Three frameworks, two dead, one on a stay of execution
The European Union has tried three times to declare that personal data may flow to the United States on the basis that American law protects it adequately. Safe Harbor lasted from 2000 until the Court of Justice of the European Union struck it down in 2015. Privacy Shield replaced it in 2016 and was struck down in 2020, in the judgment everyone calls , for a reason that had nothing to do with contracts and everything to do with what United States intelligence law permits and whether a European had anywhere to complain. The full account is in the catalogue.
The third attempt, the EU-US (DPF), was adopted in July 2023. It is formally in force today. It has been in force every day since the morning of 29 June 2026, when the United States Supreme Court removed one of the things it stands on.
I hold German citizenship alongside Brazilian, I teach a cloud security platform whose central configuration questions are where is the tenant and where does the inspection happen, and my students are in banks and telecoms and government agencies on three continents. So this is not a European story I follow from a distance. It is the legal weather over every console I teach on.
What happened on 29 June
In Trump v. Slaughter, decided 6-3, the Supreme Court held that commissioners of the Federal Trade Commission (FTC) may be removed by the President at will. That overturned a precedent from 1935 and ended the statutory independence the agency had operated under since 1914. It is a decision about the separation of powers in American constitutional law, and it says nothing about Europe.
It matters to Europe because of what the European Commission wrote when it adopted the DPF. The adequacy decision relies on the FTC as the independent authority that enforces the framework against the American companies certified under it. The privacy group noyb, run by Max Schrems, whose complaints brought down the first two frameworks, counted the references: the adequacy decision cites the FTC and its independence 259 times. On 30 June, one day after the ruling, noyb wrote to the Commission demanding an orderly repeal with transition periods - to avoid, in its words, another compliance cliff of the kind that followed the first two invalidations - and announced it would file its own annulment case before the Court of Justice within weeks if the Commission did not act.
noyb's argument is worth stating precisely, because it forecloses the obvious repair. No other American authority can step in: the Department of Transportation, the framework's other enforcer, is equally part of the executive and faces the same problem under the same logic; private arbitration cannot supply the independent public supervision that European law requires. And the commercial enforcement side is not the only prong touched. Schrems II turned on surveillance and redress, and the body that oversees intelligence access to data under the framework, the Privacy and Civil Liberties Oversight Board (PCLOB), had its Democratic members dismissed earlier in the year, with an appeals court staying those dismissals pending exactly this Supreme Court decision.
There was already a live vehicle. A French parliamentarian, Philippe Latombe, challenged the DPF in September 2023. The General Court dismissed his case in September 2025 - but explicitly limited itself to the facts as they stood when the framework was adopted, and reminded the Commission that it must monitor the American legal situation continuously and act if it changes. Latombe appealed to the Court of Justice on 31 October 2025. That appeal was pending when Slaughter came down, which means Europe's highest court already has a case in front of it through which the changed facts can be considered, before noyb files anything.
The European Data Protection Board, which groups the national regulators, said it is reviewing the implications and described the independence of the oversight bodies as central to the framework's legitimacy. The Commission has said it continues to monitor. Trans-Atlantic data flows are estimated at over 877 billion euros a year, and the general reading is that the Commission will hold the line until the court forces the question. Commentators put a judgment no earlier than late 2026 or 2027; Schrems II itself took about four years from filing to decision.
So the position as I write is: the DPF is valid, nothing has been suspended, and a Brazilian law firm's summary is accurate that transfers continue to be authorised. It is also the case, as one European analysis put it, that two of two previous frameworks have failed before this court, and the starting point for the third is worse than for either of them.
Why a court in Luxembourg keeps arriving at the same place
It is tempting to read this as bureaucratic churn - a framework, a challenge, a replacement, a challenge. It is not. The court has been asking one question for eleven years and getting the same answer.
Schrems II said that a contract between two companies cannot bind a government that is not party to it. That is why standard contractual clauses survived that judgment only conditionally: the exporter has to look past the paper at what the destination state can compel the recipient to do. Adequacy decisions are the Commission's attempt to answer that question once, for everyone, for a whole country. Each time, the court has looked at the answer and found that the American state could compel more than the framework admitted, or that a European had no independent body to appeal to, or both.
Strip the legal vocabulary and it reads like a threat model. The catalogue article makes the point that the CJEU took the surveillance record - the same cable-splitter infrastructure a European judgment described as a finding of fact - and drew a legal conclusion from it. The 29 June development is the same shape from the other side: the independence of the referee was a load-bearing assumption, and an American court removed it for American reasons. The framework did not change. The world it described did.
The practitioner's question that falls out of this is the one the catalogue article ends on: who can be compelled, and who holds the keys? If the provider can decrypt, the provider's jurisdiction is in scope, and no region selector on a console changes which government can serve an order on the company operating the console.
The Brazilian corner of the triangle
This is the part that is missing from every European write-up I have read, and it is the part that decides what a Brazilian engineer should actually do.
Brazil's data protection law, the (Lei Geral de Proteção de Dados), had a chapter on international transfers from the start, but for six years it lacked the how. That was filled on 23 August 2024 by the national authority, the (Autoridade Nacional de Proteção de Dados), with Resolution 19/2024: a full international-transfer regulation, closely modelled on the European one, with its own standard contractual clauses, a path for global corporate rules, and a mechanism for adequacy decisions. Organisations were given twelve months to put the ANPD's clauses into their contracts. That grace period ended on 23 August 2025. Since then, a transfer on a contractual basis is valid only with the ANPD's own clauses - or with specific clauses or corporate rules the ANPD has approved in advance, and as of the authority's own portal it has approved none. A foreign template, and the ANPD's guidance names the European clauses specifically, does not count on its own.
Then, on 26 January 2026, the ANPD and the European Commission recognised each other as providing adequate protection. Resolution 32/2026 was the first adequacy decision Brazil had ever issued, and it was reciprocal. Data may now flow between Brazil and the European Union in both directions without clauses at all. On the ANPD's portal, the European Union is the only entry on that list.
The United States is not on it. There is no Brazilian adequacy decision for the United States, and no sign of one. A Brazilian controller sending personal data to an American cloud provider is on the ANPD's standard clauses - which are, by construction, a contract between two companies, and which therefore inherit the exact limitation the Luxembourg court identified in 2020: they cannot bind Washington.
The triangle, drawn
Put the three edges side by side and the shape of the problem is visible:
Brazil to Europe and back: adequate, both ways, since January. A free corridor, and a genuinely new fact - the first time Brazil has ever been on that footing with anyone.
Europe to the United States: the DPF, formally valid, structurally challenged since 29 June, with a pending appeal in front of the court that has already killed its two predecessors.
Brazil to the United States: no adequacy, ANPD clauses mandatory since August 2025, and the clauses carry Schrems II's known limitation on their face.
Now notice what the new corridor does. Because Brazil and Europe are adequate to each other, Brazilian data can lawfully move to a European region without further formality. But the moment it moves onward from that European region to an American provider - a support engineer in Virginia, a backup replica, a log pipeline, a parent company - it is under the DPF, and it has imported the European problem into a Brazilian data chain. The corridor is real and it is also a conduit. An organisation that thinks it has solved the American question by choosing Frankfurt over Virginia has, in a great many real deployments, only moved the question one hop down the pipeline.
What this means at the console
The platform I teach most is a cloud security service: a broker that sits between users and the applications they reach, inspects the traffic, and enforces policy. Configuring it means answering, among other things: which data centres serve this tenant, where the inspection point sits, where the logs are retained, whether support staff in another country can view customer data, where the backups replicate to, and who holds the keys used to decrypt inspected traffic.
Every one of those is a setting. Every one of them is also, after the last two years, a legal position - and for a Brazilian customer the same setting now has three legal meanings, one per edge of the triangle. Keeping the tenant in Brazil keeps it under the LGPD alone. Pointing it at a European region moves it under a corridor that is currently clean. Pointing it at an American region - or at a European region whose operator, logs, or support are American - moves it under a framework that a court is being asked to void and under clauses that cannot reach the state that matters.
I teach engineers, not lawyers, and the thing I can honestly tell them is that the answers to those questions are not on the datasheet and cannot be produced by the legal department. They are produced by someone who knows what the product actually does with data: where metadata is processed, what a failover does to residency, whether "European region" means the disk or the operator. That knowledge is the input the lawyers need and cannot manufacture, and it has just become worth a great deal more.
What I tell students
Three things, and none of them is "wait for the court."
The question is never the paperwork. Adequacy decisions and standard clauses answer "have we signed the right thing." The court keeps answering a different question: "what can the destination state compel." Design for the second question and the first takes care of itself. Concretely: where the provider cannot decrypt, the provider's jurisdiction is largely out of scope, and that is an architecture decision - customer-held keys, inspection points you control - not a contractual one. The Crypto Wars article traces this same argument through three decades of policy; Schrems II is where it arrived from the commercial side.
Map the triangle for your own data before the court does it for you. Which flows are Brazil to Europe, which are Brazil to the United States, and which are Brazil to Europe and then onward. The third category is the one nobody has drawn, and it is where the exposure hides. This is not a large exercise for a single tenant. It is a large exercise for an estate, which is why it should start now rather than in the month after a judgment.
Have the plan that does not depend on the outcome. Europe has had two compliance cliffs in eleven years, and noyb's own letter is asking for an orderly repeal precisely to avoid a third. If the DPF falls, the organisations that will be fine are the ones that already know which flows depend on it and what they would switch to. That is a list, and it can be written this quarter.
Brazil is in an unusually good position here, and it is worth saying so. It has a modern transfer regulation, a clean corridor to the world's most demanding privacy regime, and a domestic authority that has shown it will issue adequacy decisions. What it does not have is a way around the American question, because nobody does. The court in Luxembourg has now been asked that question three times about the same country, and the honest expectation - the one to design against - is that the answer will not change until the facts in Washington do.
This post describes what courts and regulators have decided and what follows technically. It is not legal advice, and the transfer assessments it describes need a lawyer as well as an engineer.
Sources
- ComplexDiscovery, 7 July 2026: Latombe appealed to the CJEU on 31 October 2025 and that appeal was pending when Trump v. Slaughter came down, giving Europe's top court a live vehicle to weigh the changed American facts before noyb files; the European Data Protection Board said it is reviewing the decision's implications for the oversight mechanisms behind the framework, describing their independence as central to its legitimacy; noyb's 30 June letter described litigation as a last resort and urged an orderly repeal with transition periods to avoid a compliance cliff of the kind that followed Schrems I and II
- Kiteworks, 2 July 2026: on 29 June 2026 the Supreme Court issued a 6-3 decision in Trump v. Slaughter making FTC commissioners removable at presidential will, eliminating the statutory independence the agency had operated under since 1935; the Commission adopted the DPF in July 2023 after Schrems II invalidated Privacy Shield in 2020; noyb wrote to the Commission on 30 June demanding orderly withdrawal and announced a CJEU challenge within weeks; the adequacy decision formally remains in force, the Commission has not repealed it and no judgment has annulled it; transatlantic flows are worth over 877 billion euros and the expectation is that the Commission will wait for the court
- Passcreator, 19 July 2026: noyb counted 259 references to the FTC and its independence in the adequacy decision; the General Court dismissed the Latombe case in September 2025 while confirming validity only on the facts at adoption in 2023; no Schrems III case has been decided or formally filed, but it has been announced and the Latombe appeal is pending; the adequacy decision is in force but its basis - the independence of the US enforcement authority - is no longer legally guaranteed as of 29 June; two of two previous agreements failed before the court and the starting point for the third is worse; noyb said the decision cements the case for tearing up the DPF; the Privacy and Civil Liberties Oversight Board had its Democratic members dismissed, with an appeals court staying the dismissals pending the Slaughter ruling
- Secure Privacy, 4 August 2026: the Latombe appeal predates and is legally distinct from the FTC-independence argument, though both could land before the same court, giving it two routes to rule; commentators estimate a CJEU opinion no earlier than late 2026 or early 2027, Schrems II having taken roughly four years; nothing suspends the adequacy decision and the Commission's position is that it continues monitoring; the 6-3 ruling overturned the ninety-year-old Humphrey's Executor precedent and concerns US separation-of-powers law
- activeMind.legal, 2 July 2026: noyb argues in its 30 June letter that no other US authority can remedy the deficiency, the Department of Transportation being equally part of the executive and private redress being unable to provide the independent public supervision EU law requires; the FTC question concerns the commercial enforcement side, and noyb further contends the ruling has consequences for the separate architecture on government access and redress; noyb calls for a planned repeal of Implementing Decision (EU) 2023/1795 with transitional periods; the earlier Latombe challenge was dismissed by the General Court on procedural grounds and the anticipated noyb case is expected to be broader and more substantive
- IAPP, on the General Court's Latombe ruling: the court limited its ruling to the framework's validity at the time the Commission adopted its adequacy determination, called attention to the Commission's role in reviewing validity on an ongoing basis, and stated that the Commission is required to monitor continuously the application of the legal framework on which the decision is based; Latombe first filed in September 2023
- Hunton, 2 July 2026: the 2023 adequacy decision relied in part on the FTC as an independent enforcement authority; noyb argues the ruling calls into question whether the FTC remains sufficiently independent for EU-law purposes and has asked the Commission to withdraw the decision; for now these remain legal arguments rather than legal determinations
- Leonardi Advogados, São Paulo: the Supreme Court ruled on 29 June 2026 in Trump v. Slaughter that the FTC's independence from the President is unconstitutional; noyb sent a formal letter requesting orderly repeal and announced a new annulment action; despite the criticism the DPF remains fully in force and transfers continue to be authorised, because the ruling does not automatically invalidate the agreement, which ceases to apply only if repealed by the Commission or annulled by the CJEU
- ANPD, official portal on international transfers: the European Union was recognised as an adequate international organisation by the ANPD's board through Resolution 32/2026; to date there has been no board decision on specific clauses, equivalent standard clauses or global corporate rules; Resolution CD/ANPD 19/2024 is the International Data Transfer Regulation establishing the mechanisms under the LGPD - standard contractual clauses, equivalent clauses, specific clauses, global corporate rules and adequacy decisions; specific clauses may be used only if previously approved by the ANPD, and only in exceptional situations
- ANPD, Resolution CD/ANPD 19 of 23 August 2024: approves the International Data Transfer Regulation and the content of the standard contractual clauses under article 33 of the LGPD; agents using contractual clauses for international transfers must incorporate the ANPD-approved standard clauses into their contracts within twelve months of publication
- Mayer Brown, 29 August 2025: the grace period for incorporating the standard contractual clauses ended on 23 August 2025, one year after publication; from that point an international transfer is valid only with the clauses implemented or another ANPD-approved mechanism ensuring equivalent protection, on pain of fines and sanctions; at that date the authority had not yet issued any adequacy decision, with expectations of a favourable decision for the European Union
- Lefosse, on the deadline: from 23 August 2025 the use of contractual clauses as a legal basis for international transfer is valid only if the ANPD's standard clauses are adopted or specific clauses are approved in advance; agents relying on their own clauses or on foreign models, such as the European Union's SCCs, are affected
- Confidata, on the reciprocal decision: on 26 January 2026 the ANPD and the European Commission recognised each other as providing an adequate level of protection, the ANPD's first formal adequacy decision; for transfers from Brazil to the EU the standard clauses are no longer necessary; Resolution 19/2024 had filled what was, until August 2024, the LGPD's largest regulatory gap, and Resolution 32/2026 created the first free-flow corridor between Brazil and Europe; as of March 2026 there was no record of any approved global corporate rules