Trump v. Slaughter Just Put the EU-US Data Privacy Framework at Risk

What Changed on June 29 and What Counsel Must Do This Quarter
The legal foundation of your EU-to-US data transfers just cracked. On June 29, 2026, the Supreme Court ruled 6-3 in Trump v. Slaughter (No. 25-332) that the FTC Act's 'for cause' removal protections for FTC commissioners are unconstitutional, overruling Humphrey's Executor v. United States (1935) and holding that the President may remove FTC commissioners at will.
That holding is not just an administrative-law footnote. The FTC is the primary enforcement backstop for the EU-US Data Privacy Framework. If you rely on the DPF to move personal data across the Atlantic, you need to reassess that reliance this quarter — not after a court tells you to.
Here is the practitioner reality check. The DPF adequacy decision remains formally valid today. But the assumption underneath it — that an independent US regulator enforces framework commitments — has been legally reshaped. Prudent counsel treats the DPF as a mechanism under active threat, not a settled safe harbor.
The FTC Independence Problem the Commission Cannot Ignore
When the European Commission adopted the EU-US Data Privacy Framework adequacy decision on July 10, 2023, as Commission Implementing Decision EU 2023/1795, it leaned heavily on the FTC as an independent enforcer. That is the crux of the current fight.
On June 30, 2026 — one day after the ruling — NOYB, led by Max Schrems, sent a formal letter to the European Commission urging an 'orderly withdrawal' from the DPF adequacy decision. As reported by Privado, NOYB argues that the FTC is referenced 259 times in the adequacy decision as an independent enforcer, and that this independence has now been constitutionally eliminated.
The timeline that produced this moment is worth stating plainly:
- President Trump fired Commissioners Slaughter and Bedoya on March 18, 2025, without citing statutory cause.
- The D.C. district court reinstated Slaughter on July 17, 2025, holding she could be removed only for 'inefficiency, neglect of duty, or malfeasance in office' under 15 U.S.C. § 41.
- The Supreme Court reversed that reasoning on June 29, 2026.
Separately, on January 27, 2025, President Trump fired three of the five members of the PCLOB by one-sentence email, eliminating its quorum. Its annual DPF oversight reviews were suspended. The independent-oversight architecture the Commission relied on is now degraded on two fronts at once.
Cross-Border Arbitrage: Why 'Wait and See' Is the Wrong Posture
The transfer mechanism you chose is a risk allocation, not a formality
Companies that treated the DPF certification as a one-time compliance box are now exposed to a cross-border arbitrage problem. Different transfer mechanisms carry different legal durability, and the DPF is the mechanism most directly threatened by Trump v. Slaughter.
The litigation environment is already crowded. On September 3, 2025, the EU General Court dismissed Philippe Latombe's challenge in Case T-553/23, but Latombe appealed to the Court of Justice of the EU on October 31, 2025, registered as Case C-703/25 P and pending with no hearing date. NOYB has separately announced plans to file a challenge that commentators call 'Schrems III.'
Reality check for non-privacy lawyers: two prior adequacy frameworks — Safe Harbor and Privacy Shield — were struck down by the CJEU. Betting the entire transatlantic data flow on the DPF surviving a third challenge, with the independence argument now stronger than before, is not a defensible risk position. As IAPP reports, FTC independence and the DPF both face potential challenges after Slaughter.
Note the limits of what is known. The European Commission has not issued a verified formal response to NOYB's letter, and NOYB has not confirmed a CJEU filing date. Plan against the threat; do not overstate its current procedural posture.
Action Items: Rebuild Transfer Resilience Before a Ruling Forces It
Do this now, in a defined sequence
- Inventory every EU-to-US data flow that relies on the DPF. You cannot govern what you have not mapped. Identify which flows carry the DPF as their sole legal basis and which already have a fallback.
- Put Standard Contractual Clauses back on the table as primary, not backup. For DPF-only flows, execute or re-paper SCCs with a completed transfer impact assessment. Do not wait for a decision to invalidate the framework before you draft.
- Refresh your transfer impact assessments to address the independence question directly. The FTC-enforcement assumption is now contestable. Document how you assess US enforcement and redress in light of the Slaughter holding.
- Review vendor and processor contracts. Any downstream recipient relying on your DPF certification inherits the same fragility. Confirm each sub-processor has a durable transfer mechanism, not a cross-reference to your DPF status.
- Monitor Case C-703/25 P and any Schrems III filing. Assign an owner. Set a standing review so a CJEU hearing announcement triggers your contingency plan rather than a scramble.
The common mistake here is treating SCCs and the DPF as interchangeable checkboxes. They are not. SCCs require ongoing diligence and documented assessment; a lapsed DPF certification with no SCC fallback leaves a flow with no lawful basis the day an adequacy decision falls.
Key Takeaways
- The DPF is valid today but structurally exposed. Trump v. Slaughter overruled Humphrey's Executor and removed the 'for cause' protection that underpinned the FTC's status as an independent DPF enforcer.
- NOYB moved within 24 hours. The June 30, 2026 letter urging 'orderly withdrawal' cites the FTC's 259 references in the adequacy decision as proof the independence premise has collapsed.
- Two frameworks already fell. Safe Harbor and Privacy Shield were both invalidated by the CJEU; a DPF-only transfer strategy ignores that pattern and the pending Case C-703/25 P appeal.
- PCLOB oversight is degraded too. The January 27, 2025 quorum loss suspended annual DPF reviews, weakening a second pillar the Commission relied on.
- SCCs are the resilience play. Re-papering DPF-only flows with SCCs and refreshed transfer impact assessments is the concrete hedge available now.
How FinTech Law Helps You Get Ahead of Schrems III
FinTech Law helps companies operationalize cross-border transfer strategy before a ruling forces the issue — from DPF-to-SCC fallback mapping to transfer impact assessments that address the FTC independence question head-on. The firm works where product, legal, and security teams actually meet: data maps, vendor diligence, and audit trails a supervisory authority expects to see on day one of an inquiry.
If your EU-to-US flows rely on the DPF as their sole legal basis, now is the quarter to build the fallback. Start at fintechlaw.ai or contact the team to scope a transfer-resilience review.
This post is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship. Consult qualified counsel about your specific facts and obligations.