Is the Data Privacy Framework still valid? Yes: as of 11 September 2026 the EU-US Data Privacy Framework remains in force, and organisations can still transfer personal data from the European Economic Area to certified US companies in reliance on it. What has changed is the risk around it. On 29 June 2026 the US Supreme Court held in Trump v. Slaughter that the President may remove Federal Trade Commission commissioners at will, and on 31 July the European Data Protection Board asked the European Commission to closely assess whether that ruling affects the adequacy decision on which the framework rests. With an appeal against the framework already pending at the Court of Justice, and China's new rules for smaller data handlers in force since 1 September, this analysis sets out where transatlantic and international transfers stand, what could happen next and what general counsel should do now.
The short answer: the Data Privacy Framework is still valid, for now
The Data Privacy Framework is still valid because an adequacy decision stays in force until the Commission amends, suspends or repeals it, or the Court of Justice annuls it, and neither has happened. Commission Implementing Decision (EU) 2023/1795, adopted on 10 July 2023, is the legal instrument behind the framework. Nothing in the Supreme Court's judgment, the EDPB's letter or the pending litigation changes its legal effect today.
That matters because the framework is the simplest route for EU-to-US transfers. When the Commission adopted it, it said that personal data could flow safely from the EU to US companies participating in the Framework without additional data protection safeguards. A company that exports data to a certified US recipient does not need standard contractual clauses or a transfer impact assessment for that transfer, provided the recipient's certification is active and covers the type of data sent.
The honest caveat is that the framework now sits under three separate pressures at once: a US constitutional ruling that removes a structural assumption in the adequacy decision, a formal request from Europe's data protection authorities for the Commission to look again, and live litigation that could end in annulment. None of these is a ruling that the framework is invalid. Together, they are the strongest signal since 2023 that transferring organisations should know exactly which of their transfers depend on it and what they would switch to. Groups that rely heavily on US platforms may want to discuss the position with technology, media and telecoms advisers before any change is forced on them.
What the EU-US Data Privacy Framework is and how it works
The EU-US Data Privacy Framework is a self-certification scheme, run by the US Department of Commerce, combined with an EU adequacy decision recognising that certified US companies provide essentially equivalent protection. US organisations sign up to a set of privacy principles, publicly commit to them and appear on the official Data Privacy Framework programme list. The US Department of Commerce states that 10 July 2023 is the date the Commission's adequacy decision entered into force and the effective date of the framework.
The framework was the third attempt at a transatlantic arrangement. Safe Harbour fell in Schrems I in 2015 and the Privacy Shield fell in Schrems II in 2020, in both cases because the Court of Justice found that US surveillance law did not offer protection essentially equivalent to EU law. The 2023 framework answered those concerns with a US Executive Order of 7 October 2022, which limited intelligence access to what is necessary and proportionate, and with a new Data Protection Review Court to hear complaints from EU individuals, as the General Court later summarised.
Take-up has been substantial. The Commission's first periodic review report of 9 October 2024 recorded that more than 2,800 companies had certified, more than under the Privacy Shield in its first year, and that 70% of participants were small and medium-sized enterprises. That profile is important: many of the organisations most exposed to a sudden loss of the framework are not large technology groups with in-house privacy teams, but smaller service providers whose EU customers rely on their certification.
Certification does not displace the rest of the GDPR. The exporter still needs a lawful basis for processing, still owes transparency and still has to honour data subject rights such as the right of access. The framework solves only the Chapter V transfer question.
Trump v Slaughter: what the Supreme Court decided on 29 June 2026
In Trump v. Slaughter the Supreme Court held, by six votes to three, that the statutory rule allowing the President to remove FTC commissioners only for cause is contrary to the constitutional separation of powers. The case was argued on 8 December 2025 and decided on 29 June 2026. Chief Justice Roberts wrote for the majority; Justice Sotomayor dissented, joined by Justices Kagan and Jackson.
The facts were straightforward. The FTC's five commissioners each serve seven-year terms and, under 15 U.S.C. §41, could be removed only "for inefficiency, neglect of duty, or malfeasance in office". Soon after his second term began in January 2025, President Trump dismissed the FTC's two Democratic appointees, Rebecca Slaughter and Alvaro Bedoya, without identifying a statutory cause. Slaughter sued and won in the District Court, which relied on the 1935 decision in Humphrey's Executor. The Supreme Court reversed.
The EDPB's own letter quotes the core of the reasoning: the Court found that the FTC "unquestionably exercises executive power, and must therefore be controlled by the Chief Executive, in whom such power is vested". The practical consequence is that FTC commissioners now serve at the President's pleasure. That is a significant constitutional shift in the United States. For European exporters, and for advisers in the United States who certify clients under the framework, the question is narrower: what happens to an EU adequacy finding that was built partly on the FTC's independence?
The judgment does not mention the Data Privacy Framework, and the FTC continues to exist and to enforce US consumer protection law. The issue is not that US privacy enforcement has stopped. It is that one of the institutional guarantees the Commission relied on in 2023 has changed its character.
Why the FTC matters to the Data Privacy Framework adequacy decision
The FTC matters because it is the main US authority that enforces the framework's commercial privacy principles against certified companies, and the adequacy decision expressly describes it as independent. Under Article 45(2)(b) of the GDPR, the existence and effective functioning of independent supervisory authorities is one of the elements the Commission must take into account when it assesses whether a third country offers adequate protection.
The EDPB letter makes the link explicit. It notes that the adequacy decision, at recitals 58 to 60, "explicitly refers to the independence of the US authorities, including the FTC", and records that its five commissioners "may only be removed by the President for inefficiency, neglect of duty, or malfeasance in office". After Slaughter, that description no longer matches US law.
Critics put the dependence in stronger terms. On the day of the judgment, the privacy group noyb said that the Commission's decision relies on the independent FTC 259 times, and it sent a letter asking the Commission to withdraw the adequacy decision in an orderly way. Its founder, Max Schrems, said: "Given that there are no independent authorities in the US anymore, we call on the European Commission to orderly withdraw the adequacy decision on the US." noyb also said it intended to bring a new challenge before the Court of Justice.
Defenders of the framework answer that the FTC's role is confined to the commercial side. The national security safeguards that Schrems II found wanting are supervised by different bodies, principally the Data Protection Review Court. That distinction, discussed further below, is likely to be central to the Commission's response.
The EDPB letter and the Commission's options
The EDPB has asked the Commission to assess the ruling; it has not declared the framework invalid, and it has no power to do so. In a letter dated 31 July 2026 from its Chair, Anu Talus, to Commissioner Michael McGrath, the Board asked the Commission "to closely assess whether this development affects the functioning of Commission Implementing Decision EU 2023/1795" and said it "would welcome relevant actions, including the continued sharing of information with the EDPB in a timely manner".
The Commission did not immediately respond to press requests for comment on the letter, IAPP reported on 3 August 2026, and no formal public reply had been published by the time of writing. The same report recalled that Commissioner McGrath had previously said there was "too much at stake" to allow the framework to slip.
The Commission's powers here are well established. The General Court noted in its 2025 Latombe judgment that the Commission must monitor the US legal framework continuously and that, if the framework in force at the time of adoption changes, it "may decide, if necessary, to suspend, amend or repeal the contested decision or to limit its scope". In practice, the realistic options range from doing nothing and relying on other US safeguards, through seeking fresh US commitments and amending the decision, to suspension. The adequacy decision also provides for periodic reviews: the first was completed in October 2024, and the review cycle gives the Commission a formal channel to examine the question with US counterparts.
Given the political and economic weight of transatlantic data flows, the likely course is that the Commission will prefer engagement with Washington over withdrawal. But the EDPB's intervention raises the cost of inaction, because national supervisory authorities, including those in Belgium and elsewhere, will look to the Commission's reasoning when handling complaints about US transfers.
The courts: the Latombe appeal and a possible Schrems III
The Data Privacy Framework has already survived one court challenge, and a second, broader one is under way. On 3 September 2025 the General Court dismissed the action brought by Philippe Latombe, a French citizen, in Case T-553/23. It held that the Data Protection Review Court's judges are protected by safeguards ensuring their independence, can be dismissed only by the Attorney General and only for cause, and that bulk collection by US intelligence agencies meets Schrems II because it is subject to ex post judicial review.
Crucially, the General Court assessed the position "on the date of adoption of the contested decision", in July 2023. It did not examine later US developments. Mr Latombe appealed on 31 October 2025. According to the notice of appeal in Case C-703/25 P, he advances four grounds: two on the Data Protection Review Court and the right to an effective remedy, one on bulk collection and the Court of Justice's earlier case law, and one alleging contradictory reasoning about the President's power to update bulk collection objectives under Executive Order 14086. Ireland and the United States are named as other parties.
The appeal has attracted heavyweight support for the Commission. Microsoft said in June 2026 that it had been admitted as an intervener, allowing it to file briefs and take part in oral hearings. EU institutions have not always lost these fights: the Commission's recent record in the Luxembourg courts on digital regulation, including Apple's DMA gatekeeper ruling, shows they can go either way.
A separate challenge by noyb, if filed, could reach the Court of Justice through a national court referral. noyb has itself suggested such proceedings could take two to three years. The practical point is that even a successful challenge is unlikely to produce an overnight change, but the Schrems I and Schrems II precedents show that when the Court does annul an adequacy decision, the effect is immediate and there is no grace period written into the judgment.
Why the FTC ruling does not automatically reach the Data Protection Review Court
The FTC ruling does not automatically undermine the Data Protection Review Court, because the Court's protections come from a different legal source and address a different part of the framework. That is the argument made by Théodore Christakis, Kenneth Propp and Peter Swire in a piece published by IAPP on 8 July 2026, which contends that Slaughter does not undo the EU-US redress mechanism.
The Data Protection Review Court was created by Executive Order 14086 and a Department of Justice regulation. Its judges have fixed terms and may be removed only for cause. The authors stress that the FTC has never had jurisdiction over national security or signals intelligence, which was the core concern in Schrems II. On that view, Slaughter weakens the commercial enforcement pillar but leaves the surveillance redress pillar where it was.
Critics reply that the redress mechanism always rested on executive instruments that a President can amend, which is the thrust of Mr Latombe's fourth ground of appeal. The Court of Justice will ultimately decide how much weight each pillar carries. For transferring organisations, the useful takeaway is that the debate is about degrees of protection rather than a clean on or off switch, which is why a documented risk assessment remains valuable even for transfers to certified recipients.
Fallback mechanisms: standard contractual clauses, BCRs and derogations
If the Data Privacy Framework fell away, most organisations would move to standard contractual clauses, backed by a transfer impact assessment. The current clauses were adopted by Commission Implementing Decision (EU) 2021/914 and are one of the "appropriate safeguards" listed in Article 46 GDPR. Binding corporate rules serve the same purpose inside a corporate group, and Article 49 provides narrow derogations, such as explicit consent or necessity for a contract, for occasional transfers.
There is an important link that is often missed. When it adopted the framework, the Commission said that the US government access safeguards "also apply when data is transferred by using other tools, such as standard contractual clauses and binding corporate rules". That cuts both ways. It made transfer impact assessments for the United States easier after 2023, but it also means that a finding that US safeguards are no longer adequate could weaken the assessments supporting clauses as well. noyb has argued exactly that. A move from the framework to clauses is therefore a change of legal tool, not an escape from the underlying question.
Supplementary measures, such as encryption with keys held in the EU or pseudonymisation, are the main way to strengthen a clause-based transfer. The EDPB's Recommendations 01/2020 on supplementary measures remain the reference text. For multi-jurisdiction groups, cross-border specialists can help map which mechanism fits each data flow.
| Mechanism | Legal basis | Transfer impact assessment needed? | Main strength | Main weakness |
|---|---|---|---|---|
| Data Privacy Framework | Article 45 GDPR, Decision (EU) 2023/1795 | No, for certified recipients | Simple, no contract negotiation | Falls immediately if annulled or withdrawn |
| Standard contractual clauses | Article 46 GDPR, Decision (EU) 2021/914 | Yes | Works with any recipient | Relies on the same assessment of US law |
| Binding corporate rules | Articles 46 and 47 GDPR | Yes | Covers intra-group flows at scale | Slow regulatory approval |
| Article 49 derogations | Article 49 GDPR | No, but strictly construed | Useful for one-off transfers | Not suitable for systematic, repetitive transfers |
What enforcement history says about the cost of getting transfers wrong
Enforcement history shows that transfer failures produce some of the largest GDPR penalties, because regulators treat systematic transfers without adequate protection as serious infringements. Fines under Article 83(5) GDPR can reach €20 million or 4% of total worldwide annual turnover, whichever is higher, and supervisory authorities can also order transfers to stop.
Three decisions stand out. In May 2023 the Irish Data Protection Commission, following a binding decision of the EDPB, fined Meta €1.2 billion and ordered it to suspend future transfers to the US within five months; Meta had relied on the 2021 standard contractual clauses with supplementary measures. In August 2024 the Dutch regulator fined Uber €290 million after finding that it had stopped using standard contractual clauses from August 2021 while sending drivers' data to the US; Uber later moved to the Data Privacy Framework. In May 2025 the Irish regulator fined TikTok €530 million over remote access to EEA user data from China, including €485 million for breach of Article 46(1).
| Case | Regulator | Date | Fine | Transfer issue |
|---|---|---|---|---|
| Meta (Facebook) | Irish DPC, after EDPB binding decision | May 2023 | €1.2 billion | EU-US transfers on SCCs after Schrems II; suspension ordered |
| Uber | Dutch Autoriteit Persoonsgegevens | August 2024 | €290 million | EU-US transfers of driver data with no transfer tool |
| TikTok | Irish DPC | May 2025 | €530 million | Remote access from China under SCCs; laws not properly assessed |
The TikTok decision is instructive for any group with staff outside Europe. The DPC's Deputy Commissioner said the company "failed to verify, guarantee and demonstrate" that data remotely accessed by staff in China received essentially equivalent protection. Remote access counts as a transfer, and Ireland, as lead authority for many large platforms, remains the regulator to watch. EU scrutiny of large platforms is not limited to data law, as the scam advertising complaints against Google, Meta and TikTok under the Digital Services Act show.
The UK position: adequacy to 2031 and the UK Extension
The United Kingdom's own adequacy status with the EU is secure for now: on 19 December 2025 the Commission renewed the two UK adequacy decisions with a sunset clause running until 27 December 2031. The renewal followed a six-month technical extension adopted in June 2025, which gave the Commission time to assess the UK's Data (Use and Access) Act 2025. The Commission and the EDPB will review the decisions after four years.
UK-to-US transfers work differently. The UK built its own "data bridge" as an extension of the EU framework through the Data Protection (Adequacy) (United States of America) Regulations 2023, which took effect on 12 October 2023. A US company must be certified to both the EU-US framework and the UK Extension. The ICO's guidance on how the UK Extension works makes two points worth noting: the UK Extension "would not automatically fall" if the EU framework were invalidated, but if the underlying US commitments deteriorate, "it would be for the UK government to review" it. It also requires UK exporters to flag certain categories, such as genetic, biometric and criminal offence data, as sensitive.
The UK's transfer rules have also changed. Schedule 7 to the Data (Use and Access) Act 2025, which replaces the "essentially equivalent" standard with a "data protection test" asking whether protection is not materially lower than in the UK, came into force on 5 February 2026. For clause-based UK transfers to the US, the ICO has since 2023 accepted that it is reasonable and proportionate to rely on the government's published analysis of US law in a transfer risk assessment. Groups advised in the United Kingdom may therefore find that London reaches its own view on Slaughter, independently of Brussels. Elsewhere, the EU continues to extend adequacy: the Commission finalised a mutual arrangement with Brazil on 27 January 2026.
China: PIPL cross-border transfer routes and the rules in force from 1 September 2026
China regulates personal data leaving the mainland through three routes under the Personal Information Protection Law: a security assessment by the Cyberspace Administration of China, a filed standard contract, or certification by an approved body. Which route applies depends mainly on volume. The Provisions on Promoting and Regulating the Cross-Border Flow of Data, issued by the Cyberspace Administration of China on 22 March 2024, set the thresholds and exemptions that still frame the regime.
| Volume transferred since 1 January of the year | Route | Notes |
|---|---|---|
| Fewer than 100,000 individuals (non-sensitive), or transfers necessary for a contract with the individual, cross-border HR management or emergencies | Exempt from all three routes | Notice, consent and other PIPL duties still apply |
| 100,000 to 1 million individuals (non-sensitive), or sensitive data of up to 10,000 individuals | Standard contract or certification | Certification route operational since 1 January 2026 |
| More than 1 million individuals (non-sensitive), sensitive data of more than 10,000, any important data, or critical infrastructure operators | CAC security assessment | Result valid for three years, extendable |
The certification route was completed by measures released on 14 October 2025 by the Cyberspace Administration of China and the State Administration for Market Regulation, which took effect on 1 January 2026. According to China Briefing, a certificate is valid for three years, and data handlers may not split volumes to avoid the security assessment.
The newest change took effect on 1 September 2026. The Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers, issued on 22 July 2026 by the Cyberspace Administration and the Ministry of Public Security, ease notice, consent, audit and impact assessment duties for handlers processing data of fewer than 100,000 individuals. As Privacy World explains, the cross-border rules stay largely unchanged, with transfer notices, consent and necessity still required, although security assessment applications from small handlers are first reviewed at provincial level before going to the national regulator.
For multinationals, China is the mirror image of the EU problem: data flowing into China from Europe raises the TikTok question, while data flowing out of China triggers the PIPL routes. Businesses with operations in China or Hong Kong need both halves mapped. The Wingtech and Nexperia litigation is a reminder that Chinese and European legal systems increasingly collide in cross-border corporate disputes.
A practical checklist for general counsel
The most useful step now is to know precisely which transfers depend on the Data Privacy Framework, so that a sudden change becomes a planned switch rather than an emergency. Data governance already ranks as a board-level concern in surveys of technology leaders, and international transfers are where that concern becomes legal exposure.
- Map reliance. List every EU and UK transfer to the US and record whether it rests on the framework, clauses, binding corporate rules or a derogation.
- Check certifications. Confirm each US recipient's active status on the Data Privacy Framework list, and for UK data, the UK Extension, including whether HR data is covered.
- Put clauses in place as a backstop. Many data processing agreements already include standard contractual clauses that apply if the framework falls away. Check yours do.
- Refresh transfer impact assessments. Record the Slaughter judgment, the EDPB letter and the Data Protection Review Court position, and document why the assessment still holds.
- Review supplementary measures. Consider encryption with EU-held keys, pseudonymisation and data minimisation for the most sensitive flows.
- Treat remote access as a transfer. The TikTok decision shows that staff access from a third country counts.
- Map China both ways. Check whether outbound China transfers need a standard contract, certification or security assessment, and whether the 1 September 2026 simplified regime applies to any group entity.
- Brief the board. Explain the scenarios and the fallback plan, with the cost of switching.
Security teams should be part of the exercise, since encryption and access controls are the supplementary measures regulators expect. Cyber security advisers can test whether technical measures would actually prevent access in the importing country.
When to take specialist advice on international data transfers
Specialist advice is worth taking when transfers are large, sensitive or central to the business model, when a group operates across the EU, UK, US and China, or when a regulator has already opened questions. The legal position turns on detailed assessments of foreign law, and mistakes have produced nine and ten-figure fines.
For most organisations the Data Privacy Framework is still valid and still the simplest option for transfers to certified US recipients. The question for the coming months is whether the Commission responds to the EDPB, how the Court of Justice rules in Latombe, and whether noyb's promised challenge materialises. The likely effect is that the framework remains usable while those processes run, but prudent exporters will have their fallback ready. Regulatory specialists and data advisers in key markets such as Germany can help stress-test the plan before the next development arrives.
Frequently asked questions
Is the Data Privacy Framework still valid?
Yes. As of 11 September 2026 the EU-US Data Privacy Framework remains in force. Its adequacy decision stays valid until the European Commission amends, suspends or repeals it, or the Court of Justice annuls it. The EDPB has asked the Commission to assess the effect of Trump v Slaughter, but that request does not change the legal position.
What did the Supreme Court decide in Trump v Slaughter?
On 29 June 2026 the US Supreme Court held, by six votes to three, that the law protecting FTC commissioners from removal except for cause breaches the separation of powers. The President may now remove commissioners at will. The ruling overturned the 1935 Humphrey's Executor precedent as applied to the FTC.
Why does the FTC ruling matter for EU-US data transfers?
The FTC enforces the framework's privacy principles against certified US companies, and the 2023 adequacy decision describes it as independent, noting that commissioners could be removed only for cause. Independent supervision is a factor the Commission must weigh under Article 45 GDPR, so the ruling reopens part of the adequacy assessment.
What happened to the EU-US Privacy Shield framework?
The Court of Justice invalidated the Privacy Shield in its Schrems II judgment in July 2020, finding that US surveillance law did not provide protection essentially equivalent to EU law. Its predecessor, Safe Harbour, fell in Schrems I in 2015. The Data Privacy Framework replaced the Privacy Shield in July 2023.
What happens if the Data Privacy Framework is invalidated?
Transfers relying on it would lose their legal basis, and past annulments took effect immediately. Organisations would need standard contractual clauses, binding corporate rules or a narrow Article 49 derogation, backed by a transfer impact assessment. Because US safeguards also underpin those tools, the assessments would need revisiting.
Do US companies need to comply with GDPR?
US companies must comply with the GDPR when they offer goods or services to people in the EU or monitor their behaviour, or when they process data as part of an EU establishment. Separately, US companies receiving EU data under the Data Privacy Framework must follow its privacy principles.
Do standard contractual clauses need to be signed?
Standard contractual clauses are a contract, so both exporter and importer must agree to them, usually by signing or incorporating them into a data processing agreement. The parties must use the Commission's approved text without changing its substance, complete the annexes and carry out a transfer impact assessment.
Does the UK-US data bridge fall if the EU framework is struck down?
Not automatically. The ICO says the UK Extension would not automatically fall if the EU-US framework were invalidated, because it rests on separate UK regulations. But the UK government would need to review it if the underlying US commitments deteriorated, so UK exporters should plan a fallback too.
What changed in China's data rules on 1 September 2026?
Simplified rules for small-scale personal information handlers, those processing data of fewer than 100,000 individuals, took effect. They ease notice, consent and audit duties, but cross-border transfer requirements stay largely unchanged, with provincial authorities now carrying out an initial review of security assessment applications from these handlers.
Sources
- Supreme Court of the United States: Trump v. Slaughter, No. 25-332 (decided 29 June 2026)
- European Data Protection Board: Letter to Commissioner McGrath on Trump v. Slaughter (31 July 2026)
- IAPP: EDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter (3 August 2026)
- IAPP: No, Trump v. Slaughter does not undo the EU-US data-transfer redress mechanism (8 July 2026)
- noyb: US Supreme Court just blew up EU-US data transfers (29 June 2026)
- Court of Justice of the EU: Press release 106/25, Latombe v Commission (3 September 2025)
- Official Journal: Case C-703/25 P, Latombe v Commission, appeal lodged 31 October 2025
- The Register: Microsoft to assist European Commission in defence of EU-US data-sharing agreement (29 June 2026)
- European Commission: adoption of the EU-US Data Privacy Framework adequacy decision (10 July 2023)
- European Commission: Report on the first periodic review of the EU-US Data Privacy Framework (9 October 2024)
- US Department of Commerce: Data Privacy Framework Program Overview
- EUR-Lex: Regulation (EU) 2016/679 (GDPR)
- EUR-Lex: Commission Implementing Decision (EU) 2021/914 on standard contractual clauses
- EDPB: Recommendations 01/2020 on supplementary measures
- Data Protection Commission: Inquiry into Meta Platforms Ireland's EU-US data transfers
- Autoriteit Persoonsgegevens: Dutch DPA fines Uber €290 million over transfers of drivers' data to the US
- Data Protection Commission: TikTok fined €530 million over transfers of EEA user data to China (2 May 2025)
- European Commission: renewal of UK adequacy decisions (19 December 2025)
- legislation.gov.uk: Data Protection (Adequacy) (United States of America) Regulations 2023
- ICO: How does the UK Extension to the EU-US Data Privacy Framework work?
- legislation.gov.uk: Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026
- DAC Beachcroft: UK-US data bridge, ICO publishes updated TRA guidance (January 2024)
- IAPP: Brazil, EU finalise adequacy agreement (January 2026)
- China Law Translate: Provisions on Promoting and Regulating the Cross-Border Flow of Data (March 2024)
- China Briefing: China releases cross-border data transfer certification measures (October 2025)
- Privacy World: China introduces simplified personal information protection regime for small-scale handlers (6 August 2026)
About this article
This analysis was researched and written by The Corporate INTL Newsroom, which covers cross-border legal, regulatory and business developments for lawyers, professional advisers and financiers in over 150 jurisdictions. It has been checked against the US Supreme Court's judgment, the EDPB's letter, the Court of Justice's published materials, the texts of the GDPR and the relevant Commission decisions, UK legislation and regulator guidance, Chinese regulations in translation and primary reporting. The European Commission had not published a formal response to the EDPB's letter at the time of writing. This article is general information, not legal advice; for advice on a specific matter, consult a qualified adviser. Last reviewed 11 September 2026. For more analysis like this, visit the Corporate INTL newsroom or subscribe to Corporate INTL.