EDPB Requests Review of EU-US Data Privacy Framework Following Trump v. Slaughter
Summary
The European Data Protection Board has requested a review of the EU-US Data Privacy Framework following the US Supreme Court's Trump v. Slaughter ruling. The decision potentially affects the constitutional underpinnings of the DPF, which was negotiated as a replacement for the invalidated Privacy Shield.
Key Details
- Date: 2026-08-03
- Body: European Data Protection Board (EDPB)
- Trigger: US Supreme Court ruling in Trump v. Slaughter
- Framework at risk: EU-US Data Privacy Framework (DPF)
- Potential outcome: Suspension or renegotiation of the DPF
- Affected organisations: Thousands relying on DPF certifications for transatlantic data transfers
- Source: IAPP
- Reliability: Tier 2/4 โ Established cyber journalism / legal analysis
Significance
A review could lead to suspension or renegotiation of the framework, creating significant uncertainty for thousands of organisations that rely on DPF certifications for transatlantic data transfers. This has direct implications for Australian organisations that rely on the DPF for transfers from EU entities, and for New Zealand's adequacy status with the EU.
Geopolitical Context
The EDPB's review request is part of an accelerating trend of regulatory fragmentation globally โ alongside China's PI standard amendments, Singapore's AI guidelines, and the FTC's Hims lawsuit โ pointing to an increasingly complex global compliance environment.
Related
- Cyber Digest 2026 08 04
- China Proposes Significant Amendments To National Standard On Personal Informati โ Parallel regulatory development