Skip to content

A ruling by the US Supreme Court has shaken a previously little-noticed pillar of transatlantic data protection: the independence of the Federal Trade Commission. The EDPB is therefore calling for a review of the EU-US Data Privacy Framework. For businesses, this does not yet mean a halt to data transfers to the US – but it does provide a good reason to review existing transfer arrangements and consider a possible Plan B now. Switzerland is also affected.

 

A US ruling with implications for European data

At first glance, Trump v. Slaughter appears to have little to do with European data protection. On 29 June 2026, the US Supreme Court ruled on the US President’s power to remove members of the Federal Trade Commission. Specifically, the case concerned FTC Commissioner Rebecca Slaughter, who had been removed from office without any of the grounds for removal provided for by law. The Supreme Court declared the statutory restriction on the President’s power to remove commissioners to be inconsistent with the US Constitution. The FTC exercises extensive regulatory, enforcement and decision-making powers and thus exercises executive authority; its members must therefore be subject to the President’s control. In doing so, the court abandoned the special protection against removal for FTC commissioners, which had hitherto been based on the 1935 case of Humphrey’s Executor v. United States.

From a data protection perspective, the ruling is significant due to a connection that is scarcely apparent outside specialist circles: The FTC is a key enforcement authority under the EU-US Data Privacy Framework (DPF). It is precisely for this reason that the Chair of the EDPB, Anu Talus, wrote to the European Commission on 31 July 2026. The EDPB is not calling for the immediate repeal of the DPF, but is expressly urging the Commission to examine whether Trump v. Slaughter undermines the functioning of the adequacy decision.

 

Why the FTC’s independence is so important

Under Article 45(2)(b) of the GDPR, the effective functioning of independent supervisory authorities is one of the criteria on the basis of which the European Commission assesses whether a third country ensures a level of data protection that is essentially equivalent. The existence and effective functioning of independent supervisory authorities is therefore a criterion for the adequacy assessment explicitly mentioned in Article 45(2)(b) of the GDPR.

It is particularly relevant that the adequacy decision on the EU-US DPF explicitly addresses this issue. In recitals 58 to 60, the Commission describes the FTC as an independent authority, noting, amongst other things, that its five commissioners are appointed for seven years and may only be removed by the President on grounds of ‘inefficiency, neglect of duty, or malfeasance in office’. It is precisely this statutory safeguard against removal that the Supreme Court has now declared unconstitutional.

However, this does not automatically mean that, from a European perspective, the FTC can no longer be regarded as ‘independent’ or that the DPF has become invalid. Adequacy is assessed on the basis of the level of protection afforded by the system as a whole. The ruling, however, removes a specific guarantee on which the Commission had explicitly relied in its original assessment. This is precisely why a reassessment is legally significant.

 

Is the EU-US Data Privacy Framework now invalid?

No. The DPF has not automatically been rendered invalid by the US Supreme Court’s ruling. Nor does the EDPB’s letter revoke the adequacy decision. On the basis of the decision, which remains in force, personal data may, in principle, continue to be transferred to companies in the US certified under the DPF.

The next crucial question lies with the European Commission. Article 45(4) of the GDPR obliges it to continuously monitor developments in third countries that may affect an adequacy decision. If the Commission concludes that an adequate level of protection is no longer guaranteed, it must, in accordance with Article 45(5) of the GDPR, revoke, amend or suspend the adequacy decision to the extent necessary

 

The DPF is already before the Court of Justice of the European Union (CJEU)

In addition, there is a second legal issue. In September 2025, the General Court of the European Union dismissed Philippe Latombe’s action against the DPF adequacy decision and confirmed that the US guaranteed an adequate level of protection at the time the decision was adopted. However, an appeal against this judgment has been lodged with the European Court of Justice; Case C-703/25 P remains pending. As recently as June 2026, a decision was issued in these proceedings granting Microsoft leave to intervene as an intervener.

It is precisely the temporal wording of the first-instance judgement that is now significant: a judicial confirmation of adequacy at the time the decision was issued does not automatically answer the question of whether subsequent changes to US law affect the level of protection. Trump v. Slaughter therefore establishes a new, distinct subject matter for review.

 

The Swiss-US Data Privacy Framework is also affected

For Swiss companies, this development is by no means merely an EU issue. In 2024, the Federal Council recognised an adequate level of data protection under the Swiss-US DPF for transfers to certified US companies. Under Swiss law, too, the effective functioning of independent data protection authorities is expressly included among the criteria for the adequacy assessment, in accordance with Article 8 of the Data Protection Ordinance.

The parallel becomes even clearer in the adequacy assessment by the Federal Office of Justice dated 30 April 2024. It expressly states that FTC commissioners may be removed from office by the President during their seven-year term ‘only for good cause’. On this basis, the Federal Office classified the FTC and the Department of Transportation as independent supervisory authorities with sufficient powers and competences.

Trump v. Slaughter thus also alters a key premise of the Swiss assessment. Whilst the EDPB’s letter itself has no direct legal effect in Switzerland, However, the underlying question is virtually identical: following the removal of the safeguard against dismissal, can the FTC still be regarded as an independent supervisory authority to a sufficient extent for the purposes of the adequacy assessment?

 

What companies should do now

There is currently no reason for CEOs, legal counsel, data protection officers and CISOs to halt all data transfers to the US as a precautionary measure. Nor would it make sense to treat the DPF as having already failed. However, the current developments should be taken as an opportunity to review one’s own reliance on a single basis for data transfers.

In particular, organisations should ensure that their US data flows and the legal bases for them are kept up to date, regularly check the DPF certification of their US recipients, and ensure contractually that any changes to or loss of certification are notified without delay. For business-critical transfers, it is also advisable to clarify now whether standard contractual clauses or – for Switzerland – recognised standard data protection clauses could be used as an alternative basis for data transfers. Such an alternative should not merely exist on paper: should the DPF actually be suspended or revoked, the legal situation then prevailing in the third country and, where applicable, any additional technical or organisational safeguards would also need to be reassessed.

Particularly sensitive or extensive transfers should be given priority. Where technically and economically feasible, data minimisation, effective encryption, pseudonymisation or processing within Europe can further reduce the regulatory risk. The aim should not be to speculate on a decision from Brussels or Bern, but rather to design one’s own transfer architecture in such a way that a change in the legal basis remains operationally manageable.

 

Conclusion: The framework remains in place – but its stability is being reassessed

Trump v. Slaughter has not brought down the EU-US Data Privacy Framework. However, the judgement strikes at an institutional guarantee that both the European Commission and the Swiss Federal Office of Justice had explicitly included in their adequacy assessments. The EDPB has therefore rightly initiated a review by the Commission.

For businesses, the key message is therefore this: the DPF can continue to be used for the time being, but must not be confused with permanent legal certainty. Companies that take stock of their US data transfers at an early stage, prepare alternative transfer mechanisms and monitor further developments in Brussels, Luxembourg, Washington and Bern will be far better prepared for a possible change than those that only react after a ruling has been overturned.

Sources