Be honest about how you read the news on June 29, 2026.
If Trump v. Slaughter crossed your screen that day, you probably read it the way it was framed — as a fight about presidential power. Who can the President fire? Can Congress build agencies he cannot reach? Big, abstract, constitutional, and easy to file under interesting, not mine. The opinion never mentions privacy, so there was no reason to think about privacy that day. Not for a second.
By the end of July, Europe's regulators had connected what the opinion never mentioned. A two-page letter went from Brussels to Brussels — from the chair of Europe's data protection regulators to the Commissioner responsible for justice — and it put the Supreme Court's opinion next to a European legal document, pointing at the sentence where they contradict each other.
They are, it turns out, the same document. One of them just doesn't know it yet.
How your data gets across the Atlantic
Let me set the table, because this only lands if you know how the plumbing works.
Europe does not let personal data leave, as a default. Under the GDPR, your name, your location history, your purchase record, your health app's chatter — none of that can simply be shipped to a country outside the EU. There are exceptions, and the biggest one is called an adequacy decision: the European Commission formally declares that a particular country protects data well enough, and the tap opens.
The United States has one. It is Commission Implementing Decision (EU) 2023/1795, adopted on July 10, 2023, and the arrangement it blesses is the EU-U.S. Data Privacy Framework. If you have ever wondered how a European customer's data ends up on an American server without anyone going to jail, this is the answer. It is the third attempt at this bridge — the Federal Trade Commission's own guidance notes that the new framework replaces the Privacy Shield program, which the European Court of Justice knocked down in 2020, which itself replaced Safe Harbor, which the same Court knocked down in 2015. Two demolitions, three bridges. Remember that rhythm.
Now — what does the Commission have to look at before it declares a country adequate? The regulation tells it. Article 45(2) of the GDPR lists the criteria, and subparagraph (b) requires the Commission to weigh the existence and effective functioning of one or more independent supervisory authorities in the receiving country, with responsibility for ensuring and enforcing compliance with the data protection rules.
Independent. Not competent. Not well-resourced. Not usually pretty good. Independent — and the word is in the statute, not in a commentary.
So when the Commission sat down in 2023 to write the American adequacy decision, it had to name an independent American supervisor. It named the FTC. The decision says, in its own voice, that an independent supervisory authority tasked with powers to monitor and enforce compliance with the data protection rules should be in place, and then it explains why the FTC qualifies. It describes the agency as an independent authority composed of five Commissioners. And then it writes the sentence that this entire article is about:
"Commissioners are appointed for a seven-year term and may only be removed by the President for inefficiency, neglect of duty, or malfeasance in office."
That is recital 60. That is the beam holding up the bridge. Europe agreed to let your data travel to America partly because five people in Washington could not be fired for displeasing the person who appointed them.
On June 29, 2026, the Supreme Court held that they can.
What the Court held (and why it never had to think about Europe)
Trump v. Slaughter is a separation-of-powers case. The question was whether Congress could shield Federal Trade Commission commissioners from being fired at the President's pleasure — a protection that had stood since 1935, when the Court decided Humphrey's Executor.
The majority said no, and it did not leave the door ajar. The FTC, the opinion says, unquestionably exercises executive power, and must therefore be controlled by the Chief Executive, in whom such power is vested. Ninety years of precedent, the Court wrote, has not withstood the test of time. And then, in one of the flattest sentences the United States Reports has produced in a while: "If anything more is left of Humphrey's, we overrule it."
The vote was 6-3, and the logic runs all the way down. Anyone wielding the President's power is, in the majority's phrase, subject to removal by him. The law firm memos that followed put it plainly: the Court held that the FTC's statutory for-cause removal protections are unconstitutional and that commissioners must be removable by the president at will.
Read the opinion and you will not find the word adequacy. You will not find GDPR, or Brussels, or transatlantic. Why would you? No lawyer in that case was arguing about European data flows. The briefs were about Article II and the Take Care Clause and the ghost of the New Deal.
Here is where it gets interesting. A domestic constitutional ruling, argued on purely domestic terms, silently rewrote a sentence in a European legal instrument — and the people who wrote that sentence were not in the room.
The letter
On July 31, 2026, the European Data Protection Board — the body where all of the EU's national privacy regulators sit together — sent two pages on Board letterhead to Commissioner Michael McGrath. It is filed in the Board's own public register as the EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter.
What the letter does is almost clinical. It quotes the American opinion back at Brussels — the line about vast rulemaking, enforcement and adjudicatory powers, the line about executive power being controlled by the Chief Executive. Then it reminds the Commission of its own rulebook: independent supervisory authorities are, in the Board's words, "one of the key elements to be taken into account when assessing the adequacy of the level of protection in a third country," under Article 45(2)(b). Then it notes, politely, that the adequacy decision expressly says FTC commissioners may only be removed for inefficiency, neglect of duty, or malfeasance in office.
And then it asks the Commission to closely assess whether this development affects the functioning of Implementing Decision (EU) 2023/1795.
To be clear about what that is and is not: it is a request to look. It is not a finding, not a suspension, not a demand to tear anything down. Anu Talus signed a letter asking a colleague to check something.
The letter went on July 31. As of September 30, 2026, the Commission has not published an answer. When the IAPP asked for one, the Commission did not immediately respond to the request for comment. McGrath's public posture before the ruling had been warm — in April he said there was too much at stake to allow (the DPF) to slip. The ruling did not cool it: on July 22, after meeting FTC Chairman Andrew Ferguson in Washington, he posted that the EU remains committed to this Framework while monitoring it closely, Agence Europe reported. Since July 31, as far as the public record goes, nothing.
The adequacy decision is still in force. Your data is still crossing. Today.
So that settles it — the deal is dead. Right?
No — and the strongest argument against my own framing deserves an honest hearing, because it is a serious one and it comes from serious people.
Three of them, in fact. Théodore Christakis of the University of Grenoble Alpes, Kenneth Propp of Georgetown, and Peter Swire of Georgia Tech published an analysis on July 8, 2026 arguing that the ruling reaches the wrong limb of the framework entirely, under a title that does not hedge: No, Trump v. Slaughter does not undo the EU-US data-transfer redress mechanism.
Their argument turns on a distinction most coverage flattens. The adequacy decision has two halves. One is commercial — what certified companies promise about your data, and who polices those promises. That is the FTC's half. The other is government access — what American intelligence agencies may do with European data, and what remedy a European has if they overstep. That half runs through a body called the Data Protection Review Court, created by executive order rather than by statute.
And here is their point: every previous European demolition was about the second half. Schrems I and Schrems II were about surveillance and remedy, not about consumer-protection enforcement. Slaughter, by contrast, concerns an agency that has never had jurisdiction over national security or signals intelligence — the FTC never did. So the ruling, whatever else it does, cannot reach the limb that European courts have actually cut twice.
They go further. What the Supreme Court withdrew, they argue, is the power of Congress to shield an executive officer from removal — and the redress court's independence was never a gift from Congress. It comes from the executive binding itself, a structure the Court left entirely alone. They also note that the majority expressly reserved the question of adjudicators, setting the status of judges on non-Article III courts aside for another day. Their headline claim: transatlantic data transfers do not stand or fall with the FTC.
I find a lot of that persuasive. I also notice what it does not say. In the same piece, the authors write: "We do not address here the important and difficult questions Slaughter raises for the role assigned to the FTC as a supervisory body for commercial data transfers." That is not a dismissal of the problem I am describing. That is a note saying it belongs in somebody else's article.
The other honest counter-arguments are practical. The immediate legal position, as one law firm summarized it, is that the framework remains in effect unless the Commission amends or withdraws the decision, or a court invalidates it. The FTC has not gone anywhere — its own guidance still says the agency is committed to vigorous enforcement of the DPF Principles. Maneesha Mithal, who used to run the FTC's privacy division, told the IAPP the agency has not shown any retreat from commitments to enforce privacy process.
And from the industry side, an analysis by BBB National Programs — which, disclosure, administers dispute resolution for companies in the framework — points out that the Board did not conclude that the DPF is invalid nor call for suspension or revocation. Read the letter cold, they argue, and the text itself is remarkably measured. They are right that it is.
So: the agency still exists, still enforces, still answers European complaints. If independence is really about outputs — cases brought, fines levied, promises policed — then very little has changed.
Which brings me to the question that decides this, and to a courtroom that has answered it before.
Europe has ruled on this exact question — against its own members
Why might the "nothing has changed in practice" argument not survive contact with Luxembourg? The Court of Justice has been asked what "independent" means for a data protection regulator. Twice. And both times it was asked about a European country, and both times the answer was: stricter than you think.
Germany, March 9, 2010. The European Commission took Germany to court because the authorities policing private-sector data use in the Länder were subject to ordinary State oversight — the same kind of administrative supervision that applies to any government office. Not firing. Not political direction. Supervision. The Grand Chamber held that Germany "failed to fulfil its obligations under the second subparagraph of Article 28(1)" of the directive.
Read how the Court got there, because the reasoning is what matters. The word "independent," it said, is complemented by the adjective "complete" — which implies a decision-making power independent of any direct or indirect external influence on the supervisory authority. And independence does not mean merely independence from the companies being policed. The authorities, the Court held, must remain "free from any external influence, including the direct or indirect influence of the State or the Länder, and not of the influence only of the supervised bodies."
The State included. That sentence is thirteen years older than the American adequacy decision, and it answers the question the adequacy decision assumed away.
Austria, October 16, 2012. Two and a half years later, the same Grand Chamber did it again. And look at what Austria's offenses were. Its data protection commission had a managing member who was a federal official subject to supervision. Its office was integrated with the departments of the Federal Chancellery — the regulator shared premises and administration with the government it was meant to check. And the Federal Chancellor held an unconditional right to information covering all aspects of the commission's work.
That last one deserves a beat. The Chancellor could ask questions. That was a defect. The Court found that Austria "has failed to fulfil its obligations under the second subparagraph of Article 28(1)" — the same provision, the same words.
And Austria's defense was exactly the defense being offered for the FTC today: but our people are formally un-instructable, the statute says so, in practice nothing bad happens. The Court's answer was that such functional independence is not by itself sufficient to protect a supervisory authority from all external influence.
Now hold the two pictures side by side.
In Vienna, the offense was a shared office building, a seconded civil servant, and a right to be briefed. In Washington, the President may now fire a commissioner because he disagrees with her. Not for inefficiency. Not for malfeasance. Because he disagrees.
Europe has struck down its own members for very much less.
To be fair, the test for a third country is not the test for a member state. Europe asks outsiders for protection that is essentially equivalent — equivalent safeguards, not a carbon copy of its own institutions — which is exactly the phrase the Board used in its July letter. But "essentially equivalent" still has to mean something, and whatever it means, it cannot plausibly mean less independent than a regulator the Court already condemned for sharing a building. It is genuinely difficult to see how the sentence in recital 60 survives being read aloud in Luxembourg.
What the courts are doing right now (which is: something else)
The irony is hard to miss.
There is a live case in Luxembourg attacking this adequacy decision. Philippe Latombe — described by the IAPP at the time as a Member of French Parliament — lost at the General Court on September 3, 2025 and appealed on October 31, 2025; the appeal is Case C-703/25 P, and it asks the Court of Justice to annul Commission Implementing Decision (EU) 2023/1795 outright. The case caption lists the other parties as the European Commission, Ireland, and the United States of America — which is its own small education in how these cases actually work.
But read the grounds. The first one is about the rules for appointing and dismissing the judges of the Data Protection Review Court. The others are about bulk collection and prior authorization. It is a case about the surveillance limb — the limb Christakis, Propp and Swire say Slaughter does not touch. No one in that appeal is arguing about the FTC, because the appeal was drafted eight months before the Supreme Court ruled.
As of September 30, 2026, that appeal is pending. No judgment has issued. No hearing date is public.
And the other case — the one everybody has been waiting for — does not exist.
On June 29, 2026, the Austrian group noyb published its reaction within hours. Max Schrems, who has now personally demolished two versions of this bridge, called on the Commission to orderly withdraw the adequacy decision on the US. In a letter to McGrath dated the next day, noyb argued that Europe and America now have a constitutional clash of laws — EU treaty law requiring an independent supervisor, US constitutional law now forbidding one — a rift no change of administration fixes. noyb's press release also said, flatly, that it would file a lawsuit in the coming weeks, aiming to let the Court of Justice annul the current deal.
I checked on September 30, 2026. noyb's newsroom, and its own EU-US transfers project page, carry nothing about a filing; the most recent item on the transfers page is still the June 29 reaction, and the most recent noyb news of any kind is from September 21 and concerns something else entirely. In its August 3 report, the IAPP quoted Schrems saying noyb is actively working on a lawsuit to put the matter back before the CJEU. Working on. Not filed.
So here is the state of play, more than three months after the Supreme Court spoke. The regulators have asked a question. The Commission has not answered it. The challenger has announced a lawsuit and not filed it. The only case in court is about a different problem. And the data keeps moving.
Even noyb concedes the mechanics: the decision is formally in force until either the Commission repeals it or the Court of Justice annuls it. No one has done either. Everyone is waiting for someone else.
Just imagine the next three years
Let me get speculative, because the useful thing about this particular mess is that we have watched the movie twice already and we know roughly how the third act goes.
Scenario one: the slow bleed. The Commission never answers the July letter in public. It opens a quiet review, asks Washington for reassurances, receives a memorandum explaining that nothing has changed in practice, and files it. The framework limps on. Meanwhile every corporate transfer impact assessment written in Europe from now on has to describe an American regulator that serves at the President's pleasure — and every European data protection officer signing one knows it. Legal risk does not disappear when nobody names it. It just gets priced into contracts, and then into procurement decisions, and then into which cloud a German hospital buys.
Scenario two: the third demolition. A case reaches Luxembourg — noyb's, or a national referral, or the Latombe appeal expanded. Sometime in 2028 or 2029, the Court reads recital 60 out loud, reads Trump v. Slaughter out loud, and asks the Commission's agent to explain the difference between the two. There is no good answer, because there isn't one; the sentence is simply no longer true. The decision is annulled. And then we get a compliance cliff of a kind the first two did not produce, because the cloud dependency of 2029 is not the cloud dependency of 2015 — it is model training, inference, and the raw material of every AI system a European company touches.
Scenario three, the one I expect: both, in sequence. Years of managed ambiguity, then a sudden cliff, then a fourth bridge built in eleven panicked months and blessed by a fourth adequacy decision, resting on a fourth structural assumption about American institutions that holds until the next domestic constitutional ruling knocks it over from an angle nobody was watching.
And that should unsettle you regardless of which side of this you sit on. The EU-U.S. Data Privacy Framework was not undone by a privacy scandal, or a data breach, or a rogue intelligence program. It was undone — if it is undone — by a separation-of-powers case about whether a President can fire a commissioner. Nobody involved was thinking about you.
Now extend that. We are entering a decade in which AI systems are trained on data that crosses borders continuously, where model weights and inference logs and behavioral traces move at machine speed, and where the legal permission for all of it rests on documents like recital 60 — single sentences describing institutional arrangements that a domestic court in another country can vaporize on a Monday morning without mentioning the subject. There is no alert for that. There is no changelog. There is a letter, sometimes, a month later, if someone happens to read both documents.
What the smart people are saying
This is a genuinely contested question, so let me lay out the spread rather than stack a jury.
The regulators have moved, and moved carefully. Anu Talus, chairing the European Data Protection Board, did not declare anything invalid. She asked the Commission to check — and framed the ask in the Commission's own statutory language, which is how a regulator signals that this is not going away.
The challenger is unambiguous and impatient. Schrems's position is that this is structural, not political: a constitutional clash of laws that outlives any administration. He is also openly cynical about why nothing has happened — he told the IAPP that the Commission is not a legal, but a political body, and predicted it would keep the topic under the rug until the Court of Justice forced it back out. That is his characterization of other people's motives, and you should weigh it as such — but he has been right about the destination twice.
The transatlantic law-and-policy academics — Christakis, Propp and Swire — think the alarm is aimed at the wrong limb, and have the receipts to say so: they designed the argument for the redress mechanism before it existed, and they note that the General Court in the Latombe case did not rest the DPRC's independence on the formal source of its creation. Their caveat is as important as their conclusion: they explicitly leave the commercial-supervision question open.
The American constitutional right is not arguing about any of this, and that is exactly the point. Writing in the Manhattan Institute's City Journal, Ilya Shapiro called the 6-3 ruling not a gift to any President but a restoration of constitutional accountability — power traceable to someone voters can remove. Whatever you think of that, it is an argument about American democratic legitimacy that says nothing, and needs to say nothing, about a European adequacy decision. Shapiro also flags the sharpest line in the case, Justice Gorsuch's observation that the fourth branch's powers still exist; they have just been reassigned to the President. Reassigned — not abolished. For Europe's purposes, that is the whole problem in six words.
The civil-liberties side has been flagging the underlying fragility since well before this ruling. Writing for the Center for Democracy and Technology in February 2025, Silvia Lorenzo Perez documented that the Privacy and Civil Liberties Oversight Board — an institution the adequacy decision leans on for surveillance oversight — had lost its quorum, leaving it unable to function effectively with only one member remaining, and that the annual report Brussels relies on had gone on hold for an undetermined period of time. That was sixteen months before Slaughter. These are two separate wounds, arriving more than a year apart, in two different limbs of the same framework.
The practitioners are doing what practitioners do: hedging in writing. Skadden's note tells clients to consider reviewing their fallback arrangements should the adequacy decision be annulled in the future, and warns the ruling could increase the risk that European courts overturn it. Could. Nobody is predicting. Everybody is provisioning.
And business wants none of this. When the General Court upheld the framework in September 2025, the U.S. Under Secretary of Commerce for International Trade called the ruling a victory for the more than 3,400 U.S. companies that rely on transatlantic data flows to carry out their operations — a self-interested framing from a government that is itself a party to the appeal, but a real number attached to a real dependency. The U.S. Chamber of Commerce goes bigger, putting the relationship at worth about $7.1 trillion in a 2021 brief lobbying for exactly this framework. That figure is five years old and comes from an advocate, so treat it as an order of magnitude rather than a measurement. The order of magnitude is still the point.
What does this mean for you?
You are not going to fix transatlantic adequacy law. But you are downstream of it, and there are things worth knowing and a few worth doing.
Understand what is protecting you right now. If a US company holds your European data, your protection runs through promises that company made when it chose to self-certify to the Department of Commerce. Breaking them may violate Section 5 of the FTC Act's prohibition on unfair and deceptive acts (the may is the agency's own word). America polices this as a lie, not as a privacy violation. That distinction explains a great deal about how the two systems differ.
Check whether a company is even in the scheme. Commerce publishes a searchable list of participating businesses. Before you hand a European client's data to a vendor, look it up. Certification lapses; companies drop off. "We're Privacy Framework certified" is a claim you can verify in about forty seconds.
If you run or advise a business: write the fallback down now, not later. Standard contractual clauses and binding corporate rules still exist. The lawyers advising you to review fallback arrangements are not being alarmist — they are doing arithmetic on a decision that has been annulled twice before.
Stop treating "independent regulator" as a description and start treating it as a claim with a date on it. The sentence in recital 60 was true when it was written. It stopped being true on a Monday in June, and the document did not update itself. Any privacy assurance you are relying on has this property.
Watch three specific things, not the general noise. Whether the Commission answers the July 31 letter. Whether noyb converts its announcement into a filing. Whether anything moves in Case C-703/25 P. Those are the three tells; everything else is commentary.
Push for durability over diplomacy. Whatever your politics on presidential power, the lesson for anyone who cares about data rights is that a protection resting on an institutional arrangement in a foreign country is a protection with a fuse in it. Ask for rights that survive a change of court, a change of administration, and a change of continent. That is what the HAIA Foundation keeps arguing for, and this is a tidy demonstration of why.
The lesson, as I see it
Two courts have now ruled on the same word, and neither one knew it was talking to the other.
Luxembourg said, in 2010 and again in 2012, that a data protection regulator must be free from any external influence — the State's included — and it said so while striking down two of its own member states — one for subjecting its regulators to ordinary State scrutiny, the other for an office arrangement and a right to be briefed. Washington said, in 2026, that an agency exercising executive power must be controlled by the Chief Executive. Both opinions are internally coherent. Both are, in their own systems, defensible. And laid end to end they describe a bridge with no middle.
What strikes me is not that the two systems disagree. Of course they do; that is what different constitutional orders are for. What strikes me is that the disagreement was created silently, by a ruling that did not mention the subject, and that more than three months later the institution holding the pen has offered reassurance but no public answer to the regulators who asked.
I do not think Brussels is asleep. I think Brussels is doing the calculation it always does — legal exposure against political cost against a data relationship the business lobby measures in trillions — and concluding that the cheapest move is to wait for a court to force the issue, which is exactly what Schrems accuses it of. That may even be the responsible choice, given the cliff a sudden withdrawal would produce. But it is a choice, and it is being made on your behalf, about your data, without anyone telling you why.
The third bridge is still standing. The beam it rests on has been cut. Everyone with a hard hat has seen it, everyone is pointing at it, and nobody wants to be the one who says the word out loud — because the moment somebody does, a lot of very expensive traffic has to stop.
My vote? Say it out loud. Bridges that come down on a schedule hurt less than bridges that come down without warning.
Two courts, one word, and nobody told the bridge. Send this to whoever signed your company's cloud contract.






