International Standards US / EU

Schrems III Risk: Planning for a DPF Legal Challenge

How a future challenge to the EU-US Data Privacy Framework could unfold, what Latombe decided, the EO 14086 pressure points, and contingency planning that actually works.

Regulation

EU-US DPF adequacy decision (July 2023); Executive Order 14086; 28 CFR Part 201 (Data Protection Review Court); CJEU Schrems I (C-362/14) and Schrems II (C-311/18) precedent

Max Penalty

An invalidation ends adequacy with immediate effect, as in 2015 and 2020; continued transfers afterward draw Article 83(5) fines up to 4% of worldwide turnover

Enforcing Authority

CJEU and EU General Court (validity); European Commission (suspension/repeal power); EU DPAs (transfer enforcement)

Official Source

www.dataprivacyframework.gov

Executive Summary

  • Safe Harbor fell in 2015 (Schrems I) and Privacy Shield in 2020 (Schrems II), both with immediate effect; planning for a third shock is a base-rate exercise, not pessimism.
  • The first direct DPF challenge, Latombe v. Commission, was dismissed by the EU General Court in September 2025, upholding the Commission's view of the DPRC and US safeguards; appeal and future preliminary references remain open paths.
  • The structural pressure points: whether EO 14086's 'necessary and proportionate' standard operates as EU law requires, the DPRC's independence within the executive branch, and US oversight-body stability, questioned in Europe after 2025 PCLOB removals.
  • The Commission can itself suspend, amend, or repeal the decision at periodic review if US practice shifts, a quieter path than litigation.
  • Contingency planning is concrete: per-flow mechanism inventory, springing SCCs, TIA scaffolding, a 48-hour trigger playbook, and counterparty notice templates.

Twice in a decade, the legal foundation for transatlantic data flows vanished between a morning and an afternoon. Whether the third challenge is called Schrems III or something else, the pattern to plan for is known: years of quiet docket activity, then a judgment with immediate effect and no grace period. The DPF is in better shape than its predecessors, Latombe’s dismissal was a genuine win, and EO 14086 answers objections Privacy Shield never addressed, but its premises live in executive orders and oversight bodies that moved visibly in 2025. Contingency planning here is unusually cheap relative to the risk: an inventory, some pre-signed clauses, and a playbook convert a legal earthquake into an operations task.

PrecedentSafe Harbor (2015), Privacy Shield (2020): immediate invalidation, no grace period
Current postureLatombe dismissed (Sept 2025); appeal and Art. 267 references open
Pressure pointsEO 14086 operation, DPRC independence, US oversight stability
Quiet pathCommission suspension/repeal at periodic review
PlanInventory + springing SCCs + TIA scaffolds + 48-hour playbook

Building the contingency

Inventory first. Per-flow mechanism records with a cleartext-dependency flag; the DPF vs SCCs analysis drives the fallback column.

Pre-sign the fallback. Springing SCCs with major US counterparties; TIA scaffolds ready for same-week completion.

Watch the signals. CJEU docket, Commission reviews, EO 14086 and DPRC changes; your certification and recertification obligations continue regardless.

Route the bridges separately. UK and Swiss flows need their own fallback columns; they may outlive an EU judgment, briefly.

Flow inventories start with real data: map what your site actually transfers with a free scan.

Frequently Asked Questions

What did Latombe actually decide, and what does it leave open?

Philippe Latombe, a French parliamentarian, sought annulment of the adequacy decision, arguing the DPRC is not an independent tribunal and US bulk collection lacks prior authorization. In September 2025 the EU General Court dismissed the action on the merits, holding the Commission could reasonably find the DPRC sufficiently independent (judges protected from removal, procedural guarantees, executive-branch location not disqualifying under the essential-equivalence standard) and that US signals-intelligence safeguards under EO 14086, including ex post DPRC review of bulk collection, met the required level. What it leaves open: an appeal to the CJEU on points of law; a future preliminary reference under Article 267, the route both Schrems judgments took, arriving with a fuller evidentiary record from national litigation; and challenges built on post-2023 facts rather than the decision's adoption-time record, notably whether the EO 14086 machinery still operates as the Commission assumed. Latombe raised the bar for facial challenges; it does not immunize the decision against a record showing changed US practice.

What are the realistic paths to a DPF collapse, and their timelines?

Three paths, different speeds. CJEU invalidation: a preliminary reference from a national court (the Schrems pattern, complaint to DPA, litigation, reference) typically takes three to five years from complaint to judgment; an appeal of Latombe would be faster but is limited to points of law. Invalidation takes effect immediately upon judgment, no grace period, as in 2015 and 2020. Commission suspension or repeal: the decision requires periodic review, and the Commission can suspend, amend, or repeal if US safeguards degrade; the European Parliament has pushed for exactly this at various points, and material changes to EO 14086, the DPRC, or oversight bodies would force the question; timeline is political, months from a triggering event, and could include a transition period, unlike a court judgment. US-side withdrawal: a US administration could revoke or gut EO 14086; the decision's factual basis evaporates and the Commission must act. Monitoring signals worth automating: CJEU docket activity, Commission review reports, EO 14086 amendments, DPRC appointments and caseload, and PCLOB composition, several of these moved in 2025 and drew formal EU questions.

If the DPF falls, what happens mechanically to our transfers?

The adequacy basis for DPF-reliant flows disappears at the moment of invalidation. Transfers must stop or switch to an Article 46 mechanism immediately: in 2020 the CJEU gave no grace period, the EDPB confirmed none existed, and noyb filed 101 complaints against companies still running Privacy Shield-era transfers within weeks. Certified importers keep their DPF obligations for data already received (the Principles are sticky and the FTC has said framework commitments remain enforceable regardless of EU-side validity, as it did after Schrems II), but that protects the data, not the flow. SCCs signed as fallback activate, subject to the harder problem Schrems II created: the same judicial reasoning that killed the adequacy decision will color TIAs for US transfers, so expect DPA guidance within weeks on what supplementary measures suffice, and expect encryption-with-exporter-keys and pseudonymization to carry the analysis. Flows that cannot support those measures (US vendor needs cleartext access to EU data) are the genuinely exposed category; identify them now, because they are the ones that may need re-architecture rather than re-papering.

What does a real contingency plan contain?

Five artifacts, built in calm weather. Mechanism inventory: per-flow records (data category, entities, current mechanism, fallback mechanism, cleartext-dependency flag), without which nothing else executes. Springing SCCs: pre-executed clauses with key US counterparties drafted to govern if the DPF ceases to provide a valid basis, or at minimum template packs with module selection pre-made; after 2020, this became standard practice in negotiated DPAs. TIA scaffolding: destination-law analysis pre-drafted for your main US importers so post-judgment TIAs are updates, not originals; EO 14086 analysis remains relevant to SCC transfers even if adequacy falls. Trigger playbook: named convener, 48-hour assessment meeting, decision matrix (which flows switch, which pause, which escalate), counterparty notice templates, and privacy-policy edit list (participation claims may need adjusting even though certification itself survives EU-side invalidation). Exposure triage: the pre-identified cleartext-dependent flows with re-architecture options sketched (EU processing, key custody changes, vendor substitution). Companies with these five re-papered in weeks after Schrems II; the median company took most of a year.

Does a DPF collapse take the UK and Swiss bridges down too?

Not automatically, but the dependencies are real. Legally: the UK's adequacy regulations and Switzerland's recognition are independent instruments under their own laws; a CJEU judgment binds neither. Structurally: both rest on the same EO 14086 safeguards and the same Commerce Department program, and the UK Extension requires an active EU-US certification, so if a US organization's certification lapses in a post-invalidation unwind, UK coverage lapses with it (the UK Extension cannot stand alone). Politically: a CJEU finding that US safeguards fail essential equivalence would pressure the UK government's own monitoring commitments and hand ammunition to challenges under UK law; Switzerland's FDPIC would face the same question. Planning consequence: run the UK and Swiss flows through the same mechanism inventory with their own fallback column (IDTA or UK Addendum with a UK transfer risk assessment; Swiss-law SCC adaptations), and treat 'EU decision falls, UK bridge survives six more months' as a plausible middle scenario in which flow-by-flow routing, not framework-level assumptions, keeps you compliant.

Regulatory Crosswalk

SCCs + TIABCRsUK data bridge

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.