To be precise at the outset, because this topic attracts imprecision: the EU–US Data Privacy Framework adequacy decision is in force today. Transfers under it are lawful today. Everything else in this piece is about direction, not status.
What happened
On 29 June, the US Supreme Court decided Trump v. Slaughter, concerning the President's power to remove Federal Trade Commission commissioners. The 2023 adequacy decision rests, at several points, on the independence of the US bodies that enforce and oversee the framework, the FTC among them. Weaken the independence premise and you weaken a load-bearing wall of the Commission's reasoning.
The reactions were quick. noyb has asked the Commission to revoke the adequacy decision and announced a fresh challenge before the CJEU. The EDPB placed the judgment on the agenda of its 122nd plenary on 7 July. The Commission, for now, has said nothing that changes the legal position.
Claims that the framework "has collapsed" are advocacy, not analysis. But the symmetrical mistake, "adequacy survived Schrems I and II noise before, it will survive this", ignores that the challenge this time is aimed at a premise the decision itself wrote down.
The asymmetry that matters
Here is how I frame it for boards: the cost of preparing for a DPF disruption is small and mostly reusable; the cost of an unprepared disruption is a fire drill across every US vendor relationship you have, conducted on a deadline you did not choose. Twice in living memory, Safe Harbor in 2015, Privacy Shield in 2020, European companies learned that transfer frameworks can end on a single court date. The companies that suffered least were not those that predicted the judgment; they were those whose fallback was already on paper.
What preparation looks like
- Map the exposure. Which of your transfers actually rely on the DPF as the transfer tool, as opposed to SCCs that merely mention it? Most companies discover their honest answer is "we are not sure". A one-page register of US recipients, tool per recipient, fixes that.
- Stage the fallback. For DPF-only relationships, have the 2021 SCC module selection and a transfer impact assessment template ready to execute, not executed, ready. The TIA work done for your SCC transfers is largely reusable.
- Check the contract trigger. Good DPAs already oblige the vendor to cooperate in implementing an alternative tool if the current one fails. Read what yours say before you need them; add the clause at the next renewal where it is missing.
- Calibrate the watch. The events to diarise: the Commission's response to the revocation request, the CJEU docket, and EDPB statements. Nothing about this requires weekly panic; it requires a named owner who notices when one of those three moves.
The larger pattern
This is the third essay this week in which the same structural point surfaces: dependencies that live outside your legal system, frontier-model access, and now the constitutional posture of a foreign regulator, have become inputs to European compliance. You cannot contract them away entirely. You can know exactly where they touch you, and how long it takes you to move. That knowledge is the deliverable.
Status notes, 8 July 2026: the adequacy decision is in force; the EDPB's discussion outcome and the Commission's position on the revocation request were not public at the time of writing, verify before relying on this account. Commentary, not advice; transfer analysis is fact-specific.
