US ruling puts EU-US data transfers on edge: what now?
By Cyso Cloud on
Last updated on
On 29 June 2026, the US Supreme Court ruled on when the president may dismiss FTC commissioners. Although this sounds like an internal American matter, the ruling directly affects the basis on which European companies send personal data to the United States. Privacy organisation noyb says the end of any EU-US data arrangement is now in sight. This article briefly explains what's going on and what you should, and shouldn't, do about it now.

What exactly did the Supreme Court decide?
The case is Trump v. Slaughter. By a vote of 6 to 3, the Court ruled that the statutory dismissal protection for commissioners at the Federal Trade Commission (FTC) is unconstitutional. This overturned a 1935 precedent, Humphrey's Executor, which had guaranteed that protection.
The consequence: the president can now dismiss FTC commissioners without giving any reason. This doesn't mean the FTC is formally barred from being independent. Rather, the legal protection that safeguarded its independence has disappeared, and with it, that independence in practice. The ruling formally concerned only the FTC, but legal experts read it more broadly, as a stepping stone towards greater presidential control over other so-called independent regulators. You can read the full ruling from the US Supreme Court, with further context from NPR.
Why does an American ruling affect your data transfers?
Since the very first adequacy decisions, the European Commission has relied on the "independent" FTC as a regulator. Only on that basis could Brussels maintain that the US offers an adequate level of protection for personal data. According to noyb, the current EU-US Data Privacy Framework from 2023 refers to that independent FTC 259 times.
That's where the problem lies. EU law (Article 16(2) TFEU and Article 8(3) of the Charter) requires oversight by a genuinely independent authority. If that independence disappears, Schrems argues, the legal foundation for the entire transfer agreement disappears with it. It's worth noting that this is noyb's position, not a fact established by a court. But it's a position that holds up, and one that lines up closely with the earlier Schrems rulings that struck down two previous transfer arrangements.
The Data Protection Review Court, the body meant to give EU citizens legal remedies against American surveillance, is also on shaky ground. It isn't a genuine court but part of the US Department of Justice, and its independence rests on a presidential executive order that could be withdrawn at any moment.
What's actually happening now?
noyb has sent a formal letter to the European Commission calling for the adequacy decision to be withdrawn in an orderly manner. The organisation is also preparing a case for the Court of Justice of the EU within a few weeks, seeking to have the decision annulled. Such proceedings are expected to take two to three years. The full reasoning is set out in noyb's announcement.
Does anything change immediately for my organisation?
No, not straight away. The adequacy decision remains formally valid until the Commission withdraws it or the Court annuls it. In practice, data will therefore keep flowing as it does now, for the time being.
Still, doing nothing isn't a good plan. A few things worth keeping in mind:
Non-personal data can continue to flow freely. This entire discussion concerns personal data only.
Article 49 GDPR still allows necessary transfers, but that article is meant for occasional cases. Building your structural processing permanently on that exception won't hold up.
Do you work with standard contractual clauses (SCCs) or binding corporate rules instead of the Framework? Then this affects you just as much. Your impact assessments usually rely on the same American bodies, the FTC and the Data Protection Review Court, which are now losing their independence.
The uncertainty that comes with three years of legal wrangling is the real problem for most organisations. If you process sensitive customer or patient data, you don't want to find out in 2028 that the legal basis was retroactively invalid.
How do you remove that uncertainty?
By simply keeping your data in Europe, with a European provider governed by European law. No Cloud Act, no adequacy decision that could collapse, no dependence on an American regulator that just lost its independence.
That's exactly what Cyso was built for. Our Cyso Cloud runs on Dutch soil, managed by Dutch teams. We wrote previously about why maintaining high security standards is more than just a compliance tick-box in our article "From stranglehold to room to manoeuvre: why digital sovereignty is a priority now." And for government and healthcare organisations already dealing with new rules, "EU bans American cloud for sensitive data" is essential reading.
Not sure whether your current setup will hold up if the adequacy decision falls? Get in touch, and we'll look at your data flows together to identify where the risks lie.



