A European Commission spokesperson confirmed this week that the Commission will assess whether a U.S. Supreme Court ruling on presidential power to remove FTC commissioners could undermine the legal basis more than 2,800 American companies rely on to move personal data out of the EU. The ruling, Trump v. Slaughter, never mentions privacy, the GDPR, or the Data Privacy Framework. It is about who can fire a Federal Trade Commissioner, and why that question now sits at the center of transatlantic data transfer law is a chain of dependency most companies using the DPF have never had reason to think about.
The short version: the DPF's 2023 adequacy decision leans on the FTC as an independent enforcement authority policing US companies' DPF commitments. If the FTC's independence is now legally in question, so, arguably, is one of the structural guarantees the European Commission relied on when it approved the framework. Nothing has been invalidated. But the uncertainty just went up, and it arrived at a moment when the DPF's other institutional backstop, the Privacy and Civil Liberties Oversight Board, has been unable to function for over a year.

Source: Hunton Andrews Kurth, Privacy and Cybersecurity Law Blog, captured August 2026.
What the Supreme Court actually ruled
Trump v. Slaughter addressed the president's authority to remove FTC commissioners, a domestic separation-of-powers question with no privacy content on its face. As reported by Bloomberg Law, a European Commission spokesperson has since said the Commission will evaluate whether the ruling affects the DPF's validity, precisely because the FTC's role as an independent enforcement body was part of what made the 2023 adequacy decision hold up. Weaken the case for FTC independence and you weaken one of the pillars the adequacy finding was built on, even without a single word of the ruling addressing data protection directly.
Privacy advocacy group NOYB moved quickly, arguing the ruling calls into question whether the FTC remains sufficiently independent for EU law purposes and formally asking the European Commission to withdraw the DPF adequacy decision. NOYB has also said it plans further litigation before the Court of Justice of the European Union. That litigation would not start from nothing: a separate appeal from French politician Philippe Latombe, filed with the CJEU in October 2025, is already pending and directly challenges the DPF's validity.
The 2,800+ companies caught in the middle
Figure: More than 2,800 US companies hold active Data Privacy Framework certifications, a base of transatlantic data transfer reliance built up since the framework's 2023 launch.
The Department of Commerce's International Trade Administration maintains the public Data Privacy Framework List, and more than 2,800 US organizations currently appear on it with active certifications. Each one is relying on the DPF as its legal basis to receive personal data transferred from the EU. None of those certifications has been suspended. The adequacy decision remains in force, and the European Commission has been explicit that, as with all adequacy findings, it continues to monitor whether EU standards are being met and will stay in close contact with the US administration. But "still valid today" and "durable through the next CJEU ruling" are different claims, and the gap between them is what has widened since late June.
Adding to that gap: the Privacy and Civil Liberties Oversight Board has lacked a quorum since January 2025, after three of its five members were removed. PCLOB's annual review of the DPF's privacy and intelligence-related complaint remedies is one of the oversight mechanisms the adequacy decision counted on, and it has been unable to proceed with no quorum to authorize it. A framework that depends on independent FTC enforcement and an active PCLOB review is now missing one of the two and facing a live legal question about the other.
This is the third time around
The DPF is not the first EU-US transfer framework to face a CJEU challenge, and its predecessors did not survive theirs. The Safe Harbor framework was struck down by the CJEU in 2015. Its successor, Privacy Shield, was struck down in 2020. The DPF was built in 2023 specifically to address the gaps Schrems II identified, and the European General Court dismissed an earlier challenge to it in September 2024. Latombe's pending CJEU appeal and NOYB's promised follow-on litigation are attempts at a third strike, and this time they have a genuinely new argument: a Supreme Court ruling on domestic separation of powers that the DPF's architects could not have anticipated when they wrote the adequacy decision around FTC independence.
None of this means the DPF is about to fall. The Commission's own position is that the adequacy decision stays in force unless and until a court invalidates it, and no court has done that. But the pattern from Safe Harbor and Privacy Shield is that when a transfer framework's underlying guarantees come under sustained legal pressure, the invalidation, when it comes, tends to arrive abruptly rather than on a predictable timeline. Companies that built their entire cross-border transfer program around DPF certification and nothing else learned that lesson the hard way twice already.
What an adequacy reversal would mean for your privacy policy
A privacy policy that names the DPF as its sole legal basis for EU-to-US transfers is describing a mechanism that could stop being valid with limited notice, based on precedent. That is not a reason to rewrite your policy today, since the DPF remains valid and switching mechanisms preemptively creates its own compliance overhead. It is a reason to make sure your policy's transfer-mechanism language does not lock you into a single point of failure, and that you have a documented fallback, typically Standard Contractual Clauses with supplementary measures, ready to reference if the adequacy decision is ever suspended or annulled.
Our Privacy Policy Generator lets you disclose your cross-border transfer mechanisms accurately, including DPF certification alongside any backup mechanism your business has in place, so your published policy reflects the actual legal basis you are relying on rather than a single framework that regulatory history suggests should never be a company's only option.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.