Skip to content

US Court Ruling on FTC Independence Jeopardizes Data Flows to the USA

In a nutshell: The FTC ruling undermines the foundation of the EU-US Data Privacy Framework and makes data sovereignty a concrete competitive advantage for regulatory-prepared enterprises.

On June 29, 2024, the US Supreme Court ruled that the independence of the Federal Trade Commission is unconstitutional. This jeopardizes the EU-US Data Privacy Framework, as it is based on the FTC as an independent supervisory body.

In the case “Trump vs. Slaughter,” the US Supreme Court ruled that the president can dismiss FTC commissioners at any time and without cause. The FTC had previously been structured as an independent agency. In the 2023 EU-US Data Privacy Framework, the FTC is anchored as an independent monitoring authority for data processing between the EU and USA. The European Commission’s adequacy decision mentions the FTC’s control function 259 times.

Immediate consequences do not arise right away. The Framework remains formally valid until the Commission revokes it or the European Court of Justice annuls it. Max Schrems, who successfully challenged Safe Harbor (2015) and Privacy Shield (2020) in court, has called on the Commission to revoke it and announced another lawsuit. Observers are speaking of “Schrems III.” However, hundreds of thousands of European companies use US services daily and rely on a legal foundation that is now under reservation.

The case shows that cloud and software services are not constant infrastructure like electricity from a socket. A blocking such as with Anthropic’s AI models Fable 5 and Mythos 5 (a few weeks earlier) dissolves again. The FTC ruling, however, affects the legal foundation itself. This is not a technical or price problem, but a business dependency question that belongs in the executive suite.

Companies that have conscientiously implemented the GDPR already have an inventory of their processing activities and know the data flows to US services. With NIS2 (mandatory since December 6), systematic risk management is added. The EU AI Act demands transparency and documentation across the entire lifecycle of AI systems. Those who meet these requirements already have an action plan in an emergency – and thus a competitive advantage over competitors without these structures.


Source: www.it-daily.net · Published July 22, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: