Auratech Legal Solutions

EU-US Data Privacy Framework: What Companies Should Check

The EU-US Data Privacy Framework has been running for three years and remains the most convenient route for sending personal data to a United States provider. It is also the most fragile. During 2026 it has accumulated an appeal pending before the Court of Justice, a US oversight body without quorum, and a Supreme Court judgment that has cast doubt on the independence of the authority supervising its commercial pillar. It is worth knowing where each piece stands.

What it covers, and what it does not

Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 found that the United States ensures an adequate level of protection. But the adequacy is not general: it reaches only those US organisations that obtain and maintain certification under the programme run by the Department of Commerce.

Two consequences follow, and both are missed far too often. First: if the importer is not certified, the framework is of no use and standard contractual clauses are required. Second: certification has a scope, and being certified for commercial data is not the same as being certified for human resources data. Transferring payroll to a provider certified only for commercial data leaves the transfer uncovered.

The Latombe case and the appeal still alive

On 3 September 2025 the General Court dismissed the action for annulment brought against the adequacy decision in Case T-553/23. The framework survived, but not definitively: on 31 October 2025 an appeal was lodged before the Court of Justice, registered as Case C-703/25 P.

The four grounds of appeal go to the heart of the arrangement: the appointment and removal of the judges of the Data Protection Review Court in the light of the right to an effective remedy, whether that body can be regarded as a tribunal previously established by law, the absence of prior judicial authorisation for bulk collection, and the presidential power to update the objectives of that collection. As matters stand, the appeal remains pending.

The PCLOB without quorum

The national security pillar of the framework rests on Executive Order 14086 and on independent oversight by the Privacy and Civil Liberties Oversight Board. In January 2025 three of its members were removed. A federal court held the removals unlawful in May 2025 and the Administration appealed.

The result is that, as of mid-2026, the body has a single member serving in a holdover capacity and still lacks quorum: it cannot approve official reports. Its September 2025 report on signals intelligence had to be issued as a staff document without official status, although it concluded that the agencies had adapted their procedures without material breaches.

The judgment that set off European alarms

On 29 June 2026 the United States Supreme Court held, by six votes to three, that the protections shielding Federal Trade Commission commissioners from discretionary removal were unconstitutional. Since the FTC is the authority supervising the commercial pillar of the framework, the judgment directly calls into question the European requirement of independent oversight.

The European Data Protection Board responded with a letter of 31 July 2026 asking the Commission to examine whether that judgment affects the validity of the framework, stressing that the existence and effective functioning of independent supervisory authorities is a key factor in any adequacy decision.

One review in three years

The Commission published its report on the first periodic review on 9 October 2024. Its conclusions were measured: the United States had put the necessary structures in place, more than 2,800 companies had certified in the first year, no infringements were detected and the redress mechanisms were operational — though they had received no complaints at all. The Commission itself acknowledged that practical experience was necessarily limited and announced that the next review would take place after three years. No review is on record for 2025 or 2026.

What a European company should do today

The answer is not to stop using United States providers. It is to stop relying on a single leg.

Why plan B is not pessimism

It has happened twice already. Safe Harbour fell in 2015 and the Privacy Shield in 2020, and on both occasions companies without a prepared alternative found themselves transferring without cover overnight. The difference between an inconvenience and a serious problem always came down to whether there was a list of affected providers and an alternative contract ready to sign.

Today the framework is in force and fully usable. But it rests on a revocable executive order, on an oversight body without quorum and on an appeal pending before the Court of Justice. Three conditions outside your control, and worth having mapped.

That map — what leaves, where to, under what safeguard, and what would happen if that safeguard disappeared — is one of the things we verify in a data protection audit. If it has never been done, the odds are that there are transfers not recorded on any document.

Exit mobile version