A ruling by the US Supreme Court is raising new questions about the agreement governing transatlantic data transfers. The Court decided that the president may generally dismiss members of the Federal Trade Commission. Yet the regulator’s political independence was one of the safeguards cited by the European Commission when it approved the transfer of European data to the United States in 2023.
The European Data Protection Board has asked the European Commission to assess the consequences of the US ruling for the EU-US Data Privacy Framework.
In a letter dated July 31, the board emphasized that independent data protection oversight is one of the core requirements for recognizing an adequate level of protection in a non-EU country.
The framework allows European companies to transfer personal data relatively easily to certified providers in the United States. This may include customer, employee or user data processed by US cloud, software and platform companies.
The Ruling Was Not About Data Protection
The case did not concern European data, intelligence services or the General Data Protection Regulation.
US President Donald Trump had dismissed Democratic FTC Commissioner Rebecca Kelly Slaughter. Under the previous legal framework, commissioners could only be removed for specific reasons such as neglect of duty, incapacity or misconduct.
On June 29, the Supreme Court ruled by a 6–3 majority that this restriction was unconstitutional. According to the Court, the FTC exercises substantial executive power through its rulemaking, investigative and enforcement authority. Its commissioners must therefore remain under presidential control — including the president’s power to dismiss them.
The ruling primarily concerns the balance of power within the US government. Its consequences, however, extend into European data protection law.
The EU Explicitly Relied on an Independent FTC
The Federal Trade Commission is responsible for monitoring whether US companies comply with their commitments under the Data Privacy Framework.
It can investigate misleading privacy claims, pursue violations and impose or seek binding orders against companies.
In its 2023 adequacy decision, the European Commission explicitly described the relevant US authorities as independent. It also pointed to the fact that the FTC’s five commissioners could not be removed for political reasons, but only under legally defined circumstances.
That safeguard no longer exists in the same form.
The European Data Protection Board is therefore not merely asking whether the composition of a US agency has changed. It is questioning whether a central assumption behind the European approval still reflects the current legal situation.
Data Transfers Have Not Suddenly Become Illegal
For companies, the most important point is that the EU-US Data Privacy Framework remains in force.
Neither the Supreme Court nor the European Data Protection Board can automatically invalidate the European Commission’s adequacy decision. The board has requested a review, but it has not concluded that the United States no longer provides sufficient protection.
European companies may therefore continue to transfer data under the framework to certified US recipients, provided the organization appears on the official list and the relevant processing activity is covered by its certification.
Companies using other transfer mechanisms, such as Standard Contractual Clauses or Binding Corporate Rules, are also not directly affected by any possible future change to the framework. These mechanisms must nevertheless ensure an adequate level of protection in practice.
There is currently no legal basis for an immediate halt to transatlantic data flows.
The FTC Is Important — but It Is Not the Entire Agreement
The framework rests on several pillars.
The FTC primarily enforces the commercial privacy commitments made by certified companies. Separate rules govern the conditions under which US intelligence agencies may access data.
The Data Protection Review Court was created to handle complaints concerning government surveillance. In September 2025, the General Court of the European Union found that the structure of this review mechanism provided sufficient safeguards for independence and oversight. It therefore dismissed a legal challenge to the Data Privacy Framework.
The new Supreme Court ruling does not directly abolish that mechanism.
It does, however, weaken another safeguard that the European Commission explicitly examined: the independent enforcement of privacy commitments against US companies.
The agreement has not collapsed. One of its supporting assumptions has nevertheless developed a significant crack.
Two Previous Agreements Already Failed in Court
The conflict is familiar to European companies.
In 2015, the European Court of Justice invalidated the Safe Harbor agreement. In 2020, it struck down its successor, the Privacy Shield.
In both cases, the judges found that European data transferred to the United States did not receive protection essentially equivalent to EU standards — particularly because of broad US intelligence access and insufficient legal remedies.
The Data Privacy Framework introduced in 2023 is therefore already the third attempt to establish reliable rules for transatlantic data transfers.
It survived its first legal challenge in September 2025. That ruling, however, assessed the legal situation at the time of the Commission’s 2023 decision. The latest Supreme Court judgment represents a new development that could not have been considered at that point.
Companies Do Not Need Emergency Measures — but They Need a Backup Plan
Abandoning all US service providers as a precaution would currently be neither legally necessary nor operationally realistic for many companies.
It would be equally unwise, however, to rely exclusively on the long-term survival of the framework.
Companies should know which providers and processing activities depend on it, whether the relevant certifications remain valid and which contractual alternatives could be activated if the adequacy decision changes.
This is particularly relevant for cloud services, human resources software, analytics tools, customer relationship management systems and AI platforms.
Such preparations are not a response to an existing violation. They are a form of risk management. After the Privacy Shield was invalidated, many businesses had to restructure contracts and transfer assessments under intense time pressure.
A third abrupt awakening would be difficult to justify.