

Data Transfers to the US – Past and Present Developments
Introduction
In day-to-day business operations, the use of a wide range of online applications involves the transfer of personal data to other countries. This regularly includes the integration of cloud and email services, the use of analytics tools, or the use of a business partner’s systems. It is not uncommon for companies to use external service providers based in the United States of America (USA) or to collaborate with other group companies based there. Data protection in the USA is less strictly regulated than in the European Union (EU). Instead of a uniform federal data protection law, there are only state- or sector-specific laws governing the protection of consumer data. It is important for European companies to know what additional security measures must be taken when transferring data to the USA and what implications the recent ruling by the US Supreme Court has for data protection law.
Security Measures for Data Transfers to Third Countries
The European General Data Protection Regulation (GDPR) aims to establish a uniform level of data protection across the entire European Union. However, to ensure that the protection of personal data is also guaranteed beyond the borders of the European Union when data is transferred to third countries – that is, countries that are neither members of the EU nor of the European Economic Area – the GDPR requires additional security measures under Art. 44 et seq. of the GDPR, which must be complied with by the controller or the processor. It is important to note that these measures must also be complied with when transferring data to group companies and (sub-) processors in third countries.
The European Commission has the power to determine, by adopting an adequacy decision, that a third country offers an adequate level of data protection. In such cases, companies based there may be treated as if they were established in the EU. Such adequacy decisions exist for only a very small number of countries, such as Switzerland, New Zealand or Brazil. A full list of these countries can be found on the European Commission’s website.
If the European Commission has not determined that an adequate level of data protection exists, the company exporting the data must put in place suitable safeguards and ensure that data subjects have enforceable rights and remedies. Appropriate safeguards include binding corporate data protection rules or codes of conduct approved by the competent supervisory authority, which contain legally binding and enforceable obligations to ensure a level of data protection comparable to that of the GDPR. Finally, the European company may enter into a contract predefined by the EU – known as standard contractual clauses – with the company based in a third country. Under this contract, the company based in a third country is obliged to guarantee a level of data protection comparable to that of the EU.
Historical Developments Regarding Data Transfers to the US
Several attempts to simplify transatlantic data transfers to the US have failed in the past. This has given rise to tensions and instability in data protection law, which persist to this day.
Safe Harbour Agreement
Even before the GDPR came into force, the Safe Harbour Agreement was negotiated between the US and the EU. As soon as a US company publicly declared that it would comply with the data protection principles established by the US Federal Trade Commission (FTC), the European Commission deemed that the company provided an adequate level of data protection. No review ever took place. In the absence of legal provisions and legal remedies for data subjects, the European Court of Justice (ECJ) declared the agreement invalid in 2015 (ECJ, decision dated 06.10.2015 – Case No. C-362/14).
EU-US Privacy Shield
The EU-US Privacy Shield was an agreement between the EU and the US that led to a presumption of adequacy for companies certified in the US. In a judgement of July 16, 2020, the Court of Justice of the European Union (ECJ) declared the EU-US Privacy Shield invalid, as US intelligence agencies were able to access the personal data of EU citizens and, in the Court’s view, their fundamental rights were not sufficiently safeguarded (ECJ, decision dated 16.07.2020 – Case No. C-311/18). Under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act), US companies are required to hand over their customers’ data at the request of the US government, regardless of where it is stored – even if the data is located on European servers.
With regard to the further measures under Art. 44 et seq. of the GDPR, the ECJ clarified that a data-exporting company must verify, prior to the data transfer, whether the data-importing company can actually comply with the requirements set out in the standard contractual clauses in each individual case. American companies cannot defy orders from the intelligence services, so, in the Court’s view, it is generally reasonable to assume that they are also unable to comply with the standard contractual clauses. The controller must, where necessary, put in place additional safeguards.
Following the judgement, the European Commission drew up new standard contractual clauses in June 2021, which, in addition to an obligation on the part of the exporting company to verify actual compliance with the level of data protection, also include specific obligations regarding conduct in the event of government disclosure requests.
EU–US Data Privacy Framework
On July 10, 2023, the European Commission adopted the EU–US Data Privacy Framework (also known as the Trans-Atlantic Data Privacy Framework), establishing an adequate level of data protection for companies certified under it – and thereby an adequacy decision pursuant to Art. 45 of the GDPR.
This was based on stricter requirements governing access to data of European individuals by US intelligence services, as well as enhanced oversight of their activities. Access by US security authorities has been restricted. The FTC is responsible both for the administration and supervision of the data protection framework and for enforcing the regulations in relation to certified organisations. In addition, independent and impartial redress mechanisms have been established through the creation of the Data Protection Review Court (DPRC) – a court for data protection review – as well as independent dispute resolution mechanisms and an arbitration body.
The General Court of the European Union (EGC) had already been called upon to consider the EU-US Data Privacy Framework in the context of an action for annulment against the adequacy decision and, in a judgment of September 3, 2025, confirmed that an adequate level of data protection exists in the US (EGC, decision dated 03.09.2025 – Case No.: C-T-553/23). The General Court first noted that the independence of the members of the DPRC was guaranteed by a number of safeguards and conditions relating to the functioning of the DPRC and the appointment of its judges. With regard to the practices of US intelligence services, the authorisation of the contested bulk collection of personal data was subject to ex post review by the DPRC and was deemed sufficient in light of the case-law of the ECJ. The judgment expressly referred to the date on which the adequacy decision was adopted. The European Commission is required to monitor developments in the legal situation in the US on an ongoing basis and, where necessary, to suspend, amend or revoke the decision.
US Supreme Court: Trump v. Slaughter (2026)
The European Commission’s task of continuously monitoring the legal situation in the US is likely to take on particular significance following the US Supreme Court’s judgement of June 29, 2026 (Trump v. Slaughter, No. 25–332 (U.S. June 29, 2026).
Content and Outcome of the Judgement
US President Donald Trump, who has been in office since January 20, 2025, dismissed two Democratic commissioners at the FTC – Rebecca Slaughter and Alvaro Bedoya – without giving any reason. A subsequent lawsuit brought by Slaughter was initially upheld, taking into account the precedent set in Humphrey’s Executor v. United States (1935). In that case, it was ruled that, under the FTC Act of 1914, FTC commissioners may only be dismissed by the President on grounds of inefficiency, neglect of duty or malfeasance in office. The aim was to safeguard the independence and impartiality of the FTC, which, in the Supreme Court’s view at the time, primarily performed functions of the judiciary and the legislature. Its duties to implement the policy objectives enshrined in the law and to support the legislature or the judiciary would require freedom from any control by the executive.
Trump subsequently lodged an appeal with the US Supreme Court. The Court ruled that the FTC, in its current form, is an executive body and is therefore subject to the President’s control and unrestricted power to dismiss its members.
Implications for Data Protection
Without protection against arbitrary dismissal, the FTC is no longer an independent institution. The ruling therefore also has implications for data protection law, which are likely to lower the level of data protection in the US – previously regarded as adequate – and thus also have consequences for European data protection.
As an independent supervisory body, the FTC should monitor and enforce US companies’ compliance with data protection obligations. By contrast, the US intelligence services and the complaint procedures before the DPRC are overseen by the Privacy and Civil Liberties Oversight Board (PCLOB); Trump had also dismissed Democratic members from that body. A court ruling regarding the dismissals is currently pending. However, the Supreme Court’s reasoning could potentially be extended to the PCLOB on the basis of its sovereign powers.
The current EU-US Data Privacy Framework nevertheless remains in force until it is repealed by the European Commission or declared invalid by the ECJ. However, for the ECJ to review the current EU-US Data Privacy Framework, a preliminary ruling would first need to be requested by a national court or an admissible individual action brought before the Court. The appeal against the judgment of the General Court of September 3, 2025 concerning the EU-US Data Privacy Framework is currently pending before the ECJ. Even if the ECJ also bases its assessment on the legal situation at the time the adequacy decision came into force, it could provide the European Commission with valuable guidelines for the ongoing assessment of the legal situation and increase pressure on the European Commission to review the adequacy decision in light of current developments and, if necessary, to revoke it.
Next Steps
For the time being, it is important to monitor further developments in the EU, as the EU-US Privacy Framework remains applicable for the time being. As long as the EU-US Data Privacy Framework is applicable, companies may, in principle, rely on it for data transfers.
Nevertheless, companies should check whether they are working with companies in third countries, particularly in the US, and what safeguards are in place regarding the use of the service provider and the transfer of data. If data is transferred to the US solely on the basis of the EU-US Privacy Framework, standard contractual clauses or binding internal data protection policies could be used as an additional safeguard and a precautionary measure. In light of the aforementioned case law of the ECJ, it must be assessed on a case-by-case basis whether the US company can actually fulfil the obligations set out therein. The absence of an independent data protection supervisory authority in the US must therefore be taken into account, particularly in view of further developments regarding the adequacy decision, which remains to be seen.
Future problems can largely be avoided by refraining, as far as possible, from exchanging data with the US or engaging service providers based in the US. For many services, there are alternative providers who often explicitly highlight their EU-based operations and compliance with the requirements of the GDPR. It should therefore always be checked whether alternative providers are available within the EU. This trend is already evident among private internet users, two-thirds of whom, according to a survey by the telecommunications provider O2 Telefónica, already prefer European providers of digital services.
Conclusion
Personal data may only be transferred to a third country if it can be ensured that the third country in question guarantees a level of data protection comparable to that in the EU.
Following two failed attempts to simplify data exchange with the US, data transfers can currently be based on the EU-US Data Privacy Framework, which, since 2023, has been recognised as an adequacy decision certifying an adequate level of data protection in the US. However, in the case of Trump v. Slaughter (2026), the US Supreme Court granted the incumbent President, Donald Trump, the power to dismiss FTC commissioners without cause, thereby undermining the independence of data protection supervision. Following this precedent, a similar court ruling regarding the PCLOB cannot be ruled out.
If a data transfer is based solely on the EU-US Privacy Framework, it is important to bear in mind how the European Commission and the ECJ, as well as the data protection authorities, will position themselves on the agreement in the future as part of the regular reviews. In this respect, it may be advisable to rely on standard contractual clauses or binding internal data protection policies in addition to certification under the EU-US Data Privacy Framework. Given the obligation on data controllers to assess the adequacy of the level of data protection on a case-by-case basis, and the doubts as to whether US companies will be able to fulfil the obligations associated with the safeguards in the long term, it is also advisable to examine whether services can be outsourced to alternative providers based in the EU.
