EU/US data transfers under pressure: Supreme Court undermines the FTC’s independence

A recent ruling by the US Supreme Court could have far-reaching consequences for transatlantic data protection. In the case of Slaughter v. Trump, the judges ruled that members of the Federal Trade Commission (FTC) may, in principle, be removed by the President even without a statutory ground for dismissal. In doing so, the court has called into question the FTC’s previous independence.

This decision is also of considerable significance from a European perspective. The European Commission bases the EU-US Data Privacy Framework, amongst other things, on the assumption that the FTC acts as an independent supervisory and enforcement authority for data protection breaches. Under European law, however, the independence of data protection supervision is an essential prerequisite for an adequate level of data protection.

What are the implications for the EU-US Data Privacy Framework?

Legally, the Data Privacy Framework remains unchanged for the time being. The European Commission’s adequacy decision continues to apply until it is either revoked by the Commission itself or declared invalid by the ECJ. Businesses can therefore continue to rely on the Data Privacy Framework for the time being.

Nevertheless, the Supreme Court’s decision is not without significance. It removes the factual basis for a key assumption underlying the adequacy decision and is likely to reignite the debate on the long-term stability of the Framework. It remains to be seen whether and how the European Commission will respond to the changed situation in the US.

What does this mean for standard contractual clauses (SCCs)?

Businesses that rely on standard contractual clauses for data transfers to the US should also follow developments closely. The Danish Data Protection Authority points out that controllers should review their country assessment as part of the Transfer Impact Assessment (TIA). In particular, they should assess whether the conditions for independent regulatory oversight in the recipient country continue to be met.

Furthermore, the authority recommends reviewing existing exit strategies and, where necessary, refining them in order to be prepared for potential regulatory changes.

European sovereignty is gaining in importance

Current developments demonstrate once again that international data transfers can be subject to significant legal changes. For many businesses, European cloud and hosting solutions are therefore increasingly coming into focus – particularly when it comes to the processing of sensitive data.

Alongside privacy law requirements, aspects of European sovereignty are coming more into focus. The aim is to deploy critical data and digital infrastructure within Europe and to reduce dependencies on non-European legal systems.

For businesses, this means that, alongside ensuring the legal safeguards for international data transfers, strategic issues of digital sovereignty are also coming more into focus. European hosting models and data protection-compliant cloud solutions are thus becoming not just a matter of compliance, but increasingly a competitive advantage.