The EU-US data deal just lost its referee. Here's what that means.
Fabian, Founder of Bitflake July 8, 2026
Europe and the US have made three data deals. Two got struck down. The third just lost its referee, putting it on shaky ground.
First, does this affect you?
If you use any US services, almost certainly. Personal data covers anything that identifies a person: the emails in your inbox, client contacts in your CRM, employee records, even Slack messages that mention people. If your company uses Google Workspace, Microsoft 365, Slack, or Dropbox, this is about your data. Only purely internal numbers and anonymised data are unaffected.
So why do these EU-US data deals exist at all?
European law says personal data can only leave Europe if it gets the same level of protection abroad as it does at home. The US doesn't guarantee that by default. US surveillance agencies can access data held by US companies, and Europeans have almost no effective legal way to challenge it.
Every few years, the US makes a set of promises: safeguards, limits, and independent watchdogs that European customers can complain to. The European Commission considers those promises "good enough" and allows data to be legally stored in the US. The deal requires the promises and someone independent enforcing them.
Europe and the US have tried this three times now
- 2015: Safe Harbour struck down (Schrems I). Promises were self-certified, barely checked.
- 2020: Privacy Shield struck down (Schrems II). Surveillance still unchecked, no real remedy for Europeans.
- 2023: The Data Privacy Framework replaces it. New safeguards and watchdogs, same underlying problem.
What just changed
Each time, European courts found the promises weren't actually enforceable. And now the third deal has the same problem. The US Supreme Court ruled that the Federal Trade Commission (FTC), the deal's referee, may no longer be independent from the President. The FTC is the body that punishes US companies when they break their privacy promises: using your data for things they said they wouldn't, ignoring deletion requests, selling it on.
The EU-US data deal cites the FTC 259 times. Its enforcement is what made the deal's promises work. The surveillance oversight bodies have already been gutted, and now the commercial watchdog has lost its independence too.
It's not just an EU problem
The UK's own version, the UK-US data bridge, is built on the same commitments and enforcement. If the EU framework falls, it sits on the same shaky ground.
Max Schrems and his privacy organisation noyb are calling on the European Commission to withdraw the deal entirely. They are filing a lawsuit in the coming weeks to get it annulled, like the last two — likely starting a process towards a "Schrems 3".
So what now?
Nothing changes tomorrow. The deal stays formally in force until it's withdrawn or struck down, which takes time. But the pattern matters more than this one ruling. At some point the question stops being "Is this deal safe?" and becomes "Why does my company depend on this deal at all?"
It doesn't have to. European and open-source alternatives now exist for almost every tool in a typical stack, from file storage to team chat.
That's the part I'm building Bitflake for. Your tools, running on servers in your country, under laws that don't change every time a US court makes a ruling.