Law report No. GLW-5159 · filed September 29, 2026

Regulation & EnforcementReported case

EDPB Calls for Review of EU-US Data Privacy Framework

The EDPB has formally requested a review of the EU-US Data Privacy Framework after the US Supreme Court's decision in Trump v. Slaughter raised questions about adequacy.

By Grace Kim3 min read595 words

Holding

  1. The EDPB has formally requested a review of the EU-US Data Privacy Framework.
  2. The request follows the US Supreme Court's ruling in Trump v. Slaughter.
  3. The Framework rests on an Article 45 GDPR adequacy decision and its review does not suspend current transfers.
EDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter - IAPP
PlateEDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter - IAPP — AI-generated

The European Data Protection Board (EDPB) has formally requested a review of the EU-US Data Privacy Framework, the adequacy mechanism that underpins lawful transatlantic transfers of personal data from the European Union to certified companies in the United States. The request follows the US Supreme Court's decision in Trump v. Slaughter, a ruling that the Board considers relevant to the durability of the legal commitments on which the Framework rests.

The EU-US Data Privacy Framework operates as an adequacy decision under Article 45 of the EU General Data Protection Regulation (GDPR). It allows participating US organisations to receive personal data from the EU without additional transfer tools, provided they certify adherence to the Framework's privacy principles and are subject to the oversight and redress mechanisms described in the European Commission's adequacy finding. The EDPB, which brings together national data protection authorities from across the EU, does not itself adopt adequacy decisions. Its role here is to request that the competent bodies examine whether the factual and legal foundations of the Framework remain sound in light of the new judgment.

Trump v. Slaughter is the trigger for the Board's intervention. The case has drawn attention from privacy regulators on both sides of the Atlantic because of its potential bearing on the stability of executive-branch commitments embedded in the Framework's architecture. The Framework's survival depends in significant part on US presidential executive orders and the institutional arrangements they create, including the Data Protection Review Court. Any judicial development that alters the enforceability or expected longevity of those arrangements is, from the EDPB's perspective, a matter that the adequacy assessment must confront.

The Board's request signals that European regulators believe the situation has changed materially since the Commission adopted the adequacy decision. Under the GDPR, an adequacy finding must be preceded by an assessment of the level of protection in the third country, and the Commission is expected to keep that assessment under review. A formal request from the EDPB adds institutional weight to calls for that review to proceed without delay.

For practitioners, the immediate practical consequence is uncertainty rather than invalidation. The EDPB's request does not suspend the Framework, and organisations that currently rely on it for transatlantic data flows are not, by that fact alone, required to change their transfer mechanisms. Data protection officers and counsel should, however, treat the development as a prompt to revisit transfer risk assessments and contingency planning. Companies that depend heavily on the Framework may reasonably consider whether alternative transfer instruments — standard contractual clauses accompanied by transfer impact assessments, or binding corporate rules for intra-group flows — should be readied as fallback options. Given the history of transatlantic transfer arrangements collapsing under judicial scrutiny, most recently with the invalidation of the Privacy Shield in Schrems II, prudent planning is warranted.

Legal teams should also monitor the docket of any review proceeding that follows the EDPB's request. If the European Commission or another competent body opens a formal examination of the Framework's sufficiency, submissions from stakeholders may influence the scope of the review and any conditions attached to the adequacy finding's continuation.

The EDPB's action places the Data Privacy Framework back at the centre of the EU-US data transfer debate. The Board has made clear that it regards Trump v. Slaughter as a development significant enough to test the premises of adequacy, and it has asked the responsible institutions to conduct that test. Businesses with transatlantic data flows should watch the next steps closely.

via GN EU Courts (Source)

Filed under

  • data-protection
  • eu-us-data-privacy-framework
  • edpb
  • gdpr
  • transatlantic-data-transfers
Share this article:

More from Grace Kim

Grace Kim

Show full bio

Correspondent covering consumer brands and retail at Global Law Wire.

206 articles

Also before the court

« Previous articleNext article »