EU-U.S. Data Privacy Framework is Still Working Despite SCOTUS Ruling - Articles

Articles

Stay at the forefront of the consumer insights and analytics industry with our Thought Leadership content. Here you’ll find timely updates on the Insights Association’s advocacy efforts, including the latest legislative and regulatory developments that impact how we work. In addition, this section offers expert perspectives on innovative research techniques and methodologies, as well as valuable analysis of evolving consumer trends. Together, these insights provide a trusted resource for professionals looking to navigate change, elevate their practice, and shape the future of our industry.

EU-U.S. Data Privacy Framework is Still Working Despite SCOTUS Ruling

EU-U.S. Data Privacy Framework is Still Working Despite SCOTUS Ruling

A U.S. Supreme Court ruling regarding the independence of the Federal Trade Commission (FTC) has driven concerns that one of the primary mechanisms for trans-Atlantic data sharing, the EU-U.S. Data Privacy Framework (DPG), is in jeopardy.

  • The Supreme Court’s June 29, 2026, decision allowing the president to remove FTC commissioners prompted concerns that it could undermine the independence requirements supporting the EU-U.S. Data Privacy Framework.
  • Privacy advocacy group noyb urged the European Commission to begin dismantling the framework, but legal experts argue that the ruling does not affect the separate legal protections supporting the Data Protection Review Court.
  • Despite potential future legal challenges, the EU-U.S. Data Privacy Framework remains in force and continues to provide an approved mechanism for transferring personal data from Europe to the United States

The Trump v. Slaughter decision, issued June 29, 2026, overturned a 1935 precedent by declaring that FTC commissioners could be removed at the will of the President, despite attempts in law to shield them from such.

European activist group noyb quickly appealed to the European Commission, extrapolating that the court decision ruled “any independent executive authorities in the US are unconstitutional,” including the independent redress mechanism for government surveillance, the Data Protection Review Court (DPRC) inside the U.S. Department of Justice. noyb urged “the Commission to immediately take all necessary steps to allow European citizens and businesses an orderly exit from the “EU-US Data Protection Framework”. This should include an imminent plan for the orderly repeal of Commission Implementing Decision EU 2023/1795, as well as reasonable transition periods.”

noyb has made a habit of filing cases against trans-Atlantic data sharing agreements, including the predecessors to the DPF, and stated in their letter their intent to file yet another case to nullify the DPF along these lines of argument.

However, writing in an op-ed for IAPP, Kenneth Propp of the Georgetown University Law Center, Theodore Christakis of the University of Grenoble Alpes, and Peter Swire of Alston & Bird swiftly responded that noyb was wrong. Although the DPRC was created by executive action (a Biden Administration executive order) rather than law, they had argued at the time of the action that “the DPRC could meet the EU requirements of independence and effectiveness.” The EU General Court later “upheld the mechanism in Latombe v. Commission.”

The op-ed authors continue that, “Assuming the General Court was right about the DPRC, has Slaughter fundamentally altered the legal foundation on which that conclusion rests? In our view it has not, and the reasons lie in what the Slaughter decision actually held. We do not revisit the objections to the DPRC that the EU General Court considered and rejected in Latombe; we take its analysis as given and ask only what, if anything, Slaughter changes.”

The authors conclude that, "the specific U.S. law mechanism we described in 2022 and that the General Court accepted," has not changed. "The DPRC’s independence rests on a regulation that binds the executive while it remains in force; Slaughter concerns the power of Congress, leaves executive self-binding untouched, and preserves the exceptions under which the judges’ protection is permissible. The premise of the General Court’s analysis is therefore intact."

While insights professionals should take heart from the op-ed’s conclusions, since the government surveillance angle has been a key sticking point in data sharing agreements in the past, it does not let the private sector side of the issue off scot-free, and there may again be a chance for groups like noyb to try to kill the Data Privacy Framework. The Insights Association will be keeping an eye on developments.

For now, the EU-U.S. Data Privacy Framework remains in effect and in force (“adequate” for safe transfer to the U.S. under the General Data Protection Regulation (GDPR)).

Questions regarding the DPF and the Insights Association Data Privacy Framework (DPF) Services Program -- independent dispute resolution for companies self-certifying to the EU-U.S. Data Privacy Framework (EU-U.S DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) -- contact Juliana Wood.

This information is not intended and should not be construed as or substituted for legal advice. It is provided for informational purposes only. It is advisable to consult with private counsel on the precise scope and interpretation of any laws/regulation/legislation and their impact on your particular business.

Related

Share

Login

Members only Article - Please login to view
  • Back to top