18/04/2025 - Since Donald Trump's return to the White House, fears are growing about the future of the DPF. One troubling sign is the resignation of three Democratic members of the independent Privacy and Civil Liberties Oversight Board (PCLOB). This oversight body plays an important role in the DPF. While the resignation does not immediately interfere with the performance of the PCLOB's mission, it raises questions about the sustainability of the DPF. The DPF is crucial for many European companies and U.S. service providers. Without it, companies must find an alternative safeguard for using U.S. cloud services from Amazon (AWS), Microsoft (Azure) and Google (Google Cloud Platform).
Introduction
In this blog, we discuss the Data Privacy Framework (DPF) and the potential consequences of an invalidation. After all, this would not be the first time that transatlantic data transfer agreements have fallen at the Court of Justice of the European Union (CJEU). The DPF's predecessors, Privacy Shield (2020) and Safe Harbor (2000), were both successfully challenged by None of Your Business (NOYB), the privacy organization led by activist Max Schrems. While we recognize that the DPF is relevant to all data transfers to the U.S., this blog will mainly focus on U.S. cloud providers and the storage lense. In addition, we explore an alternative: European storage.
Shortly after the European Commission (EC) adopted the DPF in 2023, Schrems again announced he would challenge the adequacy decision for the DPF at the CJEU. Meanwhile, the re-election of Donald Trump and the resignation of members of the PCLOB, have further heightened concerns about U.S. surveillance practices. The PCLOB is one of the safeguards to ensure that personal data of European citizens is adequately protected when transferred to the United States (U.S.), especially with respect to intelligence and security institutions. Because of this important function, the resignation raises questions about the future of transatlantic data exchange. According to Zsolt Szabó, the State Secretary for Digitalization and Kingdom Relations, recent developments surrounding the resignation of certain members of the PCLOB do not appear to pose an immediate threat to the DPF for the time being. In a Cabinet response, he states that the PCLOB plays an essential role in monitoring and evaluating the DPF. However, the resignation does not directly impede this task. Moreover, the EC continuously monitors developments in third countries that may affect the operation of adequacy decisions. However, the Danish regulator is more skeptical about the use of U.S. cloud providers and advises companies to consider an exit strategy.
In addition, the case T-553/23 (LaTombe v. Commission), in which the DPF is under legal review, is currently pending. French parlement member Philippe La Tombe is demanding the invalidation of the DPF due to, among other things, its effects on the fundamental rights of the European Union (EU). If the case is heard on substance by the CJEU, this could potentially lead to the invalidation of the DPF. The outcome of the ruling could thus determine the future of data transfers from the EU to the U.S. The hearing took place on April 1, 2025.
The General Data Protection Regulation (GDPR) sets strict requirements for the transfer of personal data to countries outside the European Economic Area (EEA), such as the U.S. Transfer of personal data to such third countries is in principle only allowed if the country in question offers an adequate level of protection. The U.S. is not regarded as such, which means that transfer is only possible under one of the legal provisions in Chapter V of the GDPR. Relevant transfer mechanisms are:
Thus, in the context of data exchange from the EU to the U.S., the DPF was adopted as an adequacy decision by the EC. Under the DPF, companies can register if they comply with the rules under the DPF. This allows European companies to share personal data with registered companies in the U.S. without additional safeguards. In preparation for this adequacy decision, the U.S. has implemented several measures to strengthen the protection of personal data. The most significant measure is Executive Order 14086, which President Biden issued in 2022 to ensure compliance with the DPF, through, among other things, oversight by the PCLOB and the right to complain through the Data Protection Review Court (DPRC).
Want to learn more about the DPF and its impact on data transmission? Then read these our in-depth blogs about of the DPF and the contents of Executive Order 14086.
Political developments in the U.S. have clearly shaken up Europe. The European tech sector, united behind the EuroStack-initiative, recently urged the EC in an open letter to take digital sovereignty seriously. They believe that without action, Europe risks becoming almost completely dependent on foreign digital infrastructure within a few years. The letter builds on insights from Mario Draghi's report on European competitiveness, in which he provides recommendations to strengthen the European economy. Building on these insights, the letter calls for a strong European digital ecosystem to reduce dependence on foreign tech giants. The signatories call for a "Buy European" policy in procurement and incentives for the private sector to partner with local tech companies. Moreover, this message fits well with the European Union's strategy "A Competitiveness Compass for the EU" in which the EC intends to fully focus on economic growth and increasing the competitiveness of European companies.
For now, the DPF remains in place and along with the SSC’s will continue to play a crucial role in the data transfers for most organizations. As such, U.S. cloud services remain commercially appealing. However, companies that process sensitive data may want to consider whether digital sovereignty offers a more sustainable path.
Are you working on this topic and looking for a sparring partner? Considerati follows developments closely and is happy to think along with you.
Would you like to learn how your organisation can meet the AI literacy requirements? Contact us for training or tailored advice.
Our services ContactRecente blogs
The right of access is one of the fundamental rights in the General Data Protection Regulation (GDPR). In this blog, we outline the main pitfalls from…