EDPB asks Commission to review EU-US Data Privacy Framework
On July 31, 2026, the European Data Protection Board (EDPB) sent a letter to the European Commission about the U.S. Supreme Court judgment in Trump v. Slaughter (June 29, 2026). The Board asked the Commission to closely assess what the ruling means for Commission Implementing Decision (EU) 2023/1795, the adequacy decision that underpins the EU-US Data Privacy Framework (DPF).
The adequacy decision remains in force. The EDPB letter is a request for review, not a suspension of transfers.
Why the Board is concerned
Adequacy under the General Data Protection Regulation (GDPR) looks at whether a third country offers essentially equivalent protection, including effective and independent supervisory authorities. The 2023 Commission decision that supports the DPF relied, in part, on Federal Trade Commission (FTC) commissioner protections that limited presidential removal to for-cause grounds.
Trump v. Slaughter addresses presidential removal power over FTC commissioners. The EDPB letter highlights that independence of oversight bodies is a key element in adequacy assessments under Article 45(2)(b) GDPR, and asks the Commission to examine whether the judgment affects the functioning of the DPF decision.
What this means for transfer programs
For now, organizations can still rely on the DPF if they are certified and meet its requirements. Other GDPR Chapter V tools (standard contractual clauses, binding corporate rules, and narrow derogations) remain available.
Practical risk is timeline and dependency risk: if the Commission later revises or withdraws adequacy, teams that treated DPF as their only bridge will need a fallback already documented.
What to do now
- Inventory EU-to-US personal data flows and note which ones depend on DPF certification versus standard contractual clauses (SCCs) or binding corporate rules (BCRs).
- Keep DPF certifications current (annual re-certification, complaint handling, and public commitments) while the Commission reviews.
- Confirm SCC transfer impact assessments and vendor contract language still work as a backup path.
- See the GDPR page for how transfers fit into the wider program, and follow GDPR on this site for any Commission response.