FTC Ruling Puts EU-US Transfers Under Pressure
Coverage from BBB National Programs, Inside Telecom, and others

A U.
S. Supreme Court ruling in Trump v. Slaughter removed statutory protections limiting the president’s ability to remove Federal Trade Commission commissioners, raising questions about the independent oversight underpinning the EU-US Data Privacy Framework. noyb is pressing the European Commission to withdraw or transition away from the framework and is preparing possible litigation before the Court of Justice of the European Union, while the Commission assesses the ruling’s effect. The framework remains formally in force, but companies and regulators are reviewing reliance on it and considering Standard Contractual Clauses, Binding Corporate Rules, and other transfer safeguards.
If you read one thing
It clearly explains how the FTC ruling could undermine the Framework while connecting the legal risk to fallback transfer arrangements.
The counter-case
It provides the strongest contrasting account that the Framework remains operative while the Commission reviews the ruling.
The evidence
It adds practical evidence about the transfer assessments and backup plans organizations are being advised to review.
FTC independence threatens the adequacy rationale
Trump v. Slaughter removed statutory for-cause protections for FTC commissioners, creating a potential defect in the independent-oversight assumptions supporting the EU-U.S. Data Privacy Framework. The ruling's effect on the framework's broader safeguards remains contested.
The framework remains operational pending formal action
The DPF has not been suspended, repealed, or annulled, so certified organizations may still rely on it as a lawful transfer mechanism. Its continuity remains conditional on possible European Commission or CJEU action rather than secured against the independence challenge.
Organizations are preparing fallback transfer safeguards
Uncertainty is prompting reviews of transfer-impact assessments, data maps, SCCs, BCRs, and backup arrangements. If the DPF fails, companies may need greater reliance on contractual safeguards, data localization, or redesigned infrastructure, potentially at substantial cost.
Resolution depends on European review and litigation
The EDPB has asked the European Commission to assess whether the FTC ruling changes the DPF adequacy analysis, while noyb is pressing for withdrawal or transition and considering CJEU litigation. The decisive outcome therefore remains institutional and judicial rather than automatic from the U.S. ruling.
six to three
Supreme Court vote
“In Trump v. Slaughter, the Supreme Court ruled six to three that limits on the president’s power to remove FTC commissioners were unconstitutional.”
more than $10 billion USD
spending on TikTok’s European data-storage program in Ireland
“TikTok’s European data-storage program in Ireland illustrates the potential cost of regional infrastructure; the project has required years of work and more than $10 billion in spending.”
Contested Issue
Does Trump v. Slaughter fatally undermine or invalidate the EU-U.S. Data Privacy Framework, or does the framework remain legally operative pending review?
Sources disagree over the ruling's legal effect on the framework. Some characterize the loss of statutory FTC independence as destroying or seriously weakening an express premise of the adequacy decision, while others emphasize that the framework remains in force, transfers remain authorized, and formal review could clarify or reinforce its legal basis.
Adequacy basis undermined
The ruling removes or materially weakens the FTC-independence premise supporting the DPF, potentially requiring withdrawal, annulment, or an orderly transition away from the framework.
Framework remains operative
The ruling creates a question for review but does not itself invalidate or suspend the DPF; transfers remain authorized unless the Commission or a court changes the adequacy decision, and clarification could reinforce the framework.
EDPB formally requests review without suspending the framework
The EDPB has formally asked the European Commission to reassess whether the FTC-independence rationale for the EU-U.S. Data Privacy Framework remains valid after Trump v. Slaughter, while making clear that it is not seeking suspension or revocation. The framework therefore remains available for transfers pending the Commission’s review.
Previously
The U.S. Supreme Court’s Trump v. Slaughter ruling removed statutory protections limiting the president’s ability to dismiss Federal Trade Commission commissioners, raising questions about the FTC’s independence under the EU-U.S. Data Privacy Framework. European regulators are assessing the implications, while privacy group noyb is seeking withdrawal of the framework and considering litigation before the Court of Justice of the European Union. The framework remains formally available for covered transfers, but organizations may need to reassess reliance on it and on related transfer mechanisms if EU authorities or courts find that U.S. oversight no longer provides sufficient safeguards.
The story remains substantively unresolved, but the response has shifted from hypothetical reassessment toward active review of transfer practices and possible transition options.
The update adds practical implications beyond the DPF itself: organizations relying on SCCs or BCRs may need to reassess transfer impact assessments and assumptions about U.S. oversight. The ruling’s 6-3 outcome and removal of statutory for-cause protections further clarify the legal basis for the challenge, while the broader dispute remains largely unchanged.
