Skip to content
Back to Blog
PrivacyBy Ciphera Team10 min read04-04-2026

The EU-US Data Privacy Framework Is Built on an Executive Order — and That's the Problem

Safe Harbor lasted 15 years before the Court of Justice of the European Union struck it down. Privacy Shield lasted four. The Data Privacy Framework is barely three years old, already at the CJEU on appeal — and the US oversight board that underpins it has been gutted to a single member. FISA Section 702 sunsets on April 20, 2026. That's 16 days from now.

Max Schrems put it plainly: "This deal was always built on sand. Instead of stable legal limitations, the EU agreed to executive promises that can be overturned in seconds." He's been right twice before. Cross-border data flows contribute $2.8 trillion to global GDP (McKinsey/ICC, 2024). The stakes couldn't be higher.

TL;DR:

The EU-US Data Privacy Framework depends on Executive Order 14086 — not legislation — and can be revoked at any time. With the PCLOB oversight board stripped to one member, FISA Section 702 sunsetting April 20, and a CJEU appeal pending, the legal basis for 2,800+ companies transferring EU data to the US is eroding fast — and three months on, it's being tested by a legal theory nobody was watching in April (European Commission, 2024).

Update, 19-07-2026 — This post's countdown resolved, and not the way the framing implied. FISA Section 702 didn't sunset cleanly on 20-04-2026: Congress patched it twice, then let it lapse anyway on 12-06-2026 — the first lapse of the authority since 2008 (collection continues in practice under March-2026 FISA Court certifications). The DPF adequacy decision is still formally in force. But on 29-06-2026 the US Supreme Court decided Trump v. Slaughter, fully overruling Humphrey's Executor and holding that FTC commissioners can be fired at will — the same independence the Commission's adequacy decision cites 259 times. noyb has already written to the Commission demanding withdrawal and is preparing a fresh CJEU challenge ("Schrems III"). The sections below are updated in place; the shape of the risk has changed as much as its severity.

What Keeps Failing — and Why?

The EU and US have tried three times to create a stable legal framework for transatlantic data transfers. All three rest on the same flawed assumption: that US surveillance law is compatible with EU fundamental rights. Over 2,800 US companies are currently certified under the DPF (European Commission, Oct 2024). Every one of them is exposed.

The timeline speaks for itself.

FrameworkYears ActiveHow It Ended
Safe Harbor2000–2015Struck down (Schrems I)
Privacy Shield2016–2020Struck down (Schrems II)
Data Privacy Framework2023–?CJEU appeal pending

Each time, the CJEU reached the same conclusion: US law doesn't offer protections equivalent to EU fundamental rights. The specific problem? Mass surveillance under FISA Section 702 and Executive Order 12333, combined with the lack of meaningful redress for EU citizens.

The DPF's answer to this was Executive Order 14086, signed by Biden in October 2022. It introduced "proportionality" requirements for signals intelligence and created the Data Protection Review Court (DPRC) as a redress mechanism. But here's the structural weakness everyone warned about: it's an executive order. Not legislation. Revocable at any time by any president.

The European Commission completed its first periodic review in October 2024 and concluded the DPF was "functioning effectively." French MP Philippe Latombe challenged the framework at the EU General Court — and lost in September 2025. But Latombe appealed to the CJEU in October 2025. That's the same court that struck down both predecessors.

Update, 19-07-2026 — Latombe's appeal is now Case C-703/25 at the CJEU, limited to points of law, no hearing date set. On 29-06-2026 the Court granted Microsoft leave to intervene in support of the Commission's defense. Legal commentators now expect a ruling in late 2026 or early 2027.

Switzerland's adequacy decision, by contrast, was granted in 2000 and has never been challenged at any court. For more on why that matters, see why Swiss infrastructure matters for data privacy.

Why Is the DPF Under More Pressure Than Ever?

The structural supports holding the DPF together are failing. On January 27, 2025, the Trump administration fired three of five Privacy and Civil Liberties Oversight Board members — including chair Sharon Bradford Franklin. The board lost its quorum and can no longer initiate investigations or publish reports (CDT, 2025).

Why does a five-person board matter for European data protection? Because the PCLOB's annual review of EO 14086 compliance was a core piece of the DPF's credibility. That review is now on indefinite hold.

Update, 19-07-2026 — A federal court found the firings unlawful in May 2025 and ordered two of the three members reinstated; the administration appealed, and as of this writing the board still has zero quorum in practice. Beth Ann Williams, the sole remaining member, is herself on holdover status — her term expired 29-01-2026.

Update, 19-07-2026 — A larger threat than PCLOB has since emerged. On 29-06-2026 the Supreme Court's Trump v. Slaughter ruling stripped the FTC of for-cause removal protection entirely, and the Commission's own DPF adequacy decision relies on FTC independence 259 times by noyb's count (source: noyb.eu). noyb sent the Commission a formal letter demanding the adequacy decision be withdrawn and is preparing a direct CJEU challenge. Not everyone agrees this is fatal: the DPRC — the actual redress body at issue in Schrems I and II — draws its independence from an executive order and DOJ regulation, not a congressional statute, a distinction Slaughter didn't address (counter-view: iapp.org). The Commission so far: it has "taken note" and "will carefully analyse."

EO 14086 itself hasn't been formally revoked. But an executive order without oversight is a policy without teeth. Schrems raised this point directly: "What does that mean for something that doesn't even have statutory independence, but basically just executive order independence?"

The European Parliament took notice. It filed a formal question (E-000540/2025) asking the Commission about the consequences of the PCLOB firings for the DPF. The Commission's response was measured but didn't dispute the concern.

Meanwhile, the Latombe appeal sits at the CJEU. The court has a 2-for-2 track record of striking down transatlantic data frameworks when surveillance concerns reach it. As the CDT warned, the PCLOB firings "have the potential to significantly disrupt transatlantic transfers."

Our take: The DPF isn't collapsing because of a single event. It's being hollowed out from multiple directions at once — an oversight board without quorum, a redress court without statutory backing, and an executive order that exists at the pleasure of whoever occupies the White House. The EU Commission called it "functioning effectively" in October 2024. That assessment hasn't aged well.

What Happens If Section 702 Lapses?

FISA Section 702 — the surveillance authority at the heart of every EU challenge — sunsets on April 20, 2026. Congress reauthorised it in April 2024 through the Reforming Intelligence and Securing America Act (RISAA), but gave it the shortest extension ever: just two years. FBI queries of Section 702 data dropped 90%, from roughly 57,000 to approximately 5,500 after RISAA reforms (DNI, 2025).

That sounds like progress. But the picture is more complicated. CIA, NSA, and NCTC queries involving US persons rose from about 3,800 to roughly 7,800 in the same period (DNI, 2025). Surveillance didn't decrease across the board — it shifted.

The Trump administration has taken no public position on reauthorisation. If Section 702 lapses entirely, the DPF's adequacy foundation weakens — the Commission's assessment specifically relied on 702 oversight mechanisms. If Congress reforms it with warrant requirements, as the SAFE Act (Durbin/Lee) proposes, it could actually strengthen the DPF's legal footing.

Update, 19-07-2026 — It didn't get reformed; it lapsed. Congress patched the April 20 deadline twice (to 30-04, then to 12-06) before a further extension failed in the House 198–218 on 11-06-2026, over an unrelated dispute about the acting-DNI appointment. Section 702 has had no statutory basis since 12-06-2026 — the first lapse since 2008. Surveillance continues in practice under FISA Court certifications valid into 2027, but the statutory authority the Commission's adequacy finding assessed is currently unauthorized.

But here's what keeps European data protection officers awake at night: even hosted-in-Europe data isn't safe. Microsoft France's general manager testified under oath that he "cannot guarantee data safety from access by US authorities" even for EU-hosted data. The CLOUD Act allows US authorities to compel data production regardless of where it's stored. So the question isn't just where your data lives. It's who has jurisdiction over the company that holds it.

Europe Is Already Hedging Its Bets

European sovereign cloud spending is accelerating fast. The market hit $6.9 billion in 2025, is forecast to reach $12.6 billion in 2026, and will hit $23.1 billion by 2027 — tripling in two years. Europe is on track to surpass North America in sovereign cloud spending by 2027 (Gartner, Feb 2026).

All 27 EU member states signed the Berlin Declaration for European Digital Sovereignty on November 18, 2025 (Council of the EU). The political intent is clear. But does the infrastructure match?

Not yet. US hyperscalers still hold 70% of the EU cloud market. European providers are stuck at 15% (Synergy Research, 2025). Here's the frustrating part: European cloud revenues tripled between 2017 and 2024, but market share actually halved — from 29% to 15% — because US providers grew even faster.

The EU Data Act is rolling out implementation from 2025 through 2027, with cloud switching and portability provisions taking effect in September 2026. Gaia-X has grown to 180+ data spaces and 600 services, but independent assessments note "just a handful of operational databases." That's sovereignty in theory, not yet in practice.

The gap between political ambition and infrastructure reality remains enormous. But the spending trajectory tells you where this is heading.

Our take: Europe's sovereign cloud push isn't just about cost or performance. It's a direct response to the legal instability of depending on US-controlled infrastructure for European data. The Berlin Declaration made the political commitment. Whether European cloud providers can actually scale fast enough to absorb the demand is the open question — and the answer so far is: not yet.

What Should Businesses Do Right Now?

Don't wait for a court ruling to act. Over 2,800 companies depend on DPF certification as their primary transfer mechanism (European Commission, 2024). If you're one of them, start building redundancy now.

Have Standard Contractual Clauses as a backup. DPF certification alone isn't enough when the legal basis could change overnight. SCCs provide an independent transfer mechanism — though they come with their own compliance obligations.

Map where your data actually flows. Not where your vendor says it's stored — where it actually goes. Processing, backups, subprocessors, support access. The CLOUD Act means US jurisdiction follows US companies, not data location.

Conduct Transfer Impact Assessments for US-bound data. Document the specific risks of US surveillance law for your data categories. If the DPF falls, you'll need this documentation immediately.

Consider European-hosted alternatives for sensitive personal data. Not because European hosting is inherently safer — but because legal stability matters. Analytics is a common culprit: what GDPR actually requires of it — and why keeping the data in the EU takes the whole transfer question off the table — is its own guide. For a deeper look at how zero-knowledge encryption protects data regardless of jurisdiction, we've written a full guide too.

Ciphera chose Swiss infrastructure precisely because Swiss adequacy doesn't depend on an executive order. It was granted in 2000 and has never been challenged at any court. That's the kind of stability businesses need — not a framework that gets rebuilt every few years.

The pattern is clear. Safe Harbor fell. Privacy Shield fell. The DPF is standing, but the ground beneath it is shifting. Whether you're a startup handling EU customer data or an enterprise running transatlantic operations, the time to prepare for the next disruption isn't after it happens. It's now.

FAQ

Frequently Asked Questions

Yes, as of July 2026 — the adequacy decision has not been repealed or annulled. But it's under more pressure than the April 2026 assessment anticipated: FISA Section 702 lapsed on 12 June 2026 with no reauthorization yet, the PCLOB still lacks a quorum despite a court order to reinstate its fired members, and a June 2026 Supreme Court ruling (Trump v. Slaughter) stripped the FTC of independence the adequacy decision cites 259 times — prompting noyb to demand the Commission withdraw it and prepare a new CJEU challenge. The CJEU's ruling on Latombe's separate appeal (Case C-703/25) isn't expected until late 2026 or 2027.

Companies would need to rely on Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) for EU-US data transfers. Both require Transfer Impact Assessments documenting that US law provides adequate protection — which becomes harder to argue if the CJEU finds it doesn't.

From a legal stability perspective, yes. Switzerland's adequacy decision was granted in 2000 and has never been challenged. Swiss law (FADP) isn't subject to US surveillance frameworks like FISA 702 or the CLOUD Act. However, Swiss hosting alone isn't sufficient — the provider must also implement proper encryption and access controls.

Yes. After two short-term patches, the authority lapsed at midnight on 12 June 2026 — the first lapse since Congress created it in 2008. In practice, surveillance continues under FISA Court certifications approved in March 2026 that remain valid into 2027, so the operational effect has been muted so far. Congress has not reauthorized it as of this writing.

Related Articles

Get started

Put this into practice.

Ciphera builds privacy-first infrastructure — analytics, identity, bot protection, and email that don’t surveil. The tools this article describes are the ones we run.