Skip to content
Privacy and law

What is Schrems II?

Schrems II is the July 2020 Court of Justice of the European Union judgment that invalidated the EU–US Privacy Shield framework and required case-by-case assessment of other transfer mechanisms. It triggered a wave of national decisions finding conventional analytics unlawful, because those tools sent EU visitors' personal data to US servers.

Explanatory, not legal advice. Transfer law is unusually fast-moving; check the current position before relying on any summary.

What the ruling did

It invalidated Privacy Shield, the framework thousands of companies relied on to move personal data from the EU to the US, on the grounds that US surveillance law did not offer protection equivalent to EU standards. It left Standard Contractual Clauses valid, but only with a case-by-case assessment of whether the destination country’s law actually permits the protections the clauses promise.

Between 2020 and 2023, data protection authorities in Austria, France, Italy, Denmark and elsewhere issued decisions finding specific implementations of a major US analytics product unlawful for precisely this reason.

The current position

The EU–US Data Privacy Framework, adopted in July 2023, restored a transfer mechanism for certified US organisations. It is being challenged, and its two predecessors — Safe Harbour and Privacy Shield — were both struck down after similar challenges.

The reasonable planning assumption is therefore not that transfers are permanently settled, but that this area has a history of changing under organisations that built on it.

Why “no personal data” is the durable answer

Transfer rules apply to personal data. Analytics that never collects any has nothing whose transfer is regulated, and its legal position does not change when the next framework is challenged.

That is a stronger position than data residency alone. Keeping personal data in the EU narrows the problem to the case where it moves; collecting none removes the category. Both are legitimate approaches, and it is worth knowing which one a vendor is actually offering you.

Questions

Frequently asked.

Cookies, install and pricing, answered. Still stuck? Ask us anything .

01 Can sonex show revenue next to my traffic?

Yes. Connect Stripe or Polar with a read-only key and sonex reads revenue straight from your payment provider, per website. Revenue then appears as a focusable series on the Overview chart and as its own report, beside the traffic that earned it. No tracked event is needed for it to work.

02 Does sonex use cookies?

No. sonex sets no cookies and needs no consent banner. It counts visits without cookies, fingerprinting, or any personal data, so it is GDPR, PECR and CCPA-ready by default.

03 How do I install sonex?

Add one script tag to your site's <head> with your website id. It is a single lightweight tracker — no build step and no SDK required.

04 Is sonex a Google Analytics alternative?

Yes. sonex gives you the reports that matter — visitors, pages, referrers, funnels, revenue and a world map — without surveilling your audience or drowning you in configuration.

05 How is sonex priced?

By monthly tracked events. Free covers 2k events, Pro is $20/mo for 200k events, and Business is $200/mo for 2M events with team seats.

See what your traffic actually earns.

Revenue beside the visitors that produced it. No cookies, no credit card, no consent banner.

Get started