When US politics shifts, EU cloud risk changes
In recent days, a decision by the US Supreme Court has quietly increased the risk for European organisations that rely on US‑controlled cloud services. It hasn’t changed the GDPR; it has changed the US side of the deal that GDPR relies on.
For boards, DPOs and IT leaders, this means one thing: existing risk assessments for using US tech in US cloud may now rest on assumptions that are no longer safe.
What has happened – in plain English
The EU–US Data Privacy Framework (DPF) was meant to be the “fix” after Schrems II. It allowed personal data to flow to certified US companies again, on the basis that the US had improved its safeguards and that independent authorities would enforce privacy rules.
One of those authorities is the US Federal Trade Commission (FTC). Until now, the FTC was treated as an independent regulator, with commissioners that could not simply be removed for political reasons. That independence was one of the elements the European Commission pointed to when it declared the US “adequate” for data transfers. It is not a minor footnote: the Commission’s adequacy decision references the FTC’s independent status 259 times.
The US Supreme Court has now decided, in Trump v. Slaughter (29 June 2026), that the President can remove FTC commissioners at will, overturning the 91‑year‑old precedent set in Humphrey’s Executor. In other words: a key privacy watchdog is no longer independent in the way Europe thought it was. In a separate ruling issued the same day, the Court treated the Federal Reserve differently, so this is not a wholesale collapse of independence across all US agencies, but it is a direct hit on the specific body the EU adequacy decision relies on most heavily.
This is not a new EU rule. It is a US political and legal decision that changes the institutional picture the EU adequacy decision depends on.
Why this matters for EU businesses
For many European organisations, the comfort around US cloud has been based on a story like this:
- Yes, US surveillance law is broad and powerful.
- But we have an EU adequacy decision (DPF), new US executive orders, and independent US oversight bodies to balance that.
- Our transfer impact assessments conclude that, taken together, risk is manageable.
If one of those balancing elements – an independent watchdog – is weakened, that story no longer holds in the same way.
The direct implications:
- Risk assessments may be wrong. If your TIA or cloud risk model explicitly or implicitly relies on US regulators being independent and strong, that premise has changed.
- Adequacy is more fragile, and already under active challenge. Privacy rights group noyb, led by Max Schrems, has sent a formal letter to the European Commission calling for an orderly withdrawal of the DPF adequacy decision, and Schrems has stated publicly that the Commission “built a legal house of cards under industry pressure.” noyb brought both Schrems I and Schrems II, the two rulings that struck down the DPF’s predecessor frameworks.
- Architecture and sourcing are in scope. This is not just a paperwork update. If adequacy is attacked or falls, your reliance on US cloud for critical systems becomes a structural business and compliance risk.
Dear IT teams: this will not make US cloud easier
From an IT perspective, it is tempting to see this as “just another data protection story”. It isn’t.
Two hard messages for technology teams:
- Your DPO, CISO and risk colleagues are about to come under serious pressure. Regulators, auditors, and now a well-resourced privacy advocacy group, will ask them to revisit assumptions about US cloud, surveillance and oversight.
- You should not expect that “US cloud with an EU data centre” will become simpler to justify. If anything, the political instability on the US side makes these setups harder to defend for critical, regulated data.
This matters particularly in financial services, public sector and other regulated industries, where cloud and third‑party risk is already under scrutiny. IT cannot treat this as “legal noise” while continuing to plan core systems on US hyperscalers by default.
It’s not Europe changing the rules
It is important to be clear on one point: Europe has not introduced a new regulation this week.
- The GDPR, DORA, NIS2 and the AI Act are already there. They have not suddenly become stricter.
- What has changed is the US institutional landscape that the EU adequacy decision relies on. A US court, applying US constitutional law, has made a US regulator politically removable.
In other words: the risk picture has shifted because the US has decided to weaken its own checks and balances, not because the EU has invented new obstacles. For European organisations, however, the effect is the same: the legal foundation for trusting US cloud is less stable, and there is now an active, credible push to have that foundation formally withdrawn.
What boards, DPOs and CIOs should do now
This is not a call for overnight exits or panic. It is a call for structured risk management:
- Map US-controlled exposure. Identify where you rely on US cloud or US‑controlled vendors – not only primary platforms, but also support access, telemetry, AI services and security tools.
- Re-open transfer impact assessments. Explicitly consider the weakening of US institutional safeguards as a new factor. Ask whether your previous “acceptable risk” conclusions still hold for each data category.
- Classify data by access sensitivity. Move beyond simple “personal vs sensitive” labels. AML alerts, internal risk reports, vulnerability data and critical infrastructure information may require stricter treatment than ordinary HR records.
- Decide where US cloud is no longer acceptable. For some data and systems, continued reliance on US‑controlled infrastructure will remain possible with strong controls. For others, particularly high‑risk or regulated processes, the honest answer may increasingly be “no”.
- Plan to reduce dependency over time. Begin designing a multi‑year path towards more European‑controlled infrastructure: sovereign cloud, split architectures, and genuine client‑side encryption with EU‑controlled keys.
- Put this on the board and risk agenda. Given that a formal challenge to the adequacy decision is already in motion, this must not remain a technical footnote. Board‑level ownership under GDPR, DORA and NIS2 means this development belongs in risk and audit committee discussions now, not at the next scheduled review.
At Conformance, we see this as another reminder that digital sovereignty and data architecture are strategic questions, not just technical ones. Using US tech in US cloud is no longer a neutral, low‑risk choice for European organisations. It is a decision that needs to be revisited with clear eyes and updated assumptions.
How Conformance can help
At Conformance, we work every day at the intersection of EU regulation, data architecture and digital sovereignty. We combine deep expertise in GDPR, DORA, NIS2 and the EU–US data transfer regime with hands‑on experience of designing and running sovereign and sovereignty‑aware cloud solutions for regulated organisations.
In practice, we help boards, DPOs, CIOs and risk teams to:
- map and understand their current exposure to US‑controlled cloud and vendors,
- re‑open and strengthen transfer impact assessments and ICT risk analyses,
- design target architectures that reduce dependence on US infrastructure over time, and
- implement concrete exit and migration plans that can be executed when needed.
If you want to discuss what this new development means for your organisation – or how to start a structured transition towards a more European‑controlled data and cloud strategy – we are ready to help.
You are welcome to contact us via www.conformance.dk or directly by e‑mail or phone, to arrange a conversation tailored to your situation.

