EU–US Data Privacy Framework: Still Valid in July 2026 — But the Latombe Appeal and FTC Independence Questions Introduce Risk
DAC Beachcroft's July 9 analysis of the EU–US Data Privacy Framework (DPF) provides the most measured current assessment of transatlantic data transfer risk for law firms: the DPF remains formally in force as of July 2026, transfers under it are still lawful, and the Latombe appeal (which challenges its validity) remains pending without judgment. The destabilising factors the analysis identifies a
BY FRONTIER DESK · JULY 15, 2026 · 1 MIN READ
DAC Beachcroft's July 9 analysis of the EU–US Data Privacy Framework (DPF) provides the most measured current assessment of transatlantic data transfer risk for law firms: the DPF remains formally in force as of July 2026, transfers under it are still lawful, and the Latombe appeal (which challenges its validity) remains pending without judgment. The destabilising factors the analysis identifies are political rather than legal: questions about the independence of the FTC, DPRC, and PCLOB — the US oversight bodies whose independence is a structural foundation of the DPF's adequacy — have been raised in the context of the broader US executive-branch reshaping that began in 2025. The practical guidance for law firms and legal departments is to build resilience into transfer mechanisms now, rather than treating DPF validity as indefinite: refreshing Transfer Impact Assessments, building in Standard Contractual Clause fallbacks, and implementing supplemental technical measures (encryption, data residency, access controls) are the prudent steps the analysis recommends. For transatlantic practices managing client data across US and EU jurisdictions, the DPF stability analysis is a routine compliance update — but the tail risk of a CJEU invalidation judgment arriving without warning is real enough to warrant the defensive architecture DAC Beachcroft describes.