CJEU - T‑553/23, - Latombe v Commission
| CJEU - T‑553/23, Latombe v Commission | |
|---|---|
| Court: | CJEU |
| Jurisdiction: | European Union |
| Relevant Law: | Article 22 GDPR Article 32 GDPR Article 45(2) GDPR Article 47 GDPR Article 47 CFR Article 7 CFR Article 8 CFR |
| Decided: | 03.09.2025 |
| Parties: | Philippe Latombe The Commission |
| Case Number/Name: | T‑553/23, Latombe v Commission |
| European Case Law Identifier: | ECLI:EU:T:2025:831 |
| Reference from: | |
| Language: | 24 EU Languages |
| Original Source: | Judgement |
| Initial Contributor: | cci |
The General Court dismissed an action for the annulment of the Commission’s adequacy decision for the US on grounds that the Trans-Atlantic Data Privacy Framework offered a sufficient level of protection for personal data when the decision was adopted.
English Summary
Facts
The Trans-Atlantic Data Privacy Framework
The Schrems II ruling of the CJEU annulled the Commission’s adequacy decision[1] that declared that the US offered an equivalent level of protection for personal data.
Following the decision, the EU and the US established the Trans-Atlantic Data Privacy Framework (DPF). The DPF is a set of legal acts which, altogether, aim to address the shortcomings in US protection of European data highlighted by Schrems II. In particular, the DPF established:
- a Privacy and Civil Liberties Oversight Body (PCLOB) with oversight powers on the activities of intelligence agencies
- a Data Protection Review Court (DPRC) with the power to review and overturn the PCLOB’s decisions.
Based on the new safeguards introduced with the DPF, the Commission considered that the US offered an adequate level of data protection and adopted a new adequacy decision allowing for data flows (Commission Implementing Decision 2023/1795 finding an adequate level of protection ensured by the United States). The decision allowed EU entities to transfer data to US-based recipients on the basis of Article 45 GDPR (as long as the recipients were certified under the Data Privacy Framework program[2]).
Latombe's annulment action
In October 2023 French citizen Pierre Latombe[3] filed an annulment action with the CJEU against the new adequacy decision from the commission (from now on: ´the adequacy decision´). Contrary to the Commission’s findings, Latombe claimed that the US did not ensure a sufficient level of protection for personal data in the context of third-country data transfers, as required by Article 45(2) GDPR.
In particular, Latombe claimed that:
- The DPRC was not "an independent and impartial tribunal previously established by law", as required by the right to fair trial under Article 47 CFR.
- The adequacy decision violated Article 7 CFR and Article 8 CFR because the US did not ensure an adequate level of protection with regard to the bulk collection of personal data from intelligence agencies.
- The adequacy decision violated Article 22 GDPR because the US legal system did not provide guarantees against automated decision-making comparable to those provided by Article 22 GDPR.
- The data security obligations under the adequacy decision were too narrow, in violation of Article 32 GDPR and Article 42(2) GDPR.
Holding
The Court held that the DPF granted a sufficient level of data protection at the time of its adoption. On these grounds, the Court dismissed the action on merits.
Notably, the Court assessed the legality of the adequacy decision based on the factual and legal circumstances existing when the decision was adopted. The Court clarified that later legal and factual developments were not relevant to the assessment[4].
On admissibility
The Commission argued that the action was inadmissible because Latombe lacked standing for direct action. The Court, however, did not assess the admissibility on the action. Rather, the Court held that the action was unfounded and considered that in the case at hand, the proper administration of justice justified dismissing the action on its merits without ruling on admissibility.
On 47 CFREU
"Impartial and independent"
Contrary to Latombe’s arguments, the Court held that the DPRC was an independent and impartial tribunal in the sense of Article 47 CFR.
The Court considered that the appointment of judges by the Attorney General, and the requirements for the role (which were, in essence, comparable to the requirements for serving as a federal judge), were sufficient to ensure the impartiality and independence of the body.
The Court also considered that the DPRC had broad fact-finding powers as well as the power to overturn decisions from the PCLOB. Therefore, the independence and impartiality of the PCLOB (which Latombe also questioned) were not relevant to the assessment of the impartiality and independence of the DPRC.
Established by law
With regards to the requirement that a tribunal be “established by law”, the Court acknowledged that the DPRC was established via a Regulation of the AG (and, therefore, by the executive rather than a formal law of Congress).
However, the Court held that this circumstance was not enough to conclude that the DPRC was not “established by law”. In the Court’s view, the requirement that a court be established by law must not be interpreted formally but rather in relation to the guarantees of impartiality and independence of the court itself[5].
The Court held that the AG Regulation in question included sufficient guarantees in this sense. On these grounds, the Court dismissed Latombe’s argument.
On bulk data collection
As explained above, Latombe argued that the adequacy decision violated Article 7 CFR and Article 8 CFR (respectively, “Respect for private and family life” and “Protection of personal data”) because the US did not ensure an adequate level of protection with regard to the bulk collection of personal data from intelligence agencies. In particular, Latombe observed that Executive Order 12333 did not require previous authorization for bulk data collection from intelligence agencies.
The Court, on the other hand, held that bulk data collection was not, in itself, incompatible with Article 7 CFR and Article 8 CFR. The Court held that US law provided sufficiently clear and precise rules on bulk data collection and that the DPRC had the power to exercise ex-post judicial oversight.
With regards to judicial oversight specifically, the Court clarified that neither CJEU nor ECtHR case law necessarily require an ex ante authorization regime for the bulk collection of personal data. An ex post and independent judicial oversight, such as that carried out by the DPRC, may be considered sufficient if robust enough.
On Article 22 GDPR
The Court held that US law provided sufficient guarantees for data subjects with regards to automated decision-making. In this regard, the Court observed that many US-based data controllers not established in the Union are nonetheless subject to Article 22 GDPR by virtue of Article 3(2) GDPR (Territorial scope). The Court also considered that even cases falling outside the scope of the GDPR are frequently covered under sectorial US laws[6] and that such laws include sufficient safeguards with regards to automated decision-making.
On Article 32 GDPR
Latombe claimed that the requirements for data security in the adequacy decision were narrower in scope[7] that those found in Article 22 GDPR. Therefore, he argued that the adequacy decision violated Article 32 GDPR read in conjunction with Article 42(2) GDPR.
The Court, on the other hand, held that the security provisions of the adequacy decision were broad enough in scope when interpreted in light of the entire legal text. On these grounds, the Court held that the adequacy decision did not violate Article 32 GDPR.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
- ↑ Commission Implementing Decision (EU) 2016/1250 of 12 July 2016.
- ↑ See point 2.1.1. of the adequacy decision. A similar limitation was also in place for the Privacy Shield, i.e. the pre-Schrems II data transfer framework.
- ↑ Philippe Latombe is a Member of the French Parliament and a Commissioner for the French DPA (CNIL). However, he acted as a private citizen.
- ↑ See margin 22 of the ruling.
- ↑ In this regard, the Court leveraged both ECtHR case law on Article 6 ECHR (“Right to a fair trial”) and the principle of the “substantial equivalence” of safeguards in other countries as established in the Schrems II ruling.
- ↑ In this regard, the Court mentioned the Fair Credit Reporting Act, the Equal Credit Opportunity Act, the Health Insurance Portability Act (HIPAA), the Fair Housing Act, and Title VII of the Civil Rights Act.
- ↑ Specifically, Latombe pointed out that the security requirements under point III.6(f) of Annex I applied when organizations “create, maintain, use, or disseminate personal data”- a notion much narrower than that of “data processing”.




