Data Privacy Framework: Data Transfers to the USA Remain Problematic

After the failed data protection agreements “Safe Harbor” and “Privacy Shield”, the EU and the USA adopted a new data pact in July 2023, the “Data Privacy Framework”, which was controversial from day one. Why controversial? Let’s put it this way: would you like to abolish medical confidentiality? No need for banking secrecy, the privacy of correspondence or the secret ballot? You have no curtains at home, talk openly with your neighbours about your salary and your sexual preferences, and are happy to share your search history and all your holiday photos with anyone who asks? Then the new agreement is no problem for you and the text below is not relevant. To everyone else: the road to informational self-determination is long and bumpy. As an individual, you stand alone against almost the entire business world. To put the current situation into context, we’ll go back a little and take a detailed look at the problem with data processing in the USA.

A brief history of data protection and data transfers

As early as the 1970s and 1980s, the Commission of the European Communities was repeatedly called upon to draft a directive protecting the personal data of EC citizens.1, 2 This lofty wish for informational self-determination finally led to Data Protection Directive 95/46/EC in 1995. It came late, was implemented even later, and wrongly at that.3 Still, more than 30 years ago it already prohibited transferring EU citizens’ personal data to countries whose level of data protection fell short of EU law. For example: the USA.

Awkward, because on the one hand the USA was the world’s number one in digital data processing (still is?), and on the other it had no rules even remotely matching EU standards (still hasn’t..). To keep data flowing between the EU and the USA, the Safe Harbor agreement was concluded in 2000. For a full 15 years, thanks to this “safe harbour”, data was sent unchecked to Google, IBM, Amazon, Facebook … That the harbour wasn’t safe after all was clear by 2010 at the latest.4 Yet it took another 5 years for the agreement to be struck down (Schrems I ruling). So a new protection for the data was needed, and fast – the Privacy Shield! Long story short, the Privacy Shield was so controversial from the start (for good reason) that it was only a matter of time until the next one (Schrems II ruling, 2020). As you can see, bad laws take a looong time to get rid of, but new bad laws are pulled out of the drawer in no time.

In July 2023 came the third attempt – this time without Shield, Safe and co., but with a dry “EU-U.S. Data Privacy Framework”. To judge whether a Schrems III ruling is coming soon, we need to answer the key question:

What exactly is the problem with data processing in the USA?

First of all, there is no federal data protection law in the USA. There are sector-specific laws here and there, such as the GLBA in finance or HIPAA in healthcare, but beyond that each state can do as it pleases.

Second, there have been many cases of data misuse and security breaches on a massive scale (millions of people affected):

The Equifax data hack, the Cambridge Analytica scandal, 3 billion usernames (plus phone numbers, passwords etc.) stolen from Yahoo in 2013 (which was only admitted 4 years later). In 2018 it emerged that attackers had been siphoning off data on up to half a billion Marriott International guests since 2014, including passport numbers and travel details. In 2024 hackers stole the health data of around 190 million people from Change Healthcare, and in the same year the call records of more than 100 million AT&T customers. We’d have to continue the list elsewhere...

The central problem, however, is mass surveillance in the USA. The media often cover it less thoroughly than mass surveillance in, say, China, yet it hardly lags behind in scale (though it does in its consequences). US laws such as FISA, the Patriot Act, Executive Order 12333 and the Cloud Act legitimise mass surveillance by the NSA and co. and allow, among other things, access to phone data, emails, internet usage and other electronic records without individual judicial approval, even abroad.

Tools such as PRISM, Upstream Collection and XKeyscore enable real-time (!!) searches of your browsing history, chat messages, emails and more.

IMPORTANT: US laws explicitly also cover servers of US companies located abroad. So it makes no difference whether the Google/Amazon/Microsoft server is in Frankfurt or California!

Fine, you might think, let the intelligence services dig, that’s pretty much in their job description. But your favourite companies are sadly no better: they collect data on a comparable scale, sell it and use it to manipulate you. A quote from Eric Schmidt in 2009, then CEO of Google:

“If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place. But if you really need that kind of privacy, the reality is that search engines, including Google, do retain this information … It’s possible that that information could be made available to the authorities.”

By the way, when journalists googled personal details about Mr Schmidt back in 2005 and published them, the journalists were put on a blacklist5 .. including a complaint that Mr Schmidt’s privacy had been violated (mind you, the only information published was what Google itself had made available).

Back to the new EU-U.S. Data Privacy Framework – what’s different?

At its core, just one thing: a decree. The US President issued an “Executive Order” (not Order 66 but 14086) asking the intelligence services to please protect data better and to take more care that data collection is “necessary and proportionate”.6 On top of that, there is a complaints procedure for EU citizens with a “Data Protection Review Court”, which is not a real court, however, but sits within the US Department of Justice and was likewise set up by decree only. The laws stay the same: only US citizens have constitutional rights and are protected from suspicionless surveillance.

So the teacher has asked the children to please not be proportionately loud.

Where things stand in 2026: valid, but on shaky ground

Legally, the Data Privacy Framework is currently valid. In September 2025, the General Court of the EU dismissed the action brought by French MP Philippe Latombe and upheld the agreement.7 But only for the legal situation in 2023. The court expressly did not examine what has happened in the USA since then. Latombe has appealed, and the case is now before the Court of Justice of the European Union.8 So it is not all that safe. And a lot has happened since:

  • January 2025: The US President fired three of the five members of the Privacy and Civil Liberties Oversight Board (PCLOB), the very body meant to oversee the intelligence services and on which the agreement relies. A US federal court ruled the dismissals unlawful, and the government appealed.9 By summer 2026 the board had only one member left and no quorum.10
  • June 2026: The Supreme Court ruled that the President may dismiss members of the Federal Trade Commission (FTC) at any time and without cause.11 The FTC is supposed to monitor whether US companies comply with the agreement. Its independence was a key pillar of the EU’s recognition of the framework. That independence no longer exists.
  • June 2026: The legal basis for surveillance under FISA Section 702 expired because Congress could not agree on an extension. Surveillance continues anyway, based on authorisations already granted, probably until March 2027.12
  • Summer 2026: Max Schrems’ privacy organisation noyb called on the European Commission to withdraw from the agreement in an orderly manner.13 The European Data Protection Board asked the Commission to assess the consequences of the FTC ruling.14

Outlook: Schrems III?

Whether the agreement falls will once again be decided by the Court of Justice of the European Union, either in the Latombe case or in a new action that noyb has already signalled. That could take years. Safe Harbor lasted 15 years, Privacy Shield four. We’re not betting on how long it will last this time.

Let’s be honest: with or without an agreement, the real question is a different one. The business models of the big US tech companies are built on data. Apps and platforms collect whatever they can get, and protection often exists only on paper. AI companies copied millions of books from illegal shadow libraries to train their models. Anthropic paid 1.5 billion US dollars in a 2025 settlement over this.15 With AI, huge amounts of data can now be searched and analysed in seconds. It is simply not in anyone’s interest for their data to end up with US companies, whatever the legal basis.

What does this mean for you, your data, your employee surveys and customer surveys?

We believe that certain information, such as your shopping preferences, your Google searches or your conversations with friends and family, belongs to you. We’re not alone in this view: Article 8 of the EU Charter of Fundamental Rights agrees.

We also believe you certainly can’t go wrong by always looking for European, ideally German, alternatives for survey tools before choosing one of the big US players.

Either way, one thing holds true with us – your data was and is secure and belongs to you alone. For us, the usual “hosting in Germany” is not enough: LamaPoll works exclusively with German service providers and sub-processors, with no US providers in between. That’s why we don’t need an agreement with the USA at all.


Sources and references:

  1. https://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=uriserv:OJ.C_.1982.087.01.0031.01.DEU#page=9
  2. https://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=uriserv:OJ.C_.1976.100.01.0027.01.DEU#page=1
  3. https://www.spiegel.de/netzwelt/netzpolitik/urteil-gegen-deutschland-europa-befreit-datenschuetzer-von-politischem-druck-a-682540.html
  4. https://www.ldi.nrw.de/mainmenu_Service/submenu_Entschliessungsarchiv/Inhalt/Beschluesse_Duesseldorfer_Kreis/Inhalt/2010/Pruefung_der_Selbst-Zertifizierung_des_Datenimporteuers/Beschluss_28_29_04_10neu.pdf
  5. https://money.cnn.com/2005/08/05/technology/google_cnet/
  6. https://www.federalregister.gov/documents/2022/10/14/2022-22531/enhancing-safeguards-for-united-states-signals-intelligence-activities
  7. https://curia.europa.eu/juris/liste.jsf?num=T-553/23
  8. https://curia.europa.eu/juris/liste.jsf?num=C-703/25
  9. https://therecord.media/intel-oversight-firings-illegal-judge
  10. https://www.independent.org/article/2026/07/14/pclob-future-section-702/
  11. https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf
  12. https://www.cato.org/blog/fisa-section-702-lapse-assured-thankfully
  13. https://noyb.eu/sites/default/files/2026-06/Letter_noyb_EU-US_data_transfers.pdf
  14. https://iapp.org/news/a/edpb-requests-review-of-eu-us-data-privacy-framework-following-trump-v-slaughter
  15. https://www.npr.org/2025/09/05/g-s1-87367/anthropic-authors-settlement-pirated-chatbot-training-material

Last updated on October 2, 2026


  • Allianz für Cybersicherheit participant logo
  • TÜV certificate

A clean website: no trackers, no cookies!

We REALLY respect your privacy: we set NO tracking, advertising or third-party cookies on this website.

And of course we do NOT track what you do on our site either!