Policy & Ethics
Max Schrems
Founder and Chairman, noyb – European Center for Digital Rights
The Austrian lawyer whose single-handed complaints twice toppled EU-US data-transfer regimes.
Score 79/100
Why they’re on the list
Schrems' litigation single-handedly invalidated two successive EU-US data-transfer frameworks and his organisation noyb remains one of the most effective private enforcers of GDPR against Big Tech.
Max Schrems is the privacy campaigner who, more than any other individual, forced the world's largest technology companies to reckon with European data protection law. As a law student in Vienna in 2011, he requested his own personal data file from Facebook and received a PDF running to more than 1,200 pages, revealing how much information the company retained even after users believed it deleted. That discovery launched a career of strategic litigation that has repeatedly reshaped transatlantic data flows.
His complaint against Facebook's transfer of European user data to US servers led to the 2015 'Schrems I' ruling, in which the Court of Justice of the European Union struck down the Safe Harbor framework that had governed EU-US data transfers for fifteen years. Five years later, a second case, 'Schrems II', invalidated its successor, the Privacy Shield, after the court found that US surveillance law offered inadequate protection for European citizens' data. Together the two rulings forced a fundamental renegotiation of how American technology companies legally justify moving European data across the Atlantic.
In 2017, Schrems founded noyb (short for 'none of your business'), a Vienna-based non-profit that files strategic GDPR complaints against companies ranging from Google and Meta to smaller adtech and data-broker firms. Under his leadership noyb has filed complaints worth billions of euros in potential fines and has become one of the most active private enforcers of European data protection law, frequently working ahead of, or in place of, under-resourced national regulators.
Schrems trained as a lawyer at the University of Vienna and has since combined legal practice with sustained public advocacy, testifying before the European Parliament and US congressional bodies and regularly briefing journalists and regulators on data-transfer mechanics that few outside the field fully understand.
His influence lies less in any single ruling than in demonstrating that a lone, well-organised individual can compel structural change in how global data flows are governed. Two decades of EU-US data-transfer policy have been written substantially in response to his litigation, and noyb continues to test the next generation of data-protection frameworks, including the EU-US Data Privacy Framework, which he has already signalled he may challenge again.
Career timeline
- 2011Requests his Facebook data file, exposing extensive retained personal data
- 2013Files complaint over Facebook data transfers under NSA's PRISM programme
- 2015'Schrems I' ruling invalidates the EU-US Safe Harbor framework
- 2017Co-founds noyb – European Center for Digital Rights
- 2018Files GDPR complaints against Google and Facebook worth €3.9 billion
- 2020'Schrems II' ruling invalidates the EU-US Privacy Shield
- 2023Continues challenges as EU-US Data Privacy Framework is adopted