Two weeks ago the American president signed an executive order intended to fix what the European Court of Justice broke in 2020. It writes necessity and proportionality into the conduct of United States signals intelligence, and it creates a two-stage redress path for Europeans who believe their data was improperly collected: first an intelligence community civil liberties officer, then a newly created Data Protection Review Court established by regulation within the Justice Department. That is the American half of the political agreement announced in March. The European half has not really started. Nothing has changed legally, no adequacy decision exists, and any organisation told this week that transfers are now fine has been told something untrue.
What the order actually does
It binds the intelligence agencies to proportionality. Signals intelligence activities must be necessary and proportionate to validated intelligence priorities, with enumerated legitimate objectives and prohibited purposes. This is a genuine change in the internal legal framework, not a press release. It creates redress without requiring standing. The complaint path does not depend on a person proving they were surveilled, which was the specific barrier the court identified. Decisions of the review court are described as binding on the agencies. It works through a designation switch that has not yet been flipped. European residents can only use the redress mechanism once the Attorney General designates their country as a qualifying state, which requires a finding that it provides appropriate reciprocal protections. That designation has not happened. It is a procedural detail that will matter enormously to the timeline, and almost nobody outside the specialist press has noticed it.
What it does not do
Bulk collection continues, permitted where targeted collection is not feasible, subject to the new proportionality tests. The review court sits within the executive branch rather than the judiciary, created by regulation rather than statute, which means its independence rests on the strength of that regulation and the political will behind it. And a future administration can amend an executive order considerably more easily than a legislature can amend a law. Those are precisely the grounds on which a challenge will be built, and the campaigner who brought down the previous two arrangements said within a day of signature that the core issues appear unresolved.
Adequacy is a lease, not a freehold. The previous one ran four years
This is the planning assumption that matters. The first arrangement lasted fifteen years and fell in 2015. Its replacement lasted four and fell in July 2020. A third is now being assembled on the same foundations — an executive commitment about intelligence practice, assessed by the European Commission as essentially equivalent to European fundamental rights protection. It may well be adopted, and it may well hold for several years. It should not be treated as a permanent settlement, and no architecture decision should be made that is only defensible while it survives.
The path from here, and how long it takes
The European Commission must prepare a draft adequacy decision. The European Data Protection Board gives an opinion, which will be published and read carefully. Member states vote through the committee procedure. The European Parliament scrutinises, without a veto. Only then does adequacy exist. Realistically, that is the first half of next year at the earliest, and later if the board opinion is difficult or the qualifying-state designation lags. Until adoption, the obligations on every transfer out of Europe are exactly what they were last month: standard contractual clauses, a documented transfer assessment, and supplementary measures where the assessment requires them.
What to do between now and then
Keep the existing mechanism running and current. Dismantling contractual clauses and transfer assessments in anticipation of adequacy is the single worst move available, and it is being contemplated in more organisations than it should be. When adequacy arrives, treat it as a simplification layered over the fallback, not a replacement for it. Keep the assessments maintained and the clauses in the contracts. The cost of leaving them in place is close to zero; the cost of rebuilding them under time pressure is not. Build the inventory around transfers, not vendors. The question is which flows go where, under what mechanism, carrying what categories of data — not which suppliers you use. Put a mechanism-agnostic obligation in contracts. The supplier must maintain a valid transfer mechanism at all times, notify you when it changes, and cooperate with an alternative if it fails. This survives every future court decision, which no specific mechanism will. Do not repatriate architecture decisions on the strength of a framework that does not exist yet. Moving a data platform to a United States region this quarter because the problem is reportedly solved is how organisations acquire an expensive migration two years from now.
Who this actually affects
Three groups, with different positions. Organisations that never remediated after 2020 and have been running on optimism should use this period to build the assessment they skipped, because the arrival of adequacy will not retroactively legitimise the last two years. Organisations that re-architected to European hosting should leave it alone; that decision has held up well and is cheaper than reversing twice. And organisations whose transfers go somewhere other than the United States get nothing at all from this, because the framework covers certified American recipients only — which is the group most likely to misread the coming headlines.
Practical Guidance for Transfer Strategy Briefing
- Inventory transfers by flow, including support access, analytics and backup, not just primary hosting.
- Keep contractual clauses and transfer assessments live through the adoption period.
- Insert a mechanism-agnostic transfer obligation into every renewal you sign this quarter.
- Identify flows the framework will never cover and plan those separately.
- Avoid new architecture that depends on adequacy until the decision is adopted and unchallenged.
- Diarise the decision points: draft decision, board opinion, member state vote, qualifying-state designation.
- Brief the executive team on the half-life, so the next invalidation is a plan rather than a crisis.
- Align the analytics and advertising stack now, because that is where stop orders have actually landed.
The Regional Angle
Three points deserve attention from regional readers, and the first is that this framework does almost nothing for them. Over the coming months, vendors will market the new arrangement in the Gulf as a general reassurance about data protection compliance. It is not. It certifies American recipients receiving data from Europe. It says nothing about transfers from Europe to the Gulf, nothing about transfers from the Gulf to anywhere, and nothing about a regional company's obligations under its own new laws. When a supplier cites it, the correct response is a single question: which specific flow does that cover, and what mechanism covers the others. Most sales teams cannot answer, which is itself informative. The second is that the region hosts some of the largest European-origin data flows outside Europe, and they sit in sectors that rarely feature in this debate. Gulf airlines and hotel groups move European passenger, loyalty and guest data continuously, in volumes that dwarf the average technology company's transfers, under a mixture of sectoral arrangements and ordinary transfer rules. Those flows were never covered by the transatlantic mechanism and will not be covered by its successor. For an airline, a hospitality group or a travel platform here, the meaningful work is a transfer assessment on European-origin passenger and guest data, not a watching brief on Washington. The third is that the harder transfer question for regional companies is now outbound rather than inbound. The federal decree-law in the Emirates introduces cross-border transfer provisions, the financial free zones operate their own data protection laws with their own transfer regimes, and Saudi Arabia's law contains transfer restrictions that have been under active consultation. A single regional group can therefore sit under three or four different outbound regimes across its own entities, with different lists of acceptable destinations and different safeguards. The instinct to write one group transfer policy is wrong by construction here. Write one transfer register covering every flow in both directions, then map each flow to the regime that governs it — the register is portable, the policy is not.
The objection worth taking seriously
The strongest objection is that this is theatre. After the 2020 judgment, virtually nobody stopped transferring data to the United States. Enforcement was sparse and slow, the overwhelming majority of organisations did nothing beyond signing updated clauses, and business continued unaffected. If the third framework is struck down in three years, the same will happen again. Building elaborate contingency around a hypothetical future court ruling is a poor use of scarce compliance capacity, particularly for companies whose realistic risk is a ransomware incident rather than a transfer challenge. Descriptively, that is accurate, and the profession's credibility suffered from two years of warnings that mostly did not materialise. But the enforcement that did arrive is the instructive part: a series of decisions this year about a common analytics configuration produced orders to stop using a tool, not fines. A small number of organisations genuinely had to change systems at short notice, and the ones who coped were the ones who already knew which flows went where. The cost of durability here is low, because it consists mainly of not dismantling something you already have. And the expensive mistake available right now is not a missing document — it is an architecture decision taken this quarter on the assumption that the question is closed.
Common Questions
Can we rely on the new framework today?
No. There is no adequacy decision. Current obligations are unchanged until the European process completes.
Should we keep our transfer assessments once adequacy arrives?
Yes. Maintain them as a documented fallback; the marginal cost is small and the rebuild cost under pressure is not.
Does this help transfers to countries other than the United States?
Not at all. Those continue under contractual clauses, derogations or other adequacy decisions, and they are frequently the flows with the weakest documentation.
What should we expect over the next twelve months?
Expect a draft adequacy decision from the Commission within a few months, followed by a data protection board opinion that is broadly supportive and pointedly critical on the independence of the redress mechanism. Expect adoption in the first half of next year at the earliest, contingent on the qualifying-state designation being made. Expect a legal challenge to be announced within days of adoption and to reach the court eventually. Expect the pending Irish decision on a major platform's transatlantic transfers to land before any of this is finished, which will produce an awkward few weeks. And expect nothing about your obligations to change in the meantime, whatever your vendors' marketing says.
Transfer Strategy Briefing — we build the flow-level register that survives the next invalidation, keep your fallback mechanisms live through adoption, and separate the transfers this framework covers from the ones it never will.
