PrivacySignal
GDPR / Intl

EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence

Hunton Andrews Kurth LLP · · International · GDPR & International

The European Data Protection Board has called for a review of the EU-U.S. Data Privacy Framework following a U.S. Supreme Court decision affecting the independence of the Federal Trade Commission, which serves as a key enforcement body underpinning the transatlantic data transfer agreement.

Why this matters: The whole EU-U.S. data transfer deal rests on a promise: that American regulators will actually enforce privacy rules for Europeans whose data lands in the U.S. The FTC is the main enforcer making that promise credible. If a Supreme Court ruling weakens the FTC's independence, the EDPB has every reason to ask whether the deal still holds. Companies that moved data flows to rely on the framework need to watch this closely. A suspension or renegotiation would not be a paperwork problem — it would force real decisions about where data lives and under whose rules.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

GDPR / Intl
Information Commissioner's Office · · UK

ICO statement on Upper Tribunal decision

I need to work carefully here — the excerpt gives almost nothing beyond the headline. I'll write only what the headline and source reasonably imply: the UK's Information Commissioner's Office issued a public statement following a ruling by the Upper Tribunal, which is an appellate body that hears ch

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
Inside Privacy (Covington) · · International

New York Publishes Final SAFE For Kids Act Rules

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027. The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as websites, online services, and applications... Continue Reading…

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy#regulation#security Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

EDPB Publishes Draft Guidelines on Anonymisation

The European Data Protection Board has released draft guidelines updating its 2014 position on anonymisation, offering a more structured framework for determining when data can be treated as truly anonymous. The guidelines reflect the EDPB's cautious stance while attempting to give organisations clearer criteria for making that assessment.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
IAPP · · International

EDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter

The European Data Protection Board has called for a review of the EU-US Data Privacy Framework following the Trump v. Slaughter case, which relates to the dismissal of Federal Trade Commission members and raises concerns about the independence of the US enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
DataBreaches.net · · International

Cyberattack hits Liechtenstein, with 31,000 records stolen

Liechtenstein's government has confirmed a cyberattack that resulted in the theft of approximately 31,000 personal records. Given the country's population of around 41,000, the breach potentially affects the majority of its residents.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
IAPP · · International

The EDPB's draft anonymization guidelines: What they mean for your data strategy

The European Data Protection Board has released draft guidelines on anonymization, offering new technical and legal benchmarks for when data can be considered truly anonymous and therefore outside the scope of GDPR obligations. The guidelines are aimed at clarifying a standard that organizations have long applied inconsistently.

Who should care: Lawyers · Privacy officers · AI governance