This article examines the case law that shaped personal data rights and how these decisions exposed the urgent need for stronger protection, protection now provided by GDPR.
Recently, the ICO issued record‑breaking fines to British Airways and Marriott International for failing to safeguard customer data during cyberattacks. For the first time, penalties reached nine‑digit figures, setting a powerful precedent for enforcement.
These cases will be explored in Part 2 of this series.
But how did we reach this point? Who were the individuals who fought for data rights long before regulators had the power to act?
The Student Lawyer looks at the people who recognised how vulnerable personal data had become, and whose battles, later validated by global scandals and breaches, helped make GDPR both necessary and inevitable.
Figures such as Max Schrems, Edward Snowden and David Carroll have profoundly shaped public understanding of how companies process personal data.
The Cambridge Analytica scandal in 2018 confirmed their warnings and accelerated the need for GDPR’s success.
A Timeline of GDPR’s Development and the Cases That Drove It
Max Schrems and Mark Zuckerberg: Parallel Opposites
Many see Mark Zuckerberg and Max Schrems as parallel opposites.
Zuckerberg, still a Harvard student when he founded Facebook, built a platform that now has more than 2.4 billion users.
Schrems, only three years younger, realised during a semester abroad at Santa Clara University that Facebook’s handling of personal data needed to be challenged. The renegade student who built Facebook met his match in the renegade Austrian student who would become Europe’s most influential data‑rights activist.
Both men are pro‑technology and pro‑Facebook, but their optimism differs. Zuckerberg argues that Facebook promotes free speech and democracy by connecting billions of people. Schrems warns that without proper regulation, these tools give tech companies unprecedented power that could eclipse governments themselves.
Despite his criticism, Schrems uses Facebook and online crowdfunding to finance his legal battles. His story is a true David‑and‑Goliath fight, and the man who took on Facebook and won has not stopped defending Europeans’ data rights.
Schrems and Snowden: The End of Safe Harbour (Schrems I)
Schrems began filing complaints with the Irish Data Protection Commission (DPC), but progress was slow.
At the time, the DPC had only 26 employees. Eventually, his complaint reached the Court of Justice of the European Union (CJEU).
His argument: Facebook should not be allowed to transfer EU data to the United States after Edward Snowden revealed that the NSA operated mass surveillance programmes using data from major tech companies. Millions of citizens’ phone and internet records were collected.
The case concerned Article 8 of the Charter of Fundamental Rights of the European Union and the EU‑US Safe Harbour Principles. Schrems argued that Safe Harbour could no longer guarantee “adequate protection” as required by Article 25 of Directive 95/46/EC.
In 2015, the CJEU agreed. It ruled that national supervisory authorities could examine EU‑US data transfers and declared Safe Harbour invalid.
In response, the EU and US quickly negotiated a replacement: the EU‑US Privacy Shield, approved in 2016. Schrems welcomed the ruling that mass surveillance violated Articles 7 and 8 of the Charter, but he believed Privacy Shield was still fundamentally flawed.
Schrems II: Safe Harbour Down, Privacy Shield Next
Under Privacy Shield, EU‑US data transfers relied on Standard Contractual Clauses (SCCs). Schrems filed a new complaint arguing that, just like Safe Harbour, SCCs and Privacy Shield failed to meet EU legal standards.
His argument mirrored Schrems I: Privacy Shield added cosmetic protections, such as a US ombudsman, but did not address the core problem.
This time, Schrems was not alone. French data‑rights groups also brought proceedings before the General Court. The CJEU heard Schrems’s case on 9 July 2019, with a non‑binding opinion expected in December 2019 and a full judgment in 2020. That ruling will likely determine the fate of SCCs.
David Carroll and Cambridge Analytica: When Data Abuse Becomes a Global Scandal
David Carroll, a US academic and central figure in Netflix’s The Great Hack, led a case that reinforced Schrems’s argument: personal data rights must be treated as fundamental rights.
In 2017, Carroll requested his full data profile from Cambridge Analytica under the UK’s Data Protection Act 1998. The company claimed to hold 4,000–5,000 data points per person. Carroll wanted to ensure his data was not used for purposes he considered “unsettling or unlawful.”
After the 2018 Cambridge Analytica scandal revealed that Facebook data had been unlawfully used to support the Trump campaign, Carroll’s request became even more significant. Cambridge Analytica refused to provide his data and then entered liquidation on 1 May 2018.
Carroll succeeded only in securing a £15,000 fine against the company for ignoring his request. But the case raised troubling questions:
• How can individuals understand how their data is used if companies can dissolve to avoid scrutiny?
• How can regulators enforce rights when firms disappear mid‑investigation?
Carroll argued that Cambridge Analytica should not be allowed to liquidate while evading legal responsibility, but the High Court rejected this. His case highlighted the urgent need for stronger data protection.
What GDPR Changes
While Schrems and Carroll fought Facebook and other companies over unlawful data processing, the EU introduced its most ambitious reform: the GDPR, which came into force on 25 May 2018.
Schrems immediately put GDPR to work. He filed complaints against Facebook and Google worth around €4 billion, and against eight other tech firms including Amazon, Netflix, Spotify and YouTube.
He acknowledges that large fines alone will not change Silicon Valley’s culture. But he argues that a GDPR‑based class action over Cambridge Analytica could “ruin Facebook.” If 50 million people sued for $2,000 each, he notes, it could “possibly even kill them.”
Unfortunately for Schrems, the Cambridge Analytica case occurred before GDPR, and Facebook received only a £500,000 fine, the maximum under the old law.
Conclusions and Takeaways
If Schrems II succeeds, the European Commission will need to radically rethink how EU‑US data transfers are regulated. With GDPR’s far larger fines, businesses will need to be extremely cautious, and violations could have devastating consequences for tech firms.
Whether we will ever fully understand how companies like Cambridge Analytica processed personal data remains uncertain. Schrems plans to launch a “privacy bounty” to encourage whistle‑blowers to come forward.
Greater protection for whistle‑blowers is essential, especially as tech companies increasingly rely on non‑disclosure agreements.
GDPR strengthens the law where previous investigations failed, most notably Facebook’s modest £500,000 fine for its role in the Cambridge Analytica scandal.
The second and final article in this series will examine the major GDPR cases and consider what the future holds for data protection.
Not sure how close you are to qualifying?
The path-fit quiz reads your situation and shows you which routes you are ready for, and exactly what to do next. Four minutes, no account needed to start.
Check your readiness