On September 3, 2025, the European General Court rejected French MP Philippe Latombe's request to annul the EU-U.S. Data Privacy Framework (DPF). This decision allows over 3,400 U.S. organizations certified under the DPF to continue processing EU personal data without seeking alternative transfer mechanisms. However, with a two-month appeal window still open and privacy advocate Max Schrems calling the outcome "very surprising," the situation remains fluid.
What Happened
MP Latombe, also a commissioner at CNIL, filed his annulment request in September 2023. He challenged the European Commission's July 2023 adequacy decision that approved the DPF. His main argument was that the framework doesn't provide EU data subjects with adequate protection, especially concerning U.S. intelligence surveillance and the independence of the Data Protection Review Court (DPRC).
The General Court disagreed. It found the DPRC to be independent and impartial, rejected claims of inadequate oversight on U.S. intelligence agencies' bulk data collection, and emphasized the Commission's duty to monitor and potentially amend the DPF.
Timeline
- July 16, 2020: CJEU invalidates Privacy Shield in Schrems II
- July 2023: European Commission adopts adequacy decision for DPF
- September 2023: MP Latombe files annulment request
- October 2023: General Court President dismisses emergency suspension request
- April 1, 2025: Oral arguments held before General Court
- September 3, 2025: General Court rejects annulment request
- Next two months: Appeal window to CJEU remains open
Core Challenges to the Framework
This isn't about technical failures but about structural safeguards in the DPF. Latombe argued three main points:
- Independence of the DPRC: He claimed it relies too much on the U.S. Executive Branch, affecting its impartiality.
- Prior authorization for bulk collection: He argued that U.S. intelligence should require prior court or independent approval for bulk data collection.
- Judicial supervision of surveillance: He contended that bulk collection lacks clear rules and sufficient judicial oversight.
The General Court found these arguments unconvincing, citing Executive Order 14086 and related laws that limit bulk collection to specific intelligence priorities and ensure oversight by the DPRC and other bodies.
What the Relevant Standard Requires
Article 45 of GDPR sets the criteria for adequacy decisions. The Commission must ensure a third country provides "a level of protection essentially equivalent" to the EU. This involves:
- Independent oversight: Data subjects need access to independent administrative and judicial redress mechanisms.
- Necessity and proportionality: Interference with rights must be necessary and proportionate to legitimate objectives.
- Ongoing monitoring: The Commission must continuously assess the third country's protection level and can suspend or amend the adequacy decision if needed.
The General Court stressed that the Commission's role is ongoing, not a one-time decision, providing a safety net but also a reminder that adequacy isn't permanent.
Lessons and Action Items for Your Team
Don't rely solely on adequacy. The General Court's ruling is based on U.S. law as of July 2023. If you're using the DPF for EU data transfers, document your compliance and monitor legal developments. An appeal could change the landscape, and the Commission's ongoing review means conditions can shift.
Maintain backup transfer mechanisms. If you handle sensitive EU data, consider using Standard Contractual Clauses or binding corporate rules alongside DPF certification. This ensures operational resilience. When Privacy Shield collapsed in 2020, organizations with SCCs had continuity, while others faced urgent contract rewrites.
Track the appeal window. Under Article 56 of the Statute of the CJEU, Latombe has two months to appeal. If he does, the case moves to the Court of Justice, where scrutiny differs. Schrems' comment suggests privacy advocates may see this as a procedural win for the DPF.
Review your Records of Processing Activities. If you're processing EU data in the U.S. under DPF, your Article 30 records should specify DPF as the legal basis. If an appeal succeeds or the Commission suspends the framework, you'll need to pivot quickly. Document which activities rely on DPF and which alternative mechanisms you could use.
Prepare for the Commission's periodic review. The General Court noted the Commission's obligation to monitor U.S. adequacy. If U.S. laws change or DPRC issues arise, the Commission can act. Stay informed to avoid surprises if the framework's status changes.
The DPF remains in place for now, but its future depends on factors outside your control. What you can control is your organization's readiness to adapt to any changes in the legal landscape.



