Open Joint Letter on a Public Reassessment of the EU-US Adequacy Decision
On 29 June, the US Supreme Court ruled that US President Trump can remove the leaders of independent agencies and commissions, overturning nearly 90 years of precedent limiting executive power. This decision raises serious questions about one of the key safeguards underpinning the EU-US Data Privacy Framework adopted in 2023: independent supervision.
Under this Framework, personal data can be transferred from the EU to certified US organisations without additional transfer safeguards, based on the European Commission’s finding that the United States ensures a level of protection for personal data that is essentially equivalent to that guaranteed under EU law. This is not only about data protection, but also about the rule of law. The Commission relied on the existence of independent institutions capable of enforcing data protection rules. When the independence of those institutions is called into question, the Commission must reassess whether the conditions for adequacy remain fulfilled.
Following the Supreme Court’s ruling in Trump vs. Slaughter, CDT Europe – together with 36 civil society organisations and academics – have written to Commissioner McGrath urging the Commission to immediately launch a public reassessment of the EU-US adequacy decision, consult civil society and independent experts, and publish its legal assessment of the implications of this judgment.
Adequacy is not a one-off political endorsement or diplomatic gesture. It is a living legal mechanism that must be revisited whenever the facts change. Under the GDPR, the European Commission is required to keep adequacy decisions under continuous review, assessing whether the legal and institutional framework of a third country continues to provide an adequate level of protection. This includes examining the rule of law, the availability of effective judicial remedies, and the independence of supervisory and enforcement authorities. Where those conditions materially change, the Commission has a legal obligation to reassess whether its adequacy finding remains justified and people in the EU continue to receive equivalent protection when their personal data leaves the Union.
Ignoring constitutional and institutional developments would weaken not only this adequacy decision, but confidence in the adequacy framework as a whole. The credibility of the GDPR depends on applying this principle consistently, regardless of the country concerned. At times of deregulation and geopolitical pressure, this is an opportunity for the EU to demonstrate that the GDPR is a living safeguard for fundamental rights, not a static political declaration.
Read the full letter here.
Facts Only
* On June 29, the US Supreme Court ruled that the US President can remove leaders of independent agencies and commissions.
* This ruling overturned nearly ninety years of precedent limiting executive power.
* The EU-US Data Privacy Framework was adopted in 2023.
* The Framework allows personal data transfer from the EU to certified US organizations without additional safeguards.
* The European Commission based the adequacy finding on the existence of independent institutions for enforcing data protection rules.
* CDT Europe and 36 civil society organizations and academics wrote to Commissioner McGrath urging a public reassessment.
* The requirement under GDPR is for the Commission to continuously review adequacy decisions.
* Review must assess the legal and institutional framework, rule of law, judicial remedies, and authority independence.
Executive Summary
The US Supreme Court ruled that President Trump can remove leaders of independent agencies and commissions, overturning nearly ninety years of precedent regarding executive power. This decision raises concerns about the independent supervision safeguarding the EU-US Data Privacy Framework adopted in 2023. The Framework permits data transfers from the EU to certified US organizations without extra safeguards, based on the European Commission's finding that US protection is equivalent to EU law. The Commission relied on independent institutions to enforce data protection rules. Following the Supreme Court ruling, CDT Europe and other groups urged the Commission to launch a public reassessment of the adequacy decision, consult experts, and publish its legal assessment.
The text asserts that adequacy is a dynamic legal mechanism requiring continuous review under GDPR. The European Commission must assess whether the institutional framework provides adequate protection, specifically examining rule of law, judicial remedies, and the independence of supervisory authorities. Ignoring these constitutional and institutional developments risks weakening both the adequacy decision and overall confidence in the GDPR's safeguards.
Full Take
The tension presented here lies between established international data transfer mechanisms and evolving domestic constitutional structures regarding executive power. The core implication is that a mechanism predicated on institutional independence—the EU's adequacy finding—is now vulnerable to shifts in national legal norms originating from the US constitutional landscape. This moves the discussion beyond mere data privacy compliance into the realm of foundational legal architecture and the legitimacy of regulatory frameworks.
The structure of the argument hinges on framing adequacy not as a static political agreement but as a living, legally obligated assessment requiring continuous validation against evolving institutional realities. The call for public reassessment suggests that private sector assurances alone are insufficient; the durability of the data protection regime depends on adherence to principles of rule of law and institutional autonomy, regardless of geopolitical context.
The pattern detected is a strategic effort to link international regulatory stability directly to domestic constitutional shifts, positioning the EU's legal obligations as a proactive defense against perceived deregulation or external pressure. The narrative seeks to establish that the integrity of the GDPR is contingent upon maintaining a standard of governance (institutional independence) that the US ruling has threatened. This speaks to a larger pattern where abstract legal compliance is being re-anchored to tangible political and constitutional realities, suggesting that regulatory resilience requires synchronizing international legal standards with underlying principles of governance.
Bridge Questions: What specific metrics should the Commission use to objectively measure the "independence" or "effectiveness" of supervisory authorities in the context of evolving executive power? How can the principle of continuous review be operationalized when institutional assessments themselves are subject to political contestation? If the reassessment reveals a lack of equivalence, what legal mechanisms exist within the GDPR structure for enforcing changes stemming from such re-evaluations?
Sentinel — Human
The text functions as an analytical call to action, connecting a specific judicial decision to the ongoing legal obligations within the EU's data protection framework.
