The European Commission is investigating whether the EU-US Data Privacy Framework (DPF) can remain in place. The immediate trigger is a ruling by the US Supreme Court that affects the independence of the Federal Trade Commission (FTC), one of the supervisory bodies on which the framework relies.
The Supreme Court ruled in Trump v. Slaughter, on or around 29 June 2026, that the US president may dismiss and appoint FTC commissioners at his own discretion. This conflicts with a core requirement of the DPF: the supervisory authorities that enforce compliance among US companies must operate independently of the executive branch. The Commission is now examining whether that condition is still being met.
For as long as the investigation is ongoing, there is legal uncertainty about the validity of the framework. This has direct consequences for companies on both sides of the Atlantic that exchange personal data on the basis of the DPF.
What the EU-US Data Privacy Framework governs
The EU-US Data Privacy Framework entered into force in July 2023 as the successor to Privacy Shield, which was previously invalidated by the European Court of Justice. The framework enables personal data of EU citizens to be transferred to certified US companies without the need for additional legal instruments, such as standard contractual clauses.
The European Commission adopted the DPF through a so-called adequacy decision: a formal determination that the US legal system offers a comparable level of protection to that of the General Data Protection Regulation (GDPR). Such a decision rests on concrete guarantees, including the presence of independent supervisory authorities capable of handling complaints from EU citizens and enforcing compliance.
The FTC plays a central role in this. If the president can replace commissioners of that body at his own discretion, it can no longer be assumed that the FTC operates fully independently of political direction. That is precisely the question the Commission must now answer.
What the Supreme Court ruling changes
In Trump v. Slaughter, the Supreme Court ruled that statutory provisions restricting the president's ability to dismiss FTC commissioners are unconstitutional. This brings the FTC, which has traditionally functioned as an independent agency, closer to the direct sphere of influence of the executive branch.
For European privacy purposes, this is relevant because the DPF explicitly refers to the role of the FTC as an enforcement body. If the independence of that body is no longer legally guaranteed, one of the pillars on which the adequacy decision rests is undermined. The European Commission is obliged under the GDPR to periodically review adequacy decisions and to revoke them if the factual situation no longer meets the requirements.
The Commission has indicated that it will also take the broader functioning of the US legal system into account in its analysis, not just the direct consequences of this single ruling.
What this means for companies currently using the DPF
Many Dutch and European companies make use of US cloud services, advertising platforms and SaaS applications through which personal data of EU citizens is transferred to the US. A significant portion of those transfers is based on the DPF, or on certification of the US provider under that framework.
For as long as the adequacy decision remains formally in force, companies can continue to rely on the DPF as a legal basis. However, if the Commission concludes that the decision is no longer tenable and revokes it, that basis falls away. Companies would then have to fall back on alternatives such as standard contractual clauses or binding corporate rules, which entail greater administrative burdens and are in some cases legally more complex.
Previously, following the invalidation of Safe Harbor in 2015 and Privacy Shield in 2020, many organisations found themselves compelled to revise their legal arrangements for data transfers at short notice. How quickly the Commission will now reach a conclusion remains unknown.
Broader perspective for the Dutch and European AI scene
For Dutch and European startups and scale-ups working with personal data, this investigation is relevant regardless of the outcome. Many AI companies in the Dutch ecosystem run models or process training data via US infrastructure. If the DPF lapses, they will need to restructure their data flows from a legal standpoint, which costs time and money.
Investors and legal teams at venture capital funds typically monitor developments of this kind closely, as the soundness of data processing arrangements is a factor in due diligence. For policymakers in The Hague and Brussels, the case reinforces how vulnerable European data sovereignty is when it rests on legal guarantees that can be undermined by US court rulings. The debate about European digital infrastructure as an alternative thereby gains renewed factual grounding.