RC RANDOM CHAOS

SCOTUS Ruling on FTC Independence Guts Legal Basis for EU-US Data Flows

· via Hacker News

Original source

US Supreme Court Just Blew Up EU-US Data Transfers

Hacker News →

In Trump v. Slaughter, the US Supreme Court’s conservative majority endorsed the unitary executive theory, holding that laws shielding agencies like the Federal Trade Commission from presidential control are unconstitutional. The practical fallout reaches across the Atlantic: the FTC’s supposed independence has been the linchpin of every EU-US data-transfer arrangement since 2000, and the current EU-US Data Privacy Framework cites the independent FTC 259 times. EU constitutional law — Article 16(2) TFEU and Article 8(3) of the Charter — demands that data-protection oversight be genuinely independent, and privacy advocate Max Schrems argues that requirement can no longer be met by any US body.

This is the third time the foundation has cracked. The Court of Justice already struck down Safe Harbour (Schrems I) and Privacy Shield (Schrems II) over US surveillance powers and the absence of real judicial redress, yet in 2023 the European Commission approved a near-identical framework. The redress mechanism it leaned on, the so-called Data Protection Review Court, is actually an executive body inside the Justice Department whose independence rests only on a Biden executive order that Trump can revoke at will. With the FTC’s independence now legally dead, noyb has written to the Commission demanding an orderly withdrawal of the US adequacy decision and plans a CJEU lawsuit that could take two to three years.

The collapse is legal, not yet operational. The adequacy decision stays formally in force until the Commission repeals it or the court annuls it, so no transfers stop overnight. But companies leaning on Standard Contractual Clauses or Binding Corporate Rules are not insulated — their transfer impact assessments typically depend on the same now-compromised US oversight bodies, meaning they should reassess immediately and will likely conclude the transfers are no longer lawful. Non-personal data still flows freely and Article 49 GDPR still permits strictly necessary transfers, but not the wholesale offshoring of EU data to US clouds that has become routine.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.