Open Joint Letter on a Public Reassessment of the EU-US Adequacy Decision
On 29 June, the US Supreme Court ruled that US President Trump can remove the leaders of independent agencies and commissions, overturning nearly 90 years of precedent limiting executive power. This decision raises serious questions about one of the key safeguards underpinning the EU-US Data Privacy Framework adopted in 2023: independent supervision.
Under this Framework, personal data can be transferred from the EU to certified US organisations without additional transfer safeguards, based on the European Commission’s finding that the United States ensures a level of protection for personal data that is essentially equivalent to that guaranteed under EU law. This is not only about data protection, but also about the rule of law. The Commission relied on the existence of independent institutions capable of enforcing data protection rules. When the independence of those institutions is called into question, the Commission must reassess whether the conditions for adequacy remain fulfilled.
Following the Supreme Court’s ruling in Trump vs. Slaughter, CDT Europe – together with 36 civil society organisations and academics – have written to Commissioner McGrath urging the Commission to immediately launch a public reassessment of the EU-US adequacy decision, consult civil society and independent experts, and publish its legal assessment of the implications of this judgment.
Adequacy is not a one-off political endorsement or diplomatic gesture. It is a living legal mechanism that must be revisited whenever the facts change. Under the GDPR, the European Commission is required to keep adequacy decisions under continuous review, assessing whether the legal and institutional framework of a third country continues to provide an adequate level of protection. This includes examining the rule of law, the availability of effective judicial remedies, and the independence of supervisory and enforcement authorities. Where those conditions materially change, the Commission has a legal obligation to reassess whether its adequacy finding remains justified and people in the EU continue to receive equivalent protection when their personal data leaves the Union.
Ignoring constitutional and institutional developments would weaken not only this adequacy decision, but confidence in the adequacy framework as a whole. The credibility of the GDPR depends on applying this principle consistently, regardless of the country concerned. At times of deregulation and geopolitical pressure, this is an opportunity for the EU to demonstrate that the GDPR is a living safeguard for fundamental rights, not a static political declaration.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
As Brussels starts emptying for the summer, the risks of frontier AI models continue to capture the attention of policymakers as a key chapter of the AI Act becomes enforceable, and disclosure rules around the use of AI systems and AI-generated content are further clarified.
CDT Europe’s Feedback on the Draft Guidelines for the Classification of High-Risk AI Systems under the AI Act
CDT Europe responded to the European Commission’s consultation on the draft guidelines for the classification of high-risk artificial intelligence systems.
Responding to the EU-US Negotiations on Reciprocal Data Exchanges for Border Procedures
CDT Europe, together with 29 other civil society organisations and academics, sent an open joint letter to the Council of the EU regarding the worrying direction taken by the European Commission in the EU-US border negotiations with the U.S. government.