The EU-US Data Privacy Framework: Adequacy Status After Latombe
Key Takeaways
- Article 1 of Commission Implementing Decision (EU) 2023/1795, adopted 10 July 2023, finds that the United States ensures an adequate level of protection for personal data transferred to organisations on the Data Privacy Framework List maintained by the US Department of Commerce.
- In Case T-553/23, Latombe v Commission, the General Court on 3 September 2025 dismissed the action for annulment in its entirety, so the decision was not annulled and remains in force.
- An appeal against that judgment was brought on 31 October 2025 as Case C-703/25 P and published in the Official Journal on 22 December 2025, raising four grounds directed at the Data Protection Review Court and at bulk collection.
- The Commission's first periodic review, COM(2024) 451 final of 9 October 2024, concluded that the necessary structures and procedures are in place and set the next periodic review at three years.
- The UK operates a separate instrument: SI 2023/1028, in force 12 October 2023, covers transfers only to organisations listed as participating in the UK Extension.
What the Adequacy Decision Did
Commission Implementing Decision (EU) 2023/1795 was adopted on 10 July 2023. Its operative part is short. Article 1 provides that "[f]or the purpose of Article 45 of Regulation (EU) 2016/679, the United States ensures an adequate level of protection for personal data transferred from the Union to organisations in the United States that are included in the 'Data Privacy Framework List', maintained and made publicly available by the U.S. Department of Commerce."
Two features of that sentence do the work. The finding is not about the United States at large; it is about organisations on a particular list. And it is a finding under Article 45, which is one route in Chapter V of the GDPR rather than the only one.
Article 3 sets the conditions under which the finding is kept under observation. The Commission "shall continuously monitor the application of the legal framework that is the object of this Decision, including the conditions under which onward transfers are carried out, individual rights are exercised and U.S. public authorities have access to data." Article 3(3) obliges Member States and the Commission to inform each other of "any indications that the interferences by U.S. public authorities . . . go beyond what is necessary and proportionate." Article 3(5) then provides that where the Commission has indications that adequate protection is no longer ensured, "[i]f necessary, it will decide to suspend, amend or repeal this Decision, or limit its scope, in accordance with Article 45(5)" — and that it may do so where a lack of cooperation from the US government prevents it from making the assessment at all.
The Redress Mechanism
The finding rests substantially on Executive Order 14086 of 7 October 2022, published at 87 Fed. Reg. 62283. The order confines signals intelligence collection to an enumerated list of legitimate objectives and provides that such activities "shall be conducted only to the extent and in a manner that is proportionate to the validated intelligence priority for which they have been authorized, with the aim of achieving a proper balance between the importance of the validated intelligence priority being advanced and the impact on the privacy and civil liberties of all persons."
It defines the contested category expressly: "'Bulk collection' means the authorized collection of large quantities of signals intelligence data that, due to technical or operational considerations, is acquired without the use of discriminants (for example, without the use of specific identifiers or selection terms)."
Redress runs in two layers. The first is the Civil Liberties Protection Officer of the Office of the Director of National Intelligence. The second is the Data Protection Review Court, before which "a special advocate" advocates "regarding the complainant's interest in the matter." As the General Court recorded, the order "was supplemented by Attorney General Order No 5517-2022 . . . which added Part 201 to Title 28 of the Code of Federal Regulations (CFR), governing the establishment and functioning of the Data Protection Review Court." That the DPRC was created by an act of the executive rather than by Congress became one of the contested points.
Self-Certification Through Commerce
Participation is voluntary at the outset and binding once undertaken. Organisations self-certify to the Department of Commerce and, as the decision records, must "re-certify their adherence to the Principles on an annual basis." As part of that process they are "required to publicly declare their commitment to comply with the Principles, make their privacy policies available and fully implement them." An organisation that leaves the framework "must remove all statements implying that the organisation continues to participate."
Supervision on the commercial side is allocated to existing US regulators rather than to a new body. The decision assigns it principally to the Federal Trade Commission, with the Department of Transportation competent for airlines and ticket agents.
The UK Extension
The United Kingdom did not join the EU instrument; it made its own. The Data Protection (Adequacy) (United States of America) Regulations 2023, SI 2023/1028, were made on 20 September 2023, laid before Parliament on 21 September and came into force on 12 October 2023, under section 17A of the Data Protection Act 2018.
Regulation 3 is narrower than a country-level finding. It covers a transfer of personal data which "(a) is to a person in the United States of America who is indicated on the Data Privacy Framework List as participating in the UK Extension to the EU-US Data Privacy Framework; and (b) will be subject to the EU-US Data Privacy Framework Principles on receipt by that person." Regulation 4 names the independent supervisory authorities as the Federal Trade Commission and the Department of Transportation. Because it is a separate statutory instrument resting on UK powers, its fate is not determined by the outcome of proceedings in the EU courts.
The Challenge in the General Court
In Case T-553/23, Latombe v Commission, the General Court (Tenth Chamber, Extended Composition) delivered judgment on 3 September 2025. Ireland and the United States of America intervened in support of the Commission. The applicant withdrew his first plea at the hearing, leaving four.
The third plea argued that the DPRC is not an independent and impartial tribunal previously established by law under the second paragraph of Article 47 of the Charter, being "a quasi-judicial body forming part of the executive branch" created "by an act of the executive, namely a decision of the Attorney General." The Court rejected both complaints.
The second plea argued that bulk collection is not subject to prior authorisation by a judicial or administrative authority. The Court held that "there is nothing in the judgment in Schrems II, in particular in paragraph 183 of that judgment or in the expression 'any judicial review', to suggest that the bulk collection of personal data must necessarily be the subject matter of prior authorisation issued by an independent authority," and that reading the expression together with paragraphs 186 to 197 shows "the decision authorising bulk collection must be subject, as a minimum, to an ex post facto judicial review." It found that such review is provided by the DPRC, "whose decisions are final and binding." The Court also observed that Section 702 of FISA "does not authorise bulk collection, but rather only targeted collection," and so "has no relevance in the present case."
The fourth plea concerned Article 22 of the GDPR and wholly automated decisions; the fifth concerned security of processing. Both were rejected, and "the action must be dismissed in its entirety." The operative part dismisses the action and orders the applicant to pay the Commission's costs.
The judgment did not end the litigation. An appeal was brought on 31 October 2025 as Case C-703/25 P, published in the Official Journal on 22 December 2025. The appellant asks the Court of Justice to set the judgment aside and, ruling in its place, to annul Implementing Decision 2023/1795, or in the alternative to refer the case back. The four grounds allege, in outline: error in holding that the rules for appointing and dismissing DPRC judges do not undermine the Article 47 safeguards; error in treating the formal nature of the instrument establishing the DPRC as irrelevant to whether it is "previously established by law"; three errors in the ruling that ex post facto review suffices for bulk collection; and contradictory reasoning on the President's power to update the list of bulk collection objectives.
What a Vacatur Would Mean for Standard Contractual Clauses
The status point first, because it is the one most often stated loosely. The General Court dismissed the action, so Implementing Decision 2023/1795 was not annulled. It remains in force by its own terms, and the pending appeal seeks to set aside a judgment that upheld it rather than to disturb an annulment. What the Court of Justice will do with the four grounds is unresolved.
As to the separate mechanisms, the boundary is worth stating precisely. The decision is a finding under Article 45. Standard contractual clauses are a different instrument, adopted under Article 46, and neither the judgment nor the notice of appeal addresses them: the pleas and the grounds are directed at the Commission's Article 45 assessment. Annulment of an Article 45 decision would not by its own terms annul an Article 46 instrument.
What the two share is subject matter rather than legal form. The grounds of appeal attack features of United States law — the composition and legal basis of the DPRC, and the absence of prior authorisation for bulk collection — that exist independently of which Chapter V mechanism a transfer relies on. The General Court assessed those features in the course of reviewing an Article 45 finding. How any ruling on them would bear on assessments made under other mechanisms is not addressed in either document, and this post does not extrapolate beyond what they say.
The Periodic Review Cycle
Article 3(4) requires the Commission to evaluate the Article 1 finding "[a]fter one year from the date of the notification of this Decision to the Member States and subsequently at a periodicity that will be decided in close consultation with the Committee established under Article 93(1) of Regulation (EU) 2016/679 and the European Data Protection Board."
That first review produced COM(2024) 451 final, dated 9 October 2024. The Commission concluded "that the U.S. authorities have put in place the necessary structures and procedures to ensure that the Data Privacy Framework functions effectively," while noting that "experience with the practical application of the safeguards . . . is necessarily limited after just one year of operation." It identified three things to watch: the PCLOB's reports on the implementation of EO 14086 and on the redress mechanism; possible further amendments to Section 702 of FISA; and the nomination and appointment of members to fill upcoming PCLOB vacancies. It considered it appropriate "to carry out the next periodic review after three years."
The European Data Protection Board's own report, adopted 4 November 2024, took note of that suggestion and "welcome[d] that the European Commission is therefore not proposing to apply the statutory maximum period of four years," stating that "[a] review within three years or less would allow the Commission and the EDPB to more swiftly obtain comprehensive information about the practical application of the DPF." The Board also emphasised that adequate protection "must be ensured also with regard to the governmental acquisition of personal data by U.S. intelligence agencies from data brokers and other commercial entities that is not captured by EO 14086."
On those documents, the position is that the decision is in force, one periodic review has been completed, the next was set for three years from October 2024, and an appeal against the judgment upholding the decision is pending before the Court of Justice.
Background
For the underlying law rather than this development: Technology & SaaS privacy law.
Frequently Asked Questions
Is the EU-US Data Privacy Framework adequacy decision still in force?
What did the General Court actually decide in Latombe v Commission?
What are the grounds of the pending appeal?
Does the adequacy decision cover every US company?
How does the UK arrangement differ?
When is the next review of the framework due?
Sources
Everything above is reported from these documents. Follow them to verify.
- Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 pursuant to Regulation (EU) 2016/679 on the adequate level of protection of personal data under the EU-US Data Privacy Framework (July 10, 2023) regulation
- Judgment of the General Court (Tenth Chamber, Extended Composition) of 3 September 2025, Case T-553/23, Latombe v Commission, ECLI:EU:T:2025:831 (September 3, 2025) court opinion
- Appeal brought on 31 October 2025 by Philippe Latombe against the judgment in Case T-553/23 (Case C-703/25 P), OJ C/2025/6610 (December 22, 2025) docket
- Executive Order 14086 of 7 October 2022, Enhancing Safeguards for United States Signals Intelligence Activities, 87 Fed. Reg. 62283 (October 14, 2022) regulation
- Report from the Commission to the European Parliament and the Council on the first periodic review of the functioning of the adequacy decision on the EU-US Data Privacy Framework, COM(2024) 451 final (October 9, 2024) agency release
- EDPB Report on the first review of the European Commission Implementing Decision on the adequate protection of personal data under the EU-US Data Privacy Framework, adopted 4 November 2024 (November 4, 2024) agency guidance
- The Data Protection (Adequacy) (United States of America) Regulations 2023, SI 2023/1028 (September 20, 2023) regulation
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.