Full Breakdown
EU and US Data Privacy Frameworks: Recent Developments and Implications
9/8/2025, 8:45:50 PM
European Commission Proposes Data Flow Agreement with Brazil
On September 8, 2025, the European Commission proposed a mutual data flow agreement with Brazil, recognizing the country's data protection standards as comparable to the EU's General Data Protection Regulation (GDPR). This agreement aims to facilitate seamless data transfers across various sectors, including business, government, and research, potentially enhancing economic ties between the EU and Brazil, which collectively serve 670 million consumers. Henna Virkkunen, Executive Vice President for Tech Sovereignty, Security, and Democracy, emphasized Brazil as a "natural partner" amid global uncertainties. The proposal will undergo review by the European Data Protection Board (EDPB) and requires approval from EU member states and the European Parliament.
EU-US Data Privacy Framework Upheld
In a significant ruling on September 3, 2025, the European General Court dismissed a challenge to the EU-US Data Privacy Framework, which allows personal data transfers between Europe and the United States. French MP Philippe Latombe had argued that the framework's oversight mechanisms were insufficiently independent and that US bulk data collection practices violated European privacy standards. However, the court upheld the framework, affirming that US law provides adequate protection equivalent to EU standards. The ruling supports the European Commission's July 2023 adequacy decision, which established this framework following the invalidation of previous arrangements in the Schrems I and Schrems II cases.
Key Arguments and Court Findings
The court addressed two main arguments from Latombe: the independence of the Data Protection Review Court (DPRC) and the legality of bulk data collection by US intelligence agencies. The court found that the DPRC operates under sufficient safeguards to ensure independence and that prior authorization for data collection is not mandated under European law. The ruling noted that US law allows for ex post judicial review, aligning with the requirements set forth in the Schrems II precedent.
Criticism and Concerns
Privacy advocates, including Max Schrems, criticized the court's decision, arguing that it relies too heavily on executive orders rather than permanent legislation, raising concerns about the framework's long-term stability. Critics also highlighted the potential for increased surveillance and the implications of the Trump administration's recent actions on privacy safeguards.
Broader Implications for Data Governance
The developments in both the EU-Brazil agreement and the EU-US framework reflect ongoing efforts to establish robust data governance structures amid increasing scrutiny of digital privacy. The EU's commitment to data protection is evident in its regulatory frameworks, which aim to balance commercial needs with consumer rights. However, the reliance on executive assurances in the US raises questions about the durability of these agreements, particularly in light of shifting political landscapes.
What's Next?
The proposed mutual data flow agreement with Brazil will be subject to further review and approval processes, while the General Court's ruling on the EU-US Data Privacy Framework can be appealed to the European Court of Justice. As both regions navigate their respective data governance challenges, the outcomes of these processes will significantly impact international data flows and privacy standards.
Verbatim Quotes
- “the General Court dismisses the action for annulment.” — European General Court Press Release
- “the bulk collection of personal data by American intelligence agencies” — European General Court Ruling
These developments underscore the complexities of international data governance and the ongoing dialogue between privacy, regulation, and commercial interests in a rapidly evolving digital landscape.
