The EU-US Data Privacy Framework, the agreement that has governed the transfer of personal data between the EU and the US since 10 July 2023, is once again facing serious legal pressure. On 30 June 2026, the US Supreme Court ruled in Trump v. Slaughter that the independence of the Federal Trade Commission (FTC) is unconstitutional. That ruling strikes directly at one of the pillars on which the Framework rests.
Privacy organisation noyb (European Center for Digital Rights), founded by Austrian privacy activist Max Schrems, describes the consequences as the effective collapse of the agreement. Schrems is calling on the European Commission to withdraw its adequacy decision for the US immediately. Noyb has announced it will launch new legal proceedings within a matter of weeks.
This is the third time in just over ten years that a transatlantic privacy framework has come under fire. The Court of Justice of the European Union struck down the Safe Harbour agreement in 2015 (Schrems I) and the Privacy Shield in July 2020 (Schrems II). The current Framework was built in part as a response to that latter ruling.
What the Supreme Court actually decided
In Trump v. Slaughter, the Supreme Court considered whether the president may dismiss FTC commissioners at will. The case arose from the dismissal in March 2025 of Democratic commissioner Rebecca Slaughter by President Donald Trump. The Court ruled that statutory protections shielding FTC commissioners from dismissal without cause are unconstitutional. This removes the institutional independence of the regulator as it had previously been guaranteed.
That independence is far from a peripheral issue for the Data Privacy Framework. In its 2023 adequacy decision, the European Commission referenced the role of the FTC as an independent enforcer no fewer than 259 times. The reasoning was that participating US companies would be accountable for privacy violations through the FTC. Now that the Supreme Court ruling eliminates that independence, a central justification for the adequacy decision falls away, according to noyb.
Noyb prepares new legal proceedings
Noyb has indicated it will file a complaint within a few weeks, aimed at having the Data Privacy Framework annulled by the Court of Justice of the European Union. Such proceedings before the CJEU typically take two to three years. In the meantime, the Framework remains formally in force unless the European Commission itself takes action.
Schrems has called on the Commission to withdraw the adequacy decision. The Commission has not yet taken that step. Earlier, on 3 September 2025, the General Court of the EU had already rejected an action brought by French parliamentarian Philippe Latombe, who had filed a complaint against the Framework in September 2023. That dismissal did not preclude other legal avenues from remaining open.
The European Parliament voted on 11 May 2023, before the Framework had even entered into force, in favour of a resolution calling on the Commission to renegotiate the agreement. That resolution was adopted by 306 votes to 27, but carries no binding legal force.
What companies can expect now
The Data Privacy Framework is the legal instrument that allows US companies to receive personal data from the EU, provided they have enrolled in the Framework and meet its associated requirements. On 6 July 2024, the adequacy decision was also incorporated into the EEA Agreement, making it applicable across the entire European Economic Area.
As long as the Framework formally holds, companies can in principle continue to rely on it. However, the legal uncertainty now emerging is comparable to the situation in the lead-up to the Schrems II ruling in 2020. At that time, there was a period in which businesses knew that the legal basis they relied upon was being challenged, but had no clarity on the outcome.
Alternative legal bases for data transfers, such as Standard Contractual Clauses, were already adopted by many organisations as an additional safeguard following Schrems II. Companies that rely exclusively on the Framework would be well advised to reassess those alternatives, although those instruments too carry requirements that depend on the level of protection actually afforded in the receiving country.
A recurring pattern of successive agreements
The history of transatlantic privacy agreements reveals a recurring pattern. Safe Harbour lasted ten years before the Court of Justice struck it down in 2015. Its successor, the Privacy Shield, held for five years until the Schrems II ruling in 2020. The current Framework is not yet three years old and is already being challenged on points that were criticised at the time of its creation.
The root of the problem is structural in nature. Each time the EU adopts an adequacy decision for the US, it must demonstrate that US law provides a level of protection essentially equivalent to that of the GDPR. The US government holds fundamentally different views on government oversight of data use and the independence of regulators. As long as that gap is not bridged within US legislation itself, any new agreement will remain vulnerable to the same objections.
For the broader European tech and startup scene, this situation underscores how heavily the legal infrastructure for data exchange with the US depends on political and institutional developments beyond Europe's sphere of influence. Investors and founders who have built their architecture in part around transatlantic data flows will be watching these proceedings closely in the years ahead.