Geopolitics x Legal

Data Sovereignty

Trump v. Slaughter Triggers NOYB Challenge to EU-US Data Privacy Framework

A July 24 analysis by Sheppard Mullin documents the downstream legal risk from the Supreme Court's Trump v. Slaughter decision: by creating uncertainty about the independence of the Federal Trade Commission — which is the enforcement backbone of the EU-US Data Privacy Framework (DPF) — the ruling has prompted Max Schrems and NOYB to formally ask the European Commission to review the adequacy decis

BY FRONTIER DESK · JULY 30, 2026 · 1 MIN READ

A July 24 analysis by Sheppard Mullin documents the downstream legal risk from the Supreme Court's Trump v. Slaughter decision: by creating uncertainty about the independence of the Federal Trade Commission — which is the enforcement backbone of the EU-US Data Privacy Framework (DPF) — the ruling has prompted Max Schrems and NOYB to formally ask the European Commission to review the adequacy decision underpinning the DPF. The UK's own "data bridge" (its post-Brexit adequacy equivalent) is built on the same foundation and faces the same uncertainty. For law firms and legal departments relying on DPF for trans-Atlantic personal data transfers: the framework is currently in place but is under formal review challenge. Any business that has built its EU-to-US (or UK-to-US) data transfer mechanism on DPF participation should: (a) monitor the Commission's response; (b) identify what alternative transfer mechanisms (SCCs, BCRs) would substitute if the adequacy decision were suspended; and (c) brief their DPO and data governance leads accordingly. The Schrems II disruption cycle of 2020 took approximately six months from challenge to invalidation; the current challenge is at an earlier stage.

Read the full story