The European Data Protection Board wrote to the European Commission on 31 July asking it to closely assess whether a US Supreme Court ruling on the removal of Federal Trade Commission commissioners affects the continued validity of the EU-US Data Privacy Framework, the adequacy decision that underpins most transatlantic transfers of personal data. The letter, signed by EDPB chair Anu Talus and addressed to Justice Commissioner Michael McGrath, followed a discussion among all EU data protection authorities at the Board’s June plenary.
Nothing has been suspended. Nothing has been invalidated. The DPF remains fully in force, and transfers made under it remain lawful today. What the letter does is put the question formally on the Commission’s desk.
The ruling behind the letter
On 29 June the US Supreme Court decided Trump v. Slaughter, holding by six votes to three that statutory protections shielding FTC commissioners from removal by the president are unconstitutional. The ruling overturned Humphrey’s Executor, a precedent that had stood since 1935, and confirmed that commissioners now serve at the president’s pleasure. The case arose from the removal of commissioners Rebecca Slaughter and Alvaro Bedoya in early 2025.
The relevance to European data law is direct. When the Commission granted the US adequacy in July 2023, the FTC’s role as an independent enforcer of DPF commitments was part of the assessment. The EDPB’s letter restates the principle: the existence and effective functioning of independent supervisory authorities in a third country is one of the key elements in judging whether that country provides adequate protection. If FTC commissioners can be removed at will, the question is whether that element still holds.
The EDPB is not the only party pressing it. Privacy group noyb wrote to the Commission the day after the ruling arguing that no other US authority can fill the gap, and the Latombe challenge to the DPF is on appeal before the Court of Justice of the EU. A Commission spokesperson said in early July that it would assess the ruling’s implications. Under the 2023 decision, the Commission is obliged to monitor US legal developments continuously, and it can open a procedure to suspend, amend or repeal the adequacy finding if it concludes the conditions are no longer met.
What this means for email operations
Most EU organisations sending email touch this framework somewhere. US-based ESPs, CRMs, CDPs, verification services and analytics providers commonly appear on DPF certification lists, and many data processing agreements name the DPF as the transfer mechanism.
The sensible response is not alarm but an audit. Three questions cover it. First, which of your US vendors do you transfer personal data to, and under what mechanism? The answer is in each vendor’s data processing agreement, not in marketing pages. Second, for any transfer resting solely on the vendor’s DPF certification, does the agreement contain a fallback? Many DPAs already provide that Standard Contractual Clauses apply automatically if the DPF ceases to be valid; some do not. Third, where SCCs are the fallback, is your transfer impact assessment documentation ready, or would you be starting from scratch under time pressure?
Organisations that ran this exercise when Privacy Shield fell in 2020 will recognise the shape of it. The difference this time is the warning period. Schrems II arrived as a judgment with immediate effect. The current situation is a formal request for review, with a Commission assessment, a possible procedure, and a pending court case all standing between today and any change in the law. That is time to prepare, and the preparation is straightforward.
The moments to watch are any Commission response to the letter, any announced review of the adequacy decision, and developments in the Latombe appeal. We will report each as it lands.








