What Trump v. Slaughter Reveals About the Limits of Legal Privacy Protections

Privacy laws create rights and obligations. Encryption makes guarantees. The difference between the two just got a lot less abstract. As of June 2026, the U.S. Supreme Court cast doubt on one of the pillars holding up the EU–U.S. Data Privacy Framework (DPF). Here is why that matters and why some protections survive that kind of change while others do not. 

Two Categories of Privacy Protection 

It is worth distinguishing between two categories of privacy protection: those that depend on continued institutional cooperation or private-party compliance and those that do not. The first category is precisely what the GDPR covers in its Article 45 (Transfers on the basis of an adequacy decision) and Article 46 (Transfers subject to appropriate safeguards) when addressing transfers of personal data to third countries.

An adequacy decision under Article 45 GDPR is conditional on the European Commission’s continued assessment that a third country provides “an adequate level of protection.” The European Commission is obligated to monitor and revisit such a decision, as it can be withdrawn if the underlying facts change. Where an adequacy decision is in force, transfers may proceed without further action by the parties. Transfers under Article 46 GDPR apply where no adequacy decision exists and place the burden on the parties themselves. The exporter and importer must put appropriate safeguards in place, such as Standard Contractual Clauses (SCCs) adopted by the European Commission or Binding Corporate Rules (BCRs) approved by the competent supervisory authority. SCCs are, at their core, a contract: their protection depends on the contracting parties’ own continued compliance with their terms and on the courts and regulators behind them continuing to honor and enforce those terms, with no independent mechanism forcing that compliance day to day. Additionally, per the European Court of Justice decision in Schrems II, SCCs remain subject to an ongoing, case-by-case judicial assessment of whether the destination country’s law in fact permits the parties to honor them at all. Both of these GDPR mechanisms, in the end, are conditional on not being reinterpreted or struck down by a competent court, revoked by the European Commission or, in the case of a contract, simply dishonored by the parties. In short, both fall into the same category: protections that persist only for as long as the institutions or parties behind them continue to perform. 

Strong encryption operates on a fundamentally different basis. Where end-to-end encryption is properly implemented, such that the decryption key is retained exclusively by the sender or data subject and at no point transmitted to or held by the service provider, that service provider holds nothing capable of being produced in intelligible form, whether in response to a subpoena, a warrant, a court order, or a regulatory demand for disclosure. For example, messaging providers encrypt message content end-to-end based exactly on this model: the content is mathematically inaccessible to the provider, regardless of any legal pressure applied, since compulsion cannot extract a key the provider was never given. What remains available to the provider, and thus to any compelling authority, is metadata: who sent a message, who received it, and when.  

This guarantee rests on no policy, no contractual undertaking, and no institutional forbearance. It is a property inherent in the cryptographic construction itself, and it holds irrespective of the identity of the requesting party, the forum in which the request is made, or the legal authority invoked in its support. 

Distinguishing between protection that depends on continued institutional or private-party behavior and protection that does not may appear abstract as a matter of doctrine, but the recent U.S. Supreme Court judgment in Trump v. Slaughter demonstrates that it is not. 

Impact of the Trump v. Slaughter Decision on EU–U.S. Data Transfer

On June 29, 2026, the U.S. Supreme Court decided Trump v. Slaughter (“Slaughter”), overturning Humphrey’s Executor v. United States, a 1935 precedent that had protected the heads of independent agencies such as the Federal Trade Commission (FTC) from being removed by the U.S. president except “for cause.” For nine decades, that protection meant FTC commissioners could set enforcement priorities somewhat independently of the executive. Following Slaughter, FTC commissioners can be removed at the U.S. president’s discretion, as can any other executive appointee. 

The FTC is the primary federal enforcer of U.S. data privacy law through mechanisms such as the Children’s Online Privacy Protection Act (COPPA), Section 5 unfair-and-deceptive-practices actions, and data breach consent decrees. That role provided U.S. privacy enforcement a claim to consistency across changes in administration, a claim Slaughter has now considerably weakened. 

Whether Slaughter‘s effects also reach the DPF, which rests on the European Commission’s adequacy decision under Article 45 GDPR, is unclear. The European Commission’s determination that the U.S. offers protection “essentially equivalent” to the GDPR relied on several distinct independence mechanisms. In particular, it relied on the FTC’s credibility as an independent enforcer of participants’ DPF commitments, the Privacy and Civil Liberties Oversight Board’s (PCLOB) independent oversight of U.S. surveillance practices, and the Data Protection Review Court’s (DPRC) independent redress mechanism for EU data subjects (see Commission Implementing Decision (EU) 2023/1795). Of the three, the FTC’s independence is the clearest loss after Slaughter. The PCLOB’s independence is nearly as unsettled. After the U.S. president removed three of its members without cause in January 2025, it lost its quorum (see LeBlanc v. U.S. Priv. & C.L. Oversight Bd., No. 25-cv-542 (RBW), 2025 WL 1454010 (D.D.C. May 21, 2025)). The ongoing litigation over that removal was deferred pending Slaughter and is now expected to proceed under its holding. The DPRC’s independence is the genuinely contested case. While it might be argued that Slaughter applies equally here, with real consequences for the DPF’s future, it is worth keeping in mind that Slaughter addressed a case where Congress constrained the president. The DPRC’s independence rests instead on an executive order and Department of Justice regulation, with the executive constraining itself, a distinction Slaughter did not decide.

The European Data Protection Board (EDPB) has already acted on the uncertainty. On July 31, 2026, it wrote to the European Commission asking it to formally assess whether Slaughter affects the FTC’s ability to uphold its DPF commitments. The Commission has not yet indicated what, if anything, it will do in response. NOYB — the European privacy advocacy organization founded by Max Schrems, which has spent a decade challenging EU–U.S. transfer mechanisms — has already sent the European Commission a letter arguing for withdrawal of the adequacy decision and is reportedly preparing a further legal challenge at the European Court of Justice on these grounds. 

As the DPF’s adequacy decision is now in question, so too is whether SCCs offer a genuine alternative. The case-by-case assessment SCCs require rests on the same PCLOB and DPRC oversight discussed above, in addition to the unresolved tension between SCC compliance guarantees and surveillance authority under FISA Section 702. NOYB has maintained that no enforcement mechanism can remedy this defect, as the deficiency inheres in the surveillance law itself rather than in the institution charged with its oversight. 

Slaughter is a demonstration of how conditional legal protections behave. The FTC’s independence was itself such a protection, in the form of a statutory guarantee that endured for 90 years until a single judgment removed it. Thus, both of the GDPR’s principal transfer mechanisms to the United States now rest, at least in part, on foundations whose stability is newly in doubt. 

Where the Legal Mechanism Ends and Technical Measures Begin 

This is not a gap EU regulators have overlooked. In the wake of Schrems II, the EDPB issued Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data. The Recommendations set out what is required when the legal transfer mechanism alone cannot guarantee that level of protection: supplementary measures, with technical measures treated as the most robust category because they can hold even when the law of the destination country does not. 

Foremost among these is strong encryption: data encrypted in transit and at rest, with the decryption keys held by the data exporter or the data subject and never accessible to the importer. Properly implemented, this leaves no plaintext for a governmental authority to compel because the party from whom production is sought never possessed it. A subpoena may reach a company’s servers, but it cannot reach a key the organization never held.

The EDPB identifies further measures. Pseudonymization, whereby identifying information is separated and retained by the exporter such that what crosses the border is not reconstructible into personal data without a key the importer does not possess, is one such measure. It is weaker than encryption for present purposes but useful when combined with it. Split or multi-party processing, whereby no single processor holds a complete, re-identifiable dataset, is another — an architecture characteristic of multi-party computation and threshold cryptography designs. Contractual and organizational measures (for example, audit rights, transparency undertakings, and access policies) complete the EDPB’s list, though the EDPB itself acknowledges that such measures cannot override a hostile surveillance law, as their efficacy remains contingent on the counterparty government’s continued willingness to comply. 

Encryption, pseudonymization, and split processing do not depend on any party’s continued proper conduct. They alter what is technically possible, not merely what is committed to.

What “Strong Encryption” Must Mean in Practice

That claim, however, holds only if the encryption in question satisfies a specific technical standard, rather than simply carrying that designation. As the term “encrypted” is applied to a wide range of implementations of varying technical rigor, it does not reliably indicate that the underlying implementation delivers the property it purports to guarantee. 

Translating the EDPB’s own guidance into concrete technical terms, encryption capable of holding independent of the legal environment should generally exhibit several characteristics.  Foremost among these is a sound algorithm, correctly implemented. Architectural controls cannot compensate for a weak or outdated cipher or for a flawed implementation of a good one, as either introduces risks for deducing or recovering plaintext or its properties without any legal process at all. Equally necessary is end-to-end design, such that the party from whom disclosure is sought never possessed the means of decryption in the first place. This requires that keys be held by the controller or the data subject rather than the provider, since a party holding both ciphertext and key can be compelled to produce both. Another requirement is the absence of any exceptional-access mechanism. There cannot be a backdoor or a key escrow — a spare copy of the key held by a third party, ostensibly for recovery, but itself a target for compulsion. Nor can there be a “lawful access” exception — a legally mandated decryption capability built into the system for use by government authorities upon presentation of valid legal process, distinguished from a backdoor only by being authorized rather than undisclosed.

None of this substitutes for a lawful basis for the transfer in the first place. Adequacy decisions, BCRs and SCCs remain necessary as the legal foundation. Properly implemented encryption supplies a layer of protection consistent with what the EDPB’s guidance calls for on top of that foundation. It is a form of protection that does not depend on the legal mechanism’s continued validity.

Why Encryption Requires Independent Auditing

Each of the foregoing requirements is easy to state as a principle. Building a system that actually satisfies it is another matter. Verifying that it does so is harder still.  

The phrase “end-to-end encrypted” is a common example. The label often describes the encryption of message content correctly, without describing what other factors (key custody, recovery paths, and logging) determine whether the party from whom disclosure is sought can produce anything usable in response. A vendor’s design document is another example. It may represent that keys are held solely by the data subject. However, this is only a description of intended architecture, not a guarantee that the implementation matches it. Whether it does is what an independent security audit assesses. The audit can evaluate whether the key-derivation process harbors a weakness rendering the key recoverable. It can check whether a “recovery” or “support access” feature quietly reintroduces the exceptional-access path the design purports to exclude. It can trace whether logging at any point in the pipeline captures plaintext or key material in a form discoverable under legal process. And it can examine whether an escrow arrangement, protective on its face, in substance places a usable copy of the key with a second party and identify who controls that copy and under what technical conditions it could be accessed or reconstructed. None of this is ascertainable from that design document, however detailed. It can be established only through review of the implementation itself, including the code, key-management architecture, and protocol design, assessed against the representation made for it. 

A security audit’s findings, however, are only as reliable as the access it is given. An auditor who is shown a curated environment or denied access to the full implementation cannot detect what they are not permitted to see. What an audit adds over a whitepaper or design document is not certainty but a meaningfully higher barrier to hiding relevant parts of the system, provided the audit itself has genuine, verified access to the system it examines. 

A claim alone is not enough. An audit verifies whether that claim actually holds. 

Where This Leaves Privacy Protection 

Legal protections remain indispensable and worth every effort to build and defend. Most organizations, in practice, rely on adequacy decisions, BCRs, or SCCs to transfer data internationally. For EU–U.S. transfers specifically, the DPF is the relevant adequacy decision. All of these mechanisms rest on the assumption that the institutions and parties behind them will continue to behave as they always have. Slaughter tested that assumption and, in a single decision, ended an independence that had held for 90 years. Encryption, by contrast, is the layer of protection that does not depend on the continued conduct of any institution or party. That is precisely why it is the layer that warrants particular attention. 

The effectiveness of that protection, in turn, depends entirely on implementation. Where an organization relies on an encryption or key-management claim to satisfy a supplementary-measures requirement, it should establish in advance whether that claim in fact holds rather than waiting for a regulator, a court, or a third party to test it. That is the function an independent security audit performs. 

 

Written by: Dr. Dorothee Landgraf

Archives