Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 7/10

Data Security at German Companies: US Politics Threatens Transatlantic Data Transfers

The EU-U.S. Data Privacy Framework is on shaky ground. Political developments in the US and structural dependencies are putting the data security of German companies at risk. How businesses can increase their resilience.

Transatlantic Data Transfers Under Pressure: When US Politics Becomes a Threat

The exchange of data between Europe and the US is business-critical for German companies. Yet the foundations of these transatlantic transfers are becoming increasingly unstable. Political tensions and legal uncertainties are turning into a tangible risk for compliance, IT operations and business models. At the same time, structural dependencies and questions of digital sovereignty are moving further into the focus of the security debate.

What happened? – Key facts about the current situation

Transatlantic data transfers are in a critical phase. According to Handelsblatt, leading German business associations are warning about the consequences of unpredictable US policy. The reason: the US President could unilaterally call existing data transfer agreements with the EU into question and thereby turn data transfers into a political lever.

Holger Lösch, Deputy Director General of the Federation of German Industries (BDI), stressed to Handelsblatt that reliable and legally secure data traffic is "indispensable" for German industry. The failure of the current framework would have "devastating consequences": companies would have to reckon with considerable additional effort, legal uncertainty as well as potential lawsuits and fines.

A concrete sign of destabilisation can be seen in personnel changes: on 22 January 2025, several members of the Privacy and Civil Liberties Oversight Board (PCLOB) were dismissed at the instigation of US President Donald Trump. According to the Chamber of Industry and Commerce (IHK), the PCLOB has only one remaining member and therefore no longer has a quorum. This body plays a central role in overseeing the US intelligence services under the data protection agreement.

The legal basis: the Data Privacy Framework and Executive Order 14086

The central basis for transatlantic data transfers is the EU-U.S. Data Privacy Framework (DPF), in force since July 2023. On the basis of an adequacy decision under Article 45 GDPR, it permits the transfer of personal data to the US without additional authorisation – provided that the US companies involved are appropriately certified.

For many companies this agreement is essential: without this mechanism, core business processes – from cloud usage to customer management – would be almost impossible to map legally. Transferring personal data to the US is an integral part of the business model for numerous companies, for example through the use of American software, conferencing platforms, CRM systems or cloud services.

Executive Order 14086 issued by former US President Joe Biden (October 2022) sets binding data protection requirements for US intelligence services and creates oversight mechanisms, for instance through a redress procedure (Data Protection Review Court). It forms a central foundation of the EU-U.S. Data Privacy Framework, as it is intended to improve the protection of EU citizens' personal data in the US.

However, the stability of the DPF is increasingly in doubt. Back in October, the IHK warned that these developments could undermine the supporting oversight and protection mechanisms of the data protection framework. If central supervisory structures such as the PCLOB are no longer functional, or the underlying legal bases are weakened, the equivalence of the level of data protection begins to falter – and with it the central legal basis for data transfers as a whole.

The European Commission has so far stuck to this decision in order not to jeopardise data traffic. But should the legal framework in the US change substantially – for instance through a repeal of Executive Order 14086 – it would have to react. The consequences could be immediate: from additional review obligations for companies through to a complete halt of data transfers on this basis.

Court confirmation with reservations: the General Court ruling of 3 September 2025

In its ruling of 3 September 2025, the General Court of the European Union confirmed the lawfulness of the current adequacy decision. However, it explicitly tied this to the existing safeguards. At the same time, the court made clear that in the event of fundamental changes to the US legal framework, the European Commission has the option to intervene – up to and including suspending or repealing the adequacy decision.

The structural conflict: GDPR versus the US CLOUD Act

Alongside the political risks, there is a fundamental and so far unresolved structural problem: the basic difference between the European understanding of data protection and US security legislation. This conflict makes transatlantic data transfers permanently vulnerable to legal and political ruptures.

The US CLOUD Act allows US authorities to access data – even when it is physically stored on servers within the European Union. This gives rise to two central risk dimensions for companies:

  • Regulatory risk: If the agreement falls away, a legal vacuum looms. Without viable alternatives, lengthy proceedings and penalties of up to four percent of global annual turnover are on the cards.
  • Operational dependency: According to the German Federal Office for Information Security (BSI), proprietary systems from US providers create a form of "cyber dominance" – in other words, structural control over IT infrastructures.

Digital sovereignty: from strategy to operational necessity

Against this backdrop, digital sovereignty is becoming an operational necessity – no longer merely a strategic option. The ability to dispose of data on one's own terms is becoming a central prerequisite for resilience. Companies must prepare for geopolitical developments to have a direct impact on their IT and data strategy.

Three practical routes to greater resilience

1. Reduce dependencies

Companies need to analyse their software landscape: where are business-critical US solutions in use that prevent a rapid switch (vendor lock-in)? The EU Data Act provides the legal lever here to demand data portability from providers and to dismantle technical barriers to switching.

2. Plan for legal scenarios

Companies should act on several levels:

  • Migration: For sensitive areas such as HR or research, switching to European providers with jurisdiction in the EU is recommended.
  • Contractual guardrails: Where there is no alternative to US providers, companies should insist on fixing "EU data residency" (storage within the EU) in the contract. While this offers no protection against the CLOUD Act, it does make unauthorised access at the administrative level more difficult.
  • Exit strategies: Contingency plans must exist for a worst-case scenario, so that data can be moved promptly to sovereign cloud environments.

3. Implement technological safeguards

Genuine independence comes from technology, not from contracts:

  • Zero-knowledge principle: Using encryption in which the provider has no technical access to the keys ensures that data remains unreadable even if there is an obligation to hand it over in a third country.
  • Use standards: Favouring software with open interfaces (APIs) prevents permanent technological lock-in to a single manufacturer.
  • Data minimisation: Automated processes should be configured so that only the absolute minimum of data required for the process is shared.

Conclusion: act rather than hope

Transatlantic data transfers remain functional for now – but their future is uncertain. Companies are operating in a field of tension between economic necessity and growing uncertainty. The conclusion is clear: anyone hoping for stable framework conditions could be in for a surprise. Those who invest early in resilience and sovereignty, on the other hand, gain a strategic advantage in an increasingly politicised data environment.

German companies would be well advised to reassess their data protection strategy – with a focus on legal scenarios, technological independence and European alternatives. This is not a panic reaction, but responsible business continuity planning in uncertain times.