Português
Iniciar sessão Pedir uma demonstração

All articles

The Data Privacy Framework after Trump v. Slaughter

The EU-US Data Privacy Framework still applies, but the Supreme Court removed one of its foundations. What that means for your data in US clouds.

Published · 3 min read · Binadit

These articles are available in English, Dutch, German, French and Spanish.

On 29 June 2026, the US Supreme Court ruled in Trump v. Slaughter. It held that the president must be able to remove commissioners of the Federal Trade Commission (FTC) at will. That sounds like domestic US politics, but it directly affects the arrangement many European companies rely on when they use Microsoft 365, Google Workspace or a US AI service.

What the Data Privacy Framework covers

Under the GDPR, personal data may only go to a country outside the European Economic Area if the level of protection there is essentially equivalent to that in Europe. In July 2023 the European Commission found that this is the case for the United States, for US companies that have joined the EU-US Data Privacy Framework (DPF). Microsoft and Google have done so. The DPF replaced the Privacy Shield, which the Court of Justice of the EU struck down in 2020 in the Schrems II case.

One of the pillars of the DPF is independent oversight in the US. In its decision, the Commission named the FTC as that independent supervisory authority. It explicitly cited the fact that FTC commissioners are appointed for seven years and can only be removed for specific reasons.

What the ruling changes

That protection against removal is exactly what the Supreme Court has now declared unconstitutional. The FTC is therefore no longer structurally independent of the president. On 31 July 2026, the European data protection authorities, acting together in the EDPB, asked the European Commission to assess whether the DPF still offers sufficient protection.

Has the DPF lapsed?

No, not formally. The adequacy decision remains in force until the Commission repeals, suspends or amends it, or until the Court of Justice declares it invalid. Transfers to US companies with DPF certification may therefore still rely on it today.

But an important foundation has gone. A challenge to the DPF is already pending before the Court of Justice (the appeal in the Latombe case), and the Supreme Court ruling gives critics a new argument. Anyone who remembers how quickly the Privacy Shield disappeared in 2020 knows that such an arrangement can fall away overnight.

What happens if the DPF falls away

Transfers to the US are then not automatically prohibited, but they become a good deal harder. Companies must fall back on Standard Contractual Clauses (SCCs) and show, supplier by supplier, that the protection works in practice. That includes supplementary measures such as strong encryption where the supplier does not hold the key. For ordinary cloud services such as mail and file storage, where the supplier needs to read the data to process it, that is often not achievable in practice.

What you can do now

  1. Map which services send personal data to the US. Think beyond mail and files: chat, video calls, AI, backups and analytics tools count too.
  2. Look beyond the server location. A data centre in Frankfurt or Amsterdam run by a US company is still subject to US law, including the US CLOUD Act.
  3. Start with what is easy to replace. Mail, calendar, files, documents, chat and video meetings now have mature European alternatives.
  4. Do not wait for the next ruling. Moving at your own pace is cheaper and calmer than a forced migration if the arrangement suddenly lapses.

Binadit Workspace provides mail, calendar, contacts, Drive, documents, video meetings and chat on servers in the Netherlands, from a Dutch company with no US parent. No data is transferred to the US, so the DPF plays no part. See what is in Binadit Workspace or request a demo.

Sources

  • Supreme Court of the United States, Trump v. Slaughter, 29 June 2026: opinion (pdf)
  • Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework, recitals 58 to 60: EUR-Lex
  • General Data Protection Regulation, Articles 44 to 49: EUR-Lex
  • European Data Protection Board, letter to the European Commission, 31 July 2026, and the EDPB FAQ on the DPF

This article is general information, not legal advice. For a specific situation, consult a lawyer.

Pedir uma demonstração Preços