At a Glance
- International transfers of personal data under the EU-US Data Privacy Framework (DPF), which allows transfers of personal data from the EU, rely heavily on Federal Trade Commission (FTC) independence as a safeguard.
- On 29 June 2026, the US Supreme Court ruled in Trump v. Slaughter that FTC commissioners can be removed at will by the US president, overruling 91 years of precedent and eliminating the agency's structural independence. The ruling undermines a core pillar of the DPF's "adequacy decision", creating a credible risk of future invalidation.
- The European Data Protection Board (EDPB) has formally asked the European Commission (the Commission) to assess whether Trump v. Slaughter affects the continued functioning of the DPF adequacy decision.
- Thus far, neither the Commission nor the EDPB has directed organisations to stop relying on the DPF. However, organisations should begin contingency planning, including implementing Standard Contractual Clauses (SCCs) alongside DPF certification.
Background
In March 2025, President Trump removed two Democratic FTC commissioners (Rebecca Slaughter and Alvaro Bedoya) without citing statutory cause. Commissioner Slaughter challenged her removal, arguing that the FTC Act's "for-cause" removal protection (upheld since Humphrey's Executor in 1935) barred dismissal at will.
The Supreme Court of the United States (SCOTUS) disagreed, holding that statutory restrictions on the president's power to remove FTC commissioners violate the separation of powers under Article II of the US Constitution. The majority reasoned that the president must have plenary control over executive officers, and expressly overruled the 91-year-old Humphrey's Executor precedent.
As a result, SCOTUS has confirmed that FTC commissioners can be removed by the president at will, meaning in effect that the FTC is no longer structurally independent of the White House.
Impact on the DPF
Since July 2023, the EU-US Data Privacy Framework has served as a key legal basis for transfers of personal data from the EU to participating US organisations. It replaced two earlier frameworks that were each struck down by the Court of Justice of the European Union (CJEU): the Safe Harbour arrangement, which the CJEU invalidated in Schrems I (2015), and the Privacy Shield, which fell in Schrems II (2020). Thousands of US organisations have self-certified under the DPF, as it provides the most straightforward route to satisfying the General Data Protection Regulation's (GDPR) stringent requirements for international transfers of personal data to the US from the EU.
The adequacy decision underpinning the DPF relies heavily on the FTC's role as a primary enforcement authority for commercial data protection. Separately, the EU constitutional order places particular emphasis on regulatory independence in the data protection sphere: both the Treaty on the Functioning of the European Union (Article 16(2) TFEU) and the Charter of Fundamental Rights (Article 8(3)) stipulate that compliance with data protection rules must be subject to control by an authority operating free from external direction.
As such, the ruling challenges a foundational assumption of the adequacy finding. If the FTC is no longer independent, the Commission's assessment that US law provides "essentially equivalent" protection may no longer be true.
The UK Extension to the DPF, which covers personal data transfers to the US from the UK, relies on the same underlying US commitments, meaning the ruling could have parallel implications for UK-US data transfers under the UK's own adequacy regulations. The UK government expressly acknowledged the issue in a 14 July 2026 parliamentary answer, stating that it is exploring the potential impact of Slaughter on the UK Extension to the DPF, and is working with the US government to understand its implications. The UK Information Commissioner's Office (ICO) has not taken a Slaughter-specific position; its existing adequacy opinion identifies US legal developments and the effectiveness of US oversight and enforcement bodies as areas for monitoring.
That said, the UK Data (Use and Access) Act 2025, in force since 5 February 2026, replaced the transfer standard with a new "data protection test" asking whether protection in the receiving country is "not materially lower" than the UK GDPR standard. This shift to a more outcomes-based and risk-based assessment means that a CJEU annulment of the DPF would not automatically invalidate the UK Data Bridge, and the EU and UK are now applying different legal tests for international data transfers.
Commercial Oversight and Government Access
It is useful to distinguish between the two separate pillars on which the adequacy decision rests. The first pillar concerns commercial data handling: the substantive obligations that DPF-certified organisations must meet and the FTC's role in enforcing those obligations. It is this pillar that Slaughter directly undermines.
The second pillar addresses the constraints on US government access to personal data for national security purposes, together with the redress mechanism available to EU individuals through the US Data Protection Review Court (DPRC), which was established under Executive Order 14086. Notably, the earlier Schrems I and Schrems II rulings turned on deficiencies in these government-access safeguards, not on shortcomings in commercial enforcement.
The effect of Slaughter on the DPRC and the broader national-security redress framework is disputed and was not resolved by the judgment. Some commentators argue that Slaughter does not extend to the DPRC. The DPRC's protections are executive branch self-imposed (via executive order and DOJ regulation), not congressionally mandated, and the Slaughter majority was directed at congressional encroachment on executive removal power. SCOTUS expressly reserved the question of non-Article III adjudicators, and DPRC judges qualify as "inferior officers" protected under Morrison v. Olson (which Slaughter preserved).
Others have cautioned, however, that the DPRC lacks any statutory foundation and owes its existence entirely to an executive order that a future president could revoke or amend. Because the DPRC is housed within the DOJ rather than operating as a freestanding body, some analysts regard its claim to structural independence as resting on thinner ground than even that of the pre-Slaughter FTC.
Separately, concerns about the independence of the US Privacy and Civil Liberties Oversight Board (PCLOB) compound the uncertainty surrounding the DPF. In January 2025, the Trump administration removed the three Democratic members of the PCLOB, leaving the board without a quorum and limiting board-level oversight and reporting. The European Commission's adequacy decision expressly relied on the PCLOB's role in overseeing US intelligence agencies' compliance with Executive Order 14086, and the Commission, during its first annual review of the DPF, flagged the importance of upcoming PCLOB vacancies being filled. The resulting loss of quorum adds to the uncertainty surrounding the government-access dimension of the DPF, but does not mean that all PCLOB functions have ceased.
If the DPF were invalidated on commercial-oversight grounds alone, organisations could potentially continue transferring data under SCCs and Binding Corporate Rules (BCRs), provided the government-access safeguards remain intact and Transfer Impact Assessments (TIAs) support that conclusion.
EU Institutional and Regulatory Response
The European Commission has stated that it has taken note of the ruling, is carefully analysing its implications, and continues to monitor the DPF while Executive Order 14086 remains in force. The most significant post-judgment institutional development is the EDPB's letter of 31 July 2026, which formally asked the Commission to assess whether Slaughter affects the continued functioning of the DPF adequacy decision. This was a request for institutional assessment, not operational guidance to businesses, and neither the Commission nor the EDPB has directed organisations to stop relying on the DPF.
The European Center for Digital Rights (NOYB, from "none of your business") sent a formal letter to the Commission on 30 June 2026 calling for an orderly withdrawal from the DPF and has threatened the possibility of litigation seeking annulment of the adequacy decision. No confirmed NOYB challenge specific to Slaughter has been identified as filed, as of our publication date. Max Schrems stated: "Even in the European Commission's logic, the basis for any EU-US data transfer deal is dead. We call upon the Commission to start an orderly exit from the US cloud — which is not easy, but unfortunately unavoidable." Notably, NOYB calls for a managed transition, rather than abrupt invalidation, to minimise disruption.
At the national level, the Danish Data Protection Authority has issued a public statement urging data controllers to revisit their Transfer Impact Assessments in light of the ruling, explicitly noting that Slaughter could also affect transfers made on legal bases other than the DPF, including Standard Contractual Clauses.
Implications and Next Steps
The DPF remains valid, and there is no immediate legal compliance change. However, there is a credible prospect that the Commission may reassess the adequacy decision, whether through its own review process or in light of the CJEU's decision in the Latombe appeal, Case C-703/25 P, which remains pending before the CJEU as of our publication date. Organisations directly relying on DPF certification should prepare fallback mechanisms. Equally, those relying on the DPF indirectly (e.g., through SaaS vendors, cloud providers, or other processors that cite DPF certification) face supply-chain exposure if those providers lack contingency plans. Additionally, TIAs referencing FTC independence or the DPRC may require updating.
Businesses transferring personal data between the EU/UK/Switzerland and the US should:
- Assess exposure. Organisations should identify which personal data transfers to the US rely on DPF certification, whether directly or through vendors and subprocessors.
- Map fallback coverage. US clients should confirm which EU, UK, and Swiss data flows rely solely on DPF certification, and which have executable fallback mechanisms, including SCCs, the UK Addendum, the International Data Transfer Agreement, or BCRs supported by current TIAs.
- Implement fallback mechanisms. A "belt and braces" approach (e.g., putting SCCs in place alongside DPF certification) is prudent. Data processing agreements should include cascade provisions for automatic fallback to SCCs in the event of invalidation of the DPF.
- Engage vendors. US-based service providers should be asked to confirm their contingency plans in the event of DPF invalidation and whether they maintain executed transfer documentation and current TIAs that provide a basis for transfers beyond DPF certification.
- Review Transfer Impact Assessments. Any TIAs referencing FTC independence, the DPRC, or the Privacy and Civil Liberties Oversight Board should be reviewed and, where necessary, updated to reflect current circumstances.
- Consider supplementary measures. Encryption, pseudonymisation, data residency requirements, and access controls reduce reliance on legal safeguards and help demonstrate GDPR compliance.
- Monitor developments. The regulatory landscape is evolving rapidly. Organisations should track the European Commission's ongoing assessment and any formal conclusions it reaches regarding the DPF's continued validity; guidance or coordinated positions from the EDPB and national Data Protection Authorities; the Latombe appeal, Case C-703/25 P, which remains pending before the CJEU as of the publication date; any potential Slaughter-based NOYB action; and the UK government's exploration of the potential impact on the UK Extension to the DPF.