The digital rights organization noyb is asking the European Commission to prepare an orderly exit plan from the EU-US Data Privacy Framework, after arguing that a recent decision by the US Supreme Court calls into question the independence of American surveillance authorities. The request comes as a new step in contesting the framework that allows the transfer of personal data from the European Union to certified American companies.
In short
1. noyb is asking the European Commission to prepare an orderly exit from the EU-US Data Privacy Framework.
2. The organization argues that companies need reasonable transition periods, not a new abrupt break from the legal framework.
3. The letter invokes the US Supreme Court's decision in Trump v. Slaughter and its effects on independent executive authorities.
4. noyb asserts that the Federal Trade Commission can no longer be treated as equivalent to an independent oversight authority in the sense of EU law.
5. The organization states that it is also preparing a court challenge, but considers an organized transition by the Commission preferable.
The EU-US Data Privacy Framework is the mechanism currently used for the transfer of personal data from the European Union to the United States when American companies are certified under the system. It is important for cloud services, online work tools, digital advertising, data analysis, software services, and many other daily operations of European companies.
noyb is asking the Commission not to wait for a possible annulment in court, but to prepare in advance for an orderly withdrawal from the framework. The organization is requesting a plan for the repeal of the 2023 European decision regarding the adequacy of data protection in the United States and transition periods that would allow companies to adjust their contracts, infrastructure, and suppliers.
The letter signed by Max Schrems starts from the US Supreme Court's decision in Trump v. Slaughter. noyb argues that this ruling changes the American constitutional doctrine regarding independent executive authorities and directly affects institutions such as the Federal Trade Commission, which the European Commission has relied on in the architecture of the current transatlantic framework.
For European data protection law, the independence of oversight is a central element. noyb invokes Article 8(3) of the Charter of Fundamental Rights of the European Union and Article 16(2) of the Treaty on the Functioning of the European Union, which require that compliance with personal data rules be monitored by independent authorities.
The organization asserts that the Federal Trade Commission appears over 250 times in the European decision regarding the EU-US Data Privacy Framework, which shows its central role in the system of guarantees accepted by the Commission. In noyb's opinion, if the FTC can no longer be considered independent, an essential piece of the transatlantic legal framework becomes vulnerable.
The letter also rejects the idea that other American mechanisms can compensate for this problem. noyb states that private dispute resolution bodies or sectoral authorities do not have the same broad public function and horizontal applicability of the rules. The organization argues that these structures could also be affected by the same legal logic regarding American executive control.
The criticism extends to the Data Protection Review Court, a mechanism created by Executive Order 14086 by former President Joe Biden. noyb asserts that this structure is part of the US Department of Justice and cannot be treated as an independent court or tribunal in the sense of Article 47 of the Charter of Fundamental Rights of the EU.
Max Schrems describes the situation as a conflict between two legal systems. EU law requires independent oversight for data protection, while noyb argues that the new American constitutional interpretation prevents the existence of independent executive authorities. The organization states that this problem cannot be resolved quickly, as it would require major changes either in EU treaties or in the US Constitution or its interpretation.
noyb acknowledges that the Commission's decision remains in effect until it is repealed or annulled. Companies are not automatically required to stop data transfers based on the current framework, but the organization argues that they must prepare alternatives and reduce dependence on American suppliers when personal data transfers are essential for business.
For companies, an orderly transition would mean identifying data transferred to the United States, verifying cloud and software providers, reviewing contracts, assessing European suppliers, and preparing solutions to reduce legal risks. Schrems has publicly described this process as a major exercise, but also as an opportunity for the development of European alternatives.
The organization states that it is also preparing a court challenge to the European decision regarding the EU-US Data Privacy Framework. noyb presents the legal action as a last resort and argues that an organized transition by the Commission would be preferable to avoid a new "compliance cliff."
The current framework is the third major transatlantic arrangement regarding the transfer of personal data. Its predecessors, Safe Harbour and Privacy Shield, were invalidated by the Court of Justice of the European Union in the Schrems I and Schrems II cases. After each annulment, companies were forced to quickly seek other legal bases for data transfers in a climate of uncertainty.
noyb is asking that EU-US data transfers be included in a broader political program, such as the recently announced technological sovereignty package. The theme goes beyond data protection and addresses Europe's dependence on American digital infrastructure, cloud services, software tools, and platforms that process large volumes of personal data of European citizens.
Sources
Latest News
22:27
22:05
21:51
21:33
21:13
See more news