Europe's data protection world has been here before. Twice, in fact. Both times, the mechanism that let companies move personal data from the EU to the US collapsed under a Court of Justice of the European Union ruling — Safe Harbor in Schrems I (2015), Privacy Shield in Schrems II (2020). The current mechanism, the EU-US Data Privacy Framework (DPF), adopted in 2023, was built specifically to survive that history. A US Supreme Court ruling this summer has reopened the question of whether it can.
What Actually Happened
On June 29, 2026, the Supreme Court ruled 6–3 in Trump v. Slaughter that the “for-cause” removal protection for FTC commissioners violates the separation of powers, overturning Humphrey's Executor — a nearly 90-year-old precedent that had shielded the agency's independence since 1935. In practice, the President can now remove FTC commissioners at will, rather than only for documented cause.
The case began when the administration removed FTC Commissioner Rebecca Kelly Slaughter in March 2025 without citing a statutory basis. A lower court initially ruled the removal unlawful; the Supreme Court, in an opinion by Chief Justice Roberts, sided with the administration.
That reads like a US administrative-law story with no obvious EU angle. It isn't. FTC independence is one of the specific safeguards the European Commission relied on when it approved the DPF's adequacy decision in 2023 — the legal instrument that lets thousands of companies transfer personal data from the EU to the US without extra contractual safeguards. Legal analysis of that decision counts 259 separate references to FTC independence as a reason the US offered protection “essentially equivalent” to the GDPR.
Why This Hits the DPF Specifically
The DPF's legal architecture rests on the idea that US enforcement bodies — the FTC chief among them — operate independently enough of political pressure to police American companies' handling of EU personal data, with meaningful recourse for EU citizens if that data is misused. An FTC whose commissioners can be dismissed at will by the President is, on paper, a materially different institution than the one the Commission evaluated in 2023.
The ruling doesn't invalidate the DPF by itself — adequacy decisions don't unwind automatically. But it hands privacy advocates a concrete, documented factual change to point to: a core pillar of the 2023 adequacy finding no longer holds as written.
The Commission didn't cite FTC independence once or twice in passing — it built 259 separate references to it into the reasoning. That's not a footnote regulators can quietly reinterpret; it's the foundation.
noyb Has Already Moved
This isn't a hypothetical for privacy advocates to get around to eventually. On June 30, 2026 — one day after the ruling — Max Schrems' organisation noyb sent a formal letter to the European Commission demanding an orderly withdrawal from the DPF adequacy decision, calling the framework a “legal house of cards.” noyb has explicitly framed the coming legal challenge as “Schrems III,” the same organisation behind both prior invalidations.
That's a materially faster start than either previous round. If the pattern holds from here, expect a complaint to work through a national data protection authority, likely referred to the CJEU as a preliminary question — the same route that produced Schrems I and II.
The Realistic Timeline
Nothing about this moves quickly, even with noyb already at the Commission's door. Legal commentators tracking the case treat late 2026 as the earliest plausible date for a CJEU ruling, with 2027 as the more likely working assumption. The DPF is not disappearing this quarter, or likely this year.
That said, “not this quarter” is a bad reason to wait. Both previous invalidations arrived abruptly once the CJEU actually ruled, and organisations that had built their entire transfer compliance around the mechanism of the moment were left scrambling. The lesson institutional memory should supply by now: build the fallback before you need it, not after.
What to Do Now
If you move personal data from the EU to the US under the DPF, this is a “shore up the fallback” moment — not a “rip out the pipes” moment.
- Don't drop your SCCs. If you already layer Standard Contractual Clauses on top of DPF certification — the “belts and braces” approach several DPAs have recommended — keep doing it. Organisations with SCCs already in place face far less disruption if the DPF is annulled; organisations relying on DPF certification alone face a much harder transition.
- Keep your Transfer Impact Assessments current. If you run TIAs alongside SCCs, treat this ruling as the trigger to revisit them now, rather than waiting for a CJEU decision to force the issue. If you don't have a TIA process yet, that's the gap to close first — the same logic that applies to building a DPIA process before you need one applies here.
- Watch for the first DPA-level complaint. The real signal to move faster is a specific complaint filed with an EU data protection authority explicitly citing Trump v. Slaughter. That's the moment this shifts from “risk to monitor” to “active legal proceeding.” Given noyb's letter, that step could plausibly land within the next few months.
- Don't panic-migrate infrastructure. There is no indication the DPF is legally dead, and moving data flows reactively based on a single US court decision would be premature and costly. Fix the fallback; don't tear out the primary path yet.
Set alongside everything else moving in EU data protection this year — the AI Act's high-risk obligations now layered on top of GDPR, the Digital Omnibus fight over narrowing the definition of personal data, the EDPB's 2026 transparency enforcement sweep — this fits a broader pattern: the legal foundations that felt settled are being renegotiated on multiple fronts at once, from Brussels and from Washington. If you're not sure whether your organisation's transfer mechanism has a real fallback behind it, that's worth an answer before a complaint forces one. Book a free consultation with GDPRGard →
Sources
- Supreme Court of the United States — Trump v. Slaughter, No. 25-332 (June 29, 2026)
- SCOTUSblog — Trump v. Slaughter case page
- Congress.gov / CRS — Trump v. Slaughter and the Future of For-Cause Removal Protections
- Wiley — U.S. Supreme Court Allows President to Remove FTC Commissioners
- activeMind.legal — EU-U.S. Data Privacy Framework at risk following Supreme Court ruling
Also read:
- The AI Act just went live for high-risk systems — now you have two regulators
- Why every SaaS company needs a DPIA before launching AI features
- The AI Act delay doesn't cover your chatbot