News
Three Landmark Data Protection Updates in September 2025

September 2025 has been a landmark month for data protection, with 3 major developments in just three days:
- 3 September: The General Court upheld the EU-US Data Privacy Framework (DPF) in the Latombe case, securing legal certainty for transatlantic data flows.
- 4 September: The CJEU issued its EDPS vs SRB ruling, clarified the definition of ‘personal data’ and how to interpret the concept of ‘pseudonymisation’.
- 5 September: The European Commission published a draft adequacy decision for Brazil, recognizing its LGPD as essentially equivalent to the GDPR.
Together, these milestones reshape how organizations transfer data internationally and manage compliance obligations.
📆3 September - Latombe Decision Secures Stability for EU-US Data Transfers
On 3 September 2025, the General Court of the EU upheld the EU-US Data Privacy Framework (DPF), allowing companies registered under the framework to continue transferring personal data to the U.S. with legal certainty. While the decision may still be appealed, it provides much-needed clarity for organizations operating across the Atlantic.
The French MEP Philippe Latombe had challenged the 2023 adequacy decision (Case T-553/23), arguing U.S. law allowed indiscriminate surveillance, lacked independent remedies, provided weak safeguards for automated decision-making, and was too vague on data security.
The Court dismissed all these claims, concluding that:
- U.S. data collection is targeted and subject to oversight.
- The Data Protection Review Court qualifies as an independent and impartial tribunal.
- Sector-specific safeguards for automated decisions are sufficient.
- U.S. data security protections need not mirror EU rules exactly, only be essentially equivalent.
This decision is particularly relevant for sectors like Life Sciences, where international data sharing underpins research, clinical trials, and patient care.
📆 4 September - CJEU’s EDPS vs SRB Judgment: A New Lens on Pseudonymized Data
On 4 September 2025, the CJEU clarified the definition of personal data and the concept of pseudonymisation in EDPS vs Single Resolution Board (Case C-413/23P).
The Court reiterated that “personal data” should be interpreted broadly but rejected the rigid idea that pseudonymised data is always personal. Instead, identifiability must be assessed case by case: data may be non-personal for specific recipients if they cannot reasonably re-identify individuals using their own means.
However, the Court stressed that controllers remain responsible for transparency obligations. Even when recipients cannot re-identify individuals, controllers must still inform data subjects about the identity of recipients and the transfer itself.
For the Life Sciences sector, where pseudonymised data flows between sponsors, CROs, labs, and regulators, this judgment is highly significant. It calls for organizations to embed risk-based identifiability assessments into governance frameworks and compliance protocols. National authorities and the EDPB are now expected to provide guidance on implementation.
📆 5 September - Draft Adequacy Decision for Brazil
On 5 September 2025, the European Commission published its draft adequacy decision for Brazil under the GDPR.
If adopted, the decision will recognize that Brazil’s LGPD ensures protections equivalent to the GDPR, enabling EU-Brazil data transfers without the need for Standard Contractual Clauses (SCCs) or other safeguards.
This would:
- Simplify operations and partnerships for businesses.
- Provide individuals with stronger protections and clarity on how their data is handled abroad.
The draft is now with the EDPB and Member States for review. Meanwhile, Brazil’s authority, the ANPD, has welcomed the draft and expressed interest in reciprocal recognition.
✅ Conclusion
In the span of three days, international data protection saw a wave of change: the Latombe ruling secured EU-US data flows, the CJEU refined the treatment of pseudonymised data, and the European Commission opened the door for free EU-Brazil transfers.
At MyData-TRUST, our team of DPOs and experts are closely following these developments. We help organizations - particularly in Life Sciences and health data - navigate cross-border compliance, implement robust governance, and adapt to evolving regulatory frameworks.
📩 Feel free to reach out to our team at [email protected] to discuss how we can support your projects.

