A US Supreme Court ruling just put Google Analytics' EU data transfers back in question
If your website uses Google Analytics and serves visitors in the EU, the legal basis for sending their data to the US just got shakier — again. On 29 June 2026 the US Supreme Court ruled, 6-3, that the President can fire Federal Trade Commission commissioners at will. That sounds like domestic US politics, but it knocks out the exact thing the EU-US Data Privacy Framework — the deal that currently makes GA4's transatlantic data flow legal — leans on to prove US oversight is trustworthy. Austria's noyb (Max Schrems' group, the people who killed the last two of these deals) has already written to Brussels asking it to pull the plug.
To be clear up front, because the internet will over-read this: nothing is illegal today. The Data Privacy Framework is still formally in force, no regulator has told anyone to stop, and this is uncertainty, not a ban. But it's the same kind of uncertainty that hung over EU analytics between Schrems II and the current deal — and if you run a tool that never ships your visitors' personal data to the US in the first place, none of it touches you. This post explains what actually changed, why the Framework is exposed, and the honest version of what switching tools does and doesn't fix.
What the court actually decided
The case is Trump v. Slaughter (No. 25-332). In March 2025 the President removed FTC Commissioner Rebecca Slaughter; the statute said commissioners could only be removed "for inefficiency, neglect of duty, or malfeasance in office." The Court sided with the President and, in doing so, overruled Humphrey's Executor v. United States — a 1935 precedent that had protected the independence of agencies like the FTC for nearly ninety years.
| Fact | Detail |
|---|---|
| Case | Trump v. Slaughter, No. 25-332 |
| Decided | 29 June 2026 |
| Vote | 6-3, opinion by Chief Justice Roberts |
| Holding | For-cause removal protection for FTC commissioners is unconstitutional; the President may remove them at will |
| Precedent overruled | Humphrey's Executor v. United States (1935) |
The domestic consequence is that the FTC — and, by the same logic, agencies like the NLRB and MSPB — is no longer structurally independent of the White House. That's the part that reaches across the Atlantic.
Why the Data Privacy Framework is exposed
When the European Commission granted the US "adequacy" in July 2023 (Commission Implementing Decision (EU) 2023/1795, the legal instrument behind the Data Privacy Framework), it had to explain how US law protects EU citizens' data to a standard "essentially equivalent" to the GDPR. A central pillar of that argument was independent oversight and redress — and the FTC's independence is cited throughout the adequacy decision as proof the enforcement is real. noyb counts more than 250 references to it.
Pull the independence out, and noyb's argument is blunt: the factual premise the Commission relied on no longer holds. In their words, "the entire structure of the EU-US Data Privacy Framework has just collapsed." On 30 June 2026 Schrems sent the Commission a formal letter calling for an "orderly withdrawal" from the adequacy decision, and said noyb would file its own annulment case at the Court of Justice of the EU "in the coming weeks" if Brussels doesn't act.
Not everyone thinks the FTC is the load-bearing part. Some privacy lawyers argue the adequacy decision leans harder on the redress route the US built for EU citizens — the Data Protection Review Court, created by executive order — which this ruling leaves untouched, and that the FTC's role is smaller than noyb makes out. That's a real debate, and it's why nobody credible is calling the deal dead today. What isn't in dispute is that a safeguard the Commission cited throughout its decision has just been weakened, at the exact moment the deal's most effective critic is heading back to court.
Two other things worth keeping straight, because they cut against the panic:
- The Framework is still valid. Implementing Decision (EU) 2023/1795 stays in force until the Commission repeals it or the CJEU annuls it. As of today it has done neither, and the Commission has said only that it's assessing the ruling and is "in close contact with the US administration."
- This isn't the same as the pending EU-side challenge. A separate case (Latombe, C-703/25 P) is already working its way up to the CJEU. What's new here is a US-side event — the removal of the safeguard the deal was built on — that hands that kind of challenge fresh ammunition.
So it's not "GA4 is now banned." It's "the mechanism that was supposed to make EU→US transfers safe has a new, serious crack in it, and the people who broke the last two frameworks are back in court."
What this means if you use Google Analytics
Google LLC self-certifies under the Data Privacy Framework (its listing is active), and it relies on that certification — with Standard Contractual Clauses as a backstop — to legitimize moving EEA personal data to the United States. That's the plumbing under GA4 for European sites: your visitors' data goes to Google in the US, and the DPF is a big part of what makes that lawful.
If the DPF's foundation is genuinely in doubt, so is that transfer story. And the backstop is not obviously safer: Standard Contractual Clauses require a "transfer impact assessment" that weighs whether US oversight bodies actually protect the data — an assessment that, until last month, took the FTC's independence as a given. The same ruling that dents the DPF dents the fallback.
None of this forces an immediate change. But it is exactly the sort of live legal risk that made EU regulators uneasy about Google Analytics after Schrems II — and it's worth knowing whether your analytics even puts you in the blast radius.
The honest part: what actually helps
Here's where a lot of privacy-tool marketing would tell you their product makes you immune. It doesn't work like that, and pretending otherwise would be the opposite of the point.
The transfer problem is specifically about sending EU residents' personal data to a US company. There are two honest ways a tool sidesteps it, and only one of them is airtight:
- Keep the data in the EU. Useful, but on its own it's a weaker guarantee than it sounds — a US-headquartered provider can be subject to US legal process regardless of where the servers physically sit. "EU-hosted" is not the same as "outside US reach" — a point Plausible makes on its own EU-hosting pages.
- Don't collect personal data at all. If there's no personal data, there is nothing to transfer, and the entire adequacy question is moot. This is data minimisation, and it's the only version that doesn't depend on a legal deal holding up.
We should be straight about our own stack, because it's the same honesty we'd want from anyone else: Simplytics runs on Cloudflare, and Cloudflare is a US-headquartered company. What makes the transfer question a non-event for us isn't a jurisdiction claim — it's that there's no personal data on the move. Simplytics sets no cookies, never stores IP addresses (the last byte is dropped before the IP is hashed into a same-day deduplication key, then nothing is kept), takes each visitor's country from Cloudflare's CF-IPCountry edge code rather than an IP lookup, and wipes raw visit records nightly — only anonymous aggregates survive. The primary analytics database sits in the EU (Warsaw), but that's the belt; the braces are that there's nothing personally identifiable to argue about in the first place.
| Google Analytics 4 | Cookieless, aggregate analytics (e.g. Simplytics) | |
|---|---|---|
| Personal data sent to a US company? | Yes — that's what the DPF has to legitimize | No personal data collected to transfer |
| Depends on the Data Privacy Framework? | Yes (with SCCs as backup) | No |
| Affected if adequacy is withdrawn? | Directly | Not for the analytics data |
| Consent banner needed in the EU? | In practice, yes | No — no cookies, no personal data |
The category that clears this bar isn't just us — Plausible, Fathom, and Simple Analytics are cookieless and privacy-first too, and each dodges the transfer question to the degree it avoids collecting and exporting personal data. The differentiator we'll actually stand behind is price and scope: the same escape from the transatlantic-transfer headache used to mean either running your own server or paying $9-15/month for a hosted privacy tool. Simplytics does the core job — visitors, pages, referrers, sessions, countries, events, funnels — for $1/month, with EU data and no banner. A lot of functionality for a lot less money, and nothing riding on a data deal that keeps getting litigated.
What to actually do
You don't need to rip anything out this week. But this is a reasonable moment to know where you stand:
- Check whether your analytics transfers personal data to the US. If you use GA4, it does, and the DPF is part of what makes that lawful. If you use a cookieless, aggregate-only tool, it generally doesn't.
- Watch the Commission, not the headlines. The trigger that would actually change your obligations is the Commission repealing the adequacy decision or the CJEU annulling it — not a law firm blog (including this one) saying the sky is cracking.
- If you were already uneasy about EU→US transfers, this is the nudge. A tool that collects no personal data takes the whole question off your plate, permanently, rather than betting on the next framework surviving longer than the last two did. It's the same logic behind the EU's own moves to simplify cookie rules and France's consent exemption for privacy-clean analytics: the less personal data you touch, the fewer legal deals you have to hope hold.
The bottom line: on 29 June 2026 the US Supreme Court removed the FTC independence that the EU-US Data Privacy Framework was built on, and noyb is asking Brussels to withdraw the adequacy decision that lets Google Analytics send EU data to the US. The deal is still in force, so this is risk, not a ban. But if your analytics never collects personal data to begin with, there's nothing in that transfer to lose — which is a quieter place to be than waiting to see whether the third transatlantic data deal in a decade outlasts the second.