Cross-Border Transfers

The EU-US Data Privacy Framework: Adequacy Status After Latombe

September 1, 2026

The adequacy decision underpinning EU-US data transfers has been through one court challenge and one periodic review. This post states the status of Implementing Decision 2023/1795 by its own terms, describes the redress mechanism it relies on, and takes the posture of the legal challenge from the General Court's judgment and the notice of appeal rather than from commentary.

Read more →
Cross-Border Transfers

Nobody Defined What a Data Transfer Is, So the Regulators Did It Themselves

August 24, 2026

Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.

Read more →
GDPR

When the GDPR Reaches a US Company, and What It Requires Once It Does

August 12, 2026

The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.

Read more →