StartupsEventsJobsNewsTV
Founders·Investors·Ecosystem·
DutchStartup.ai
EventsJobsNewsTV
All articles

News

EU-US Data Privacy Framework under pressure following US Supreme Court ruling

1 July 2026·4 min read

The EU-US Data Privacy Framework, the agreement that has governed the transfer of personal data between the EU and the US since 10 July 2023, is once again facing serious legal pressure. On 30 June 2026, the US Supreme Court ruled in Trump v. Slaughter that the independence of the Federal Trade Commission (FTC) is unconstitutional. That ruling strikes directly at one of the pillars on which the Framework rests.

Privacy organisation noyb (European Center for Digital Rights), founded by Austrian privacy activist Max Schrems, describes the consequences as the effective collapse of the agreement. Schrems is calling on the European Commission to withdraw its adequacy decision for the US immediately. Noyb has announced it will launch new legal proceedings within a matter of weeks.

This is the third time in just over ten years that a transatlantic privacy framework has come under fire. The Court of Justice of the European Union struck down the Safe Harbour agreement in 2015 (Schrems I) and the Privacy Shield in July 2020 (Schrems II). The current Framework was built in part as a response to that latter ruling.

What the Supreme Court actually decided

In Trump v. Slaughter, the Supreme Court considered whether the president may dismiss FTC commissioners at will. The case arose from the dismissal in March 2025 of Democratic commissioner Rebecca Slaughter by President Donald Trump. The Court ruled that statutory protections shielding FTC commissioners from dismissal without cause are unconstitutional. This removes the institutional independence of the regulator as it had previously been guaranteed.

That independence is far from a peripheral issue for the Data Privacy Framework. In its 2023 adequacy decision, the European Commission referenced the role of the FTC as an independent enforcer no fewer than 259 times. The reasoning was that participating US companies would be accountable for privacy violations through the FTC. Now that the Supreme Court ruling eliminates that independence, a central justification for the adequacy decision falls away, according to noyb.

Noyb prepares new legal proceedings

Noyb has indicated it will file a complaint within a few weeks, aimed at having the Data Privacy Framework annulled by the Court of Justice of the European Union. Such proceedings before the CJEU typically take two to three years. In the meantime, the Framework remains formally in force unless the European Commission itself takes action.

Schrems has called on the Commission to withdraw the adequacy decision. The Commission has not yet taken that step. Earlier, on 3 September 2025, the General Court of the EU had already rejected an action brought by French parliamentarian Philippe Latombe, who had filed a complaint against the Framework in September 2023. That dismissal did not preclude other legal avenues from remaining open.

The European Parliament voted on 11 May 2023, before the Framework had even entered into force, in favour of a resolution calling on the Commission to renegotiate the agreement. That resolution was adopted by 306 votes to 27, but carries no binding legal force.

What companies can expect now

The Data Privacy Framework is the legal instrument that allows US companies to receive personal data from the EU, provided they have enrolled in the Framework and meet its associated requirements. On 6 July 2024, the adequacy decision was also incorporated into the EEA Agreement, making it applicable across the entire European Economic Area.

As long as the Framework formally holds, companies can in principle continue to rely on it. However, the legal uncertainty now emerging is comparable to the situation in the lead-up to the Schrems II ruling in 2020. At that time, there was a period in which businesses knew that the legal basis they relied upon was being challenged, but had no clarity on the outcome.

Alternative legal bases for data transfers, such as Standard Contractual Clauses, were already adopted by many organisations as an additional safeguard following Schrems II. Companies that rely exclusively on the Framework would be well advised to reassess those alternatives, although those instruments too carry requirements that depend on the level of protection actually afforded in the receiving country.

A recurring pattern of successive agreements

The history of transatlantic privacy agreements reveals a recurring pattern. Safe Harbour lasted ten years before the Court of Justice struck it down in 2015. Its successor, the Privacy Shield, held for five years until the Schrems II ruling in 2020. The current Framework is not yet three years old and is already being challenged on points that were criticised at the time of its creation.

The root of the problem is structural in nature. Each time the EU adopts an adequacy decision for the US, it must demonstrate that US law provides a level of protection essentially equivalent to that of the GDPR. The US government holds fundamentally different views on government oversight of data use and the independence of regulators. As long as that gap is not bridged within US legislation itself, any new agreement will remain vulnerable to the same objections.

For the broader European tech and startup scene, this situation underscores how heavily the legal infrastructure for data exchange with the US depends on political and institutional developments beyond Europe's sphere of influence. Investors and founders who have built their architecture in part around transatlantic data flows will be watching these proceedings closely in the years ahead.

In this article

ECEuropese CommissieUitvoerend orgaan van de Europese UnieFTFederal Trade CommissionAmerikaanse regelgever tegen oneerlijke handelspraktijkenNnoybPrivacyrechten verdedigen door juridische actiesEPEuropees ParlementWetgevend orgaan van de Europese UnieECEuropean Center for Digital RightsDigitale rechten verdedigen in EuropaEHEuropees Hof van JustitieEuropese rechtbank voor interpretatie en handhaving van EU-rechtAHAmerikaans HooggerechtshofHoogste rechtbank van de Verenigde StatenEGEuropees GerechtEuropese rechterlijke instantie voor juridische geschillen

Relevant from our ecosystem

AI4CosmeticsAI4CosmeticsStartupAI automatiseert veiligheids- en R&D-workflows voor cosmeticabedrijvenClemberClemberStartupCybersecurity-analyses in minuten in plaats van weken voor consultantsManukaiManukaiStartupVoorspelt veiligheidsrisico's wereldwijd voor bedrijven en reizigers

In this article

ECEuropese CommissieUitvoerend orgaan van de Europese UnieFTFederal Trade CommissionAmerikaanse regelgever tegen oneerlijke handelspraktijkenNnoybPrivacyrechten verdedigen door juridische actiesEPEuropees ParlementWetgevend orgaan van de Europese UnieECEuropean Center for Digital RightsDigitale rechten verdedigen in EuropaEHEuropees Hof van JustitieEuropese rechtbank voor interpretatie en handhaving van EU-rechtAHAmerikaans HooggerechtshofHoogste rechtbank van de Verenigde StatenEGEuropees GerechtEuropese rechterlijke instantie voor juridische geschillen

Relevant from our ecosystem

AI4CosmeticsAI4CosmeticsStartupAI automatiseert veiligheids- en R&D-workflows voor cosmeticabedrijvenClemberClemberStartupCybersecurity-analyses in minuten in plaats van weken voor consultantsManukaiManukaiStartupVoorspelt veiligheidsrisico's wereldwijd voor bedrijven en reizigers
PreviousFieldWatch launches AI platform for artificial turf pitches and secures investment from ROM Utrecht RegionNextGoogle restricts Meta's access to Gemini computing capacity

Sources

This article draws in part on the following sources.

  • euractiv.com
  • dig.watch
  • noyb.eu
  • techzine.eu
  • iapp.org
  • epc.eu
  • edendata.com
  • wikipedia.org
  • youtube.com
  • workforcebulletin.com
  • data-privacy-framework.com
  • ibgids.nl

Related articles

dutchstartup2 days ago

While hiring systems select for the past, ObjectivEye is building AI for the labour market of tomorrow

The real problem in recruitment is not scarcity. It is that the system is fundamentally broken. Noura El Ouajdi, founder of ObjectivEye, spent years observing this from TNO: organisations make decisions based on CVs and intuition, while the labour market is changing faster than ever. Her answer is…

Noura el OuajdiNoura el OuajdiObjectivEyeObjectivEyeTTNO
dutchstartup2 days ago

Utrecht-based Moveshelf wins Children's Hospital Los Angeles as a client and joins European home care project

Utrecht-based Moveshelf, active in motion analysis, has integrated its platform into the Motion and Sports Analysis Lab at Children's Hospital Los Angeles. The company is also participating in RE:HOME, a European project focused on smart home care for neurological paediatric patients.

MoveshelfMoveshelfCHChildren's Hospital Los AngelesAbsolute Audio Labs B.V.Absolute Audio Labs B.V.
ai2 days ago

OpenAI introduces ChatGPT Work, an AI agent that completes tasks autonomously

OpenAI has launched ChatGPT Work, an AI agent within ChatGPT that independently executes complex projects and delivers end products such as spreadsheets, presentations and web applications. The launch is accompanied by the merger of the Codex app into the ChatGPT desktop app and the introduction of the GPT-5.6 model family.

OpenAIOpenAIMicrosoftMicrosoftAnthropicAnthropic
DutchStartup.ai

The platform for the Dutch AI scene.

About·Contact·Privacy·Terms