Many will recall Schrems I (2015) and Schrems II (2020), which invalidated the Safe Harbour and Privacy Shield, creating significant disruption for transatlantic data transfers. Now the future of the EU-US Data Privacy Framework has once again been called into question following the US Supreme Court’s decision in Trump v. Slaughter. The case concerned the President’s power to remove Federal Trade Commission (FTC) commissioners and raises the question as to whether the FTC can still be considered sufficiently independent for the purposes of EU data protection law.
Why is the Data Privacy Framework being questioned?
This has led to speculation that a fresh challenge to the Data Privacy Framework may be imminent, as referred to as ‘’Schrems III”. The argument is that if the FTC is no longer considered an independent regulator, this could weaken the foundations of the Data Privacy Frameworks adequacy decision.
There is no immediate change to the legal position in the UK. The Data Privacy Framework remains valid and organisations can continue relying on it for transfers of personal data to participating US organisations. Any challenge would need to progress through the European courts before the position changes.
What does this mean for UK organisations
Whilst any challenge is likely to focus initially on the EU-US Data Privacy Framework, a successful challenge could also have implications for the UK’s data bridge arrangements with the United States. UK organisations that transfer personal data to the US may therefore wish to review their existing transfer mechanisms and ensure that alternative safeguards remain available should the position change.
For now, the Data Privacy Framework remains in force. Nevertheless, organisations should stay on top of developments, review their transfer mechanisms and consider any risk with potential new suppliers located in the US.
Talk to our team
Our specialist Data Protection lawyers advise businesses on international data transfer requirements, supplier due diligence, contractual safeguards and regulatory compliance. To discuss how these developments discussed in this article could affect your organisation, please get in touch.