· Openers · Digital Sovereignty · 4 min read
The Uncertain Bridge Across the Atlantic – Part 3: The Data Privacy Framework – The Third One That Fell
In 2023 the third major EU-US agreement was put in place. It lasted less than three years. In June 2026 the US Supreme Court removed the independent oversight the entire deal relied on. Three collapses in eleven years is a pattern.
In 2023 the EU and the US tried again.
The new agreement was called the EU-US Data Privacy Framework. It was supposed to finally solve the problems once and for all. More certified companies. Continued smooth data transfers to American cloud services. GitHub, major cloud platforms, everyday SaaS tools — everything would now be “legal” again.
Many people breathed a sigh of relief.
Less than three years later the question was open again.
What was the third agreement built on?
The big promise was that the US had now “strengthened” the protections. Two things in particular were often mentioned:
- The Federal Trade Commission (FTC) would act as an independent supervisory authority.
- There was a special “Data Protection Review Court” and other mechanisms to handle complaints.
In the European Commission’s adequacy decision that approved the framework, the FTC’s independence is referenced more than 250 times. It was a central pillar.
If that pillar gives way — what happens to the whole house?
June 2026: The pillar collapses
On 29 June 2026 the US Supreme Court ruled in the case Trump v. Slaughter.
The Court held that the President has the authority to remove FTC commissioners at will. The old protections that made the FTC “independent” of political power were deemed unconstitutional.
Suddenly the authority on which the entire DPF rested was no longer independent in the way the EU requires.
EU law (the Charter of Fundamental Rights) requires that supervision of data protection must be carried out by an independent authority. Not an authority that can be directly directed by the President.
On the same day Max Schrems and the organisation noyb called on the European Commission to withdraw its approval of the agreement.
It was not only the FTC
Other parts of the “protection” had already been weakened:
- The PCLOB (Privacy and Civil Liberties Oversight Board) had lost its quorum.
- The special court for data protection complaints was created by executive order — something that can be changed at any time.
- Certain surveillance laws had lapsed or been called into question.
Together they painted a picture: the third agreement rested on a legal construction that was sensitive to political winds in the US.
What does this mean for organisations using US services?
Nothing becomes illegal overnight as long as the agreement formally remains in force.
But:
- Uncertainty is back. Every assessment (TIA) you perform for Standard Contractual Clauses or Binding Corporate Rules becomes harder to justify.
- In public procurement and audits the question “how are you handling this risk?” will be asked more often and more sharply.
- For organisations handling particularly sensitive data (health, children, citizen data, research, defence) the impact is even greater.
The question has shifted from “Is this allowed today?” to “How long can we count on it being allowed?”
Three collapses in eleven years
- Safe Harbor: ~15 years
- Privacy Shield: ~4 years
- Data Privacy Framework: ~3 years
This is not bad luck. It is a pattern.
Every time the approach has been to patch the symptoms without changing the fundamental differences in how the two sides view privacy and state power.
Where do we stand now?
Formally the third agreement is still in force. The European Commission has not withdrawn it. The courts have not invalidated it.
But the foundations have been weakened in a way that is hard to ignore.
Many European organisations — especially those that take digital sovereignty seriously — have already chosen another path: They build as much as possible without needing to rely on transatlantic data transfers for core operations.
In the final part we look at exactly that path. What does it actually mean to choose solutions within your own legislative jurisdiction — and why it delivers more than just “compliance”?
Want to understand how you can reduce dependence on agreements that can change at any moment?
Openers helps municipalities, agencies, businesses and non-profits choose and implement solutions where data and control stay within Swedish or European jurisdiction.
Book a meeting or explore our infrastructure and compliance offerings.