Does the U.S. Supreme Court’s Decision Change the Rules for Transferring Personal Data to the United States?

Jul 7, 2026

Does the U.S. Supreme Court’s Decision Change the Rules for Transferring Personal Data to the United States?

by František Nonnemann, Vice-Chair of the Committee of the Association for Personal Data Protection (Czech Republic)

A recent decision of the U.S. Supreme Court clarified the constitutional status of federal agencies, including the Federal Trade Commission (FTC), which plays a key role in overseeing the processing of personal data. What impact, if any, will this decision have on transfers of personal data from the European Union to the United States?

The U.S. Supreme Court’s judgment in Trump v. Slaughter, delivered on 29 June 2026, has prompted discussion among European data protection experts. The organisation NOYB – European Center for Digital Rights argues that the judgment calls into question one of the foundations of the EU–U.S. Data Privacy Framework (DPF) and has called on the European Commission to review its adequacy decision.

The Judgment Does Not Directly Concern Data Protection

Although the judgment has frequently been linked to the DPF, the U.S. Supreme Court did not address data protection directly. The case concerned the constitutional status and independence of the US federal agencies and the scope of the President’s authority to remove their senior officials.

The Court built on its previous case law concerning the powers and responsibilities of executive branch agencies and concluded that the President must be able to supervise officials exercising executive power on behalf of the federal government. It therefore rejected the previous interpretation under which members of the Federal Trade Commission (FTC) could be removed by the President only in exceptional circumstances. The FTC is the federal agency responsible, among other things, for enforcing rules on the protection of personal data.

 

Significance of the Judgment for the GDPR

The judgment is significant because of the FTC’s role in enforcing data protection law and in the operation of the EU–U.S. Data Privacy Framework.

The Data Privacy Framework is based on Commission Implementing Decision (EU) 2023/1795, in which the European Commission concluded, pursuant to Article 45 GDPR, that organisations certified under the DPF ensure an adequate level of protection for personal data. The Commission assessed not only U.S. legislation but also how that legislation is enforced.

The adequacy decision identifies the FTC as the principal civil enforcement authority responsible for ensuring compliance by organisations participating in the DPF. It refers to the FTC’s powers to investigate breaches of the rules, impose corrective measures and enter into settlements with companies that fail to comply with their obligations.

 

What Is NOYB’s Argument?

NOYB’s argument is based on this aspect of the adequacy decision. According to NOYB, the European Commission relied on the assumption that the FTC operates as an independent supervisory authority when assessing the adequate level of protection. If, as the U.S. Supreme Court has now held, the President may remove FTC Commissioners without the limitations previously understood to apply, one of the key assumptions on which the Commission’s adequacy decision was based has changed.

NOYB has therefore called on the European Commission to review the adequacy decision underlying the DPF and has also announced that it intends to rely on this argument in any future proceedings before the Court of Justice of the European Union.

Does the Judgment Mean the End of the Data Privacy Framework?

The U.S. Supreme Court’s judgment does not change the European Commission’s adequacy decision concerning certified organisations and therefore does not affect the legal framework governing transfers of personal data under DPF.

The European Commission has neither amended its adequacy decision nor initiated a review of it. As of today, the European Data Protection Board (EDPB) has not issued any statement indicating that the judgment affects the continued use of the Data Privacy Framework.

Nothing currently changes for controllers or processors. U.S. organisations certified under the DPF may continue to receive personal data on the basis of the adequacy decision, and organisations in the European Union may continue to rely on this transfer mechanism.

The Future of Data Transfers to the United States

When adopting the Data Privacy Framework, the European Commission assessed a comprehensive set of legal, institutional and procedural safeguards. The status of the FTC was one of them, but it was not the sole basis for the adequacy decision. Any future review will therefore not depend solely on the FTC’s independence. Instead, it will assess whether the United States as a whole continues to ensure a level of protection that is “essentially equivalent” to that guaranteed within the European Union.

This standard was established by the Court of Justice of the European Union in Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Schrems II) (Case C-311/18), in which the Court invalidated the European Commission’s Privacy Shield adequacy decision in 2020. That judgment subsequently led to the adoption of the current adequacy decision for the Data Privacy Framework.

The judgment in Trump v. Slaughter may therefore provide a new argument in future challenges to the validity of the Data Privacy Framework. However, the judgment alone does not lead to the conclusion that the DPF no longer satisfies the requirements of Article 45 GDPR or that organisations should immediately change the legal basis for transferring personal data to the United States.

Conclusion

The U.S. Supreme Court’s judgment affects the constitutional status of the FTC and may reopen the debate on one of the assumptions underlying the European Commission’s DPF adequacy decision. The judgment itself, however, does not change the current legal framework governing transfers of personal data to the United States or the obligations arising from it.

Whether the judgment will affect the future of the Data Privacy Framework and the rules governing transfers of personal data to the United States will depend primarily on whether the adequacy decision becomes subject to review by the European Commission or the Court of Justice of the European Union, and on the outcome of that review. Until then, nothing changes for data exporters in the European Union. Even so, it is better to be prepared for anything…

František Nonnemann, Vice-Chair of the Committee of the Association for Personal Data Protection (Czech Republic)

Recent news

AI Officer and DPO

An article by Vladan Rámiš and František Nonnemann, Association for Personal Data Protection, Czech Republic

read more