Twice in a decade, the legal foundation for transatlantic data flows vanished between a morning and an afternoon. Whether the third challenge is called Schrems III or something else, the pattern to plan for is known: years of quiet docket activity, then a judgment with immediate effect and no grace period. The DPF is in better shape than its predecessors, Latombe’s dismissal was a genuine win, and EO 14086 answers objections Privacy Shield never addressed, but its premises live in executive orders and oversight bodies that moved visibly in 2025. Contingency planning here is unusually cheap relative to the risk: an inventory, some pre-signed clauses, and a playbook convert a legal earthquake into an operations task.
| Precedent | Safe Harbor (2015), Privacy Shield (2020): immediate invalidation, no grace period |
|---|---|
| Current posture | Latombe dismissed (Sept 2025); appeal and Art. 267 references open |
| Pressure points | EO 14086 operation, DPRC independence, US oversight stability |
| Quiet path | Commission suspension/repeal at periodic review |
| Plan | Inventory + springing SCCs + TIA scaffolds + 48-hour playbook |
Building the contingency
Inventory first. Per-flow mechanism records with a cleartext-dependency flag; the DPF vs SCCs analysis drives the fallback column.
Pre-sign the fallback. Springing SCCs with major US counterparties; TIA scaffolds ready for same-week completion.
Watch the signals. CJEU docket, Commission reviews, EO 14086 and DPRC changes; your certification and recertification obligations continue regardless.
Route the bridges separately. UK and Swiss flows need their own fallback columns; they may outlive an EU judgment, briefly.
Flow inventories start with real data: map what your site actually transfers with a free scan.