Skip to main content

EU-U.S. Data Transfers After Slaughter v. Trump : Why the DPF Holds — and What DPOs Must Do Now

Content Suite: EU-U.S. Data Transfers after Slaughter v.Trump

Event: EFDPO Webinar Follow-Up
Date of Webinar: August 27, 2026

Panelists:

  • Tim Wybitul, Partner, Latham & Watkins (Frankfurt)
  • Michael Will, President, Bavarian Data Protection Authority (BayLDA)
  • Prof. Kenneth Propp, Georgetown University (Washington, D.C.)

Moderator: Dr. Christoph Bausewein, Assistant General Counsel, CrowdStrike (on behalf of EFDPO)

Background and Legal Context of the U.S. Supreme Court Decision

The recent decision by the U.S. Supreme Court in Slaughter v. Trump (June 2026) sparked widespread debateacross the transatlantic privacy community. Across media and specialized forums, the immediate questionarose: Is the EU-U.S. Data Privacy Framework (DPF) at risk again? Are we facing an impending “Schrems III”?
 
To shed light on these complex U.S. constitutional law developments, the European Association of DataProtection Officers (EFDPO), in cooperation with the German Association of Data Protection Officers (BVD), hosted an expert webinar on August 27, 2026.
 

The core message delivered by the panelists — Tim Wybitul (Latham & Watkins), Michael Will (President of BayLDA), and Prof. Kenneth Propp (Georgetown University), moderated by Dr. Christoph Bausewein (CrowdStrike / EFDPO) — was unanimous: There is no reason for alarm. The decision has no immediateconsequences for the EU-U.S. Data Privacy Framework. However, forward-looking organizations must notremain passive; privacy professionals should proactively prepare for future legal shifts and potential long-term changes.

What Happened in Slaughter v. Trump?

The U.S. Federal Trade Commission (FTC) is a regulatory agency enforcing consumer protection, privacy, andantitrust laws. By statute, the FTC consists of five commissioners, with a maximum of three belonging to thePresident’s political party to ensure bipartisan continuity across administrations.

Early in his second term, President Trump summarily removed the two Democratic commissioners prior to theexpiration of their terms. As the enabling statute stipulated that commissioners could only be removed “forcause,” the commissioners sued. In June 2026, the U.S. Supreme Court ruled in Slaughter v. Trump:

 

Statutory for-cause protection from removal for FTC Commissioners is incompatible with the U.S. doctrine of separation of powers (the “unitary executive doctrine”). The President must possess the authority to remove executive officers at will.

 

Key Takeaways from the Ruling:

  1. Focus of the Decision: The ruling reinforces presidential control over independent executive branch agencies.
  2. No Disruption to FTC Privacy Enforcement: The ruling impacts political leadership rather than day-to-day operations. Routine privacy enforcement is carried out by career, non-political staff whose recommendations are standardly endorsed. While enforcement priorities naturally shift between administrations, this reflects long-standing U.S. administrative practice rather than a structural collapse.
  3. Implications for PCLOB: A parallel proceeding regarding the removal of members of the Privacy and Civil Liberties Oversight Board (PCLOB) resumed following Slaughter. However, as the PCLOB serves an advisory role without direct executive enforcement powers, its core function remains distinct.

Why the EU-U.S. Data Privacy Framework (DPF) Remains Intact

The panelists unanimously dispelled fears regarding an immediate invalidation of the DPF, highlighting clear legal distinctions between the institutions involved:

  1. The Data Privacy Review Court (DPRC) is Protected: The CJEU’s Schrems II ruling primarily targeted redress mechanisms against U.S. national security surveillance (e.g., FISA Section 702). In response, the U.S. established the Data Privacy Review Court (DPRC). Crucially, the DPRC was created not by congressional statute, but via an Executive Order and Department of Justice (DOJ) regulations.
    DPRC judges can only be removed for cause under these DOJ regulations. The Supreme Court in Slaughter expressly affirmed that the landmark Nixon precedent from the Watergate era remains good law: the Attorney General is legally bound by DOJ regulations unless and until they are formally withdrawn. Furthermore, the Court explicitly refrained from ruling on “inferior” executive officers such as DPRC judges. The DPF redress mechanism therefore remains fully protected.
  2. Essential Equivalence, Not Identical Structures: Even if the FTC’s independence is scrutinized under European standards, GDPR Article 52 does not mandate that foreign jurisdictions mirror EU institutional setups identically. The CJEU standard is “essential equivalence.” The FTC represents only one component of the U.S. privacy framework, alongside robust state-level enforcement bodies such as State Attorneys General and the California Privacy Protection Agency (CPPA).

Practical Guidance for Organizations: Preparing “Fallback Options”

While there is no immediate need to halt transatlantic data transfers, the panel unanimously agreed that privacy landscapes evolve rapidly. Sound risk management requires companies to prepare for long-term shifts or future CJEU challenges.

Actionable Steps for DPOs and Compliance Teams:

  1. Maintain Business Continuity: The DPF remains a valid, legally binding adequacy mechanism for certified U.S. organizations.
  2. Maintain Standard Contractual Clauses (SCCs) as a Fallback: Ensure that current EU Standard Contractual Clauses (SCCs) are executed in parallel with key U.S. service providers certified under the DPF.
  3. Keep Transfer Impact Assessments (TIAs) Up-to-Date: Regularly review and refresh TIAs. A well-structured TIA should rely primarily on the DPF while documenting valid SCCs and supplementary measures as a ready fallback.
  4. Monitor Long-Term Strategy: Evaluate vendor resilience and encryption safeguards (where service providers lack access to cleartext data) for mission-critical workflows.

 

Also read on: https://www.mlex.com/mlex/articles/2510042/us-ruling-clouds-future-of-eu-us-data-transfers