Dark clouds over the EU-US Data Privacy Framework

DCU Law and Tech regularly publishes blog posts discussing the topics Law and Technology written by a variety of authors.

Elio Machado Neto

Following the recent decision of the US Supreme Court, the independence and supervisory capacity of the US Federal Trade Commission (FTC) are being reconsidered on the other side of the Atlantic, due to the important role it plays in the EU-US Data Privacy Framework (DPF).

Trump v. Slaughter: A Brief Summary

In the month of June, the US Supreme Court, in the case Trump v. Slaughter, ruled that the President must have the power to remove Federal Trade Commission (FTC) commissioners at will because the FTC exercises executive power, moving away from almost one hundred years of precedent. The ruling was not unanimous among the US justices and has raised concerns in Europe over the impact on the 2023 adequacy decision known as the EU-US Data Privacy Framework (DPF) that allows data transfer between the EU and the United States under GDPR.

The ruling was in the context of a lawsuit filed by Rebecca Slaughter, one of the two commissioners removed by President Trump because they were not aligned with his Administration’s priorities. Slaughter argued that her dismissal  violated the FTC Act’s statutory removal protections and the Supreme Court’s precedent in Humphrey’s Executor v. United States, which had upheld such protections. Writing for the majority, Chief Justice John Roberts concluded that the FTC’s statutory restrictions on the President’s power to remove commissioners are unconstitutional because they interfere with the President’s authority over the Executive Branch and the separation of powers under the U.S. Constitution.

In practical terms, the independence of regulatory agencies in the US is likely to be interpreted more restrictively. The US President is entitled to remove commissioners and heads of independent agencies or commissions such as the FTC without reasonable cause.  However, due to the central position occupied by the FTC in the EU-US Data Privacy Framework, this interpretation will influence the ongoing monitoring of the DPF. Under Article 45(3) of the GDPR, the EU Commission is obliged to carry out periodic reviews of  adequacy decisions at least every four years, as was done recently for South Korea’s adequacy decision. The ongoing monitoring takes into consideration all relevant developments in the given jurisdiction. 

Additionally, any eventual consideration brought to the attention of the Court of Justice of the EU (CJEU) may impact EU-US data transfers, as it has occurred on two occasions over the past decade. The significance of the Supreme Court’s ruling becomes clearer when considered against the troubled history of EU-US data transfers. 

A Transatlantic Digital Odyssey: From Safe Harbour to the DPF 

The data transfer between the EU and the US in the last decade has been marked by many U-turns, following the judgments of the CJEU in Schrems I (Case C-362/14) and Schrems II (Case C-311/18). 

In Schrems I, the CJEU invalidated the Safe Harbour Decision in 2015, based on the adequacy decision adopted by the EU Commission under the predecessor of the GDPR, Directive 95/46/EC, in 2000. The Court held that the EU Commission had not sufficiently ensured that U.S. law afforded a level of protection essentially equivalent to that guaranteed within the EU, particularly in light of broad surveillance powers and the lack of effective judicial redress for EU data subjects.

Similarly, in Schrems II, the CJEU invalidated the EU-U.S. Privacy Shield in 2020. The framework, which had been approved in 2016, was found inadequate because U.S. surveillance laws and the absence of enforceable rights for EU individuals were incompatible with EU fundamental rights. This situation was already stressed by the court in 2015.

It took three years, as well as a series of compromises by the Biden administration, before a new adequacy decision could be considered. The European Commission adopted the EU-U.S. Data Privacy Framework Adequacy Decision on 10 July 2023 following  adjustments implemented by the United States in response to the concerns identified by the CJEU in Schrems II. In particular, President Biden signed Executive Order 14086 on 7 October 2022, introducing additional safeguards governing U.S. signals intelligence activities. The Executive Order requires that access to personal data by U.S. intelligence agencies be necessary and proportionate to defined national security objectives and establishes enhanced oversight mechanisms over intelligence activities.

Another key point addressed was the establishment of a new two-tier redress mechanism for individuals from qualifying jurisdictions, including the EU, under the Regulation on the Data Protection Review Court issued by the U.S. Attorney General (AG Regulation), which complements Executive Order 14086. Under this system, complaints concerning access to personal data by U.S. intelligence authorities are first reviewed by the Civil Liberties Protection Officer within the Office of the Director of National Intelligence. It may subsequently be appealed to the newly created Data Protection Review Court (DPRC), an independent review body empowered to issue binding remedial decisions. 

Furthermore, the adequacy decision takes into account the mechanisms in place to ensure compliance by participating US organisations. Those entities wishing to receive personal data under the EU-U.S. Data Privacy Framework must self-certify their compliance with its Principles through the US Department of Commerce. They also need to be subject to oversight and enforcement by the US Federal Trade Commission (FTC) or the US Department of Transportation (DoT). 

On the basis of these legislative, administrative, and enforcement safeguards, the EU Commission concluded that the United States provides an equivalent level of protection to that afforded to EU data subjects. It is important to highlight that adequacy decisions  are not dependent on the literal replication of EU law, but they require that foreign legal systems ensure a certain required level of protection in terms of effective implementation, supervision and enforcement.   

In 2024, as required by Recital 211 of the DPF, the EU Commission carried out a first review to verify that the reforms introduced by Executive Order 14086 had been effectively implemented. The review concluded that the constitutive elements of the framework were in place, with safeguards and limitations applying to the processing of data by the more than 2,800 DPF-certified companies and to access by US authorities.  

The DPF at a Crossroads: It may happen again 

Soon after the US Supreme Court’s ruling, NGOs, like NOYB, called on the EU Commission to repeal the DPF and announced that they were taking measures to bring the case to the CJEU.

However, it would not be the first time that the EU-US Data Privacy Framework is brought to the attention of the CJEU. In 2025, the General Court dismissed the Latombe Case, initiated by French parliamentarian, Philippe Latombe, seeking the annulment of the DPF. Latombe argued that the bulk collection practices of US intelligence agencies remained too broad. The claim also questioned the independence and impartiality of redress mechanisms such as the Data Protection Review Court (DPRC), due to their link to the Executive Branch. Nonetheless, the General Court concluded that the reforms implemented by Executive Order 14086 and AG Regulation were sufficient to provide an equivalent level of protection to EU data subjects. The Latombe case is now pending an appeal under Case C-703/25

As previously mentioned, the EU Commission is obliged to monitor developments in third countries that could affect the functioning of adequacy decisions, such as the case Trump v. Slaughter.  It is in this context that the Chair of the European Data Protection Board (EDPB), in a letter to the EU Commission, stressed the need to monitor the impact of the US Supreme Court’s decision on the EU data transfers, since the independence of the FTC and its commissioners is explicitly mentioned on the DPF. Furthermore, it highlighted that, under Article 45(2) of the GDPR, the existence and effective functioning of one or more independent supervisory authorities in the third country, in the context of data transfers, is one of the key elements required for an adequacy decision to be granted to a third country or international organisation. 

The EU-US Data Privacy Framework is due to be formally reviewed by the EU Commission next year. The coming months will be critical to comprehend the real impact on the         FTC’s independence and its repercussions for the data protection guarantees offered by the US. Much will depend on the European Commission’s political appetite for addressing the issue amid the current tensions in EU-US relations in the digital field, as exemplified by recent Trump’s reaction to Google’s €890 million fine under the DMA, in light with the  February 2025 Memorandum on Defending American Companies and Innovators from Overseas Extortion and Unfair Fines.

In addition, judicial review of the DPF is not out of the picture, with the Latombe case still pending on appeal and possible new legal procedures brought to the CJEU in light of the Trump v. Slaughter case. These developments should be closely monitored not only by data protection rights advocates but also by businesses, given the compliance cost involved in case the adequacy decision is suspended, withdrawn or invalidated.

Image: G. Edward Johnson, CC BY 4.0 <https://creativecommons.org/licenses/by/4.0>.

Suggested citation:

Elio Machado Neto, ‘Dark clouds over the EU-US Data Privacy Framework (Comparative Digital Law Blog, 18 August 2026) <https://lawandtech.ie/dark-clouds-over-the-eu-us-data-privacy-framework>.

Elio Machado Neto is an Associate at Zeidler Group and a European Master in Law, Data and Artificial Intelligence (EMILDAI) graduate. In addition, Elio is a co-editor of the Comparative Digital Law Blog.

Share:

More Blog Posts