EU-U.S. Data Privacy Framework (DPF) is under threat

  • Author: Arno Schlösser, DP-Dock GmbH
  • Last updated: July 2026
  • Category: Data Security

The ruling of the US Supreme Court in the case of Trump v. Slaughter calls into question the legality of transatlantic data transfers following its decision of 29.06.2026.

The U.S. Supreme Court was to rule on the legality of President Trump's firing of Rebecca Slaughter, a Democratic Commissioner of the Federal Trade Commission ( "FTC "). The president removed the commissioner without stating any cause, even though such action had previously been considered constitutionally impermissible with respect to members of independent agencies. The court held that the president has the constitutional authortiy to remove the heads of independent agencies or commissions, including the FTC, without having to demonstrate cause. The decision was based on the so-called unitary executive theory, under which the Constitution vests executive power in the President. Accordingly, agencies exercising executive powers must remain subject to presidential control, including the President’s authority to remove their officers at any time and without providing reasons.


Relevance for Data Protection Law

The EU-US Data Privacy Framework (‘DPF’), concluded in 2023, relies heavily on the FTC as an independent supervisory and enforcement authority.

The EU’s adequacy decision, on which the DPF is based, relies substantially on the independence and effectiveness of the U.S. oversight and enforcement mechanisms to ensure that EU data subjects personal data are afforded a level of protection that is essentially equivalent to that guarantees within the EU. The FTC plays a central role in this framework, as it is responsible for enforcing DPF obligations of participating U.S. companies. It monitors whether companies certified under the DPF actually comply with the data protection principles to which they have committed.

The Supreme Court’s decision raises the question of whether the independent oversight on which the DPF is based can still satisfy this standard if a key U.S. enforcement authority may be reconstituted through immediate presidential dismissal of its commissioners. It may therefore be argued that such authorities can no longer be regarded as sufficiently independent supervisory authorities within the meaning of EU law.

For the EU-US. Data Privacy Framework, the decision therefore has significant implications. Although the adequacy decision remains in force for the time being, doubts are growing as to whether the U.S. oversight and enforcement mechanisms will continue to satisfy European legal requirements in the long term.

The issue is further intensified by the ongoing proceedings before the General Court of the EU and the already announced legal challenge by Max Schrems and the Vienna-based digital rights NGO ‘NOYB’ against the Data Privacy Framework.

The EU Commission may also review the adequacy decision on its own initiative if it considers that EU data subjects no longer receive an equivalent level of protection of personal data to that guaranteed under the GDPR.

Accordingly, the DPF remains formally in force until either the European Commission repeals the adequacy decision or the Court of Justice of the European Union (CJEU) declares it invalid.

Experts expect any proceedings before the CJEU to take approx. two to three years.


Practical Implications for Businesses

Companies that currently rely on the DPF as the legal transfer mechanism of personal data to the U.S. should not wait to for further developments before taking action.


We recommend;

  • review their transfers of personal data to the United States and identify which data flows currently rely on DPF certification and would therefore be affected if the DPF were suspended or invalidated;
  • review their Transfer Impact Assessments ("TIAs"); and
  • assess alternative transfer mechanisms, such as the EU Standard Contractual Clauses ("SCCs") or Binding Corporate Rules ("BCRs"), to ensure that appropriate fallback mechanisms are in place.

If you have any questions about anything in this article or about international data transfers in general, please feel free to contact us.

GDPR General Data Protection Regulation USA EU Flag Paragraph
© Bernulius / stock.adobe.com | #205370012

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed