Five years ago this site argued that the architecture is the defense: when the legal layer around your data is contested, the durable answer is who holds the bytes, not who signs the papers. That argument just got its best evidence yet, from the highest court in the United States.

On June 29, in Trump v. Slaughter, the US Supreme Court held that the statutory protection shielding FTC commissioners from at-will removal is unconstitutional — a 6-3 decision overturning Humphrey's Executor (1935) on unitary executive theory. Since 2000, every EU-US data-flow deal has relied on the FTC as the independent enforcer of privacy obligations. The current adequacy decision relies on that independence 259 times. EU law requires independent oversight of data protection (Article 16(2) TFEU, Article 8(3) of the Charter), and the Commission had certified the FTC as meeting that bar.

The FTC's independence is now, by US constitutional law, a design flaw.

Where It Stands Tonight

The house is creaking but standing. Concretely:

  • The adequacy decision remains in force. No Commission repeal has been proposed. It stands until the Commission withdraws it or the Court of Justice annuls it.
  • noyb (Max Schrems) has formally asked the Commission to withdraw it, calling the framework's foundation dead, and announced an annulment lawsuit if the Commission doesn't act — a suit that, if filed, takes two to three years to reach a final ruling. As of tonight it has not been filed.
  • The EDPB weighed in on July 31, writing to the Commission that supervisory-authority independence is a key adequacy criterion and asking the Commission to assess Slaughter's impact on the Framework.
  • The counter-argument is serious. IAPP's legal analysis (Christakis, Propp, Swire) holds that Slaughter does not sink the Data Protection Review Court — the surveillance-redress body Schrems II was actually about — because the DPRC's independence rests on internal executive regulations binding the executive (the Accardi/State Farm actus contrarius line), not on congressional removal protections, and the Court expressly reserved the question of adjudicators. Slaughter directly hits the commercial enforcement half; the surveillance half hangs on separate, shakier-but-different supports. Latombe, which upheld the redress mechanism, is under appeal at the CJEU regardless.

So: the commercial-enforcement leg of the adequacy decision has lost its factual basis; the surveillance-redress leg survives on contested grounds; the decision stands anyway; and the fix, if it comes, arrives on litigation timescales measured in years. This is the third time in a decade the legal plumbing between the EU and US has failed — Safe Harbour (2015), Privacy Shield (2020), and now a framework whose foundations cracked without anyone flipping a switch.

The Pattern

Each collapse drove the same migration at different speeds: lawyers rewriting transfer paperwork, then large enterprises re-contracting, then — slowly — regions building their own capacity. The first two failures are why Germany's public sector runs Nextcloud at 50,000-seat scale, why Belgium forked Element's Matrix stack for 750,000 civil servants, and why sovereignty-washing became a marketing category. The pattern to expect now is not a cliff. It is exactly what the last two rounds produced: a decade of legal uncertainty, during which the org chart of the internet quietly got redrawn toward whoever holds the data.

The 259 reliance is worth sitting with, because it's the whole story of legal-layer trust in one number. When the Commission certified the framework in 2023, it did the reasonable thing: it counted the references. What it couldn't count was a foreign constitutional amendment — which is effectively what a 6-3 ruling overturning 90 years of precedent is. You cannot put a clause in a contract that binds another sovereign's court system. Everyone in the negotiation rooms knew this. The paperwork got signed anyway, because the alternative was expensive.

The alternative is still expensive. It's also the only option that has survived every round so far.

What This Means for a Fire Hall

Small organizations are not parties to adequacy decisions, but they inherit their failure modes. If your co-op, clinic, or municipal office runs membership lists, client records, or email on US-owned clouds — with or without a DPA in the onboarding folder — the legal basis just got softer, and the trajectory is one-directional. The compliance answer is to wait for lawyers to finish arguing. The architecture answer predates this ruling and outlasts the next one:

  1. Count what you actually hold. Most community organizations can enumerate their sensitive data in an afternoon: member lists, donor records, intake forms, email archives. Knowing where each one lives is the entire prerequisite.
  2. Move the sensitive set to infrastructure you or your jurisdiction controls. Self-hosted Nextcloud, a regional co-op provider, a municipal data haven. Free is the most expensive option when the "free" tier is the product — and the price is now quoted in court dockets.
  3. Treat every adequacy decision as a lease, not a deed. Three US-EU data deals in thirty years; none survived contact with a court. Whatever your lawyer says is settled today, build so that the regime's collapse is an inconvenience, not an extinction event.

None of this requires believing noyb over the IAPP, or the reverse. That fight is about which legal theory saves the framework. The architecture argument doesn't need a winner: both sides concede the commercial-enforcement leg is damaged, both concede litigation runs for years, and neither can promise the decision survives the CJEU. When the lawyers cannot tell you what the law will be in 2029, the only control left is where the bytes live.

The courts will take years to decide what this ruling meant. Your data doesn't have to wait for them.