FISA 702
In shortThe reason the EU Court of Justice has struck down a data deal twice.
Section 702 of the Foreign Intelligence Surveillance Act is the provision European–American data transfer has hung on for more than a decade. It allows the NSA to target the communications of people outside the United States when those communications sit with a US provider.
The decisive point: the people affected are non-Americans, and non-Americans enjoy no Fourth Amendment protection. There is no individual judicial authorisation in the European sense, but an annual approval of certifications by the FISA court.
Why the Court of Justice got involved
The Court of Justice of the European Union found in 2015 (Safe Harbor) and again in 2020 (Privacy Shield) that American surveillance powers are not limited to what would count as proportionate in the EU, and that the people affected have no effective remedy. See Schrems II.
In response, the US government created a two-stage redress mechanism by Executive Order 14086 in 2022, including the Data Protection Review Court. Today's adequacy decision rests on that. See Adequacy decision.
The open question
An executive order is not a statute. A subsequent administration can amend or revoke it without Congress. That is exactly why European supervisory authorities treat the current arrangement as workable for day-to-day operations, but not as permanently safe.
What follows from it
In practice: transferring personal data to the United States today is lawful while the decision stands. But building an architecture that would not survive the loss of that decision means building in a risk whose timing is outside your control.
That is the real reason companies look at alternatives — not distrust, but the impossibility of planning around a legal basis that gets renegotiated every few years.