Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 04, 2026 · 8 min read

EDPB Asks Brussels to Review the EU-US Data Privacy Framework

EDPB Chair Anu Talus wrote to Commissioner Michael McGrath on 31 July 2026 asking the Commission to closely assess whether the Supreme Court's 6 to 3 ruling in Trump v. Slaughter leaves the FTC independent enough to underpin adequacy. The decision is still in force.

A letter is not a court judgment. But when the body that coordinates every data protection authority in Europe asks the European Commission to look again at the legal basis for most transatlantic data flows, read the letter rather than the headlines about it. The EU-U.S. Data Privacy Framework has not been struck down. What changed on 29 June 2026 is that one of the pillars the Commission leaned on when it declared the United States adequate now looks noticeably less sturdy.

Key Takeaways

  • The US Supreme Court ruled 6 to 3 on 29 June 2026 in Trump v. Slaughter (No. 25-332) that statutory limits on the President's power to remove FTC Commissioners are unconstitutional, effectively overruling Humphrey's Executor (1935).
  • EDPB Chair Anu Talus wrote to Commissioner Michael McGrath on 31 July 2026 asking the Commission to closely assess how the ruling affects the FTC's ability to uphold Data Privacy Framework commitments.
  • GDPR Article 45(2)(b) makes "the existence and effective functioning of one or more independent supervisory authorities" a key element of any adequacy finding, and Commission Implementing Decision (EU) 2023/1795 relied in part on the FTC being exactly that.
  • Adequacy remains in force today: no court has annulled the decision, and organisations certified under the framework can still lawfully receive EU personal data.
  • If adequacy did fall, transfers would revert to Standard Contractual Clauses plus a transfer impact assessment per vendor, which is paperwork rather than a shutdown.
Small European Union and United States flags standing on a polished negotiating table beside closed leather document folders and empty chairs in a diplomatic meeting room

What Did the EDPB Actually Ask For?

A review, not a revocation. The letter published in the EDPB's correspondence register on 31 July 2026 asks the Commission to "closely assess" how Trump v. Slaughter affects the FTC's posture and its capability to uphold Data Privacy Framework commitments. It does not call for suspension, and it does not declare the framework invalid.

The reasoning is compact. As the EDPB put it, "the existence and effective functioning of one or more independent supervisory authorities in the third country, with responsibility for ensuring and enforcing compliance with the data protection rules, is one of the key elements to be taken into account when assessing the adequacy of the level of protection in a third country." That sentence is close to a quotation of GDPR Article 45(2)(b). Source: iapp.org.

The pattern is familiar. The EDPB writes first, publishes guidance second and lets national authorities enforce third, as it did with its July 2026 draft guidelines on anonymisation. This is an opening move, not an endgame.

Why Is FTC Independence Load Bearing for Adequacy?

Because the FTC is the body that punishes a certified US company for breaking its Data Privacy Framework promises, and adequacy assumes the punishment is real. When an organisation self certifies, its published commitments become enforceable under Section 5 of the FTC Act as a prohibition on unfair or deceptive practices. Source: ftc.gov.

Take away the independence and that promise starts to look conditional on who occupies the White House. Commission Implementing Decision (EU) 2023/1795, adopted on 10 July 2023, described the FTC as an independent agency of five Commissioners protected by for cause removal. The Court has now removed the protection, yet the Commission's adequacy decisions page still lists the United States as adequate.

Scope matters here. The ruling concerned the FTC alone, but the same for cause language sits in the founding statutes of more than two dozen US agencies, which is why it reads as a structural change rather than a personnel dispute.

Is This the Setup for Schrems III?

Practitioners are asking because the structural argument matches the two that already worked. Safe Harbour fell in October 2015 and Privacy Shield in July 2020, both at the Court of Justice, both because the US side failed to deliver protection essentially equivalent to EU law. The third framework has not repeated the pattern so far. In Case T-553/23 Latombe v Commission, decided 3 September 2025, the General Court dismissed the annulment action in its entirety. That judgment predates Trump v. Slaughter, an appeal is pending, and Skadden expects a Court of Justice ruling in early to mid 2027. Meanwhile noyb has asked the Commission to withdraw the adequacy decision outright.

The arithmetic is uncomfortable. Safe Harbour lasted fifteen years, Privacy Shield four, and the Data Privacy Framework is three years old with a live constitutional question attached to one of its pillars. Two of three transatlantic frameworks have been annulled. A programme that treats the third as permanent infrastructure is betting against its own history.

The Serious Case That Nothing Has Changed

There is a real counter argument, and compliance teams should not skip it. The IAPP published a piece titled "No, Trump v. Slaughter does not undo the EU-US data-transfer redress mechanism" arguing that the ruling addressed congressional restrictions on the President, not limits the executive imposes on itself by regulation.

The distinction matters because the redress mechanism EU citizens use for national security complaints, the Data Protection Review Court, was created by Executive Order 14086 rather than by statute. The majority expressly reserved the question of adjudicators and left both United States v. Nixon and Morrison v. Olson intact. Skadden adds that the decision "does not change or invalidate the substance of those agencies' actions", and that state attorneys general keep independent authority of their own.

So the honest status is uncertainty, not collapse. As Hunton summarised, these are legal arguments rather than legal determinations: no court has invalidated the framework, and certified US companies remain eligible to receive covered transfers. Source: hunton.com.

What This Means for Your Email Stack

More of your email infrastructure sits on this legal foundation than you probably realise. Twilio, which owns SendGrid, states publicly that Twilio Inc. complies with the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. framework. Klaviyo says it participates and relies on the framework to move data from the EU to the US. HubSpot hedges, using a mix of mechanisms including Standard Contractual Clauses for US transfers.

All of them carry subscriber records, delivery logs and engagement data across the Atlantic. Engagement data is the underrated part: an open log built from a tracking pixel records who opened, when, from which IP address and on which client. European regulators increasingly treat that as personal data rather than anonymous analytics, as France's CNIL did in its recommendation on email tracking pixels and consent.

Losing adequacy would be less dramatic than the headlines suggest and far more tedious. Transfers would revert to Standard Contractual Clauses plus a transfer impact assessment per vendor and per data category. The framework never made transfers legal so much as let organisations skip that assessment, and against the backdrop of the wider run of GDPR enforcement activity, the paperwork is the point.

What Should Compliance Teams Do Now?

Four things, none urgent, all cheaper before a judgment than after one. Nothing here assumes the framework falls; each step earns its keep if it holds.

  • Split your vendor list by transfer mechanism. For every US processor in your Article 30 record, note whether you rely on the framework, on SCCs, or on both. Marketing and analytics stacks lean hardest on certification.
  • Confirm the fallback language is already in the contract. Many data processing agreements name the framework as primary with SCCs as a stated fallback. Some do not. Renegotiate those now, while there is no deadline pressure.
  • Refresh transfer impact assessments. Any assessment citing FTC independence as a safeguard describes a state of affairs that ended on 29 June 2026. Update the reasoning and date it.
  • Watch two calendars. The Commission's periodic review runs on the schedule in the adequacy decision; the Latombe appeal runs on its own. Either can move first.

Checking a vendor's status takes a minute. The Department of Commerce publishes the participant list, and the EDPB maintains an FAQ for European businesses covering what certification does and does not include.

The Bottom Line for Individuals

If your email lands in a US server farm but you are not the person accountable for it, the lesson is about the limits of the instrument. Cross border adequacy governs whether an organisation may lawfully move data about you between jurisdictions. It does not govern how much gets collected, and it changes nothing about what a message does when it renders in your inbox.

Frameworks like this one are negotiated between governments, reviewed on multi year cycles, and occasionally annulled years after the transfers they authorised took place. That is slow, structural protection, and it is valuable. It is also the wrong tool if your question is what a specific sender learns about you this afternoon. National regulators move faster on that question, as Italy's Garante did when it set out its rules on email tracking pixels in May 2026, but even they set obligations for senders rather than intercepting anything on your end.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.