Tech Gets Real: Protect Yourself in the AI Era
Jun 30, 2026 · 13 min · 11 segments
The US Supreme Court’s Slaughter ruling on Monday, which overturned longstanding precedent called Humphrey’s Executor, is seriously bad news for American companies who handle Europeans’ personal data…
Okay, this is complicated, but I'm going to try and make it as simple as possible.
Under European data protection law, so privacy law, it is generally not allowed to send people's personal data off to a third country outside of the EU unless that country has an adequate data protection framework of its own.
In other words, if the country doesn't have decent privacy laws, you're generally speaking not supposed to send people's personal information there.
And personal data in Europe means any data that can be connected with an identifiable person.
If a third country does have adequate privacy laws, then the European Commission, which is the executive body of the EU... issues an adequacy decision, and that says it's fine to send people's information off to that country, generally speaking.
The problem is, the country that people generally want to send their personal data off to is the United States, and that's because that's where big tech comes from.
In fact, it doesn't really have much privacy legislation at all at the federal level, apart from if you're talking about medical data and if you're talking about children's data.
This put the European Commission in a tricky position because it meant that they couldn't simply issue an adequacy decision for the US, which was Europe's biggest ally.
And what they essentially did was the companies promised that even though their country didn't have adequate data protection laws, those companies would stick to the kind of rules that Europeans expect to see in terms of protecting people's data.
Okay, this is complicated, but I'm going to try and make it as simple as possible.
Under European data protection law, so privacy law, it is generally not allowed to send people's personal data off to a third country outside of the EU unless that country has an adequate data protection framework of its own.
In other words, if the country doesn't have decent privacy laws, you're generally speaking not supposed to send people's personal information there.
And personal data in Europe means any data that can be connected with an identifiable person.
If a third country does have adequate privacy laws, then the European Commission, which is the executive body of the EU... issues an adequacy decision, and that says it's fine to send people's information off to that country, generally speaking.
The problem is, the country that people generally want to send their personal data off to is the United States, and that's because that's where big tech comes from.
In fact, it doesn't really have much privacy legislation at all at the federal level, apart from if you're talking about medical data and if you're talking about children's data.
This put the European Commission in a tricky position because it meant that they couldn't simply issue an adequacy decision for the US, which was Europe's biggest ally.
And what they essentially did was the companies promised that even though their country didn't have adequate data protection laws, those companies would stick to the kind of rules that Europeans expect to see in terms of protecting people's data.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.