Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

EU data-transfer scrutiny: the collapse of Privacy Shield and Dropbox's exposure

2020 onward

MediumStatus: OngoingYear: 2020

When the EU's top court struck down the EU–US Privacy Shield in 2020, Dropbox — which had self-certified under the framework — was among the US cloud services left exposed to European data-protection regulators questioning whether personal data could lawfully be transferred to the United States.

What happened

On 16 July 2020 the Court of Justice of the European Union, in the 'Schrems II' judgment, invalidated the EU–US Privacy Shield framework, the mechanism many American companies used to legitimize transfers of Europeans' personal data to the United States. The court held that US surveillance law did not provide European data subjects with protection essentially equivalent to that guaranteed under EU law.

Dropbox had self-certified under the EU–US and Swiss–US Privacy Shield frameworks to cover its transfers of certain personal data from the European Economic Area and Switzerland to the United States. With Privacy Shield gone, that basis evaporated, and the CJEU's ruling imposed heightened obligations on companies relying on the alternative mechanism of Standard Contractual Clauses — requiring case-by-case assessments and supplementary safeguards. In its own SEC filings, Dropbox acknowledged that European regulators could apply differing standards and require additional measures, and that the uncertainty around transatlantic data transfers created compliance risk.

This is regulatory and legal exposure rather than a single named lawsuit against Dropbox: the judgment applied broadly to US cloud providers, and critics and some European authorities argued that storing EU residents' personal data on US-based services such as Dropbox had become legally fraught. The risk has been partly addressed by the later EU–US Data Privacy Framework (adopted in 2023), but the area remains contested.

On 10 July 2023 the European Commission adopted the adequacy decision establishing the EU–U.S. Data Privacy Framework. On 3 September 2025 the EU General Court dismissed a challenge to that decision brought by French citizen Philippe Latombe (Case T-553/23, Latombe v Commission), finding that, as of the decision's adoption, the United States ensured an adequate level of protection for personal data transferred from the EU. The Court noted that, under the decision, the Commission 'is required to monitor continuously' the framework and 'may decide, if necessary, to suspend, amend or repeal' it. Dropbox's privacy policy states that 'Dropbox, Inc. complies with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, as well as the UK Extension to the EU-U.S. Data Privacy Framework' under the U.S. Department of Commerce's program, and that its certification 'does not include the FormSwift portion of the Services.'

Impact

Schrems II turned Dropbox's cross-border data flows into an ongoing legal and compliance liability, requiring it to re-paper its transfer mechanisms and absorb the risk that EU regulators or courts could restrict its handling of European personal data. It strengthened the case for EU-based and sovereignty-focused competitors and made data residency a recurring concern for European business customers evaluating Dropbox. Dropbox itself flagged the regulatory uncertainty as a material risk in its public filings.

Dropbox's Response / Official Position

Dropbox disclosed the data-transfer risk in its SEC filings, noting the invalidation of Privacy Shield and the added obligations on Standard Contractual Clauses, and stated it relied on alternative transfer mechanisms and supplementary measures. It positioned compliance with evolving EU data-protection requirements, including GDPR, as an ongoing effort rather than a resolved matter.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation