An Early Warning for the Data Privacy Framework

The Data Protection Act 2018 has been around long enough now that we are all fairly comfortable in relation to our obligations and rights. But for this article we need to peer under the bonnet and get into the nitty gritty a little. 

For the purposes of this article, we will be looking at the EU GDPR and specifically US data transfers. Our data protection legislation applies the EU GDPR Regulations and, importantly, directly imports and relies on the EU's own Article 45 adequacy findings, including those in respect of the US. 

Under Article 45(2)(b) any data transfer to a third country relies upon the EU declaring an adequacy decision for the territory in question. Adequacy is reliant upon the EU being satisfied that the territory in question has independent supervisory oversight that can oversee and police the rights of data subjects with independence and impartiality. 

Data transfers between the EU and the US have been on somewhat of a journey over the years. To understand where we now find ourselves, we need to understand where we’ve been. It all started in 2000 with Safe Harbour. 

Safe Harbour and Mr Schrems (Schrems I)

The Safe Harbour framework was established in 2000 to allow EU-US data transfers. In 2015, Austrian lawyer Schrems complained to the Irish DPC after the Snowden leaks, arguing Facebook's transfer of his data to US servers wasn't adequately protected given what was revealed about NSA surveillance. In October 2015 the CJEU invalidated the Commission's 2000 adequacy decision on the basis that the program did not ensure an adequate level of protection for the fundamental rights of European citizens concerning privacy and personal data.

Privacy Shield and Mr Schrems (Schrems II)

The European Commission and US Secretary of Commerce announced the adoption of the Privacy Shield in July 2016 to replace the Safe Harbour framework. It was created to be more robust than Safe Harbour in that it had a new independent redress channel specifically for national security/intelligence complaints (the Privacy Shield Ombudsperson Mechanism), a built-in yearly health check involving the Commission, the Department of Commerce, and the Federal Trade Commission (FTC), tighter onward transfer rules and a defined complaint-handling timeline. 

On paper the Privacy Shield appeared more robust, but at launch even the Article 29 Working Party were flagging concerns including that bulk data collection was still permitted “where deemed necessary for national security” and that the Ombudsperson's powers weren't guaranteed to be adequate.

In the background, the wheels slowly turned on the Schrems I timeline. After Safe Harbour fell in 2015, Schrems' original complaint against Facebook got sent back to the Irish DPC. Facebook had switched to relying on Standard Contractual Clauses instead of Safe Harbour, so the DPC brought proceedings asking the CJEU whether the SCCs themselves held up given the same US surveillance concerns. The CJEU's answer in 2020 went further than asked;  it upheld SCCs generally, but struck down the Privacy Shield on the grounds that there was disproportionate intelligence access and the Ombudsperson redress mechanism wasn't independent or binding. 

The Data Privacy Framework

The Data Privacy Framework arrived in July 2023, built specifically to answer the flaws identified in the Privacy Shield. On the intelligence access side, a new US Executive Order introduced proportionality limits on surveillance, restricting collection to what was deemed necessary. On redress, the Ombudsperson was replaced with a standing body, the Data Protection Review Court, with the power to issue binding decisions rather than simply confirming that procedures had been followed. 

So far so good, but there was still a critical, fundamental weakness: the FTC. Commercial enforcement, making sure US companies actually kept their DPF promises day to day, still fell to the Federal Trade Commission. The US has no dedicated data protection authority of its own, so that job landed with the FTC, using its general powers over unfair and deceptive trade practices to hold DPF-certified companies to account.  

The Data Privacy Framework relies upon the fact that the FTC is independent and that the administration can only remove the FTC Commissioners  “for cause” (inefficiency, neglect of duty, or malfeasance in office) a protection meant to insulate the agency from political control. That’s where things under the current administration unravel. 

Enter Mr Trump (Trump v Slaughter) 

In March 2025, the Trump Administration fired two of the FTC Commissioners on the basis that their continued service was “inconsistent with his administration’s priorities”.  The termination was challenged by Kelly Slaughter (one of the commissioners fired) in the courts and on 29 June 2026, the Supreme Court ruled 6–3 that the FTC’s “for‑cause” removal restriction was unconstitutional, holding that officers exercising executive power must be removable by the President at will. For all intents and purposes, the FTC was no longer insulated from political control and the independence premise the Commission relied on for the FTC's enforcement role no longer holds. 

Third Time’s the Charm? 

There’s a pattern here. Three times now the EU has agreed a US data transfer framework, and three times the framework has come apart, or is coming apart, on some version of the same problem: whether the body meant to hold the US side accountable is actually effective. Safe Harbor had no independent redress mechanism at all. Privacy Shield had one, but it was not independent, and it could not issue binding decisions. The Data Privacy Framework fixed that specific gap by creating the Data Protection Review Court, only for its other independence pillar, the FTC, to fail as collateral damage from a domestic power struggle. Each iteration has attempted to shore up the previous flaws but none has addressed the underlying one: an independent US oversight body that cannot, in practice, remain fully independent of the administration in power.

Things are likely to change (again) 

The European Data Protection Board has formally asked the European Commission to reassess the DPF in light of the ruling, though it stresses the adequacy decision remains in force unless and until annulled by the Commission or CJEU. 

While nothing immediate has changed, we must view the Supreme Court’s ruling as an early warning sign that things are likely to change again and be ready for that change. In practice, it’s advisable to pre-empt that by:

·       Re‑assessing US transfer risk assessments and consider your exposure if the DPF falls;

·       Consider reinforcing transfers with Standard Contractual Clauses (SCCs) and any additional safeguards that may be required; and

·       Monitor for any Commission review or CJEU litigation targeting the DPF post‑Slaughter.