privacydeep-dive

The EU–US Data Privacy Deal Just Collapsed. What Now?

A June 2026 Supreme Court ruling destabilized the EU–US Data Privacy Framework. Here's what it means for personal files stored with US cloud services.

On June 29, 2026, the US Supreme Court issued a ruling in Trump v. Slaughter that upended the legal foundation of cross-Atlantic data transfers. In a 6-3 decision, the court ruled that the Federal Trade Commission’s independence from presidential control is unconstitutional — a finding that sent privacy lawyers on both sides of the Atlantic scrambling within hours of the announcement.

The ruling may seem distant from where you store your photos, documents, and personal files. It isn’t.


Why the FTC’s Independence Mattered for Your Privacy

The EU–US Data Privacy Framework (DPF) — the agreement that allows US companies to legally process the personal data of EU residents — was built on a specific promise: that EU citizens whose data crossed the Atlantic would be protected by an independent US regulator with real enforcement power.

That regulator was the Federal Trade Commission.

The EU granted the DPF its “adequacy” status — essentially a finding that US privacy protections are equivalent to European ones — partly because it believed the FTC operated independently from political influence. The FTC’s theoretical independence was a cornerstone of every EU–US data transfer deal since 2000.

If the FTC can be dismissed at will by a US president, the argument goes, it was never truly independent. And if it was never truly independent, the adequacy finding rests on a claim that is no longer defensible.

Privacy advocacy group noyb, led by lawyer Max Schrems, made this point publicly within hours of the ruling. The organisation has since asked the European Commission to begin “orderly withdrawal” of the DPF and has announced plans to file a new legal challenge.


What the Ruling Actually Changes Right Now

Here is the important distinction: the European Commission’s adequacy decision for the DPF has not been withdrawn as of July 2026. US companies certified under the DPF can still legally receive EU personal data.

But “still legal” and “safe to rely on indefinitely” are different questions.

The DPF has been challenged before — and its predecessors were struck down. The “Safe Harbor” agreement was invalidated in 2015 after Schrems challenged it following the Snowden revelations. Its replacement, “Privacy Shield,” was struck down in 2020 in the case known as Schrems II, again citing inadequate limits on US government surveillance and inadequate independent enforcement. Each time, EU regulators and companies scrambled to find alternative legal bases, and EU citizens found their data in an uncertain position for months or years during the transition.

Noyb’s new challenge will take time — the Schrems II process took several years from filing to ruling. But the legal vulnerability it identifies is real and, based on the pattern, consequential.


A Brief History of These Deals Being Struck Down

To understand why this moment matters, the history is worth knowing.

Safe Harbor (2000–2015) was built on self-certification: US companies declared that they met EU data protection standards. Max Schrems challenged this after the Snowden revelations showed US intelligence services could access data held by US companies at scale. The Court of Justice of the EU struck it down in October 2015.

Privacy Shield (2016–2020) replaced it with more formal mechanisms. Schrems challenged this too, and in July 2020 the CJEU invalidated it — again citing the lack of adequate limits on US government surveillance and the lack of genuinely independent enforcement.

The Data Privacy Framework (2023–present) was specifically designed to address both previous failures: new presidential executive orders limiting US intelligence access to EU data, and formal FTC enforcement listed as a key safeguard. The Trump v. Slaughter ruling casts doubt on both pillars simultaneously — both the durability of executive order-based protections under a new administration and the independence of the FTC as an enforcer.

The pattern of challenge-invalidation-replacement has played out twice. Lawyers now acknowledge it may be entering its third cycle.


What This Means for Your Files Stored With US Services

If you are an EU resident storing personal files — photos, documents, voice notes, journal entries — with a US-based cloud service, the practical implications break down into several categories.

Nothing changes immediately. The DPF is still formally in force. Services relying on it as their legal basis for EU-to-US data transfer can continue to do so until a court orders otherwise.

Legal uncertainty creates real risk. In the aftermath of Schrems II, some companies had to stop transferring data, delete data they had already transferred, or restructure their infrastructure to keep EU data within EU data centres. That process took months and, for some users, meant uncertainty about access to stored data. If history repeats, something similar is plausible in the next two to three years.

Enforcement may weaken in practice. Even if the DPF survives its current challenge, the practical enforceability of privacy commitments depends on a regulator with the will and independence to act. If the FTC is removable at presidential will, EU-based users have fewer practical recourses when US companies fall short of their stated privacy commitments — regardless of what the framework documents say.

Data residency becomes more important. Companies that store EU data in EU-based data centres, rather than routing it to US servers, are not subject to the DPF at all. For them, these rulings are largely irrelevant. For everyone else, the uncertainty applies.


The Alternatives Available Today

For EU residents thinking carefully about where to store personal data after this ruling, the question is simple: where are my files actually stored, and under whose jurisdiction?

EU and Swiss-based services. Cloud storage providers headquartered and operating within the EU or adequacy-jurisdiction countries — such as Proton Drive (Switzerland) or Internxt (Spain) — are not subject to the DPF because no transatlantic transfer takes place. Their infrastructure sits inside EU-adequate jurisdictions, which means US legal demands have no direct reach.

Data residency options from large providers. AWS, Microsoft Azure, and Google Cloud all offer region-lock options that can keep data within specific geographic regions. For enterprise users, this is a workable response. For individual users of consumer services built on top of those platforms, the controls may not be accessible or even exist.

Local and device-level storage. For files that don’t need to be accessed from multiple devices — sensitive personal documents, for instance — local storage with local backup remains completely outside the US regulatory environment. It requires more self-management, but the threat model it addresses is different.

Knowing your provider’s architecture. Some US-headquartered services store data regionally, with EU users’ data housed in EU data centres. This doesn’t eliminate all DPF exposure but reduces it significantly. It’s worth asking your current provider explicitly where your files are physically stored.


Surveillance Concerns Beyond the DPF

The DPF discussion focuses on the legality of commercial data transfers. But the broader concern that has driven all three cycles of challenge — US government surveillance of data held by US companies — has not changed since Schrems originally raised it in 2013.

US intelligence law, including Section 702 of the Foreign Intelligence Surveillance Act, gives US authorities broad access to data held by US companies regardless of where the users are located or where the data is physically stored. EU courts have repeatedly found this incompatible with EU fundamental rights. The DPF attempts to manage this tension through executive order-based safeguards — but those safeguards can be modified by the executive that created them, without congressional action or judicial review.

This is not a hypothetical concern for ordinary users. Practising journalists, lawyers with EU clients, activists in politically sensitive situations, and anyone dealing with medical or legal matters may have specific reasons to care whether their stored files are accessible to intelligence agencies under laws that provide limited notice and no right of challenge.

For most people storing holiday photos and grocery lists, the practical risk is low. But understanding that the legal framework managing this risk has a structural instability — one that has now failed twice, and is challenged a third time — is relevant to any informed decision about where to store personal files.


GDPR Compliance Is Not the Same as DPF Stability

It is worth being clear about what GDPR compliance does and does not provide.

A service that is GDPR-compliant has met obligations around how it collects, uses, and retains data: lawful basis for processing, user rights to access and deletion, transparency about data practices, and requirements for breach notification. These obligations exist regardless of the DPF’s status.

GDPR compliance does not, however, resolve the question of whether a US service’s legal basis for receiving EU data in the first place is valid. If the DPF is invalidated, a GDPR-compliant US service still needs a legal basis for the transfer — which may require using Standard Contractual Clauses, which have their own legal challenges, or restricting EU data to EU infrastructure.

These are ultimately regulatory and corporate architecture questions, not something individual users can resolve by reading a privacy policy. What users can do is understand the distinction, ask where their data is physically stored, and make decisions accordingly.


What to Watch

For users who want to stay informed as this develops:

  • The European Data Protection Board is expected to issue guidance on the DPF’s status following the Trump v. Slaughter ruling. This is the most authoritative source.
  • Noyb’s legal filings, which will become public record once filed, will define the legal argument that may ultimately succeed or fail.
  • Your cloud provider’s DPA (Data Processing Agreement) will specify which legal mechanism it relies on for EU transfers. If it relies solely on the DPF and the DPF is later invalidated, your provider will need to update its legal basis — and may or may not communicate that clearly.

The core message is not to panic and move everything immediately. The DPF is currently in force. The message is to understand that this situation has a track record — two previous agreements struck down in 15 years — and to make storage decisions with that track record in mind.


Storing Files With That Context

daftei is GDPR and CCPA compliant. Files are encrypted at rest with AES-256 and in transit with TLS 1.3. The operational model — no advertising, no data sales, no third-party AI training on user content, permanent and irreversible erasure 30 days after account deletion — does not depend on which transatlantic agreement happens to be in effect at any given time.

The broader EU data transfer question is one that any US-connected service must navigate. For users with specific concerns about EU data sovereignty, understanding where files are physically stored and what happens if the DPF is formally withdrawn is a reasonable thing to verify with any provider you use.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts