[{"data":1,"prerenderedAt":493},["ShallowReactive",2],{"navigation-docs_de":3,"/blog/schrems-iii-eugh-urteil-posts_de":50,"/blog/schrems-iii-eugh-urteil-surround-posts_de":487},[4],{"title":5,"path":6,"stem":7,"children":8,"page":49},"De","/","de",[9],{"title":10,"path":11,"stem":12,"children":13,"page":49},"Docs","/docs","de/1.docs",[14,24],{"title":15,"path":16,"stem":17,"children":18},"Einführung","/docs/getting-started","de/1.docs/1.getting-started/1.index",[19,20],{"title":15,"path":16,"stem":17,"children":-1},{"title":21,"path":22,"stem":23,"children":-1},"Migrations-Fahrplan","/docs/getting-started/migration-fahrplan","de/1.docs/1.getting-started/2.migration-fahrplan",{"title":25,"path":26,"stem":27,"children":28,"page":49},"Technologien","/docs/technologien","de/1.docs/2.technologien",[29,33,37,41,45],{"title":30,"path":31,"stem":32,"children":-1},"Nextcloud","/docs/technologien/nextcloud","de/1.docs/2.technologien/1.nextcloud",{"title":34,"path":35,"stem":36,"children":-1},"Matrix / Element","/docs/technologien/matrix","de/1.docs/2.technologien/2.matrix",{"title":38,"path":39,"stem":40,"children":-1},"ONLYOFFICE","/docs/technologien/onlyoffice","de/1.docs/2.technologien/3.onlyoffice",{"title":42,"path":43,"stem":44,"children":-1},"Ubuntu Linux","/docs/technologien/ubuntu","de/1.docs/2.technologien/4.ubuntu",{"title":46,"path":47,"stem":48,"children":-1},"Keycloak","/docs/technologien/keycloak","de/1.docs/2.technologien/5.keycloak",false,{"id":51,"title":52,"authors":53,"badge":59,"body":61,"date":475,"description":476,"extension":477,"faq":478,"howto":478,"image":479,"meta":481,"navigation":482,"path":483,"seo":484,"stem":485,"__hash__":486},"posts_de/de/3.blog/9.schrems-iii-eugh-urteil.md","Schrems III – Was das EuGH-Urteil 2026/2027 für deutsche KMU bedeutet",[54],{"name":55,"to":56,"avatar":57},"europioneer Team","https://europioneer.io",{"src":58},"/favicon.svg",{"label":60},"Recht",{"type":62,"value":63,"toc":459},"minimark",[64,68,104,107,112,123,130,134,166,170,173,199,206,210,213,265,272,276,281,301,305,326,330,345,349,352,415,430,434,453],[65,66,52],"h1",{"id":67},"schrems-iii-was-das-eugh-urteil-20262027-für-deutsche-kmu-bedeutet",[69,70,71,75,76,79,80,83,84,87,88,93,94,98,99,103],"p",{},[72,73,74],"strong",{},"Max Schrems"," hat es zweimal geschafft. ",[72,77,78],{},"Safe Harbor (2015) — gekippt. Privacy Shield (2020) — gekippt."," Jetzt steht der dritte Anlauf: ",[72,81,82],{},"Schrems III",", gerichtet gegen den ",[72,85,86],{},"EU-US Data Privacy Framework (DPF)",". Die meisten Datenschutzjuristen rechnen mit einem dritten Sieg der Kläger. Verschärft wird die Lage durch den ",[89,90,92],"a",{"href":91},"/blog/cloud-act-2026","CLOUD Act"," und parallel die neue ",[89,95,97],{"href":96},"/blog/nis2-dsgvo-microsoft-paradox","NIS2-Pflicht"," sowie die Erfüllbarkeitsprobleme des ",[89,100,102],{"href":101},"/blog/bsi-grundschutz-microsoft-365","BSI-IT-Grundschutzes"," mit Microsoft 365.",[69,105,106],{},"Was bedeutet das für Ihr Unternehmen?",[108,109,111],"h2",{"id":110},"worum-geht-es","Worum geht es?",[69,113,114,115,118,119,122],{},"Der ",[72,116,117],{},"EU-US Data Privacy Framework"," ist der ",[72,120,121],{},"dritte Versuch"," der EU-Kommission, einen rechtlichen Rahmen für Datenübertragungen in die USA zu schaffen, nachdem die ersten beiden gescheitert sind.",[69,124,125,126,129],{},"Schrems' zentraler Vorwurf: Das DPF ändert nichts an der Grundlage des Problems — ",[72,127,128],{},"US-Geheimdienste haben weiterhin Zugriff"," auf personenbezogene Daten von EU-Bürgern über FISA Section 702 und Executive Order 12333. Trump 2.0 hat diese Zugriffe sogar verstärkt.",[108,131,133],{"id":132},"warum-die-kläger-gute-karten-haben","Warum die Kläger gute Karten haben",[135,136,137,144,154,160],"ol",{},[138,139,140,143],"li",{},[72,141,142],{},"Strukturelle Argumentation:"," Das DPF basiert auf US-Versprechen, nicht auf Gesetzesänderungen",[138,145,146,149,150,153],{},[72,147,148],{},"Trump-Faktor:"," Die zweite Trump-Administration hat 2025 das ",[72,151,152],{},"Privacy and Civil Liberties Oversight Board (PCLOB)"," politisch besetzt und entkernt — eine Säule des DPF",[138,155,156,159],{},[72,157,158],{},"Präzedenzfall:"," Der EuGH hat in Schrems I und II mit deutlichen Worten geurteilt; eine Kehrtwende wäre schwer zu begründen",[138,161,162,165],{},[72,163,164],{},"CJEU-Generalanwalt-Indikationen:"," Die ersten Gutachten lassen einen kläger-freundlichen Tenor erkennen",[108,167,169],{"id":168},"was-passiert-nach-einem-urteil-zugunsten-der-kläger","Was passiert nach einem Urteil zugunsten der Kläger?",[69,171,172],{},"Die ungefähre Choreographie kennen wir aus Schrems II:",[135,174,175,181,187,193],{},[138,176,177,180],{},[72,178,179],{},"Adequacy Decision wird ungültig"," — sofortige Wirkung",[138,182,183,186],{},[72,184,185],{},"Übergangsfrist"," wahrscheinlich 3–6 Monate",[138,188,189,192],{},[72,190,191],{},"Standardvertragsklauseln (SCCs)"," mit zusätzlichen Schutzmaßnahmen werden zur Notlösung — aber Aufsichtsbehörden prüfen härter",[138,194,195,198],{},[72,196,197],{},"Datenexporte in die USA"," werden faktisch sehr schwierig",[69,200,201,202,205],{},"Konkret: Microsoft 365, Google Workspace, AWS, Salesforce, Slack, Zoom werden ",[72,203,204],{},"rechtlich noch fragwürdiger"," als heute.",[108,207,209],{"id":208},"konkrete-bußgeld-risiken","Konkrete Bußgeld-Risiken",[69,211,212],{},"Vorbild Schrems II-Folge:",[214,215,216,229],"table",{},[217,218,219],"thead",{},[220,221,222,226],"tr",{},[223,224,225],"th",{},"Fall",[223,227,228],{},"Bußgeld",[230,231,232,241,249,257],"tbody",{},[220,233,234,238],{},[235,236,237],"td",{},"Meta (Irland, 2023)",[235,239,240],{},"1,2 Mrd. €",[220,242,243,246],{},[235,244,245],{},"Amazon (Luxemburg, 2021)",[235,247,248],{},"746 Mio. €",[220,250,251,254],{},[235,252,253],{},"WhatsApp (Irland, 2021)",[235,255,256],{},"225 Mio. €",[220,258,259,262],{},[235,260,261],{},"H&M (Hamburg, 2020)",[235,263,264],{},"35 Mio. €",[69,266,267,268,271],{},"Auch KMU sind betroffen: Es gibt mehrere Bußgelder im ",[72,269,270],{},"unteren bis mittleren sechsstelligen Bereich"," wegen Nutzung von US-Cloud-Diensten ohne tragfähige Rechtsgrundlage.",[108,273,275],{"id":274},"was-unternehmen-jetzt-tun-sollten","Was Unternehmen jetzt tun sollten",[277,278,280],"h3",{"id":279},"sofort-vor-dem-urteil","Sofort (vor dem Urteil)",[135,282,283,289,295],{},[138,284,285,288],{},[72,286,287],{},"Datenfluss-Audit:"," Welche personenbezogenen Daten gehen in welche US-Dienste?",[138,290,291,294],{},[72,292,293],{},"Transfer Impact Assessment (TIA)"," pro US-Dienst dokumentieren",[138,296,297,300],{},[72,298,299],{},"Backup-Plan"," für die wichtigsten Tools entwickeln (Was, wenn DPF morgen fällt?)",[277,302,304],{"id":303},"mittelfristig-12-monate","Mittelfristig (12 Monate)",[135,306,308,314,320],{"start":307},4,[138,309,310,313],{},[72,311,312],{},"EU-Alternative pilotieren"," — eine Abteilung, ein Tool nach dem anderen",[138,315,316,319],{},[72,317,318],{},"Migrationsbudget einplanen"," — Notfall-Migration nach Urteil ist 3–5x teurer",[138,321,322,325],{},[72,323,324],{},"AVV-Klauseln neu verhandeln"," mit US-Anbietern (oft erfolglos, aber dokumentiert)",[277,327,329],{"id":328},"strukturell","Strukturell",[135,331,333,339],{"start":332},7,[138,334,335,338],{},[72,336,337],{},"EU-First-Policy"," etablieren: Neue Tools werden zuerst aus EU-Anbietern geprüft, nur bei Lücken zu US-Anbietern gegriffen",[138,340,341,344],{},[72,342,343],{},"Souveränität als Compliance-Anforderung"," in Lieferantenverträge schreiben",[108,346,348],{"id":347},"welche-tools-sind-sofort-einsatzbereit","Welche Tools sind sofort einsatzbereit?",[69,350,351],{},"Was wir bei europioneer für Sie aufsetzen:",[353,354,355,361,367,376,385,391,397,403,409],"ul",{},[138,356,357,360],{},[72,358,359],{},"E-Mail & Kalender:"," Mailcow / Stalwart + Nextcloud",[138,362,363,366],{},[72,364,365],{},"Office-Suite:"," ONLYOFFICE / Collabora",[138,368,369,372,373],{},[72,370,371],{},"Datei-Speicher:"," ",[89,374,30],{"href":375},"/blog/nextcloud-vs-onedrive-sharepoint",[138,377,378,372,381],{},[72,379,380],{},"Team-Chat:",[89,382,384],{"href":383},"/blog/microsoft-teams-alternative","Element/Matrix",[138,386,387,390],{},[72,388,389],{},"Videocalls:"," Element Call / Jitsi / BigBlueButton",[138,392,393,396],{},[72,394,395],{},"Passwortmanager:"," Vaultwarden",[138,398,399,402],{},[72,400,401],{},"Single Sign-On:"," Keycloak",[138,404,405,408],{},[72,406,407],{},"CRM:"," EspoCRM, SuiteCRM, Odoo",[138,410,411,414],{},[72,412,413],{},"Projektmanagement:"," OpenProject",[69,416,417,418,421,422,425,426,429],{},"Alle gehostet in ",[72,419,420],{},"Deutschland",", vollständig ",[72,423,424],{},"DSGVO-konform",", ",[72,427,428],{},"kein CLOUD Act",".",[108,431,433],{"id":432},"fazit","Fazit",[69,435,436,437,440,441,444,445,448,449,429],{},"Schrems III ist keine Frage des ",[72,438,439],{},"Ob",", sondern des ",[72,442,443],{},"Wann",". Wer 2026 noch ohne Plan auf US-Cloud setzt, betreibt ",[72,446,447],{},"bewusstes Compliance-Risiko",". Wer migriert, kauft sich Rechtssicherheit — und ",[89,450,452],{"href":451},"/blog/microsoft-vs-opensource","spart in den meisten Fällen sogar Geld",[69,454,455],{},[89,456,458],{"href":457},"/contact?subject=Schrems-III","Kostenfreies Schrems-III-Vorbereitungsgespräch buchen →",{"title":460,"searchDepth":461,"depth":461,"links":462},"",2,[463,464,465,466,467,473,474],{"id":110,"depth":461,"text":111},{"id":132,"depth":461,"text":133},{"id":168,"depth":461,"text":169},{"id":208,"depth":461,"text":209},{"id":274,"depth":461,"text":275,"children":468},[469,471,472],{"id":279,"depth":470,"text":280},3,{"id":303,"depth":470,"text":304},{"id":328,"depth":470,"text":329},{"id":347,"depth":461,"text":348},{"id":432,"depth":461,"text":433},"2026-05-12T00:00:00.000Z","Max Schrems hat seine dritte Klage gegen den EU-US Data Privacy Framework eingereicht. Beobachter rechnen mit einem Urteil zugunsten der Kläger. Was Unternehmen jetzt tun sollten.","md",null,{"src":480},"https://images.unsplash.com/photo-1589829545856-d10d557cf95f?w=1200&q=80",{},true,"/de/blog/schrems-iii-eugh-urteil",{"title":52,"description":476},"de/3.blog/9.schrems-iii-eugh-urteil","zbexdU3GE_xDdXA7rwQ7o_bqc3igLa4lfFrvS483pUI",[488,478],{"title":489,"path":490,"stem":491,"description":492,"children":-1},"Microsoft 365 in Schulen – Warum NRW, Hessen, Niedersachsen aussteigen","/de/blog/microsoft-365-schulen","de/3.blog/8.microsoft-365-schulen","Datenschutzbehörden und Schulministerien lehnen Microsoft 365 zunehmend ab. Was Schulträger und Eltern 2026 wissen müssen – und welche Alternativen es gibt.",1779405614758]