Two previous EU-US data transfer agreements were struck down by the European Court of Justice. Safe Harbour died in 2015. Privacy Shield died in 2020. Both were killed by Max Schrems, through noyb, on the same grounds: US surveillance law provides inadequate protection for EU personal data, and there's no independent judicial redress mechanism.

The third agreement — the EU-US Data Privacy Framework, adopted in 2023 — was always a copy of the previous two with a new name and a few cosmetic adjustments. The Biden administration created a "Data Protection Review Court" via executive order. It's not a court. It's an executive body inside the US Department of Justice that exists at the President's pleasure.

Everyone knew this was fragile. The Commission adopted it anyway, under industry pressure. Now the fragility is manifest.

What Happened

On June 29, 2026, the US Supreme Court decided Trump v. Slaughter. The ruling, grounded in the unitary executive theory, holds that the FTC's independence from the President is unconstitutional. The President can now remove FTC commissioners at will.

This matters because the EU-US Data Privacy Framework's adequacy decision relies on the FTC as the independent US privacy enforcement authority. The Commission references FTC independence 259 times in the decision. EU treaty law — Article 16(2) TFEU and Article 8(3) of the Charter of Fundamental Rights — requires that data protection oversight be performed by an independent authority. The US just eliminated the independence of the authority the Commission relied on.

noyb filed a formal letter to the European Commission the same day, calling for an orderly withdrawal of the adequacy decision. Max Schrems' statement: "Even in the European Commission's logic, the basis for any EU-US data transfer deal is dead."

What Happens Next

The framework is formally still in force. It stays in force until the Commission repeals it or the CJEU annuls it. There's no immediate legal cliff.

But the trajectory is clear. The Latombe case — a challenge to the DPF already before the EU courts — is working its way through the system. The General Court's ruling on that challenge is pending. If the CJEU gets a Schrems III case, the legal argument is now stronger than it was for Schrems I or II, because the independence problem is no longer speculative. It's a Supreme Court ruling.

The practical timeline: months to a year or more before formal invalidation, if it comes. But organizations making infrastructure decisions today should be planning for a world where transferring personal data to US cloud providers requires Standard Contractual Clauses with Transfer Impact Assessments — and those assessments now have a Supreme Court decision to cite as a deficiency.

Why This Matters for Community Infrastructure

If you're a European community organization — a town office, a fire hall, a small business, a co-op — and you're deciding between Microsoft 365 / Google Workspace / AWS and a self-hosted Proxmox stack, the data transfer situation is a risk factor that doesn't apply to the self-hosted option.

Here's the structural difference:

US cloud provider. Your data is processed by a US company. The company is subject to the CLOUD Act. The legal basis for transferring EU personal data to that company is the Data Privacy Framework, which is now on life support. If the DPF is invalidated, your provider needs to scramble for SCCs, and those SCCs need a Transfer Impact Assessment that accounts for US surveillance law — which is what killed the previous two agreements. You carry this risk. You can't fix it. You can't audit the provider's compliance. You wait for the provider's lawyers to tell you it's fine.

Self-hosted infrastructure. Your data stays on hardware you control, in a jurisdiction you chose, with retention policies you configured. There's no transatlantic transfer because there's no transatlantic provider. The CLOUD Act can't compel a European community organization running its own Proxmox cluster because there's no US corporate entity to compel. The DPF's collapse is irrelevant to you.

This isn't a theoretical distinction. It's the difference between carrying a regulatory risk you can't control and not carrying it at all.

The Broader Pattern

Three data transfer agreements. Two already dead. The third now structurally undermined. The pattern is not that the EU and US keep failing to negotiate a good deal. The pattern is that the US legal system cannot provide the protections EU law requires, because those protections are incompatible with how US surveillance and executive power actually work.

Safe Harbour was built on voluntary corporate commitments. It died because US surveillance law overrode them. Privacy Shield was built on promises from two administrations. It died because promises aren't laws. The Data Privacy Framework was built on FTC independence and an executive-order "court." The FTC independence is gone. The executive order is revocable.

Each iteration takes years to negotiate, years to challenge, and years to replace. During those years, organizations using US providers operate under legal uncertainty. Some of that uncertainty is manageable — SCCs exist, binding corporate rules exist, derogations under Article 49 GDPR exist for necessary transfers. But none of them solve the underlying problem: US surveillance law doesn't meet EU adequacy standards, and the US isn't going to change its surveillance law to satisfy the EU.

The Honest Assessment

The DPF might survive. The Commission might find a way to argue that FTC independence wasn't load-bearing despite citing it 259 times. The CJEU might take years to rule, and by then the political landscape could shift. The Latombe ruling might go in the Commission's favor on procedural grounds without reaching the substance.

But if you're making infrastructure decisions with a five-year horizon — which is what community infrastructure decisions are — you should plan for the DPF being invalidated. Not because it's certain, but because the cost of planning for it and being wrong is low (you deployed FOSS infrastructure you control), while the cost of not planning for it and being right is high (you're scrambling to migrate off a US provider under legal pressure, with your data in their format, on their timeline).

The communities that own their infrastructure won't notice when Schrems III lands. The ones that rent it from US providers will. That's the whole argument, again.

Sources

  • noyb, "US Supreme Court just blew up EU-US Data Transfers," June 29, 2026
  • Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework adequacy decision)
  • Trump v. Slaughter, US Supreme Court, June 2026
  • GleSYS, "EU data sovereignty in 2026: New rules for your infrastructure," July 29, 2026