Your transfer program has relied on the EU-US Data Privacy Framework (DPF) as a clean, low-friction path for moving personal data from the EEA to the United States. On June 29, 2026, the US Supreme Court decided Trump v. Slaughter, ruling that Federal Trade Commission commissioners can be removed by the president without cause. Privacy group noyb says that ruling knocks out the load-bearing pillar the European Commission used to justify the DPF's adequacy decision in the first place, and it has told Brussels to begin an "orderly withdrawal." If your organization certifies transfers under the DPF today, or is weighing whether to lean on it instead of Standard Contractual Clauses (SCCs), you need to know what actually changed and what didn't.
Key Takeaways
- The DPF is fully valid today. Nothing about Trump v. Slaughter or noyb's June 30, 2026 letter has suspended or annulled the adequacy decision: transfers made under it right now are lawful.
- noyb's argument is structural, not procedural: the Commission's 2023 adequacy decision cites FTC independence 259 times as proof of meaningful US oversight, and the Supreme Court just removed that independence.
- A CJEU appeal of the DPF's validity (Case C-703/25 P) is already pending, with no hearing date set. It is a second, separate legal track that could reach a verdict before or after any new noyb challenge.
What actually changed on June 29
The Supreme Court's 6-3 ruling in Trump v. Slaughter overturned Humphrey's Executor v. United States, the 1935 precedent that let Congress shield multi-member agency heads, including FTC commissioners, from at-will presidential removal. The case began when President Trump fired FTC Commissioner Rebecca Slaughter in 2025 without citing "inefficiency, neglect of duty or malfeasance," the statutory standard Congress had set for FTC commissioners since 1914. The Court's majority held that standard unconstitutional. The mechanism matters here, not just the headline: the ruling doesn't touch the DPF directly, but it strips the FTC of the specific attribute (insulation from presidential removal) that the European Commission relied on when it decided the FTC could act as an independent enforcer of US companies' DPF commitments.
That's the pillar noyb is pointing at. In its June 30, 2026 letter to the Commission, noyb noted that the Commission's own 2023 adequacy decision references FTC independence 259 times as the reason US enforcement meets the EU's GDPR data protection principles for oversight. An FTC commissioner who can be replaced by the president at will is no longer independent in the sense the Commission's own text requires. noyb chair Max Schrems has framed the ask bluntly, telling the Commission it should move away from US cloud infrastructure, calling the shift difficult but, in his words, "unfortunately inevitable."
Why this counts as a "Schrems III" moment, not a footnote
Privacy lawyers are already calling a potential third round of DPF litigation "Schrems III," after Max Schrems' two prior cases invalidated the DPF's predecessors, Safe Harbor (Schrems I, 2015) and Privacy Shield (Schrems II, 2020). Both of those rulings turned on the same underlying question: does US law give EU data subjects protections and redress that are "essentially equivalent" to EU law. Schrems I found no adequate US oversight body existed. Schrems II found the redress mechanism (an ombudsperson) wasn't independent enough of the executive branch. The DPF was built specifically to answer Schrems II by creating the Data Protection Review Court (DPRC) and leaning on FTC enforcement to give US companies' commitments real teeth.
The reason the FTC-independence argument isn't a side issue is that it attacks the same load-bearing joint the prior two cases attacked: whether US oversight is genuinely insulated from the executive. noyb isn't arguing a new, unrelated defect. It's arguing that the Supreme Court just reopened the exact wound the DPF was designed to close. That is what separates this from routine post-adequacy grumbling and is why practitioners are treating it as a serious, not cosmetic, risk to the framework's legal foundation.
The pending CJEU appeal is a separate track, and still has no hearing date
Before the Supreme Court ruling existed, the DPF was already facing a court challenge. French parliamentarian Philippe Latombe brought a direct annulment action against the adequacy decision, and on September 3, 2025, the EU General Court dismissed it in Case T-553/23, finding the DPRC sufficiently independent and US bulk-collection limits adequate at the time the Commission made its decision. Latombe appealed that dismissal to the Court of Justice of the European Union (CJEU) on October 31, 2025; the appeal was registered as Case C-703/25 P and is limited to points of law. As of this writing, no hearing date has been scheduled.
That appeal predates and is legally distinct from the FTC-independence argument noyb is now raising, though both could ultimately land in front of the same court. noyb has said it intends to file its own separate annulment challenge "within weeks" of its June 30 letter if the Commission doesn't act first, which would give the CJEU two live routes to eventually rule on the DPF's validity: Latombe's appeal of a decision that predates the Supreme Court ruling, and a fresh noyb case built specifically around it. Legal commentators are estimating a CJEU opinion isn't likely before late 2026 or early 2027 at the earliest. Multi-year timelines aren't unusual for cases of this complexity; Schrems II itself took roughly four years from filing to judgment.
The compliance takeaway right now
Nothing here suspends the adequacy decision. The Commission has not announced any move to amend, suspend, or withdraw it; its public position so far is that it continues monitoring whether US oversight still delivers adequate protection and remains in contact with the US administration, and Commissioner Michael McGrath has said the Commission's objective is to continue full implementation and enforcement of the DPF as it stands. The European Commission's transfer impact assessment process for SCC-based transfers is unaffected either way. What has changed is the confidence level a privacy team should assign to the DPF surviving in its current form over a multi-year horizon. That's a portfolio-risk question, not a today's-transfers-are-illegal question.
A risk-tiering framework for your transfer program
Rather than reacting to headlines, sort your organization's EU-to-US transfers into one of three postures and treat each differently.
| Category | What it means | What changed for you this week | Recommended posture |
|---|---|---|---|
| DPF-only reliance | You certify under the DPF and have no SCCs or BCRs in place as a fallback for the same transfers | Nothing is illegal today, but you have zero contractual backup if the DPF is annulled with a short or no transition period | Start drafting SCCs as a parallel mechanism now, before a ruling forces an emergency migration under time pressure |
| DPF-plus-SCCs | You certify under the DPF but also maintain SCCs (or BCRs) for the same data flows as a documented fallback | Your immediate legal exposure is effectively unchanged; you already have a bridge if the DPF falls | Refresh your Transfer Impact Assessments (TIAs) to confirm the SCC fallback would independently hold up, since TIAs written years ago may not reflect current US surveillance-law analysis |
| SCCs-only | You never adopted the DPF and rely solely on SCCs or BCRs for US transfers | You are structurally insulated from a DPF annulment, but not from separate scrutiny of SCCs themselves | Treat the Irish High Court's June 3, 2026 confirmation of TikTok's €530 million transfer fine as your live case study: that fine landed because TikTok's TIA didn't rigorously engage with the destination country's actual laws, not because SCCs as a mechanism failed |
The organizations with the most exposure aren't the ones using the DPF today. They're the ones who have never built a fallback mechanism and would have to construct one from scratch under deadline pressure if the Commission or the CJEU moved quickly. A multi-entity governance platform that maps which of your subsidiaries, products, and vendors actually depend on the DPF gives you the lead time other companies won't have.
What a defensible interim posture looks like
You do not need to migrate off the DPF today, and doing so reactively before any ruling exists would be premature. A defensible posture over the next 6-12 months looks like three concrete steps.
First, know exactly where you're exposed. Most privacy teams can name their DPF certification status in general terms but can't produce a list of every specific data flow, vendor, and subsidiary that depends on it without a data mapping exercise. A live Data Map and Record of Processing Activities that tags each transfer by legal mechanism turns "we probably use the DPF for some US vendors" into an actual, exportable list you can act on before a deadline, not after one.
Second, build the SCC fallback in parallel rather than after a ruling. Drafting and executing SCCs with every DPF-certified vendor takes real time — legal review, vendor negotiation, and documentation don't compress well under a court-imposed deadline. Starting that work now, even while the DPF remains valid, is the single highest-leverage action a DPF-reliant organization can take this quarter.
Third, if you operate across multiple EU and US entities, don't let this become a single-team blind spot. Transfer risk shows up differently depending on which subsidiary, product line, or vendor relationship is involved, which is exactly the kind of cross-entity visibility gap that multi-entity management is built to close — one dashboard that shows every entity's transfer-mechanism exposure rather than requiring each local team to track it independently.
What to Do This Quarter
- Nothing about your current DPF transfers is unlawful today; there is no automatic risk to reroute around.
- The specific thing to fix, this quarter, is the absence of a documented SCC fallback for any transfer that relies solely on the DPF.
- The CJEU appeal (C-703/25 P) has no hearing date, and noyb's promised new lawsuit hasn't been filed yet as of this writing. Treat both as multi-year processes, not imminent deadlines.
Frequently Asked Questions
Is the EU-US Data Privacy Framework still valid right now?
Yes. The Commission's 2023 adequacy decision remains in force, and transfers made under DPF certification today are lawful. Neither the Supreme Court's Trump v. Slaughter ruling nor noyb's June 30 letter has any automatic legal effect on the adequacy decision itself.
What is "Schrems III"?
It's the name privacy lawyers have given to a potential third CJEU case challenging the DPF's predecessor frameworks' fate, following Schrems I (which invalidated Safe Harbor in 2015) and Schrems II (which invalidated Privacy Shield in 2020). No case bearing that name has been filed yet; it refers to noyb's stated intent to bring a fresh annulment challenge built around the FTC-independence argument.
What did the Supreme Court actually rule in Trump v. Slaughter?
That FTC commissioners, like heads of other multi-member independent agencies, can be removed by the president without the "inefficiency, neglect of duty or malfeasance" cause Congress had required since 1914. The 6-3 decision overturned the 90-year-old Humphrey's Executor precedent. The ruling concerns US separation-of-powers law, not the DPF directly — its relevance to the DPF is that the Commission's adequacy decision relied specifically on FTC independence as evidence of adequate US oversight.
Has the CJEU set a hearing date for the appeal of the DPF's validity?
No. Case C-703/25 P, Philippe Latombe's appeal of the General Court's September 2025 dismissal of his challenge, was registered in October 2025 and remains pending with no hearing date announced as of July 2026.
Should my organization stop using the DPF and switch entirely to SCCs?
Not as an immediate, reactive move. A wholesale switch before any ruling exists risks disrupting operations for a risk that hasn't materialized as a legal obligation yet. The more defensible move is building an SCC fallback in parallel with your existing DPF certification, so you aren't starting that work from zero if the framework is later suspended or annulled.
Are SCCs automatically safer than the DPF?
Not automatically. SCCs require a genuine Transfer Impact Assessment that engages with the destination country's actual laws and practices, not a templated checklist. The Irish High Court's June 2026 confirmation of TikTok's €530 million fine is a reminder that SCCs backed by a weak TIA carry their own real enforcement risk.
How long is this likely to take to resolve?
Multi-year. Schrems II itself took about four years from filing to CJEU judgment, and legal commentators are estimating a CJEU opinion on the current appeal isn't likely before late 2026 or early 2027 at the earliest — before accounting for any separate noyb case that hasn't been filed yet.
What should a privacy team do this week, specifically?
Identify every data flow that relies solely on DPF certification with no SCC fallback in place, and prioritize drafting SCCs for those first. That's the concrete gap between "fine today" and "exposed if the framework changes," and it's the one action within a team's direct control regardless of how the litigation plays out.
Relying on the DPF without knowing exactly which entities, vendors, and data flows depend on it is the actual risk here, not the litigation itself. Secure Privacy's Privacy & AI Governance Platform maps every processing activity and transfer mechanism across your organization through Data Map & ROPA, so you can see DPF-dependent transfers at a glance instead of reconstructing that list under deadline pressure. For organizations spanning multiple EU and US entities, its multi-entity management gives legal and compliance teams one place to track transfer-mechanism exposure across every subsidiary — before a court forces the question. Book a demo to see how it maps your DPF exposure in a single working session.




