International data transfers are constantly evolving, and recent developments on both sides of the Atlantic are a reminder that organisations should regularly review how they transfer personal data across borders.
On 29 June 2026, the US Supreme Court issued its decision in Trump v. Slaughter, ruling that the US President can remove Commissioners of the US FTC (Federal Trade Commission) at any time. The FTC is one of the key authorities responsible for overseeing organisations certified under the EU-US DPF (Data Privacy Framework).
As a result, the decision has raised questions about the future of the DPF and whether it could face legal challenges.
What does this mean for your organisation?
For now, nothing has changed. The EU-US Data Privacy Framework remains a valid way to transfer personal data from Europe to participating organisations in the United States, and organisations already relying on the DPF can continue to do so.
The European Commission has confirmed that it is reviewing the implications of the Supreme Court’s decision. However, at the time of writing, it has not announced any plans to suspend or withdraw the DPF. In any case, the decision is a useful reminder that international data transfer rules can change. Many organisations will remember the replacement of Safe Harbor with Privacy Shield, followed by the introduction of the current Data Privacy Framework. Building a flexible and resilient approach to international data transfers is becoming increasingly important.
Europrivacy and Interprivacy
Alongside these developments, there has also been positive news from Europe earlier this year.
On 16 April 2026, the EDPB (European Data Protection Board) adopted two important Opinions on the Europrivacy certification scheme. The first extends the Europrivacy certification to organisations outside the European Economic Area that are subject to the GDPR.
The second approves a specific version of the Europrivacy certification criteria to be used, together with binding and enforceable commitments, as an appropriate safeguard for international data transfers under Articles 42 and 46 GDPR. This is the first GDPR certification approved for this purpose.
This provides organisations with an additional option to support international data transfers while demonstrating a strong commitment to privacy and data protection.
The international extension of the scheme, Interprivacy, further supports organisations operating across multiple jurisdictions by providing a recognised framework for international privacy governance.
Why consider certification?
International data transfers are becoming increasingly complex. Organisations need to demonstrate not only that they comply with legal requirements today, but also that they have a robust and adaptable privacy programme for the future.
Recognised certifications such as Europrivacy and Interprivacy provide organisations with an opportunity to strengthen their privacy governance, demonstrate accountability through independent assessment, and enhance confidence among customers, business partners and regulators.
Overall certifications could strengthen an organisation’s international data transfer strategy and support your wider privacy and compliance objectives.