The United States Supreme Court ruled, in Trump v. Slaughter, on June 29, 2026, that the Federal Trade Commission’s (FTC) independence from the President is unconstitutional. Although the ruling concerns the FTC’s independence, it has raised concern over its possible effects on the EU-US Data Privacy Framework (DPF), currently the main legal basis for transferring Europeans’ personal data to US companies.
In the case, the Supreme Court held, by a 6-3 majority, that members of independent regulatory agencies such as the FTC may be freely removed by the President of the United States, reversing an understanding settled since the Humphrey’s Executor precedent (1935) and adopting the so-called “unitary executive theory,” under which the President must hold control over all bodies of the Executive Branch. The FTC’s independence was precisely one of the elements on which the European Commission built, in 2023, its adequacy decision regarding the United States: the agency’s autonomy as the authority overseeing compliance with the DPF is referenced 259 times throughout the European instrument itself.
The reaction was immediate: the Austrian organization noyb, led by Max Schrems — responsible for the actions that led to the invalidation of the former Safe Harbor and Privacy Shield agreements — sent a formal letter to the European Commission requesting an orderly repeal of the EU-US agreement and announced that it also intends to file a new action seeking to have the Court of Justice of the European Union (CJEU) annul the DPF. In the organization’s view, European law requires that data protection supervision be carried out by an independent authority; accordingly, by removing that autonomy from the FTC, the Supreme Court’s decision would have stripped away the basis on which the European Commission recognized the US as a country offering protection “essentially equivalent” to that of the GDPR.
Noyb further contends that the vulnerability would not be limited to the FTC. According to the organization, the judicial redress mechanism created to meet the European Union’s requirements — the so-called Data Protection Review Court — is not, technically, a court, but a body attached to the US Department of Justice, whose independence stems solely from an executive order issued by former President Joe Biden and may be revoked at any time by the current administration. The entity also argues that the decision’s impact would not be confined to the DPF: companies that transfer data on the basis of Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) likewise tend to rely, in their impact assessments, on the activity of US executive bodies now stripped of independence, such as the Privacy and Civil Liberties Oversight Board (PCLOB) and the Data Protection Review Court itself — which, in noyb’s assessment, would render those assessments equally vulnerable to challenge.
Despite the criticism, the Data Privacy Framework remains fully in force, and international data transfers between the European Union and the United States continue to be authorized. This is because the Supreme Court’s decision does not automatically invalidate the agreement, nor does it, on its own, alter the European Commission’s adequacy decision, which ceases to apply only if it is formally repealed by the Commission itself or annulled by the CJEU.