Live tracker of every court case and regulatory challenge to the EU-US Data Privacy Framework. Status, next milestones, and what each outcome would mean. Updated monthly.
Every active challenge to the EU-US Data Privacy Framework, in one place. Last updated: July 11, 2026 · Next scheduled review: August 2026 · Get an email when this page changes: [form]
The DPF is in force. Transfers to certified US companies (including Google, Meta, Microsoft) are lawful. One appeal is pending before the EU's highest court. No ruling is imminent.
| What it is | Appeal against the General Court judgment that upheld the DPF |
| Court | Court of Justice of the EU (CJEU) |
| Filed | October 31, 2025 |
| Status | Pending. No hearing date announced as of June 2026 |
| Realistic decision window | 2027-2028 (typical CJEU appeal duration: 1.5-2.5 years) |
| Stakes | The CJEU invalidated both previous frameworks (Safe Harbor 2015, Privacy Shield 2020). A successful appeal invalidates the DPF with immediate effect |
| Background | Full plain-language explainer ↗ |
History of this case: filed by French MP Philippe Latombe as a direct annulment action in September 2023 (T-553/23) → interim suspension rejected (October 2023) → General Court dismissed the action and upheld the DPF (September 3, 2025) → appeal filed.
| What it is | Max Schrems' organization stated after the September 2025 judgment that it is considering its own, broader challenge to the DPF |
| Status | Not yet filed as of June 2026 |
| Why it matters | noyb's two previous campaigns produced Schrems I and Schrems II. Its complaints engine (the 101 complaints of 2020) is also how abstract rulings became concrete enforcement against Google Analytics |
Not a court case, but the DPF's foundation: the US redress mechanism exists by executive order, amendable by any US administration without notice. A material change on the US side could trigger Commission review or give the CJEU fresh grounds. We track public developments here as they occur.
| Proceeding | Outcome | Date |
|---|---|---|
| Latombe v. Commission, first instance (T-553/23) | DPF upheld by the General Court | September 3, 2025 |
| Latombe interim measures request | Rejected | October 2023 |
The two-step insurance, detailed in our guide ↗ : know which of your tools send personal data to US companies, and keep your analytics history exportable. You can also shrink your stake in this docket: analytics from an EU-owned vendor, hosted in the EU, that writes nothing to the visitor's device by default and stores no raw IP, has very little riding on how C-703/25 P ends ↗. Your other vendors probably do have something riding on it, which is why step one is the inventory, not the swap.
How Datalenk actually works, so you can hold us to it. Datalenk is cookieless by default: the standard snippet writes nothing to the visitor's device, no cookie and no localStorage, and no raw IP is ever stored (it is used in memory to derive a coarse location, then discarded). Uniqueness within a day comes from a server-side hash of the site, the IP and the user agent, salted with a secret that rotates every 24 hours, which is what makes following the same person from one day to the next impossible, for us too. Customers can explicitly opt into a Persistent layer that stores a pseudonymous first-party identifier for 90 days, which brings the consent question back: our dashboard makes them tick a box that says so before it turns on. We run that layer on datalenk.com ourselves, and we disclose it in our own privacy policy. No visitor data we collect for our customers leaves the EU. We are a French company, and like every SaaS we use a small number of US vendors for our own operations, billing and transactional email; they are named in our privacy policy. That is the honest shape of "EU-owned analytics", and it is the same question you should put to every vendor on your list.
Cookieless, EU-hosted analytics that ties every visit to the revenue it actually brought in. 14-day free trial.