What happened

The European Data Protection Board (EDPB) has sent a letter to the European Commission asking it to review the EU-US Data Privacy Framework. The background is a US Supreme Court ruling concerning the independence of the US regulator, the FTC, which the EDPB says may affect the safeguards the agreement rests on. Hunton and IAPP have summarised the situation, and Sweden's data protection authority IMY has noted that the ruling may affect transfers to the US.

Important: the adequacy decision from July 2023 still stands. The EDPB has written a request, not a ruling.

Why it concerns an ordinary company

The Data Privacy Framework is the legal basis that makes it easy to use US services. Microsoft 365, Google Workspace, most CRM and support tools, and by now nearly every AI service. If you hold employee or customer personal data in any of them, which you do, it rests in practice on this agreement.

This is also the third time the same thing has happened. Safe Harbour fell in 2015. Privacy Shield fell in 2020. Each time, thousands of European companies stood wondering what to do. The pattern is clear enough that it pays to prepare once, properly.

But do nothing drastic because of a letter

Here we want to be straight, because this question attracts alarming headlines. A letter from the EDPB does not mean your cloud services become unlawful tomorrow. IAPP has published a well-argued counter-analysis holding that the redress mechanism the agreement relies on survives the ruling.

Panic-migrating your whole operation to a European cloud because a regulator wrote a letter is expensive, disruptive and probably unnecessary. Not knowing which vendors you have, and on what basis you send data to them, is a problem regardless of how this question ends.

What we recommend

  • Make a vendor list. Which services process personal data for you, where are they, and on what legal basis? It takes an afternoon and costs nothing.
  • Note which ones are American. Those are the ones affected if the agreement changes. You want to know which they are before you need to know.
  • Ask your most important vendors what their plan B is. The large ones already have answers, for example about EU data residency. It costs you an email.
  • Move nothing in a panic. Make decisions when there is a decision to respond to, not when there is a headline.

This kind of mapping is part of our IT consulting: documented, in plain language and vendor-neutral. Want to know where your personal data actually goes today? Book a free consultation.