The FTC Question and the Future of EU-US Cross-Border Data Transfers

Contributors

Aswah Javed

Associate Data Privacy Analyst at Securiti

Aiman Kanwal

Assoc. Data Privacy Analyst at Securiti

Published September 7, 2026

Listen to the content

The legal structure of American administrative governance underwent a seismic shift when the U.S. Supreme Court decided Trump v. Slaughter (No. 25–332). By striking down ninety years of precedent originally established in Humphrey’s Executor v. United States (1935), the Court ruled that statutory "for-cause" removal protections protecting Federal Trade Commission (FTC) Commissioners violate Article II of the U.S. Constitution.

This step has not only given rise to debates over the expansion of executive control over regulatory agencies but has also put international supervisory bodies on high alert. By removing the FTC's statutory independence, the Supreme Court has affected the primary supervisory mechanism that underpins the EU-US Data Privacy Framework (DPF).

Background

Shortly after taking office for a second term, President Donald Trump fired FTC Commissioners Rebecca Kelly Slaughter and Alvaro Bedoya, without citing a statutory ground for the action. As per a century-old law, 15 U.S.C. §41, a President is only allowed to fire an FTC commissioner for a serious reason such as inefficiency, neglect of duty, or malfeasance in office. The White House asserted that its continued service was inconsistent with administrative policy, invoking the President’s Article II executive removal powers.

Commissioner Slaughter filed suit in the U.S. District Court for the District of Columbia, challenging the termination as ultra vires as per the precedent set in Humphrey’s Executor Case. The District Court granted summary judgment for Slaughter and prohibited the executive branch from interfering with her official capacity. Then, the Supreme Court granted certiorari before judgment to decide whether Congress can constitutionally restrict a President’s ability to remove independent agency leaders at will.

In a 6–3 decision, the U.S. Supreme Court ruled in favor of President Trump and officially overruled Humphrey’s Executor. The key elements of the Court’s ruling were as follows:

  • Article II Directives: The Court emphasized that Article II, Section 1 of the U.S. Constitution vests executive power solely in the President, who retains the responsibility under Section 3 to ensure that federal statutes are faithfully executed. To fulfill this duty, subordinate officials executing federal law must remain subject to presidential oversight and at-will removal.
  • Historical Precedent: Drawing on the "Decision of 1789" and Chief Justice Taft’s analysis in Myers v. United States (1926), the majority maintained that removing executive officers represents an inherent constitutional authority that Congress cannot restrict by statute.
  • Rejection of Humphrey’s Executor: The majority rejected the distinction established in 1935, which categorized the FTC as exercising "quasi-legislative" and "quasi-judicial" responsibilities rather than core executive power. Given that contemporary independent agencies exercise broad enforcement and investigative authority, the Court determined that they exercise executive power and must answer directly to the President.

Impact on EU-US Data Privacy Framework

The EU-US Data Privacy Framework (EU-US DPF) is the legal mechanism that permits personal data to flow from the European Union to companies in the United States. The European Commission adopted it in July 2023, following the Court of Justice's decision in Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Case C-311/18) ("Schrems II”), which invalidated its predecessor, the Privacy Shield. It operates as an adequacy decision, a formal determination that the United States affords European data a level of protection essentially equivalent to that guaranteed within the EU. In its absence, transatlantic transfers must rely on more cumbersome safeguards, such as Standard Contractual Clauses.

At first glance, Trump v. Slaughter bears no relation to this regime. The case concerns presidential authority and the removal of FTC commissioners, not data protection or international transfers. Its relevance is indirect but significant. The Framework depends on the Federal Trade Commission as an enforcement authority, and the ruling reshapes the FTC's constitutional standing. A separation-of-powers decision has therefore become a data protection concern. To understand how, it is necessary to examine what the Framework rests upon.

The EU-US DPF rests on two distinct foundations:

  • The first is commercial enforcement. When a US company certifies under the DPF, it undertakes binding commitments concerning its handling of European data, and those commitments require an effective enforcer. That role belongs to the Federal Trade Commission. The FTC investigates violations, holds certified companies to their obligations, and provides European individuals with a route to redress on the commercial side.
  • The second foundation is government access, which governs the treatment of European data by US intelligence agencies once it reaches American soil. It comprises limits on surveillance and an independent redress body, the Data Protection Review Court, established in response to Schrems II. Trump v. Slaughter affects the first foundation alone. The FTC is the Framework's commercial enforcer, and it is precisely the FTC's independence that the ruling removes.

Independence is not incidental to this structure. Under EU law, supervision of data protection must be carried out independently, and this is a legal requirement rather than a matter of preference. It is enshrined in Article 8(3) of the Charter and Article 16 of the TFEU, and it underpins Article 45 of the GDPR. Article 45(2)(b) treats the existence of an effective, independent supervisory authority as a key criterion for any adequacy decision. The European Commission was mindful of this when it approved the DPF in 2023. In Implementing Decision (EU) 2023/1795, it characterized the FTC as an independent enforcement authority and relied on the fact that commissioners could be removed only for cause, namely inefficiency, neglect of duty, or malfeasance. That premise no longer holds. Following Slaughter, FTC commissioners serve at the pleasure of the President and may be removed at will. The authority the Commission described as independent is no longer independent in the sense EU law requires, and the essential equivalence on which the adequacy decision depends is now in question.

This is not an unprecedented difficulty. It is the third occasion on which the same fault line has opened. Safe Harbor was struck down in Schrems I, and Privacy Shield in Schrems II. In both instances, the Court of Justice found US oversight bodies insufficiently independent to satisfy EU standards. The DPF was designed to remedy that deficiency, and Slaughter reopens it from a different direction. The earlier cases concerned government surveillance and redress; this one concerns the commercial enforcer. The present difficulty also carries a sharper edge. The earlier failures were addressed through renewed negotiation and a new executive order, whereas this one does not lend itself to so straightforward a repair. The FTC's independence cannot be restored by legislation once the Supreme Court has held such independence to be unconstitutional. The defect is structural, and it may prove more enduring than those preceding it.

EDPB Intervention

The European response was immediate. On 31 July 2026, EDPB Chair Anu Talus wrote to Commissioner Michael McGrath, requesting that the Commission assess closely whether the ruling affects the FTC's capacity to uphold its commitments under the Framework. Her central observation was that an independent supervisory authority is a key element in determining whether a third country provides adequate protection. The letter is not a judgment, and it altered nothing by itself. Its significance lies in its source: when the body that coordinates every data protection authority in Europe asks the Commission to reconsider, the request carries considerable weight.

Civil Society Response (NOYB)

The day after the decision, NOYB - European Center for Digital Rights, a non-profit organization working on the enforcement of privacy laws, petitioned the European Commission to initiate an orderly withdrawal of the adequacy decision, arguing that the constitutional foundation of the agreement has failed. NOYB announced plans to challenge the adequacy decision before the Court of Justice of the European Union (CJEU), laying the groundwork for a third major judicial review of transatlantic data transfers under the EU-US DPF.

Conclusion

Trump v. Slaughter illustrates the friction between domestic separation-of-powers jurisprudence and international regulatory frameworks. By seeking to centralize executive authority over domestic administrative agencies, the Supreme Court altered the structural independence required for cross-border regulatory recognition, forcing multinational enterprises to re-evaluate how personal data is managed across international borders. Organizations managing cross-border data processing must reassess compliance with the U.S. Adequacy Decision as it remains valid until formally revoked by the European Commission or struck down by the CJEU.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 59:11
Data Controls for AI: Findings from the 2026 GigaOm DSPM Research
Watch Now View
Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Latest
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach View More
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach
Picture this: a fictional but entirely plausible scenario. An Australian financial institution's AI systems spend six months accessing a customer data repository nobody has...
View More
One Unrevoked Key, 37.5 Million People: What the Coupang data breach reveals about data access
Executive summary In June 2026, South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.68 billion won (approximately $409 million) which was the largest...
How to Choose the Right DSPM Platform View More
How to Choose the Right DSPM Platform
Learn how to choose the right DSPM platform by evaluating data coverage, classification accuracy, contextual risk, AI security, and automated remediation.
What is Data Stewardship? All You Need to Know View More
What is Data Stewardship? All You Need to Know
Discover what data stewardship is, types, importance, how it differs from data governance, use cases, challenges, benefits and how Securiti helps.
View More
Green-Light AI, Not Data Exposure
Learn the five critical data-layer controls enterprises need to prevent sensitive data exposure and enable secure, scalable AI agent adoption.
Agentic AI Readiness View More
Agentic AI Readiness: Why Your Enterprise Needs a New Data Security Paradigm
Learn how to secure Agentic AI by discovering sensitive data, mitigating AI risks, and building an enterprise-ready AI security strategy.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
"The Algorithm Did It" Is Now Dead in Court View More
“The Algorithm Did It” Is Now Dead in Court
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New