ARTICLE
5 September 2025

EU General Court Upholds EU-U.S. Data Privacy Framework

FK
Frankfurt Kurnit Klein & Selz

Contributor

Frankfurt Kurnit provides high quality legal services to clients in many industries and disciplines worldwide. With leading practices in entertainment, advertising, IP, technology, litigation, corporate, estate planning, charitable organizations, professional responsibility and other areas — Frankfurt Kurnit helps clients face challenging legal issues and meet their goals with efficient solutions.
On September 3, 2025, the General Court of the European Union issued a ruling upholding the validity of the EU–U.S. Data Privacy Framework ("DPF").
Worldwide Privacy

On September 3, 2025, the General Court of the European Union issued a ruling upholding the validity of the EU–U.S. Data Privacy Framework ("DPF"). This decision brings some stability to transatlantic data flows, though potential appeals may still arise.

Background

The DPF, adopted by the European Commission in 2023, was designed to replace the Safe Harbor and Privacy Shield frameworks, both of which were previously invalidated based on concerns that U.S. surveillance practices lacked adequate safeguards for EU citizens' personal data.

Following the adoption of the DPF, French lawmaker Philippe Latombe challenged the framework, arguing that it failed to meet EU data protection standards. Latombe argued that: (i) the U.S. Data Protection Review Court ("DPRC") depends on the executive and is neither impartial nor independent; and (ii) the practice of U.S. intelligence agencies collecting bulk personal data in transit from the European Union is illegal as it lacks prior authorization of a court or independent administrative body.

The General Court's Decision

The General Court dismissed Latombe's action for annulment, concluding that, at the time of adoption, the United States ensured "an adequate level of protection" for EU personal data. The Court decided that the DPRC is independent, counter to Latombe's argument. Per the General Court, several safeguards ensure its independence, and judges may only be dismissed for cause by the Attorney General. Additionally, the court held that bulk collection of data does not require prior authorization but rather must be subject to ex post judicial review. Such review is provided by the DPRC.

Implications for Businesses

The ruling provides increased legal certainty for companies that rely on transatlantic data transfers. However, an appeal to the Court of Justice of the European Union ("CJEU") is still possible. Given the CJEU's decision on previous adequacy frameworks, the DPF may still face a challenge. And, privacy activist Max Schrems, whose challenges struck down the prior two frameworks, has already voiced skepticism by suggesting that a "broader review of U.S. surveillance law could produce a different outcome." Facing such challenges, companies should maintain a flexible compliance program.

www.fkks.com

This alert provides general coverage of its subject area. We provide it with the understanding that Frankfurt Kurnit Klein & Selz is not engaged herein in rendering legal advice, and shall not be liable for any damages resulting from any error, inaccuracy, or omission. Our attorneys practice law only in jurisdictions in which they are properly authorized to do so. We do not seek to represent clients in other jurisdictions.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More