Regulation
Schrems III readiness: what happens to your tools if DPF falls?
Twice the EU Court of Justice has struck down US data-transfer agreements (Schrems I and II). The third, the Data Privacy Framework, is already before the Court, while three simultaneous shocks in the US are shaking its foundation. Here is the readiness status for the tools in our catalogue, in three colours.
History has repeated itself twice. Safe Harbor fell in 2015 (Schrems I, C-362/14). Privacy Shield fell in 2020 (Schrems II, C-311/18). Both times thousands of companies suddenly lacked a legal basis for transfers to the US. The successor, the Data Privacy Framework (DPF), still applies. The Commission’s adequacy decision from July 2023 has neither been annulled nor withdrawn. But pressure on DPF is now greater than ever.
Legal situation in brief (as of 15 July 2026)
- DPF is already before the CJEU. The General Court dismissed the first annulment action in September 2025 (Latombe case, T-553/23). The judgment is appealed and is now before the CJEU (C-703/25 P). No hearing date has been set.
- Three shocks in the US in quick succession:
- On 29 June 2026 the Supreme Court held in Trump v. Slaughter that removal protections for FTC commissioners are unconstitutional. The adequacy decision refers to the FTC’s independence hundreds of times.
- The oversight body PCLOB has had no members since January 2026, following dismissals in January 2025.
- The surveillance law FISA 702 expired on 12 June 2026 without reauthorisation. Existing certifications remain valid into 2027, however.
- noyb is acting. On 30 June 2026 Max Schrems’ organisation sent a formal letter to the Commission demanding that the adequacy decision be withdrawn “in an orderly manner”. It also announced it will bring its own annulment action, already dubbed Schrems III. Estimated proceedings: 2–3 years.
- A counter-narrative exists. Several prominent scholars (Christakis, Propp, Swire) argue that the Slaughter ruling does not hit DPF’s redress mechanism, the DPRC, only the FTC’s commercial supervision. The Commission has “noted” the ruling but not acted.
- Most important for Swedish companies: IMY advises preparedness. In a statement on 3 July 2026 the Swedish data protection authority says the adequacy decision still applies, while organisations should “be prepared for how to proceed if the adequacy decision were to be annulled”.
It is that preparedness this page gives you. We do not predict the outcome. But preparedness is cheap. Panic afterwards is expensive.
Traffic light: 55 % green, 24 % yellow, 21 % red
Green: 101 tools (55 %). These are Swedish or EU/EEA vendors with EU data storage, and tools that run entirely locally on your own computer. If DPF falls they are essentially unaffected. The data never leaves EU jurisdiction. Most Swedish tools are here (full list) and European options such as Mistral and Nextcloud.
Yellow: 44 tools (24 %). These are either non-EU vendors that store data in the EU (the company’s jurisdiction remains), or EU vendors without confirmed EU storage. The question is: does any part of the processing rely on DPF? Check the vendor’s list of sub-processors.
Red: 38 tools (21 %). These are non-EU vendors without EU data storage. Processing in practice takes place in the US or another third country. It usually relies on DPF or standard contractual clauses (SCC). If DPF falls these must be reassessed. Note noyb’s caveat: the SCC route is also affected, because transfer impact assessments (TIAs) build on the same US oversight structures. SCC is a backup route that requires a fresh assessment, not a safe harbour.
Filter for yourself: the CLOUD Act status shows each tool’s origin. In the explore view you can filter by EU data storage.
What you should do now (not later)
- Inventory your red tools. Which services you use store data in the US? These are the ones a DPF fall would hit first.
- Check DPF certification for your US vendors. The EDPB’s updated guidance from January 2026 says that as an exporter you should verify that the recipient’s certification is active and covers the right data types. This applies especially to HR data. Search the register at dataprivacyframework.gov.
- Identify what is sensitive. Marketing copy in a US tool is a non-issue. Customer data and personal data are the real risk.
- Have a European backup plan per category. You do not need to switch today. But you should know where you would switch. Our “European alternatives” pages and comparisons are there for exactly that.
- Follow the process. We monitor the Latombe appeal, noyb’s action and Commission announcements under News and update this page at every major step.
The lesson from Schrems II
When Privacy Shield fell in July 2020 the judgment took effect immediately, with no transition period. More than 5,000 certified companies were affected. Today’s DPF register covers around 2,800 organisations. Delays became expensive. Meta received a record €1.2 billion fine in 2023 for continuing transfers to the US. Both Austrian and French supervisory authorities rejected ordinary Google Analytics use. Companies that already knew where their data was could pivot within days. The rest spent months mapping flows under time pressure. This time you can be in the first group.
This is a situational overview, not legal advice. Updated 15 July 2026. Next update when noyb’s action is filed or the Commission acts.
Sources
- IMY – US court ruling may affect transfers to the US (3 July 2026)
- noyb – US Supreme Court just blew up EU-US Data Transfers (30 June 2026)
- General Court – Latombe v Commission, T-553/23 (judgment 3 Sept 2025)
- EDPB – FAQ on Data Privacy Framework, v2.0 (Jan 2026)
- IAPP – counter-analysis: Trump v. Slaughter does not undo the EU-US redress mechanism (8 July 2026)
Tools mentioned
Mistral (Le Chat)
Mistral AI
France's answer to ChatGPT and one of the few European AI models in the top class, with EU data storage.
- European model in top class
- EU data storage
- Slightly weaker than the largest American ones
Best for: Those who want a powerful AI chat within the EU.
Nextcloud
Nextcloud
German platform for files, collaboration, chat and calendar, Europe's great alternative to Google Workspace and Microsoft 365.
- Comprehensive: files, chat, calendar, documents
- German, can run on own EU servers
- Requires server operation
Best for: Companies that want control over files and collaboration within the EU.
Proton Mail
Proton
Encrypted email from Switzerland, built for privacy. Popular European alternative to Gmail and Outlook.
- Strong encryption and privacy
- Data is processed by default in Switzerland, which has an EU adequacy decision
- Switzerland is outside the EU (but has an adequacy decision)
Best for: Businesses that want secure email outside the American giants.
Related articles
This is general information, not legal advice. See How we review.