebook therefore welcomes the efforts already underway between EU and US lawmakers to evaluate the potential for an "enhanced" EU-US framework – a Privacy Shield Plus. These efforts will need to recognise that EU Member States and the US are both democracies that share common values and the rule of law, are deeply culturally, socially and commercially interconnected, and have very similar data surveillance powers and practices"

— Nick Clegg

In March 2021 possible repercussions on trans-Atlantic intelligence services and surveillance have surfaced again. Citing national security and member states' rights, a new initiative has formed in an attempt to keep European intelligence services beyond court jurisdiction. EU member state governments, led by France, are seeking to insert a national security exemption into the pending ePrivacy Regulation that would exclude third-party states such as the U.S.[47]

In May 2021 the Irish High Court rejected judicial review proceedings (brought by Facebook Ireland Limited) seeking to stop a preliminary draft decision (PDD) of the DPC.[48] Facebook alleged a number of complaints, including procedural faults, unfair targeting of Facebook versus other data processors, and the failure of the court to answer questions by Facebook regarding the proceedings. Mr Justice David Barniville rejected each of Facebook's submissions and held the DPC's procedures were lawful; however, he did acknowledge that Facebook's questions regarding the proceedings should have been answered.

NOYB - "None Of Your Business"

[edit]

In 2017, Schrems co-founded NOYB. NOYB aims to launch strategic court cases and media initiatives in support of the General Data Protection Regulation (GDPR), the proposed ePrivacy Regulation, and information privacy in general.[49][50] After 2017, many of the latest court cases he has been involved in have been brought forth by NOYB instead of Schrems personally.

Publications

[edit]

Schrems has authored the following books in German:

  • Kämpf um deine Daten (Fight for your Data), 2014
  • Private Videoüberwachung (Private Video Surveillance Law), 2011

Awards and honors

[edit]

Notes

[edit]
[edit]
Revisions and contributorsEdit on WikipediaRead on Wikipedia
from Grokipedia
Maximilian Schrems (born 10 October 1987) is an Austrian lawyer and data protection activist who gained prominence for initiating legal proceedings against Facebook's data transfer practices to the United States, culminating in two landmark rulings by the Court of Justice of the European Union: Schrems I, which invalidated the EU-US Safe Harbour framework in 2015 for failing to ensure adequate protection against US government surveillance, and Schrems II, which struck down the successor Privacy Shield arrangement in 2020 on similar grounds of insufficient safeguards and remedies for EU data subjects.[1][2][3] Schrems, who studied law at the University of Vienna and spent a semester at Santa Clara University, founded the non-profit NOYBEuropean Center for Digital Rights in 2017 to systematically enforce GDPR compliance through collective complaints and court actions against major technology firms for violations such as unlawful tracking and data processing without consent.[4][5] His advocacy, rooted in empirical analysis of data flows and surveillance risks, has compelled revisions in international data transfer mechanisms and heightened scrutiny on the compatibility of non-EU legal regimes with fundamental EU privacy rights, influencing global privacy enforcement strategies.[6][7]

Early Life and Education

Maximilian Schrems was born in Salzburg, Austria, in October 1987.[8][9] Schrems pursued legal studies at the University of Vienna, earning a bachelor's and master's degree in law, followed by doctoral research that provided foundational knowledge in European Union data protection frameworks.[10][9] As a law student there, he developed expertise relevant to privacy regulations, completing his academic training prior to broader engagement with data policy issues.[11][12] In approximately 2010–2011, during his university studies, Schrems undertook a semester abroad at Santa Clara University School of Law in Silicon Valley, California.[4][11][13] This period immersed him in the U.S. technology ecosystem, highlighting contrasts in data handling practices between American firms and European legal standards, and fostering early awareness of transatlantic privacy dynamics.[14][15]

Origins of Privacy Activism

Initial Engagement with Facebook Data Practices (2011)

In 2011, while studying law at the University of Vienna, Max Schrems invoked Article 8 of the European Data Protection Directive (95/46/EC) to request a complete copy of his personal data from Facebook, where he had been a user since 2008. Facebook responded by providing him with over 1,200 pages of data, compiled into a downloadable archive that included detailed records of his interactions, such as verbatim chat histories, lists of rejected friend requests, instances of unfriending others, IP addresses from every device login, and even data from deleted or private posts that users assumed were permanently removed.[16][17][18] The revelation of this extensive, granular tracking—spanning categories like wall posts, messages, and metadata from three years of use—highlighted discrepancies between Facebook's user-facing privacy assurances and its actual data retention practices under Irish law, as the company's European headquarters were in Dublin. Schrems identified specific issues, including the storage of data users had explicitly deleted or hidden, which he argued violated principles of data minimization and purpose limitation in EU directives.[19][17] Prompted by these findings, Schrems filed 22 formal complaints with the Irish Data Protection Commissioner (DPC) in late 2011, targeting Facebook Ireland Ltd. for alleged breaches of data protection rules, such as unauthorized retention of sensitive interaction logs and inadequate transparency on data handling. These submissions, self-funded and pursued individually without institutional backing, drew initial media scrutiny to Facebook's European compliance gaps and positioned Schrems as an early, empirical critic driven by direct evidence rather than abstract advocacy.[20][21][19]

Schrems I: Challenging Safe Harbor (2013-2015)

In June 2013, following Edward Snowden's revelations of extensive U.S. National Security Agency (NSA) surveillance programs such as PRISM, Max Schrems filed a formal complaint with the Irish Data Protection Commissioner (DPC) against Facebook Ireland Limited.[22] The complaint specifically challenged the adequacy of the EU-U.S. Safe Harbor framework, under which Facebook transferred personal data of European users to servers in the United States, arguing that U.S. laws permitted indiscriminate government access without equivalent protections to those in the EU Data Protection Directive 95/46/EC.[7] Schrems contended that empirical evidence from leaked documents demonstrated bulk data collection practices that exposed EU citizens' data to risks incompatible with fundamental rights under Articles 7 and 8 of the EU Charter of Fundamental Rights.[2] The Irish DPC rejected the complaint in 2013, stating it lacked authority to question the European Commission's 2000 adequacy decision (Decision 2000/520/EC) validating Safe Harbor.[23] Schrems then initiated judicial review proceedings in the Irish High Court in 2014, seeking an order to suspend data transfers and asserting that the DPC's inaction violated EU law by failing to verify Safe Harbor's ongoing adequacy amid U.S. surveillance realities.[24] On June 18, 2014, the High Court referred preliminary questions to the Court of Justice of the European Union (CJEU) regarding the Commission's competence to assess U.S. protections and the DPC's duty to investigate systemic risks to data subjects' rights.[22] In Case C-362/14, the CJEU ruled on October 6, 2015, that the Safe Harbor decision was invalid, as the Commission had not fully examined U.S. laws allowing public authorities unrestricted access to personal data transferred under the framework.[7] The Court emphasized causal deficiencies: U.S. legislation, including Section 702 of the FISA Amendments Act, enabled generalized surveillance without proportionality limits or effective judicial redress accessible to non-U.S. persons, falling short of EU standards requiring necessity, proportionality, and oversight.[2] This empirical grounding in surveillance program details invalidated reliance on Safe Harbor for adequacy, compelling national data protection authorities to suspend transfers and verify alternative mechanisms independently.[25] The ruling's immediate effects disrupted transatlantic data flows, with over 4,000 companies delisted from the Safe Harbor program within weeks and many shifting to standard contractual clauses (SCCs) or binding corporate rules as interim solutions, despite the Court's directive for case-by-case adequacy assessments.[26] This transition exposed vulnerabilities in SCCs, as they could not override U.S. law's primacy in access requests, prompting heightened scrutiny of all transfer tools to mitigate risks from state surveillance.[27]

2014 Austrian Class Action

In August 2014, Max Schrems initiated a collective redress action against Facebook Ireland Limited in the Vienna Regional Court under Austria's consumer protection laws, seeking damages for alleged violations of data protection rules.[28] The suit represented Schrems personally along with thousands of other Austrian Facebook users who joined via an online platform he established, eventually encompassing around 25,000 participants.[29] Plaintiffs claimed €500 per person in non-punitive compensation, totaling potentially €12.5 million, for Facebook's purportedly unlawful practices including tracking users' online activities across non-Facebook websites without explicit consent and processing personal data in breach of EU directives on privacy.[29][30] The Vienna Regional Court initially dismissed the claims in 2015, ruling that Austrian courts lacked jurisdiction over Facebook Ireland, the entity's European base, and that Schrems did not qualify as a consumer under relevant EU law.[31] On appeal, the Austrian Higher Regional Court in 2016 partially reversed this, recognizing Schrems' consumer status for his individual claim due to Facebook's targeted advertising and data practices directed at him as an end-user, but questioned the viability of aggregating claims from multiple users under Directive 93/13/EEC on unfair contract terms.[31] The court referred the matter to the European Court of Justice (ECJ) in case C-498/16, seeking clarification on whether national collective actions could encompass claims from consumers across EU member states governed by varying domestic laws.[32] In its January 25, 2018, judgment, the ECJ ruled that Schrems could pursue his personal damages claim in Austrian courts as a consumer, given Facebook's establishment of general jurisdiction there through localized operations and contracts.[32] However, the court invalidated the class-action element, holding that EU consumer protection directives do not authorize member states to extend collective redress to claims arising under other countries' laws, as this would undermine the uniformity of EU law and jurisdictional limits.[32][33] This confined the action to Austrian-domiciled users only, effectively dismantling the broader collective suit despite its scale.[34] The case underscored limitations in national mechanisms for cross-border consumer privacy enforcement, prioritizing individualized remedies over expansive class actions absent harmonized EU-wide procedures, and yielded no collective financial recovery though it established grounds for Schrems' solo pursuit under Austrian law.[32][30] Subsequent individual proceedings continued in Austria, highlighting the action's role in testing domestic avenues for data misuse redress separate from adequacy-focused challenges.[31]

GDPR Complaints Against Tech Giants (2018-2019)

On May 25, 2018, the day the General Data Protection Regulation (GDPR) became enforceable, the None of Your Business (NOYB) organization, founded by Max Schrems, filed four coordinated complaints in Austria targeting Google (specifically Android implementations), Facebook, WhatsApp, and Instagram.[35][36] These complaints alleged violations of GDPR Articles 4(11), 6(1)(a), and 7, asserting that the companies employed "all-or-nothing" consent mechanisms in their terms of service and privacy policies, which bundled acceptance of broad data processing for personalized advertising with essential service access, rendering consent neither freely given nor granular as required.[37][38] NOYB's submissions included technical audits demonstrating how user data—such as location, browsing history, and device identifiers—was processed for real-time bidding in ad auctions without valid legal basis, often exceeding stated purposes and infringing purpose limitation under Article 5(1)(b).[35] The complaints sought administrative fines up to 4% of each company's global annual turnover, potentially totaling billions of euros given the firms' revenues—Facebook's 2017 turnover exceeded €40 billion and Google's over €100 billion—while demanding cessation of non-compliant practices.[39][40] Under GDPR's one-stop-shop mechanism (Article 56), investigations shifted to lead supervisory authorities: Ireland's Data Protection Commission (DPC) for Meta subsidiaries (Facebook, Instagram, WhatsApp) due to their European headquarters in Dublin, and France's CNIL for Google Android.[41] This coordination highlighted early enforcement challenges, as national authorities deferred to leads, delaying resolutions amid criticisms of the DPC's perceived leniency toward U.S.-based tech firms.[42] Initial outcomes emerged in 2019, with CNIL fining Google €50 million on January 21 for lacking transparent, valid consent in ad personalization, directly referencing NOYB's arguments on bundled consents and inadequate information under Articles 5, 12, and 13.[43][44] The DPC, however, advanced Meta probes slowly, issuing no major fines by late 2019 despite NOYB's evidence of ongoing tracking via pixels and APIs that evaded user controls, exposing gaps in cross-border enforcement where lead authorities handled disproportionate caseloads from EU-wide operations.[45] These actions marked NOYB's strategic pivot to GDPR's complaint mechanisms (Article 77), amassing empirical data on ad tech ecosystems to challenge systemic overreach rather than isolated incidents, though full Meta accountability awaited later EDPB interventions.[41]

Schrems II: Invalidating Privacy Shield (2015-2020)

Following the invalidation of the Safe Harbor framework in Schrems I, the European Commission adopted the EU-US Privacy Shield adequacy decision on July 12, 2016, as a successor mechanism to facilitate data transfers between the EU and US.[3] Max Schrems, building on his prior complaint against Facebook's data practices, challenged the adequacy of Privacy Shield through a renewed submission to the Irish Data Protection Commissioner (DPC) in September 2015, arguing that US surveillance laws continued to undermine EU data protection standards.[46] He specifically highlighted deficiencies in protections against bulk data collection under Section 702 of the Foreign Intelligence Surveillance Act (FISA) amendments and Executive Order 12333, which enabled US intelligence agencies to access non-US persons' data without individualized suspicion or equivalent judicial oversight to that required under EU law.[47] Schrems contended that these programs, informed by empirical evidence from Edward Snowden's 2013 disclosures, allowed indiscriminate surveillance lacking the necessity, proportionality, and effective redress mechanisms enshrined in Articles 7, 8, and 47 of the EU Charter of Fundamental Rights.[48] The Irish DPC, tasked with investigating Facebook Ireland's transfers of EU users' data to the US, suspended reliance on Privacy Shield and sought guidance from the Irish High Court, which referred preliminary questions to the Court of Justice of the European Union (CJEU) on October 3, 2017.[46] In parallel, Facebook defended its use of Standard Contractual Clauses (SCCs) under Commission Decision 2010/87 for transfers absent adequacy decisions, but Schrems intervened to argue that US laws rendered such clauses ineffective without supplementary safeguards.[49] The CJEU's analysis emphasized causal linkages between US legal authorizations and actual intelligence practices, rejecting Privacy Shield's self-certification and ombudsperson mechanisms as insufficient to ensure equivalence, given the primacy of national security exceptions over privacy rights and the absence of independent oversight for EU citizens' data.[50] On July 16, 2020, the CJEU delivered its judgment in Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Case C-311/18), annulling the Privacy Shield decision in its entirety due to the US's failure to provide essentially equivalent protections.[3] The Court invalidated Privacy Shield on grounds that FISA 702 and EO 12333 permitted generalized access to EU data for foreign intelligence without adequate limits, and US redress options, such as the Privacy and Civil Liberties Oversight Board, lacked binding authority or independence from executive influence.[47] [48] Conversely, the CJEU upheld the validity of SCCs as a transfer tool, provided data exporters conduct case-by-case assessments of the recipient country's laws and practices; where equivalence is absent, exporters must implement verifiable supplementary measures—such as encryption or pseudonymization—to compel compliance, or terminate transfers if risks persist.[49] [51] This ruling imposed immediate obligations on over 5,000 US entities self-certified under Privacy Shield, triggering a compliance scramble involving transfer impact assessments and alternative mechanisms like Binding Corporate Rules.[52] Empirical scrutiny of US surveillance, drawn from declassified FISA court opinions and intelligence reports, underscored the decision's grounding in verifiable practices rather than abstract assurances, compelling global firms to prioritize causal risk evaluations over presumed adequacy. The outcome reinforced Schrems' advocacy for rigorous, evidence-based validation of international data flows, highlighting persistent asymmetries in transatlantic privacy frameworks.[53]

Founding and Operations of NOYB

Establishment and Organizational Structure

NOYB, formally known as None of Your Business, was established in June 2017 by Max Schrems as an Austrian non-profit association (Verein) headquartered in Vienna, Austria, with the aim of scaling GDPR enforcement through strategic litigation and collective actions.[54] The organization emerged in the lead-up to the GDPR's entry into force on May 25, 2018, to address enforcement gaps in digital privacy rights by leveraging crowd-funding, volunteer legal expertise, and systematic complaint validation tools.[54] Its initial budget targeted €500,000 annually, sourced primarily from crowdfunding campaigns and memberships to ensure operational independence without reliance on corporate funding.[54] Organizationally, NOYB employs a two-tier governance model: an executive board, initially comprising Schrems as managing director (pro bono), Christof Tschohl, and Petra Leupold, oversees daily operations, supported by a general assembly of 20-40 expert and institutional members meeting biennially.[54] The team, now exceeding 20 legal and IT specialists across Europe, prioritizes empirical fact-finding—using automated tools for data access requests and compliance checks—before pursuing high-impact cases, distinguishing its approach from ideologically driven activism.[55] Funding remains transparent and donation-based, with over 5,000 supporting members enabling sustained operations focused on individual rights enforcement rather than broad advocacy.[55] In December 2024, NOYB received approval from the European Commission as a Qualified Entity under Directive (EU) 2020/1828, granting it authority to initiate cross-border representative actions for GDPR violations and consumer redress across EU member states, backed by designations in Austria and Ireland.[56] This status formalizes its role in collective litigation, allowing it to represent affected individuals without mandates in injunction and redress proceedings.[56] By mid-2020, NOYB had already filed over 100 complaints targeting unlawful EU-US data transfers, demonstrating its commitment to precedent-setting enforcement.[57]

Major Enforcement Campaigns

NOYB has conducted large-scale, data-driven enforcement campaigns targeting systemic GDPR violations in consent mechanisms, filing coordinated complaints across multiple European data protection authorities (DPAs) to compel uniform enforcement. These efforts rely on automated audits and software tools to scan websites for non-compliance, such as deceptive cookie banners that fail to offer a straightforward rejection option or bundle essential cookies with trackers. In August 2021, NOYB submitted 422 formal GDPR complaints against websites using unlawful cookie banners to ten DPAs, followed by 226 additional complaints in August 2022 against users of the OneTrust banner software for pre-checked deceptive settings. These actions identified widespread issues, with NOYB's scans revealing that many banners violated Article 7 GDPR by not enabling freely given consent, prompting some operators to add compliant "reject all" buttons but resulting in limited fines due to DPA delays.[58][59][60] A parallel campaign addressed "pay or consent" models and tracking walls, where websites condition access on either paying a fee or consenting to behavioral tracking, arguing these undermine valid consent under GDPR Recital 43 by exerting economic pressure. NOYB filed complaints in 2021 against seven German and Austrian news sites employing such walls, and in November 2023 targeted Meta's €251.88 annual subscription for ad-free access as a coercive alternative to tracking consent. Their 2025 "Pay or Okay" report analyzed industry data showing consent rates exceeding 99% in these systems—far higher than standard banners—indicating invalidity, while the European Data Protection Board issued a 2024 opinion cautioning against such models unless equivalent non-tracking alternatives exist without payment. Outcomes include ongoing investigations but enforcement lags, with NOYB suing German DPAs in June 2025 for inactivity in related cases, as only 1.3% of complaints before EU DPAs typically yield fines.[61][62][63] NOYB extended campaigns beyond U.S. firms to platforms like Amazon, TikTok, and Chinese services such as AliExpress and WeChat, focusing on access rights violations under Article 15 GDPR where companies failed to provide complete user data exports. In July 2025, NOYB lodged complaints against TikTok, AliExpress, and WeChat for ignoring data access requests, part of a broader push revealing non-compliance in over 90% of tested cases for valid consent mechanisms across sectors. These efforts yielded fines tied to prior consent audits, including €210 million against Meta in 2023 for cookie violations in France, but highlighted enforcement challenges, with privacy gains from heightened compliance offset by protracted DPA processes and low resolution rates. Coordinated filings have spurred EDPB task forces for consistency, though critics note the empirical audits' focus on scalable violations prioritizes deterrence over isolated disputes.[64][65][66]

Publications and Intellectual Contributions

Books and Key Writings

Schrems authored Private Videoüberwachung: Rechtliche Rahmenbedingungen der privaten Videoüberwachung in 2011, a legal analysis focused on the regulatory constraints and practical implementation of private video surveillance systems under Austrian and EU law.[67] The book delineates permissible uses, data minimization requirements, and liability risks for operators, drawing on statutory provisions like the Austrian Data Protection Act to emphasize verifiable compliance over discretionary practices. His 2014 publication Kämpf um deine Daten offers a practical guide for individuals to reclaim control over personal data, illustrated through Schrems' own experiences requesting data from Facebook under EU directives. In it, he critiques corporate profiling techniques that aggregate user data without explicit consent, using empirical examples from over 1,200 pages of disclosed Facebook records to demonstrate incentives for mass surveillance and inadequate safeguards in transatlantic transfers.[68] Schrems advocates causal safeguards, such as mandatory audits and user-initiated deletions, arguing that self-reported compliance by firms fails to mitigate risks from bulk data access by third parties.[69] Beyond books, Schrems has contributed key writings critiquing GDPR implementation, including a 2018 guest commentary in Der Standard on consent mechanisms, where he highlighted flaws in "pay or okay" models that incentivize users toward weaker privacy options, supported by data on declining opt-out rates across EU platforms.[70] These pieces prioritize empirical tracking of enforcement gaps, such as underreported data breaches, to push for verifiable, technology-neutral rules over reliance on corporate declarations.[71]

Perspectives on Privacy, Surveillance, and Regulation

Advocacy for Stronger Data Protections

Schrems posits privacy as a fundamental right that preserves individual autonomy by limiting the manipulative power of information asymmetries, describing it as "informational redistribution" to ensure personal data remains under the individual's control rather than enabling external transparency and coercion.[72] This stance draws on empirical evidence from U.S. surveillance practices, such as the PRISM program exposed in 2013 by Edward Snowden's leaks, which demonstrated bulk data collection by agencies like the NSA under laws including FISA Section 702, allowing warrantless access to non-U.S. persons' data held by tech firms without equivalent safeguards or judicial oversight available to EU citizens.[73] [7] He argues these mechanisms enable disproportionate government access, undermining EU data protection standards and exposing transferred personal data to risks absent in European frameworks.[72] While endorsing the GDPR's risk-based approach to processing activities—scaling obligations to potential harms—Schrems contends its effectiveness hinges on robust enforcement, which he describes as lacking, rendering the regulation a "paper tiger" after five years of implementation due to insufficient political will for an "enforcement culture."[74] He criticizes national Data Protection Authorities (DPAs) for inconsistent application and under-resourcing, advocating increased budgets to enable proactive investigations rather than reactive complaints, as evidenced by NOYB's campaigns filing over 500 GDPR cases across Europe to compel action.[75] Schrems favors this decentralized model of independent national DPAs over centralized EU-U.S. adequacy frameworks, which he views as prone to executive overreach and inadequate scrutiny of foreign surveillance laws.[76] In line with first-principles reasoning on consent as a causal prerequisite for legitimate data use, Schrems challenges practices yielding "fake consent," such as bundled tracking agreements that fail to inform users of downstream risks like surveillance exposure, insisting on granular, informed chains of consent to treat data akin to personal property under user dominion.[7] This counters narratives of inevitable privacy erosion by highlighting precedents where user controls, when enforced, mitigate harms without halting innovation, as seen in GDPR-driven adjustments by firms to prioritize opt-in mechanisms over default profiling.[74]

Critiques of EU-US Data Adequacy Frameworks

Max Schrems has argued that EU-US adequacy frameworks, including the Safe Harbor arrangement (established 2000 and invalidated by the CJEU on October 6, 2015) and the Privacy Shield (adopted 2016 and invalidated on July 16, 2020), fail structurally because U.S. laws enable executive overrides that prioritize intelligence collection over commercial privacy commitments.[77] Specifically, provisions under Section 702 of the FISA Amendments Act (reauthorized periodically, including through 2023) and Executive Order 12333 (issued 1981 and expanded post-2013 Snowden disclosures) permit bulk acquisition of signals intelligence targeting non-U.S. persons without probable cause or prior judicial authorization, allowing agencies to access data transferred under self-certification without equivalent safeguards for EU subjects.[77] These mechanisms, Schrems contends, rest on unverifiable executive assurances rather than binding judicial constraints, as U.S. national security letters and gag orders can compel disclosure secretly, empirically demonstrated by documented NSA programs like PRISM that bypassed company-level protections.[77] Schrems rejects self-certification as a core adequacy tool, viewing it as empirically weak against intelligence priorities, since participating firms commit only to commercial standards that U.S. law does not extend to government access requests, lacking enforceability when surveillance imperatives arise.[77] He has extended this critique to the EU-U.S. Data Privacy Framework (adopted July 10, 2023), asserting it introduces no substantive reforms to underlying U.S. surveillance statutes, merely rebranding prior arrangements: "We now had 'Harbors', 'Umbrellas', 'Shields' and 'Frameworks' - but no substantial change in US surveillance law."[77] The framework's redress options, including the Data Protection Review Court, fail to provide EU data subjects with effective judicial remedies under Article 47 of the EU Charter of Fundamental Rights, as non-U.S. persons remain outside constitutional protections and lack direct standing or verifiable enforcement.[77] In response, Schrems advocates supplementary measures for any transatlantic transfers, such as end-to-end encryption, pseudonymization, or data minimization to render transferred data inaccessible or useless to U.S. agencies, combined with contractual guarantees of judicial redress—rejecting adequacy decisions as standalone solutions due to their causal vulnerability to overrides.[78] While acknowledging that these frameworks facilitate substantial transatlantic trade volumes (estimated at trillions in annual data flows supporting economic integration), he prioritizes the causal risks of unmitigated mass surveillance, which empirically expose EU individuals to disproportionate collection without recourse, over diplomatic optimism that overlooks U.S. legal asymmetries.[77]

Criticisms and Economic Impacts

Allegations of Disrupting Innovation and Trade

Critics from the technology sector and business associations have argued that Max Schrems' successful legal challenges, particularly the 2020 Schrems II ruling invalidating the EU-US Privacy Shield, have imposed substantial regulatory burdens on transatlantic data flows, which underpin a $7.1 trillion economic relationship between Europe and the United States.[79] These invalidations are claimed to disrupt essential mechanisms for personal data transfers, forcing companies to adopt alternative safeguards like standard contractual clauses (SCCs) under heightened scrutiny, thereby elevating compliance expenses and operational complexities.[80] A survey by DIGITALEUROPE of EU digital industry firms revealed that 92% of those reassessing SCCs post-Schrems II reported moderate or high costs associated with such evaluations, with 85% of respondents relying on SCCs for data transfers to non-EU countries.[81] Small and medium-sized enterprises (SMEs) faced particular challenges, as 39% were unaware of their likely use of SCCs for data exports, potentially exposing them to greater regulatory risks and forcing ad hoc relocalizations of data processing that inflate IT infrastructure expenses.[81] BusinessEurope echoed these concerns, noting that 92% of its members viewed the added compliance demands as moderately or highly burdensome, contributing to a broader chilling effect on cross-border digital trade.[80] Such disruptions are alleged to undermine EU competitiveness by hindering adoption of US-based cloud services and AI technologies, which depend on seamless access to global datasets; for instance, restrictions have led to reduced use of non-EU processors by 12% of firms in one survey and prompted bans or distrust of providers like AWS and Microsoft in sectors such as French health data hubs.[80] The Information Technology and Innovation Foundation (ITIF) estimates that severing or complicating these flows could shrink EU GDP by 1% annually, resulting in up to $1.5 trillion in losses and 1.3 million job cuts by 2030, while isolating European firms from US innovation ecosystems critical for AI training and cloud scalability.[80] These impacts are framed by detractors as prioritizing stringent privacy standards over efficient data-driven efficiencies that fuel global market integration.[80]

Responses to Claims of Ideological Bias

Critics, including policy analysts from the Information Technology and Innovation Foundation (ITIF), have accused Schrems of exhibiting anti-U.S. bias by applying stricter scrutiny to data transfers involving American firms compared to those from other jurisdictions, such as his 2016 statement that standard contractual clauses could facilitate EU data flows to China without the same invalidation risks as to the United States, despite China's own surveillance practices.[82] This disparity, they argue, stems not purely from legal analysis but from a selective emphasis on U.S. laws like Section 702 of the FISA Amendments Act, potentially reflecting ideological prejudice against American tech dominance rather than uniform privacy enforcement.[83] In response, Schrems has maintained that his challenges are grounded in empirical evidence from the 2013 Edward Snowden disclosures, which specifically highlighted U.S. government access to tech company data under programs like PRISM, providing causal basis for targeting transatlantic transfers without implying broader anti-U.S. animus.[67] NOYB's enforcement record counters bias claims by demonstrating actions against non-U.S. entities, including over 500 complaints in 2023 against European websites for unlawful cookie consent practices and filings against Chinese apps for data transfers in 2025, alongside cases targeting the EU Parliament for internal breaches.[84][85][86] Privacy advocacy groups, such as the Electronic Privacy Information Center (EPIC), have praised Schrems' approach for its rigorous application of EU law, crediting it with strengthening data protections without ideological favoritism.[7] However, right-leaning commentators warn that such litigation contributes to transatlantic frictions, potentially deterring U.S. venture capital investments in Europe by heightening regulatory uncertainty and fostering perceptions of EU protectionism over collaborative security analytics.[87][83] Schrems rebuts these by emphasizing that privacy enforcement yields targeted services compliant with consent, not blanket rejection of innovation benefits.[88]

Awards and Recognitions

Notable Honors and Achievements

In 2011, Schrems received the Defensor Libertatis award, the positive prize of the Austrian Big Brother Awards, for initiating the Europe vs. Facebook campaign that highlighted privacy violations in the platform's data practices.[89] This recognition from the privacy advocacy event underscored his early efforts to document and challenge Facebook's handling of European user data through over 20 formal complaints filed with the Irish Data Protection Commissioner.[90] In 2013, the Electronic Privacy Information Center (EPIC) presented Schrems with its International Privacy Champion Award for his advocacy culminating in the Schrems I judgment by the Court of Justice of the European Union, which invalidated the EU-US Safe Harbor framework due to inadequate protections against US surveillance. These accolades from nongovernmental privacy organizations reflect appreciation within advocacy networks for advancing data protection litigation, though award selections in such circles often emphasize regulatory stringency amid debates over transatlantic trade implications. Schrems's leadership of NOYB (None of Your Business), established in 2017, has involved filing hundreds of GDPR complaints across Europe, yielding administrative fines totaling €1.69 billion as of 2024 from authorities investigating violations like unlawful data transfers and consent mechanisms.[91] [45] These outcomes have empirically influenced GDPR enforcement patterns, with NOYB actions accounting for a significant share of major penalties, including €1.2 billion against Meta in 2023 for EU-US data flows post-Schrems II.[92]

Recent Developments and Ongoing Efforts (2021-2025)

Challenges to the EU-US Data Privacy Framework

In July 2023, shortly after the European Commission's adoption of the EU-US Data Privacy Framework (DPF) on July 10, NOYB, led by Max Schrems, announced plans to challenge its adequacy decision in the Court of Justice of the European Union (CJEU), citing insufficient reforms to US surveillance laws such as Section 702 of the Foreign Intelligence Surveillance Act (FISA), which permits bulk data collection without individualized warrants equivalent to EU standards.[77] Schrems argued that the DPF's safeguards, including Executive Order 14086 establishing a Data Protection Review Court (DPCR), fail to provide non-US persons with judicial redress comparable to that required under EU law, as the DPCR lacks independence from executive influence and binding enforcement power, relying instead on internal US executive reviews.[93] Throughout 2024, NOYB urged European data protection authorities (DPAs) to suspend data transfers under the DPF pending CJEU review, filing complaints against companies relying on it and highlighting empirical evidence from US government disclosures showing over 200,000 FISA 702 acquisitions annually affecting non-US data without adequate minimization procedures tailored to EU privacy rights.[94] These efforts emphasized causal persistence of surveillance risks, noting that US intelligence practices documented in annual transparency reports had not materially changed since the invalidation of prior frameworks in Schrems I (2015) and Schrems II (2020), despite diplomatic assurances.[95] In March 2025, Schrems publicly questioned the necessity of an immediate full-scale challenge, suggesting that recent US administrative adjustments—such as proposed FISA reforms debated in Congress—might expose framework flaws without litigation, though he maintained that core issues like the absence of EU-equivalent ex ante judicial oversight rendered the DPF empirically inadequate for mass transfers.[88] By September 2025, following the EU General Court's dismissal of French MEP Philippe Latombe's annulment action against the DPF adequacy decision on September 3—which upheld the framework's compliance with essential equivalence under EU Charter rights—Schrems and NOYB criticized the ruling for overlooking DPCR's structural weaknesses, including its lack of adversarial proceedings and non-binding outcomes, and reaffirmed intent to file a Schrems III-style challenge within months to test these gaps directly.[96][97] NOYB's strategy balances legal realism against transatlantic economic pressures, prioritizing verifiable US surveillance data over Commission assurances, with Schrems noting in 2025 analyses that the DPF's reliance on self-certification by US firms exposes up to 60 million EU users' data to unremedied access risks, as quantified in ODNI reports.[93] Potential CJEU proceedings, if initiated, could yield a decision by late 2026, forcing interim DPA suspensions and supplemental measures like encryption for transfers.[98]

Campaigns Against AI Data Practices

In 2024, Schrems' privacy advocacy organization, NOYB (None of Your Business), initiated multiple GDPR complaints against major AI developers for unlawfully processing personal data in model training. These actions targeted practices such as scraping public posts, lacking transparency on data sources, and failing to provide mechanisms for data subject rights like deletion or rectification, arguing that aggregated or "anonymized" training data embedded in large language models (LLMs) evades GDPR obligations under Articles 5, 12-23.[67][99] A prominent campaign focused on OpenAI's ChatGPT, with NOYB filing a complaint on August 1, 2024, to the Austrian Data Protection Authority (DPA). The filing alleged no lawful basis for processing EU users' data—estimated at tens of millions of datapoints from web scraping—violating purpose limitation and data minimization principles, as training data was mixed indiscriminately without separation by use case. NOYB highlighted ChatGPT's "hallucinations" (fabricated personal information) as breaching accuracy requirements, with no effective rectification possible due to data's irreversible integration into weights; OpenAI's input/output filters were deemed insufficient GDPR compliance. The complaint sought fines up to 4% of global turnover and model retraining exclusions for EU data, amid broader scrutiny including Italy's temporary ChatGPT ban in March 2023 for similar transparency failures.[100][99] Parallel efforts addressed Meta's AI initiatives, with NOYB submitting coordinated complaints on June 6, 2024, to data protection authorities in 11 EU countries against Meta's scraping of public Facebook and Instagram posts—potentially billions of items—for training models like Llama without granular consent or legitimate interest. Schrems contended this repurposed behavioral data (e.g., likes, comments inferring sensitive traits) violated CJEU precedents like Schrems v. Meta (2024), which rejected blanket "legitimate interest" overrides, and ignored purpose limitation by blending data across unrelated AI applications. A NOYB survey of 1,000 EU users found only 7% consented to such use, underscoring opt-out inadequacies in Meta's "pay or okay" model.[101][102] NOYB extended scrutiny to X (formerly Twitter), filing nine GDPR complaints in August 2024 across EU DPAs over X's scraping of user posts and interactions to train the Grok LLM without explicit consent or transparency. The actions claimed violations of data protection by default, as opt-outs were buried and ineffective against already-harvested data, potentially including inferred sensitive information from public discourse. Similar concerns prompted a June 27, 2025, complaint against Bumble's AI matchmaking feature, alleging unauthorized processing of profile data (e.g., sexual preferences) for opaque algorithmic enhancements lacking impact assessments.[103] Schrems has publicly argued that current AI architectures inherently conflict with GDPR's purpose limitation, as mixed datasets prevent data isolation for specific uses, rendering compliance illusory without segregated training pipelines—a stance echoed in his critiques at forums like CPDP LatAm in July 2024. These campaigns, building on Schrems' prior successes invalidating transatlantic data transfers, aim to enforce ex-ante restrictions rather than post-hoc fines, though outcomes remain pending amid DPA backlogs and industry pushback claiming pseudonymization suffices.[104][67]

References

User Avatar
No comments yet.