The U.S. Supreme Court's recent decision in Trump v. Slaughter has introduced significant new questions for American companies that rely on the EU-U.S. Data Privacy Framework toβ¦
The U.S. Supreme Court's recent decision in Trump v. Slaughter has introduced significant new questions for American companies that rely on the EU-U.S. Data Privacy Framework to move personal data across the Atlantic. In a 6-3 ruling, the Court upheld President Trump's March 2025 without-cause removal of Federal Trade Commission Commissioner Rebecca Kelly Slaughter, meaningfully broadening the scope of presidential control over independent federal agencies. The ruling reshapes long-standing assumptions about the structural independence of agencies like the FTC and, in doing so, may unsettle regulatory arrangements that depend on that independence.
One of the most immediate international implications concerns the EU-U.S. Data Privacy Framework, the mechanism that permits participating U.S. organizations to receive personal data from the European Union under an adequacy determination issued by the European Commission. The Framework's viability rests, in part, on the ability of the FTC to enforce privacy commitments free from direct political control. With the President's authority to remove FTC Commissioners now confirmed to extend beyond traditional for-cause limits, European regulators are examining whether the agency's enforcement posture remains sufficiently independent to satisfy the adequacy standard under EU law.
The European Commission has signaled that it is reassessing the Framework in light of the ruling. Although no formal action has been announced, prior transatlantic data transfer regimes have been invalidated by the Court of Justice of the European Union over comparable concerns, and stakeholders on both sides of the Atlantic will be attentive to how this review unfolds. Any change to the Framework's status could disrupt data flows that underpin cross-border commerce, cloud services, human resources operations, and marketing activities.
U.S. businesses that transfer personal data from the EU should monitor developments closely and consider proactive steps. These may include reviewing current reliance on the Framework, preparing to implement standard contractual clauses or binding corporate rules as alternative transfer mechanisms, and updating internal privacy documentation. Conducting transfer impact assessments and maintaining flexibility in vendor agreements can also help mitigate potential disruption.
This article is provided for general informational purposes only and does not constitute legal advice. Clients with specific questions about international data transfers or the implications of Trump v. Slaughter should seek tailored guidance from qualified counsel.