Three frameworks, two dead, one on a stay of execution

The European Union has tried three times to declare that personal data may flow to the United States on the basis that American law protects it adequately. Safe Harbor lasted from 2000 until the Court of Justice of the European Union struck it down in 2015. Privacy Shield replaced it in 2016 and was struck down in 2020, in the judgment everyone calls , for a reason that had nothing to do with contracts and everything to do with what United States intelligence law permits and whether a European had anywhere to complain. The full account is in the catalogue.

The third attempt, the EU-US (DPF), was adopted in July 2023. It is formally in force today. It has been in force every day since the morning of 29 June 2026, when the United States Supreme Court removed one of the things it stands on.

I hold German citizenship alongside Brazilian, I teach a cloud security platform whose central configuration questions are where is the tenant and where does the inspection happen, and my students are in banks and telecoms and government agencies on three continents. So this is not a European story I follow from a distance. It is the legal weather over every console I teach on.

What happened on 29 June

In Trump v. Slaughter, decided 6-3, the Supreme Court held that commissioners of the Federal Trade Commission (FTC) may be removed by the President at will. That overturned a precedent from 1935 and ended the statutory independence the agency had operated under since 1914. It is a decision about the separation of powers in American constitutional law, and it says nothing about Europe.

It matters to Europe because of what the European Commission wrote when it adopted the DPF. The adequacy decision relies on the FTC as the independent authority that enforces the framework against the American companies certified under it. The privacy group noyb, run by Max Schrems, whose complaints brought down the first two frameworks, counted the references: the adequacy decision cites the FTC and its independence 259 times. On 30 June, one day after the ruling, noyb wrote to the Commission demanding an orderly repeal with transition periods - to avoid, in its words, another compliance cliff of the kind that followed the first two invalidations - and announced it would file its own annulment case before the Court of Justice within weeks if the Commission did not act.

noyb's argument is worth stating precisely, because it forecloses the obvious repair. No other American authority can step in: the Department of Transportation, the framework's other enforcer, is equally part of the executive and faces the same problem under the same logic; private arbitration cannot supply the independent public supervision that European law requires. And the commercial enforcement side is not the only prong touched. Schrems II turned on surveillance and redress, and the body that oversees intelligence access to data under the framework, the Privacy and Civil Liberties Oversight Board (PCLOB), had its Democratic members dismissed earlier in the year, with an appeals court staying those dismissals pending exactly this Supreme Court decision.

There was already a live vehicle. A French parliamentarian, Philippe Latombe, challenged the DPF in September 2023. The General Court dismissed his case in September 2025 - but explicitly limited itself to the facts as they stood when the framework was adopted, and reminded the Commission that it must monitor the American legal situation continuously and act if it changes. Latombe appealed to the Court of Justice on 31 October 2025. That appeal was pending when Slaughter came down, which means Europe's highest court already has a case in front of it through which the changed facts can be considered, before noyb files anything.

The European Data Protection Board, which groups the national regulators, said it is reviewing the implications and described the independence of the oversight bodies as central to the framework's legitimacy. The Commission has said it continues to monitor. Trans-Atlantic data flows are estimated at over 877 billion euros a year, and the general reading is that the Commission will hold the line until the court forces the question. Commentators put a judgment no earlier than late 2026 or 2027; Schrems II itself took about four years from filing to decision.

So the position as I write is: the DPF is valid, nothing has been suspended, and a Brazilian law firm's summary is accurate that transfers continue to be authorised. It is also the case, as one European analysis put it, that two of two previous frameworks have failed before this court, and the starting point for the third is worse than for either of them.

Why a court in Luxembourg keeps arriving at the same place

It is tempting to read this as bureaucratic churn - a framework, a challenge, a replacement, a challenge. It is not. The court has been asking one question for eleven years and getting the same answer.

Schrems II said that a contract between two companies cannot bind a government that is not party to it. That is why standard contractual clauses survived that judgment only conditionally: the exporter has to look past the paper at what the destination state can compel the recipient to do. Adequacy decisions are the Commission's attempt to answer that question once, for everyone, for a whole country. Each time, the court has looked at the answer and found that the American state could compel more than the framework admitted, or that a European had no independent body to appeal to, or both.

Strip the legal vocabulary and it reads like a threat model. The catalogue article makes the point that the CJEU took the surveillance record - the same cable-splitter infrastructure a European judgment described as a finding of fact - and drew a legal conclusion from it. The 29 June development is the same shape from the other side: the independence of the referee was a load-bearing assumption, and an American court removed it for American reasons. The framework did not change. The world it described did.

The practitioner's question that falls out of this is the one the catalogue article ends on: who can be compelled, and who holds the keys? If the provider can decrypt, the provider's jurisdiction is in scope, and no region selector on a console changes which government can serve an order on the company operating the console.

The Brazilian corner of the triangle

This is the part that is missing from every European write-up I have read, and it is the part that decides what a Brazilian engineer should actually do.

Brazil's data protection law, the (Lei Geral de Proteção de Dados), had a chapter on international transfers from the start, but for six years it lacked the how. That was filled on 23 August 2024 by the national authority, the (Autoridade Nacional de Proteção de Dados), with Resolution 19/2024: a full international-transfer regulation, closely modelled on the European one, with its own standard contractual clauses, a path for global corporate rules, and a mechanism for adequacy decisions. Organisations were given twelve months to put the ANPD's clauses into their contracts. That grace period ended on 23 August 2025. Since then, a transfer on a contractual basis is valid only with the ANPD's own clauses - or with specific clauses or corporate rules the ANPD has approved in advance, and as of the authority's own portal it has approved none. A foreign template, and the ANPD's guidance names the European clauses specifically, does not count on its own.

Then, on 26 January 2026, the ANPD and the European Commission recognised each other as providing adequate protection. Resolution 32/2026 was the first adequacy decision Brazil had ever issued, and it was reciprocal. Data may now flow between Brazil and the European Union in both directions without clauses at all. On the ANPD's portal, the European Union is the only entry on that list.

The United States is not on it. There is no Brazilian adequacy decision for the United States, and no sign of one. A Brazilian controller sending personal data to an American cloud provider is on the ANPD's standard clauses - which are, by construction, a contract between two companies, and which therefore inherit the exact limitation the Luxembourg court identified in 2020: they cannot bind Washington.

The triangle, drawn

Put the three edges side by side and the shape of the problem is visible:

Brazil to Europe and back: adequate, both ways, since January. A free corridor, and a genuinely new fact - the first time Brazil has ever been on that footing with anyone.

Europe to the United States: the DPF, formally valid, structurally challenged since 29 June, with a pending appeal in front of the court that has already killed its two predecessors.

Brazil to the United States: no adequacy, ANPD clauses mandatory since August 2025, and the clauses carry Schrems II's known limitation on their face.

Now notice what the new corridor does. Because Brazil and Europe are adequate to each other, Brazilian data can lawfully move to a European region without further formality. But the moment it moves onward from that European region to an American provider - a support engineer in Virginia, a backup replica, a log pipeline, a parent company - it is under the DPF, and it has imported the European problem into a Brazilian data chain. The corridor is real and it is also a conduit. An organisation that thinks it has solved the American question by choosing Frankfurt over Virginia has, in a great many real deployments, only moved the question one hop down the pipeline.

What this means at the console

The platform I teach most is a cloud security service: a broker that sits between users and the applications they reach, inspects the traffic, and enforces policy. Configuring it means answering, among other things: which data centres serve this tenant, where the inspection point sits, where the logs are retained, whether support staff in another country can view customer data, where the backups replicate to, and who holds the keys used to decrypt inspected traffic.

Every one of those is a setting. Every one of them is also, after the last two years, a legal position - and for a Brazilian customer the same setting now has three legal meanings, one per edge of the triangle. Keeping the tenant in Brazil keeps it under the LGPD alone. Pointing it at a European region moves it under a corridor that is currently clean. Pointing it at an American region - or at a European region whose operator, logs, or support are American - moves it under a framework that a court is being asked to void and under clauses that cannot reach the state that matters.

I teach engineers, not lawyers, and the thing I can honestly tell them is that the answers to those questions are not on the datasheet and cannot be produced by the legal department. They are produced by someone who knows what the product actually does with data: where metadata is processed, what a failover does to residency, whether "European region" means the disk or the operator. That knowledge is the input the lawyers need and cannot manufacture, and it has just become worth a great deal more.

What I tell students

Three things, and none of them is "wait for the court."

The question is never the paperwork. Adequacy decisions and standard clauses answer "have we signed the right thing." The court keeps answering a different question: "what can the destination state compel." Design for the second question and the first takes care of itself. Concretely: where the provider cannot decrypt, the provider's jurisdiction is largely out of scope, and that is an architecture decision - customer-held keys, inspection points you control - not a contractual one. The Crypto Wars article traces this same argument through three decades of policy; Schrems II is where it arrived from the commercial side.

Map the triangle for your own data before the court does it for you. Which flows are Brazil to Europe, which are Brazil to the United States, and which are Brazil to Europe and then onward. The third category is the one nobody has drawn, and it is where the exposure hides. This is not a large exercise for a single tenant. It is a large exercise for an estate, which is why it should start now rather than in the month after a judgment.

Have the plan that does not depend on the outcome. Europe has had two compliance cliffs in eleven years, and noyb's own letter is asking for an orderly repeal precisely to avoid a third. If the DPF falls, the organisations that will be fine are the ones that already know which flows depend on it and what they would switch to. That is a list, and it can be written this quarter.

Brazil is in an unusually good position here, and it is worth saying so. It has a modern transfer regulation, a clean corridor to the world's most demanding privacy regime, and a domestic authority that has shown it will issue adequacy decisions. What it does not have is a way around the American question, because nobody does. The court in Luxembourg has now been asked that question three times about the same country, and the honest expectation - the one to design against - is that the answer will not change until the facts in Washington do.

This post describes what courts and regulators have decided and what follows technically. It is not legal advice, and the transfer assessments it describes need a lawyer as well as an engineer.

Sources