The EU-US Data Privacy Framework has been running for three years and remains the most convenient route for sending personal data to a United States provider. It is also the most fragile. During 2026 it has accumulated an appeal pending before the Court of Justice, a US oversight body without quorum, and a Supreme Court judgment that has cast doubt on the independence of the authority supervising its commercial pillar. It is worth knowing where each piece stands.

What it covers, and what it does not

Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 found that the United States ensures an adequate level of protection. But the adequacy is not general: it reaches only those US organisations that obtain and maintain certification under the programme run by the Department of Commerce.

Two consequences follow, and both are missed far too often. First: if the importer is not certified, the framework is of no use and standard contractual clauses are required. Second: certification has a scope, and being certified for commercial data is not the same as being certified for human resources data. Transferring payroll to a provider certified only for commercial data leaves the transfer uncovered.

The Latombe case and the appeal still alive

On 3 September 2025 the General Court dismissed the action for annulment brought against the adequacy decision in Case T-553/23. The framework survived, but not definitively: on 31 October 2025 an appeal was lodged before the Court of Justice, registered as Case C-703/25 P.

The four grounds of appeal go to the heart of the arrangement: the appointment and removal of the judges of the Data Protection Review Court in the light of the right to an effective remedy, whether that body can be regarded as a tribunal previously established by law, the absence of prior judicial authorisation for bulk collection, and the presidential power to update the objectives of that collection. As matters stand, the appeal remains pending.

The PCLOB without quorum

The national security pillar of the framework rests on Executive Order 14086 and on independent oversight by the Privacy and Civil Liberties Oversight Board. In January 2025 three of its members were removed. A federal court held the removals unlawful in May 2025 and the Administration appealed.

The result is that, as of mid-2026, the body has a single member serving in a holdover capacity and still lacks quorum: it cannot approve official reports. Its September 2025 report on signals intelligence had to be issued as a staff document without official status, although it concluded that the agencies had adapted their procedures without material breaches.

The judgment that set off European alarms

On 29 June 2026 the United States Supreme Court held, by six votes to three, that the protections shielding Federal Trade Commission commissioners from discretionary removal were unconstitutional. Since the FTC is the authority supervising the commercial pillar of the framework, the judgment directly calls into question the European requirement of independent oversight.

The European Data Protection Board responded with a letter of 31 July 2026 asking the Commission to examine whether that judgment affects the validity of the framework, stressing that the existence and effective functioning of independent supervisory authorities is a key factor in any adequacy decision.

One review in three years

The Commission published its report on the first periodic review on 9 October 2024. Its conclusions were measured: the United States had put the necessary structures in place, more than 2,800 companies had certified in the first year, no infringements were detected and the redress mechanisms were operational — though they had received no complaints at all. The Commission itself acknowledged that practical experience was necessarily limited and announced that the next review would take place after three years. No review is on record for 2025 or 2026.

What a European company should do today

The answer is not to stop using United States providers. It is to stop relying on a single leg.

  • Verify the certification. Check that the importer appears as active on the official Department of Commerce list and that the scope of its certification covers the type of data you transfer. Certification is annual: it lapses, and when it lapses the transfer is left bare.
  • Document the transfer basis in the record of processing activities and in the contract with the provider.
  • Keep standard contractual clauses signed in parallel or ready to activate. It is the cheapest contingency plan there is.
  • Keep a transfer impact assessment on file. With the framework in force it is not formally required, but it is your evidence of diligence the day it stops being in force.
  • Apply supplementary technical measures: encryption with keys managed in the Union, pseudonymisation and minimisation of what leaves.
  • Write the plan B. Identify your critical United States providers, the alternatives hosted in the Union and the realistic migration time for each.

Why plan B is not pessimism

It has happened twice already. Safe Harbour fell in 2015 and the Privacy Shield in 2020, and on both occasions companies without a prepared alternative found themselves transferring without cover overnight. The difference between an inconvenience and a serious problem always came down to whether there was a list of affected providers and an alternative contract ready to sign.

Today the framework is in force and fully usable. But it rests on a revocable executive order, on an oversight body without quorum and on an appeal pending before the Court of Justice. Three conditions outside your control, and worth having mapped.

That map — what leaves, where to, under what safeguard, and what would happen if that safeguard disappeared — is one of the things we verify in a data protection audit. If it has never been done, the odds are that there are transfers not recorded on any document.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Your email address will not be published. Required fields are marked *