The U.S. Supreme Court’s decision in Trump v. Slaughter raises serious questions about the viability of the EU-US Data Privacy Framework (DPF)—a legal arrangement that many organizations rely on to receive personal data from Europe without putting extra safeguards in place—by undercutting the independence of executive branch agencies, on which the EU pinned its approval of the DPF. If your organization relies on the DPF to transfer personal information, it is time to review alternative mechanisms to provide the required safeguards for such transfers.

I. Background: The EU-US Data Privacy Framework

The European Commission (EC) adopted the EU-US Data Privacy Framework (DPF) via Implementing Decision (EU) 2023/1795 on July 10, 2023 (the “Adequacy Decision”), permitting the free transfer of personal data from the EEA to US organizations that self-certify through the DPF. Self-certification is enforceable under US law, principally by the Federal Trade Commission (FTC) under Section 5 of the FTC Act.

The Adequacy Decision heavily relied on the political independence of executive branch enforcement authorities, including the FTC, the Data Protection Review Court (DPRC), and the Privacy and Civil Liberties Oversight Board (PCLOB), and their freedom from interference and influence by the executive branch, pursuant to EU treaty law that requires data protection oversight to be carried out by an “independent” authority. In September 2025, the EU General Court upheld the Adequacy Decision against a legal challenge by French MEP Philippe Latombe, further citing the independence of and for-cause removal provisions for DPRC judges. However, that ruling is now on appeal to the Court of Justice of the European Union (CJEU).

II. Challenges to Independence (Trump v. Slaughter)

Beginning in early 2025, the Trump Administration took numerous actions to limit the independence of independent agencies, including by firing three Democratic members of the PCLOB and two Democratic FTC Commissioners, including Rebecca Kelly Slaughter, for “inconsisten[cy] with [the] Administration’s priorities,” despite the FTC Act’s for-cause removal protection. Ms. Slaughter sued for reinstatement. On June 29, 2026, the U.S. Supreme Court decided Trump v. Slaughter, holding that the FTC’s for-cause removal provision violates the separation of powers and that officers exercising executive power “must be removable by the President at will,” effectively eliminating independence protections for the FTC and other agencies exercising executive functions.

III. Implications for the DPF

Given the Adequacy Decision’s reliance on the political independence of enforcement authorities such as the FTC, the Slaughter decision significantly undermines the basis of the Adequacy Decision. EU treaty law’s requirement that data protection oversight be carried out by independent authorities, and the EU General Court’s decision (currently on appeal to the CJEU), which relied on the fact that DPRC judges may be dismissed only by the Attorney General and only for cause, are now ripe for further challenge. Privacy advocate Max Schrems—whose earlier lawsuits already led EU courts to strike down the DPF’s two predecessor frameworks, known as “Safe Harbor” and “Privacy Shield”—has already called on the EC to provide for an “orderly exit” from the DPF.

IV. Practical Recommendations

We recommend that organizations with cross-border data transfer obligations take the following steps:

  1. Review and Update Transfer Impact Assessments (TIAs). Any TIA that references the independence of the FTC, DPRC, or PCLOB must be revised to reflect the current legal landscape. Organizations using SCCs or BCRs are not exempt from this requirement.
  2. Evaluate Alternative Transfer Mechanisms. Standard Contractual Clauses (SCCs) remain available but require a robust TIA. While the TIA may now be harder to complete favorably, the addition of supplementary technical measures as described below may be sufficient. Binding Corporate Rules (BCRs) provide an intra-group mechanism but require approval by relevant Data Protection Authorities (DPAs). If organizations want to move to BCRs as a transfer mechanism, that process should begin now.
  3. Implement Supplementary Measures. Where alternative transfer mechanisms, such as SCCs, are used, consider supplementary technical measures, such as encryption, pseudonymization, and data localization, to mitigate surveillance risks.
  4. Monitor Regulatory Developments. Track statements from the European Commission, EDPB, and national DPAs; the Latombe appeal before the CJEU; and any US legislative or executive action that may affect the DPF architecture.
  5. Engage Legal Counsel. Given the complexity of the legal landscape, organizations should work with experienced data protection counsel to assess their specific exposure and develop a tailored compliance strategy.

V. Conclusion

The Trump v. Slaughter decision represents a seismic shift in U.S. administrative law with immediate implications for transatlantic data transfers. Organizations with cross-border data transfer obligations should take proactive steps to evaluate their exposure, diversify their transfer mechanisms, and prepare for the real possibility that the DPF’s Adequacy Decision may be suspended, withdrawn, or invalidated by the European Commission or the CJEU. Should you have any questions regarding certification under the EU-US Data Privacy Framework, the EU Standard Contractual Clauses, or any compliance obligations for data transfers between the EU and the United States, please reach out to David A. Wheeler, Alfred C. Tam, Kate H. Campbell, Josh A. Hanson, or your Neal Gerber Eisenberg attorney.


The content above is based on information current at the time of its publication and may not reflect the most recent developments or guidance. Neal, Gerber & Eisenberg LLP provides this content for general informational purposes only. It does not constitute legal advice, and does not create an attorney-client relationship. You should seek advice from professional advisers with respect to your particular circumstances.