FTC Independence Falls: What the Supreme Court’s Slaughter Ruling Means for UK-US Data Transfers
1st July 2026
On 29 June 2026, the US Supreme Court issued a decision that may do to EU-US data transfers what the Schrems II ruling did in 2020. In a 6-3 ruling in Trump v. Slaughter, the Court overturned the 1935 precedent of Humphrey’s Executor and held that the Federal Trade Commission’s (FTC) ‘for-cause’ removal protections are unconstitutional. The President can now fire FTC commissioners at will.
That sounds like a US constitutional law story, and at first glance it is. But for anyone who transfers personal data from the EU or the UK to a US controller or processor, which is most British businesses, it is also a data protection story. The FTC was the load-bearing wall of the entire architecture of EU-US data flows, and the European Commission relied on its ‘independence’ 259 times in the current EU-US Data Privacy Framework. With independence gone, so is the architecture.
Why this matters for data transfers
EU and UK data protection law restricts the transfer of personal data to ‘third countries’ unless an adequate level of protection is guaranteed. For the US, that protection has come through three successive adequacy frameworks:
- Safe Harbor (2000),
- Privacy Shield (2016), and now
- EU-US Data Privacy Framework (2023).
The first two were struck down by the Court of Justice of the European Union instigated by the Austrian Privacy activist Max Schrems, hence the Schrems I and Schrems II judgments. The third has been the subject of pending litigation in the EU since the day it was adopted.
EU treaty law, specifically Article 16(2) of the Treaty on the Functioning of the European Union and Article 8(3) of the EU Charter of Fundamental Rights, requires that data protection oversight is carried out by an independent authority. Because the US has no national data protection regulator, the European Commission designated the FTC as the equivalent body. That choice held the whole structure together. The Slaughter ruling has removed it.
What the experts are saying
Privacy advocacy group noyb, run by Max Schrems, was unambiguous in its response: ‘the basis for any EU-US data transfer deal is dead’. Schrems is urging the European Commission to retire the US adequacy decision in a managed way, and has sent it a formal letter to that effect. noyb has also signalled that a CJEU challenge, what some commentators are calling ‘Schrems III’, is being prepared.
Legal commentary has caught up quickly. Norwegian law firm Schjødt had flagged exactly this risk back in January 2026, predicting that the FTC’s independence would be central to the survival of the DPF because EU constitutional law requires that data protection oversight be carried out by an independent body. In dissent, Justice Sotomayor warned of ‘a President who emerges with far greater power than ever before’.
What it means for UK-US transfers
For UK businesses, the immediate question is the UK-US Data Bridge: an extension of the EU-US framework brought into force by the Data Protection (Adequacy) (United States of America) Regulations 2023 on 12 October 2023. The Data Bridge allows UK businesses to transfer personal data to US organisations that have certified to both the EU-US Data Privacy Framework and the UK Extension. It rests on the same foundation as the EU framework: the same FTC oversight, the same Data Protection Review Court that exists only by Executive Order, and the same political settlement that Slaughter has just disturbed.
If the European Commission moves to repeal or amend its adequacy decision, the UK government will face pressure to follow. The ICO has not yet commented on the Slaughter ruling at the time of writing. UK businesses should not assume that the Data Bridge is insulated from developments in the EU.
What UK businesses should do now
- Do not panic. The EU-US Data Privacy Framework and the UK-US Data Bridge are both formally in force. A Commission Implementing Decision remains in force until the Commission repeals it or the CJEU annuls it. There is no immediate cliff edge.
- Take stock. Identify which of your processors and sub-processors operate in the US, which framework you currently rely on, and which alternative mechanism (IDTAs, SCCs & BCRs) you would use if the Data Bridge fell away. As noyb has noted, the transfer impact assessments behind those alternatives also rely on US bodies whose independence is now in doubt.
- Refresh your transfer assessments. Under the Data (use and Access) Act 2025 (DUAA), transfer risk assessments are now framed as a ‘data protection test’. Our earlier piece on the ICO’s updated guidance is a good starting point.
- Monitor the political signals. The European Commission has made clear that “digital sovereignty” is a serious policy objective. If this leads to concrete action on the DPF, the UK may have limited time to decide whether to follow. Continuing to permit transfers of EU data to the US — or even UK data alone — would deepen divergence from the EU and could put the UK’s adequacy decision at risk.
What’s next
Even by the standards of EU-US data transfers, the next twelve months will be unusually active. noyb’s CJEU challenge is likely to take two to three years to reach a final decision. The Commission may move sooner, particularly if Member States press for it. And the UK government, facing parallel pressures, will need to decide whether the international transfer regime eased in the DUAA, can carry the Data Bridge in its current form. We will keep tracking this and write again when there is something concrete for UK controllers and processors to act on.
How Griffin House Consultancy Can Help
International data transfers are one of the most volatile areas of data protection right now. We help organisations audit their US data flows, classify transfers by mechanism, refresh transfer impact assessments under the DUAA’s new test, and prepare contingency plans for adequacy changes. Whether you currently rely on the UK-US Data Bridge, International Data Transfer Assessments or on standard contractual clauses, this is a good week to look at the paperwork. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533, and one of our team will be happy to talk it through.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.