A New Schrems III? This Time, It Comes From Across the Atlantic
The US Supreme Court's Trump v. Slaughter ruling knocked out the constitutional footing under the EU–US Data Privacy Framework's core assumption — independent US oversight. What it means for DACH CISOs and DPOs, and what to do this quarter.
Published on July 6, 2026
On 29 June 2026, the US Supreme Court decided a case that, on its face, has nothing to do with data protection. In Trump v. Slaughter, a 6–3 majority held that the statutory protection shielding Federal Trade Commission members from removal without cause is unconstitutional — largely abandoning Humphrey’s Executor, the 1935 precedent that made independent agencies possible in the first place1. The reasoning is the “unitary executive” theory: all executive power belongs to the President, so anyone exercising it must be removable by him at will2. For Washington, this is a separation-of-powers story. For Brussels — and for every European company with data in a US cloud — it is something else: the European Commission’s adequacy decision for the EU–US Data Privacy Framework relies on the FTC as an independent enforcer 259 times — a count made by noyb, covering every reference in the decision3. The load-bearing assumption of the FTC’s institutional independence has just lost its constitutional footing.
To see why this one ruling lands so hard, you have to see the whole road that led to it. This is not a new argument. It is the third round of a fight that began in 2000 — and every previous round ended the same way.
Key Takeaways
- The ruling is real and broad. Trump v. Slaughter (No. 25-332, decided 29 June 2026) declares the FTC’s for-cause removal protections unconstitutional and largely abandons Humphrey’s Executor — with read-across to roughly two dozen multi-member agencies designed to be independent4, 5.
- The pattern is twenty-six years old. Safe Harbour (2000) fell in Schrems I (2015); Privacy Shield (2016) fell in Schrems II (2020); the DPF (2023) is built on the same structural assumptions — and the US institutional facts it relies on have been changing since January 20256, 7.
- Independence is not decoration in EU law — it is a treaty requirement. Article 16(2) TFEU and Article 8(3) of the Charter require independent oversight of data protection; a third country must offer essentially equivalent protection to receive an adequacy decision8.
- The DPF’s redress layer was always executive, not judicial. The Data Protection Review Court (DPRC) is a body inside the US Department of Justice created by Executive Order 14086 — amendable or revocable by a later executive order; the PCLOB has lacked a quorum since January 20259, 10.
- Nothing is invalid today. The adequacy decision remains in force until the Commission repeals it or the CJEU annuls it. noyb has formally asked the Commission for an orderly withdrawal and announced a fresh lawsuit; the Latombe appeal has been pending at the CJEU since October 202511, 12.
- SCCs are not a clean escape hatch. A Transfer Impact Assessment that cites the independence of the DPRC or PCLOB now describes a legal architecture that no longer exists as written. TIAs need updating regardless of which transfer tool you use13.
Twenty-six years of the same argument: 2000–2026
Every EU–US data deal has been a wager that American oversight structures could satisfy a European constitutional requirement. The wager has now been tested three times.
| Date | Event |
|---|---|
| 26 Jul 2000 | Safe Harbour: the Commission’s first US adequacy decision (2000/520/EC) |
| Jun 2013 | Snowden disclosures put US mass surveillance on the record |
| 6 Oct 2015 | Schrems I (C-362/14): CJEU annuls Safe Harbour |
| 12 Jul 2016 | Privacy Shield: the second adequacy decision |
| 16 Jul 2020 | Schrems II (C-311/18): CJEU annuls Privacy Shield — surveillance law plus the lack of independent, binding redress |
| 7 Oct 2022 | Executive Order 14086 creates the CLPO and the Data Protection Review Court — by presidential order, not by statute |
| 10 Jul 2023 | Data Privacy Framework: the third adequacy decision (Implementing Decision (EU) 2023/1795), leaning on the FTC 259 times |
| Jan 2025 | The PCLOB loses its quorum after the removal of its Democratic members |
| Mar 2025 | Trump fires FTC commissioners Rebecca Slaughter and Alvaro Bedoya without statutory cause; they sue on 27 March |
| 17 Jul 2025 | DC district court: the removal was unlawful; Slaughter is reinstated |
| 3 Sep 2025 | EU General Court dismisses the Latombe annulment action — the DPF survives first instance |
| Sep 2025 | Supreme Court stays the reinstatement and takes the case before the appeals court can rule (certiorari before judgment) |
| 31 Oct 2025 | Latombe appeal lodged at the CJEU — redress and surveillance safeguards squarely attacked |
| 8 Dec 2025 | Oral argument in Trump v. Slaughter |
| 29 Jun 2026 | 6–3 decision: for-cause removal protection unconstitutional; Humphrey’s Executor largely abandoned. Same day: noyb formally asks the Commission to withdraw the adequacy decision and announces a lawsuit |
Read as a sequence, January 2025 to June 2026 records a step-by-step change — first through personnel decisions, then through a constitutional ruling — in exactly the oversight layer the adequacy decision describes. For the legal assessment, motive is beside the point. What matters is narrower and harder: the institutional facts on which the 2023 decision was based are no longer the institutional facts of 2026.
What the Supreme Court actually decided
The facts are simple. In March 2025, early in his second term, President Trump fired the FTC’s two Democratic commissioners, Rebecca Slaughter and Alvaro Bedoya, without citing any of the statutory grounds — “inefficiency, neglect of duty, or malfeasance in office” — that federal law required14. Slaughter sued on 27 March and won at first instance: on 17 July 2025 the district court called the removal ultra vires and reinstated her15. The Supreme Court stayed that order in September, took the case before the appeals court ruled, heard argument on 8 December 2025, and on 29 June 2026 held that the for-cause protection itself violates the Constitution’s separation of powers. Whoever exercises executive power must answer to the President — and be removable by him, at will16.
Three features make the decision bigger than one agency. First, the Court did not distinguish Humphrey’s Executor away; it abandoned it in substance, removing the constitutional foundation under every similarly structured body17. Second, the logic is categorical: it attaches to the function (exercising executive power), not to the FTC specifically. US commentary counts roughly two dozen multi-member federal agencies affected18. Third — and most relevant for the European analysis — the Court drew one exception: in the parallel case over Federal Reserve Governor Lisa Cook, it held the President could not remove a Fed governor at will, treating the central bank as a distinct constitutional case19. The legal consequence for Europeans is precise: the protected category is narrow — and the essential institutional guarantees of the DPF are modelled on the FTC, not on the constitutionally distinct position of the Federal Reserve. Whatever one thinks of the ruling, that classification is now the law of the destination country an adequacy assessment has to describe.
Why this is a Brussels problem
The GDPR’s third-country regime runs on one concept: essential equivalence. A third country does not need identical rules to receive an adequacy decision, but it must offer protection essentially equivalent to EU law — and EU law makes independent supervision a constitutional-grade requirement. Article 16(2) TFEU and Article 8(3) of the Charter of Fundamental Rights both demand that compliance with data protection rules be subject to control by an independent authority20. That is why Schrems II did not fail Privacy Shield on paperwork: it failed it on institutions — surveillance without proportionality, and an “Ombudsperson” that was neither independent nor empowered to bind the intelligence services21. And this requirement is not a policy preference: the Commission cannot bargain below it in a fourth framework — on the prevailing view, changing these constitutional requirements would take an amendment of EU primary law22. The EU side of the equation is fixed; whether it is satisfied can only be determined by the state of US law — and the underlying institutional facts changed on 29 June 2026.
The 2023 adequacy decision was the answer to that ruling, and in the field of commercial enforcement it relies chiefly on the FTC — referenced 259 times23. On the government-surveillance side, it relies on the redress mechanism created by Executive Order 14086 on 7 October 2022: the Civil Liberties Protection Officer within the intelligence community, and above it the Data Protection Review Court. The DPRC, despite its name, is not an Article III court. It sits inside the Department of Justice, and its independence exists by grace of the same executive order that created it — an instrument that can be amended or revoked by a later executive order24. The Privacy and Civil Liberties Oversight Board, the third oversight pillar, lost its quorum in January 2025 when its Democratic members were removed — a fact already on the record months before the FTC litigation began25.
Put the pieces together and the question inevitably arises. If for-cause protection for FTC commissioners is unconstitutional because the President must control everyone exercising executive power, on what basis would the CLPO or the DPRC — pure creatures of the executive — be more independent? The Supreme Court did not decide anything about the DPF. It decided something underneath the DPF.
The Schrems III scenario — and its actual timeline
The reaction was immediate. On the day of the ruling, noyb sent a formal letter to the European Commission calling for an orderly withdrawal of the adequacy decision and announced a lawsuit aimed at putting the DPF before the CJEU26. Max Schrems’ framing — “the entire structure of the EU-US Data Privacy Framework has just collapsed” — is advocacy, but the underlying argument no longer requires much construction: the CJEU annulled Safe Harbour in 2015 and Privacy Shield in 2020 on records of institutional inadequacy that, in the view of many observers, went less far than today’s27.
There is also already a vehicle in motion. French MP Philippe Latombe’s annulment action was dismissed by the General Court on 3 September 2025 — a ruling that upheld the DPF as the facts stood that day — but his appeal has been pending before the CJEU since 31 October 2025, attacking precisely the adequacy of redress and surveillance safeguards28. The CJEU has historically been stricter than the General Court on US surveillance questions; it is the court that killed both predecessor frameworks. Every fact in the table above that post-dates 3 September 2025 is a fact the General Court never weighed. Trump v. Slaughter hands the appellant a record no adequacy defender wanted to brief.
And yet: none of this is fast. A CJEU annulment procedure typically runs two to three years29. The Commission has not signalled withdrawal. The adequacy decision is valid law today, and transfers made under it remain lawful until it falls. Panic is not a compliance strategy — but neither is pretending the ground has not shifted.
It also helps to be precise about what would not fall even in the worst case. The GDPR regulates personal data only — non-personal data keeps flowing regardless. And Article 49 GDPR permits genuinely necessary transfers to any third country: the hotel booking, the contract with a US counterparty, the individual transaction. What Article 49 does not permit is what most organisations actually do — the structural, wholesale offshoring of EU personal data into US processing environments as a matter of architecture rather than necessity30. That is the exposure to measure, and it is exactly the line a Schrems III ruling would draw.
The uncomfortable detail: your SCCs feel it too
The reflex answer — “we’ll just switch to Standard Contractual Clauses” — deserves a closer look. SCCs after Schrems II come with homework: a Transfer Impact Assessment evaluating whether the destination country’s law lets the importer actually honour the clauses. For the US, TIAs written since 2023 almost universally cite the EO 14086 architecture — CLPO, DPRC, PCLOB oversight — as the reason government-access risk is acceptable31. After January 2025 (PCLOB) and June 2026 (Slaughter), a TIA that leans on the independence of those bodies describes a world that no longer exists as written. noyb draws the maximalist conclusion that such assessments must now “logically come to the conclusion that data transfers are not legal anymore”32; the pragmatic reading is narrower — the assessments must be redone, honestly, with the new facts. Either way, a TIA built on those earlier institutional assumptions should be reviewed and updated where necessary.
This is the same lesson we keep meeting in different costumes: a signed document is not a control. A DPA does not process data lawfully by existing (The DPA Is a Promise, Not a Control), and an adequacy decision does not protect data by existing either. What protects data is architecture — which is why the most durable answer to this entire news cycle is technical, not contractual: if a US authority compels your provider, the question that decides the outcome is where the key lives (Where Is the Key?).
What a DACH CISO/DPO should actually do this quarter
First, know your exposure. Produce a current inventory of transfers that rest on the DPF — directly, or indirectly via processors and sub-processors whose certifications you accepted. For most organisations the honest answer includes the hyperscaler stack, the productivity suite, and half the SaaS estate (The Microsoft 365 Dilemma).
Second, dual-track your critical transfers. For transfers you cannot afford to lose, put SCCs in place alongside the DPF now — including an updated TIA, since SCCs too only hold with a defensible transfer assessment — so a future annulment is a paperwork event rather than an operational one. That was the difference in July 2020 between companies that shrugged off Schrems II and companies that spent a year in legal triage.
Third, refresh the TIA honestly. Update transfer assessments to reflect Slaughter, the PCLOB’s condition, and the executive-order nature of the DPRC. If the assessment still concludes “acceptable,” it should do so because of supplementary measures you control — encryption with customer-held keys, pseudonymisation before transfer, EU-boundary processing — not because of US institutional promises.
Fourth, treat sovereignty as a roadmap item, not a slogan. Several member states have announced moves to decouple from US service providers, and some US providers are responding with separate EU data-processing offerings33. You do not need to exit the US cloud this quarter. You need a written answer to the question your board will ask when Schrems III headlines arrive: “what is our plan if adequacy falls?”
Safe Harbour lasted fifteen years. Privacy Shield lasted four. The DPF’s central assumption was substantially weakened by the US Supreme Court before the framework turned three. The trend line is not subtle.
The DPF survived Latombe at first instance and remains valid law. But its central assumption — that the EU can rely on independent oversight inside the US executive branch — has now been called seriously into question by the highest court of the country making the promise. Whether the framework falls in Luxembourg in two years or is quietly renegotiated first, the organisations that will not care either way are the ones whose transfer stack never depended on the promise in the first place. Is yours one of them?
-
Trump v. Slaughter, No. 25-332, 609 U.S. ___ (2026), argued 8 December 2025, decided 29 June 2026 (6–3). Slip opinion: https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf . The statutory ground was 15 U.S.C. §41 (“inefficiency, neglect of duty, or malfeasance in office”). ↩
-
The unitary-executive reasoning: “a subordinate who exercises the President’s power is subject to removal by him”, and Congress may not condition that removal on cause. See SCOTUSblog, Court allows Trump to fire FTC commissioner and overturns major restraint on presidential power, 29 June 2026: https://www.scotusblog.com/2026/06/court-allows-trump-to-fire-ftc-commissioner-and-overturns-major-restraint-on-presidential-power/ ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
Trump v. Slaughter, No. 25-332, 609 U.S. ___ (2026), argued 8 December 2025, decided 29 June 2026 (6–3). Slip opinion: https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf . The statutory ground was 15 U.S.C. §41 (“inefficiency, neglect of duty, or malfeasance in office”). ↩
-
On the overturning of Humphrey’s Executor v. United States, 295 U.S. 602 (1935), and the read-across to roughly two dozen multi-member agencies: NPR, Supreme Court cements Trump’s power over agencies long considered independent, 29 June 2026: https://www.npr.org/2026/06/29/nx-s1-5816232/supreme-court-ftc-independent-agencies-humphreys-executor ; The Hill, 29 June 2026: https://thehill.com/regulation/court-battles/5935135-supreme-court-trump-independent-agencies-firing-protections/ ↩
-
Safe Harbour: Commission Decision 2000/520/EC of 26 July 2000, annulled by CJEU, C-362/14 (Schrems I), judgment of 6 October 2015; Privacy Shield: adequacy decision of 12 July 2016, annulled by CJEU, C-311/18 (Schrems II), judgment of 16 July 2020. Chronology summarised in the noyb statement (fn. 3). ↩
-
Executive Order 14086 of 7 October 2022; the Data Protection Review Court was established under it within the US Department of Justice: https://www.justice.gov/opcl/redress-data-protection-review-court ; https://www.justice.gov/opcl/executive-order-14086 ↩
-
Article 16(2) TFEU: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12016E/TXT ; Article 8(3) of the Charter of Fundamental Rights: https://eur-lex.europa.eu/eli/treaty/char_2012/oj/eng . The essential-equivalence standard: CJEU, C-311/18 (Schrems II). ↩
-
Executive Order 14086 of 7 October 2022; the Data Protection Review Court was established under it within the US Department of Justice: https://www.justice.gov/opcl/redress-data-protection-review-court ; https://www.justice.gov/opcl/executive-order-14086 ↩
-
noyb, US Cloud soon illegal? Trump punches first hole in EU-US Data Deal (PCLOB members removed, board paralysed), 23 January 2025: https://noyb.eu/en/us-cloud-soon-illegal-trump-punches-first-hole-eu-us-data-deal ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
General Court, judgment of 3 September 2025 dismissing the Latombe action (press release): https://curia.europa.eu/site/upload/docs/application/pdf/2025-09/cp250106en.pdf ; on the appeal lodged 31 October 2025 and pending before the CJEU: WilmerHale, European Court of Justice to Review Challenge to EU-U.S. Data Privacy Framework, 1 December 2025: https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
Trump v. Slaughter, No. 25-332, 609 U.S. ___ (2026), argued 8 December 2025, decided 29 June 2026 (6–3). Slip opinion: https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf . The statutory ground was 15 U.S.C. §41 (“inefficiency, neglect of duty, or malfeasance in office”). ↩
-
Procedural history (firings March 2025; suit filed 27 March 2025; district court summary judgment and reinstatement 17 July 2025; Supreme Court stay and certiorari before judgment September 2025): Trump v. Slaughter, Justia case page: https://supreme.justia.com/cases/federal/us/609/25-332/ ; Constitutional Accountability Center case tracker: https://www.theusconstitution.org/litigation/slaughter-v-trump/ ↩
-
The unitary-executive reasoning: “a subordinate who exercises the President’s power is subject to removal by him”, and Congress may not condition that removal on cause. See SCOTUSblog, Court allows Trump to fire FTC commissioner and overturns major restraint on presidential power, 29 June 2026: https://www.scotusblog.com/2026/06/court-allows-trump-to-fire-ftc-commissioner-and-overturns-major-restraint-on-presidential-power/ ↩
-
On the overturning of Humphrey’s Executor v. United States, 295 U.S. 602 (1935), and the read-across to roughly two dozen multi-member agencies: NPR, Supreme Court cements Trump’s power over agencies long considered independent, 29 June 2026: https://www.npr.org/2026/06/29/nx-s1-5816232/supreme-court-ftc-independent-agencies-humphreys-executor ; The Hill, 29 June 2026: https://thehill.com/regulation/court-battles/5935135-supreme-court-trump-independent-agencies-firing-protections/ ↩
-
On the overturning of Humphrey’s Executor v. United States, 295 U.S. 602 (1935), and the read-across to roughly two dozen multi-member agencies: NPR, Supreme Court cements Trump’s power over agencies long considered independent, 29 June 2026: https://www.npr.org/2026/06/29/nx-s1-5816232/supreme-court-ftc-independent-agencies-humphreys-executor ; The Hill, 29 June 2026: https://thehill.com/regulation/court-battles/5935135-supreme-court-trump-independent-agencies-firing-protections/ ↩
-
On the Federal Reserve exception (Governor Lisa Cook not removable at will, decided alongside the expansion of removal power over other agencies): NBC News, Supreme Court rules Trump can’t fire Fed member Lisa Cook, grants him more power over other independent agencies: https://www.nbcnews.com/politics/supreme-court/supreme-court-rules-trump-cannot-fire-fed-member-lisa-cook-grants-powe-rcna234931 ↩
-
Article 16(2) TFEU: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12016E/TXT ; Article 8(3) of the Charter of Fundamental Rights: https://eur-lex.europa.eu/eli/treaty/char_2012/oj/eng . The essential-equivalence standard: CJEU, C-311/18 (Schrems II). ↩
-
Safe Harbour: Commission Decision 2000/520/EC of 26 July 2000, annulled by CJEU, C-362/14 (Schrems I), judgment of 6 October 2015; Privacy Shield: adequacy decision of 12 July 2016, annulled by CJEU, C-311/18 (Schrems II), judgment of 16 July 2020. Chronology summarised in the noyb statement (fn. 3). ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
Executive Order 14086 of 7 October 2022; the Data Protection Review Court was established under it within the US Department of Justice: https://www.justice.gov/opcl/redress-data-protection-review-court ; https://www.justice.gov/opcl/executive-order-14086 ↩
-
noyb, US Cloud soon illegal? Trump punches first hole in EU-US Data Deal (PCLOB members removed, board paralysed), 23 January 2025: https://noyb.eu/en/us-cloud-soon-illegal-trump-punches-first-hole-eu-us-data-deal ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
Safe Harbour: Commission Decision 2000/520/EC of 26 July 2000, annulled by CJEU, C-362/14 (Schrems I), judgment of 6 October 2015; Privacy Shield: adequacy decision of 12 July 2016, annulled by CJEU, C-311/18 (Schrems II), judgment of 16 July 2020. Chronology summarised in the noyb statement (fn. 3). ↩
-
General Court, judgment of 3 September 2025 dismissing the Latombe action (press release): https://curia.europa.eu/site/upload/docs/application/pdf/2025-09/cp250106en.pdf ; on the appeal lodged 31 October 2025 and pending before the CJEU: WilmerHale, European Court of Justice to Review Challenge to EU-U.S. Data Privacy Framework, 1 December 2025: https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩
-
noyb, US Supreme Court just blew up EU-US Data Transfers, 29 June 2026: https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers — including the count of 259 FTC references in Commission Implementing Decision (EU) 2023/1795 ( https://eur-lex.europa.eu/eli/dec_impl/2023/1795/oj/eng ), the formal letter to the Commission, the announced lawsuit, the 2–3 year CJEU timeline, and the position on SCC/BCR impact assessments. ↩