Cybersecurity Policy Report, Supreme Court’s Slaughter Ruling Seen Undermining EU-U.S. Privacy Pact, (Jun 30, 2026)
By Tony Foley
Commenting on the U.S. Supreme Court’s ruling yesterday in Trump v. Slaughter, the European Center for Digital Rights (NOYB) questioned whether the court’s ruling, which concluded that the president can remove members of the Federal Trade Commission, essentially nullifies the current European Union-U.S. Data Privacy Framework (DPF) for cross-border transfers of personal data between the EU and the U.S.
NOYB arguments. In a news release describing its position, NOYB said the court decided that the independence of the FTC was unconstitutional under the “unitary executive theory” that the U.S. president has power over all executive bodies. “Given that the EU relied on the ‘independence’ of the FTC as a privacy watchdog in almost all cases, the entire structure of the EU-US Data Privacy Framework has just collapsed,” the release said. Specifically, the watchdog said that under EU treaty law, oversight regarding data protection matters must be done by an independent authority, which, prior to yesterday’s ruling, has historically been the FTC in the U.S.
NOYB further contended that, while the Biden administration created a Data Protection Review Court to act as an independent legal redress mechanism, the court was in fact an executive body within the U.S. Justice Department whose independence could be changed by President Trump. “Even in the European Commission's logic, the basis for any EU-US data transfer deal is dead,” said NOYB founder Max Schrems. “We call upon the Commission to start an orderly exit from the U.S. cloud—which is not easy, but unfortunately unavoidable. The Commission built a legal house of cards under industry pressure. Now that it clearly collapses, it has to take responsibility.”
The news release further contends that while some companies may not directly rely on the DPF and instead use standard contractual clauses (SCCs) and binding corporate rules (BCRs), these instruments also rely on an impact assessment, which in turn relies on formerly independent executive bodies such as the Privacy and Civil Liberties Oversight Board (PCLOB) or the Data Protection Review Court.
NOYB has sent a formal letter to the EC asking it to take appropriate steps to repeal the EU-U.S. DPF. Noting that many EU Member States had already moved toward a “digital sovereignty” approach and begun to decouple from U.S. cloud service providers, NOYB nevertheless maintained that, due to the “massive pressure” the U.S. continues to place on the EU to facilitate data flows, it will file a lawsuit in the coming weeks aiming to allow the Court of Justice of the EU (CJEU) to annul the current DPF. However, the group added that the lawsuit was likely to take several years before a final decision.
EC reaction. In a press briefing today, the EC said it was analyzing whether the Slaughter decision would have implications for the DPF. The EC spokesperson emphasized that the commission’s 2023 decision ratifying the DPF remained in place but that the EC would continue to monitor adequacy and work closely with U.S. officials on the matter. Finally, the U.S. executive order on which the DPF is based continues to be in place and provides key safeguards for personal data transfers from the EU.
News: InternationalLegislation DataPrivacy GDPR