Trump v. Slaughter Just Broke the FTC's Independence Shield — Here's What That Does (and Doesn't) Do to Your EU-US Data Transfers
The EU-US Data Privacy Framework is fully valid today. If you certify under it, or you rely on a US vendor that does, your transfers are lawful right now — nothing has been suspended, withdrawn, or annulled. Keep that sentence in mind, because most of the coverage from the last seven weeks reads like the opposite is already true.
On June 29, 2026, the US Supreme Court decided Trump v. Slaughter, stripping Federal Trade Commission commissioners of the "for-cause" removal protection they'd held since 1935. Within 24 hours, noyb — Max Schrems' organization, the one that killed Safe Harbor and Privacy Shield — sent the European Commission a letter demanding an "orderly withdrawal" from the Data Privacy Framework (DPF). A month later, the European Data Protection Board sent its own letter asking the Commission to look into it. And sitting quietly in the background, filed back in October 2025 and barely mentioned in any of this summer's coverage, is a real, docketed CJEU appeal — Case C-703/25 P — that's been working through the system for ten months already.
This post pulls those threads apart: what the Supreme Court actually held, what the EU's own institutions are actually asking for (which is narrower than noyb's ask), why the legal mechanics mean some of your transfers are more exposed than others, and what to do about it before a headline forces you into it.
What the Supreme Court actually decided
Trump v. Slaughter (Docket No. 25-332) is a 6-3 decision, decided June 29, 2026, that explicitly overrules Humphrey's Executor v. United States, 295 U.S. 602 (1935) — the nine-decade-old precedent that let Congress shield FTC commissioners from at-will presidential removal. The Court's own language, quoted directly in the European Data Protection Board's subsequent letter to the Commission: the FTC "has accumulated vast rulemaking, enforcement and adjudicatory powers" and "unquestionably exercises executive power, and must therefore be controlled by the Chief Executive, in whom such power is vested." The practical result: the President can now remove FTC commissioners without citing "inefficiency, neglect of duty, or malfeasance in office" — the old statutory standard is gone.
A companion case, Trump v. Cook, decided the same term, preserved removal protections for Federal Reserve Board governors as a narrow carve-out (the Court treated the Fed's role in monetary policy as different in kind from an ordinary executive agency). That detail matters for one reason: it shows the Court drew a line rather than blowing up every independent-agency structure at once. The FTC fell on the wrong side of that line. That's the entire holding — a US constitutional separation-of-powers ruling about who can fire whom. It says nothing about the EU, GDPR, or data transfers. What connects it to your compliance obligations is a specific number: the Commission's own adequacy decision text.
Why an FTC removal case touches your GDPR compliance at all
Adequacy decisions under GDPR Article 45 — the legal basis for transferring personal data to a non-EU country without extra safeguards — require the European Commission to assess, among other things, whether the destination country has "one or more independent supervisory authorities" with real enforcement power (Article 45(2)(b)). Commission Implementing Decision (EU) 2023/1795, the actual adequacy decision underlying the DPF, leans on the FTC as that independent enforcer for the commercial side of the framework — the "Principles" that participating US companies self-certify to. The decision's own text (paragraphs 58-60) specifically cites the statutory for-cause removal protection as evidence of the FTC's independence.
That's the paragraph Trump v. Slaughter just deleted the underlying fact of.
The EDPB's letter to the Commission, dated July 31, 2026 and addressed to Commissioner Michael McGrath, is worth reading in exactly the terms it uses — because it's more restrained than most of the press coverage suggests. EDPB Chair Anu Talus writes that the Board "asks the European Commission to closely assess whether this development affects the functioning of Commission Implementing Decision EU 2023/1795 and would welcome relevant actions, including the continued sharing of information with the EDPB in a timely manner." That's a request for an assessment and better communication — not a demand for suspension, and not a finding that adequacy has already lapsed. If your compliance team has seen headlines conflating the EDPB letter with a call to abandon the DPF, that's a misreading of the primary document.
noyb's letter, sent the day after the ruling and dated June 30, 2026, goes considerably further: it calls on the Commission to "orderly withdraw the adequacy decision on the US," and it points out that the Commission's own adequacy decision references the FTC's independence 259 times. noyb also announced it would file an annulment action at the CJEU "in the coming weeks."
As of this writing, that lawsuit has not been filed. Seven-plus weeks have passed since the "coming weeks" promise. This is worth tracking as an open item, not treating as done — a filed CJEU annulment action is a materially different risk signal than an announced intention to file one.
The distinction almost nobody in the coverage is making
Here's the part that actually matters for how worried you should be: the DPF has two structurally separate pillars, and Trump v. Slaughter doesn't hit them the same way.
Pillar 1 — commercial enforcement. US companies self-certify to the DPF Principles (things like purpose limitation, data integrity, accountability for onward transfers) and the FTC enforces those commitments against companies that violate them. This is the pillar the FTC's independence directly underpins, and it's the pillar Trump v. Slaughter genuinely destabilizes — an FTC that answers to presidential removal at will is a materially different enforcement backstop than the one the Commission assessed in 2023.
Pillar 2 — government access and redress. This is the pillar that actually killed Safe Harbor and Privacy Shield: whether EU citizens whose data lands in US government surveillance systems (FISA 702, EO 12333) have a meaningful remedy. That remedy runs through the Data Protection Review Court (DPRC), created by Executive Order 14086 — not through the FTC. Legal analysis published after the ruling (IAPP) points to two reasons this pillar is less directly exposed: first, Trump v. Slaughter's holding is specifically about Congressional limits on presidential removal power, and the DPRC's independence instead rests on constraints the executive branch imposed on itself through EO 14086 and DOJ regulation — a different legal category the Nixon-era principle ("the executive is bound by the rules it makes for itself, for as long as those rules remain in force") leaves untouched. Second, DPRC judges may qualify as "inferior officers," a category of removal protection the Court's opinion expressly reserved from its holding (citing Morrison v. Olson and United States v. Perkins).
Translating that into a compliance-relevant fact: if you rely on Standard Contractual Clauses (GDPR Article 46) rather than DPF certification, your immediate legal exposure from this specific ruling is lower. SCCs were never built on FTC independence — they run on contractual enforcement plus the same EO 14086 government-access safeguards that underpin the DPRC. Your existing Schrems II-era Transfer Impact Assessment obligations still apply in full (nothing about this changes that), but you're not sitting on the pillar that just cracked.
If your primary transfer mechanism is DPF certification — either because you certified directly or because a vendor did (AWS, Google Cloud, Microsoft, and most large US SaaS vendors maintain active DPF certifications) — you're exposed to a mechanism the Commission's own adequacy decision leaned on for its "independent enforcement" finding, and that finding no longer describes reality without some kind of Commission response.
The pending case nobody's citing enough: C-703/25 P
While the noyb/EDPB story played out over the summer, an actual CJEU appeal has been sitting on the docket since October 2025 with comparatively little attention.
French MP Philippe Latombe filed the first direct judicial challenge to the DPF adequacy decision at the EU General Court. On September 3, 2025, the General Court dismissed it (Case T-553/23), rejecting all four grounds: it found EO 14086 provides adequate ex post judicial review for bulk data collection, that the DPRC has "sufficiently strong structural protections," that GDPR plus sector-specific US law adequately covers automated decision-making, and that DPF data security requirements are substantially equivalent to GDPR's. Latombe appealed to the CJEU on points of law on October 31, 2025 — that's Case C-703/25 P. As of this writing, no hearing date has been announced.
Why this matters more than it's being treated: this is a real, already-pending case before the court that has invalidated two prior EU-US transfer frameworks (Safe Harbor in Schrems I, Privacy Shield in Schrems II). It doesn't need noyb to actually file its promised annulment action to produce a ruling — the CJEU could rule on C-703/25 P regardless of what happens with noyb's separate case. If you're building a monitoring checklist for DPF risk, a scheduled hearing date on C-703/25 P belongs on it right next to "did noyb actually file" and "how did the Commission respond to the EDPB letter."
What actually changes today, and what doesn't
| Claim | Status as of August 20, 2026 |
|---|---|
| DPF adequacy decision is suspended or withdrawn | False. Commission Implementing Decision (EU) 2023/1795 remains in force. Transfers made under DPF certification today are lawful. |
| noyb has filed its CJEU annulment action | Not yet. Announced June 30, 2026 as "coming weeks"; unfiled as of this writing, 7+ weeks later. |
| The EDPB has called for withdrawal | No. Its July 31, 2026 letter asks the Commission to "closely assess" the impact and share information — a narrower ask than noyb's. |
| A CJEU case on DPF adequacy is already pending | True. Case C-703/25 P (Latombe appeal), filed October 31, 2025, no hearing date yet. |
| SCC-based transfers depend on FTC independence | No. SCCs (GDPR Art.46) rely on contractual enforcement and EO 14086 government-access safeguards, not FTC removal protections. |
| DPF-certified transfers rest partly on the FTC's independence as assessed in 2023 | Yes, per the adequacy decision's own text (§58-60) and the EDPB's July 31 letter. |
What to actually do about it
1. Map which of your transfers depend on DPF certification specifically, not just "a US vendor." Check whether your critical vendors certify under the DPF (most large cloud/SaaS vendors publish this on their trust/compliance pages) versus relying on SCCs with you as the exporting controller. These carry different risk profiles under this specific ruling.
2. Don't touch anything based on this ruling alone. The DPF is valid today. A premature migration triggered by a Supreme Court case about US administrative law, before the Commission has even responded to the EDPB, is a self-inflicted cost with no compliance benefit yet.
3. If you're DPF-reliant, dust off (or build) your SCC fallback and TIA documentation now. Not because DPF is dead, but because if the Commission suspends or the CJEU annuls the decision, DPF-certified transfers become unlawful the day that happens — there's historically been no grace period for the adequacy mechanism itself, only for the fallback mechanisms you'd already documented. Having a current Transfer Impact Assessment ready for your DPF-reliant vendors converts a scramble into a paperwork switch.
4. Track three concrete triggers, not vibes:
- Any public Commission response to the EDPB's July 31 letter (Ref. Ares(2026)7540711).
- Whether noyb actually files its promised CJEU annulment action.
- A scheduled hearing date for Case C-703/25 P.
5. For net-new infrastructure decisions, the durable fix is sidestepping the adequacy-decision dependency entirely. Hosting your primary data stores on infrastructure with no US parent entity means no CLOUD Act exposure and no dependency on whichever transfer mechanism GDPR Article 45/46 currently recognizes for US transfers — because there's no transfer.
See also
Our Schrems III warning signs guide from May 2026 laid out six observable triggers to watch for, and flagged "change in US administration / EO 14086 revocation" as the highest-probability trigger at the time. Worth an honest correction here: that's not what happened. The actual escalation this summer came from an entirely different legal mechanism — a Supreme Court separation-of-powers ruling about FTC removal power, unrelated to EO 14086 itself — that none of the six warning signs specifically anticipated. Treat that guide's general framework (map your transfers, build TIA documentation, architect for transfer-mechanism independence) as still sound, but treat its trigger-probability ranking as superseded by what's in this post.
sota.io is a European PaaS platform incorporated in the EU, with no US parent company and no US data centers. Hosting your primary infrastructure there means CLOUD Act exposure and DPF/SCC adequacy questions simply don't apply to that layer of your stack — there's no transfer to assess.
EU-Native Hosting
Ready to move to EU-sovereign infrastructure?
sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.