Sources: US and EU are in talks to allow companies, including Facebook and other US tech firms, to keep storing and accessing Europeans' personal data in the US
Context & Ripple Effects
This report lands mid-crisis for transatlantic data flows: the EU had declared the previous transfer pact illegal in 2020, leaving Facebook and other US firms legally exposed. The playbook is familiar — back in 2015, Silicon Valley companies signed side agreements with the EU and built European data centers to stay compliant while a replacement was negotiated, and the talks reported here became the preliminary EU-US deal reached six months later, with the US promising surveillance changes.
What makes the stakes legible is the trust gap underneath: a survey across six EU countries found roughly 84% of people don't trust US tech companies with their personal data, so any new pact has to survive both regulators and public opinion — which is why the draft approval published in December 2022 leaned explicitly on those promised surveillance reforms.
First-order effects
- Facebook and other US tech firms get a path to keep storing and accessing Europeans' personal data on US soil rather than being forced into wholesale relocation of EU user data to European infrastructure.
Second-order effects
- Privacy rights advocates, who were already signaling legal challenges when the 2016 safe harbor deal was struck, have a template to attack again — meaning the successor pact inherits the same litigation vulnerability that killed its predecessor.
Third-order effects
- The recurring pattern — pact struck down, side arrangements and EU data centers as stopgap, renegotiated deal hinging on US surveillance changes — points toward a structural cycle where transatlantic data legality is permanently provisional, and firms hedge by keeping EU-region infrastructure in place regardless of the current agreement's fate.
The trend: Transatlantic data governance is settling into a cycle of invalidated pacts and renegotiated replacements, with US surveillance-reform commitments as the recurring hinge — leaving companies to maintain dual-region compliance indefinitely.