Transatlantic data transfers in 2026 legally still work. Companies can still move personal data from the EU to certified US providers, and the EU-US Data Privacy Framework that authorizes it is still valid and in force. The problem is what that legality rests on: a framework that is one ruling from the Court of Justice of the EU away from collapse, exactly as its two predecessors were. In 2026 that foundation picked up two new cracks. If your meeting or call data touches a US processor, you are carrying that fragility whether you priced it in or not. This is a risk map of where transatlantic transfers stand right now, and why sovereign processing removes the bet entirely.
How EU to US transfers work today
An EU to US transfer of personal data is lawful today mainly through one of two mechanisms. The first is the adequacy decision the European Commission adopted in 2023: the Data Privacy Framework. If a US company self-certifies under the framework, EU organizations can send it personal data as if it were staying inside the EU, with no extra paperwork. The second is Standard Contractual Clauses, the contractual fallback used for transfers to US recipients that are not certified, or as a belt-and-braces layer on top.
Both mechanisms assume the same thing: that data leaving the EU is still protected to an "essentially equivalent" standard. That assumption is where meeting data gets exposed. A recording of a sales call, a transcript of a board meeting, the notes generated from it: if identifiable EU participants are on the call, all of it is personal data under the GDPR, and often confidential business content on top. The moment that audio or transcript reaches a US processor, you have made a transatlantic transfer, and it needs a valid mechanism to stand on.
The EU-US Data Privacy Framework (DPF) is the adequacy decision adopted by the European Commission in July 2023 that allows personal data to flow from the EU to US companies that self-certify compliance with its principles. It is the third transatlantic transfer framework. Its two predecessors, Safe Harbor and Privacy Shield, were both struck down by the Court of Justice of the EU.
Three frameworks, two already struck down
The Data Privacy Framework is not a first attempt. It is the third try at the same problem, and the first two both failed in court. Safe Harbor, adopted in 2000, was invalidated by the Court of Justice of the EU in 2015 in the case now known as Schrems I. Privacy Shield, its replacement, was invalidated by the same court in 2020 in Schrems II. In both rulings the court found the same core defect: US surveillance law let intelligence agencies reach EU data in ways that EU law does not consider proportionate, and EU citizens had no effective redress.
That is the pattern worth internalizing. The European Commission approves a framework, businesses build on it, and the Court of Justice of the EU later invalidates it. The court has been consistently more skeptical of US safeguards than the political bodies that negotiate these deals. The Data Privacy Framework was engineered to answer Schrems II, with a new Data Protection Review Court and executive-order limits on bulk collection. Whether those answers hold is now, once again, a question for the courts.
2025: the DPF survived its first challenge
The framework has already won its first round. On 3 September 2025 the EU General Court dismissed an action brought by French Member of Parliament Philippe Latombe seeking to annul the Data Privacy Framework. As the Court of Justice summarized in its official press release, the General Court rejected Latombe's two central arguments: that the US Data Protection Review Court is not genuinely independent, and that bulk collection of data by US intelligence agencies lacks adequate safeguards. The court found the review court does amount to an independent tribunal and that ex post judicial oversight was sufficient.
Read the caveat, though, because it is the whole story. The General Court judged the framework on the facts and the law as they stood when the Commission adopted its adequacy decision in 2023. As the IAPP noted, it was a deliberately narrow review, and it did not resolve the deeper question of whether US law has since changed in ways that break the equivalence. A win judged on 2023 facts is a fragile thing to build on when it is 2026 and the facts have moved.
2026: two new cracks
Two developments since have widened the risk. The first is procedural. On 31 October 2025 Latombe appealed the General Court's ruling to the Court of Justice of the EU. That matters because of who now holds the pen. The Court of Justice is the same body that struck down both Safe Harbor and Privacy Shield, and it has historically taken a harder line on US surveillance than the General Court did. An appeal before the more skeptical court is exactly the venue in which the previous two frameworks died.
The second crack is substantive, and it landed in the summer of 2026. On 29 June 2026 the US Supreme Court ruled 6-3 in Trump v. Slaughter that statutory limits on the President's power to remove Federal Trade Commission commissioners are unconstitutional. The FTC is one of the enforcement and redress pillars the Data Privacy Framework relies on, and its independence was part of what made the arrangement credible to EU regulators. The day after, on 30 June 2026, noyb, the group founded by Max Schrems, wrote to the European Commission arguing that no other US authority can cure that independence deficiency, and announced it is preparing a fresh challenge to the framework, the one commentators are already calling "Schrems III."
None of this means the framework has fallen. As of July 2026 it is still valid, and transfers under it are still lawful. What has changed is the probability distribution. A pending appeal before a skeptical court, plus a newly weakened enforcement pillar, plus an announced challenge from the litigant with a two-for-two record of winning them, is not a stable base for a multi-year data strategy.
What is actually at risk for your data
Play out the scenario the pattern points to. If the Court of Justice strikes down the Data Privacy Framework, adequacy disappears overnight, the way it did in 2015 and again in 2020. There is no grace period baked into an invalidation. Every transfer running on framework adequacy becomes unlawful the moment the judgment lands, and every data-governance posture built on it becomes retroactively questionable, including transfers you made in good faith while it was valid.
Standard Contractual Clauses are the usual fallback, but they are not a free pass. Since Schrems II, using them for a US transfer requires a transfer impact assessment: an honest evaluation of whether US law actually protects the data to an equivalent standard. US surveillance statutes such as FISA Section 702 and the government-access powers behind the CLOUD Act make that assessment hard to pass for exactly the kind of sensitive content meetings produce. We walk through why an EU data center does not solve this in the CLOUD Act loophole your AI vendor isn't telling you about.
For meeting and call data this is concrete, not abstract. A conversation-intelligence tool that records your calls, transcribes them, and runs AI analysis on the transcript is moving some of the most sensitive material your business generates, deal terms, personnel discussion, strategy, across the Atlantic to a US processor. If that vendor's legal basis is the Data Privacy Framework and the framework falls, the basis falls with it. We map that specific exposure for one common category in Gong, EU data sovereignty, and GDPR.
Sovereignty removes the bet
There is a category of organizations for which none of this is a live risk: the ones that never transfer the data in the first place. This is the part worth sitting with. Every mechanism above, adequacy, Standard Contractual Clauses, transfer impact assessments, exists to authorize a transatlantic transfer. If there is no transfer, there is nothing to authorize and nothing for a court to invalidate. The entire risk map above collapses to a blank page.
That is what data sovereignty delivers. Sovereign processing keeps every stage of the pipeline, audio capture, transcription, storage, and the AI analysis on top, under EU jurisdiction with no US processor in the chain. Your legal posture stops depending on the survival of the Data Privacy Framework, the outcome of the Latombe appeal, or whether Schrems III succeeds. Those become other people's problems. If you want the fuller definition and the difference between residency and sovereignty, we cover it in what is sovereign AI.
The honest framing is that transatlantic transfers are a bet. Right now the bet is still paying out, the framework holds, and it may hold for years. But it is a bet you keep having to place, re-place after each ruling, and re-justify in every audit. Sovereignty is the option to stop betting. For meeting data specifically, that is not a compliance nicety; it is the difference between a data strategy that survives the next Court of Justice judgment and one that has to be rebuilt around it.