Trump v Slaughter and Transatlantic Data Flows
On June 29, breaking with long-standing precedent, the United States Supreme Court ruled in Trump v Slaughter that a US president does not need cause to remove a Commissioner of the Federal Trade Commission. The Supreme Court’s decision puts the EU-US data transfer regime in peril. That regime rests on the assumption that the Federal Trade Commission supervises the handling of European personal data in the United States independently. After Trump v Slaughter, that assumption of independence no longer holds. While there are ways to fix this, the odds seem low.
Data Transfers in a Fragmented World of Fundamental Rights
How much administrative friction democracies impose on the transfer of their residents’ personal data to one another is a contemporary yardstick of the trust they place in each other’s commitment to the rule of law and fundamental rights. This friction is not a bureaucratic accident but a necessity: without it, data-related fundamental rights could simply be circumvented by moving that data abroad over the internet.
Measured against that yardstick, the European Union’s default posture toward the rest of the world is one of mistrust. European data protection law permits the transfer of personal data to third countries only under qualified conditions designed to ensure a level of protection essentially equivalent to that guaranteed within the Union. The gold standard among these conditions is a determination by the European Commission, through an administrative decision, that the third country “ensures an adequate level of protection” (Article 45 GDPR). Once such a decision is in place, data transfers require no further authorisation.
While other routes to lawful transfer exist (Articles 46, 47, and 49 GDPR), an adequacy decision under Article 45 GDPR is, by a wide margin, the administratively most simple and broadest basis for such transfers. Its practical significance is substantial: virtually every economic activity today involves the exchange of personal data – a fact particularly true for information intermediaries such as Alphabet, Meta, and X. Disruptions to such transfers thus carry economic stakes whose full extent is difficult to foresee.
We Have Been Through a Lot: Adequacy Decisions on the United States
This economic relevance generates immense political interest in facilitating data transfers from Europe to the United States with as little friction as possible. Reflecting these interests, the European Commission has now determined – three times – that the United States offers an adequate level of protection. Twice, in proceedings brought by the Austrian activist Max Schrems, the European Court of Justice annulled these decisions for failing to adequately address access to European data by US intelligence agencies (Schrems I, 2015 and Schrems II, 2020 – Edward Snowden sends his regards). Following intense negotiations and substantial improvements (for example General Court, Latombe, 2025, paras. 6-7) to the protection of European personal data against intelligence access in the US, the Commission determined again, in 2023, that the United States offered an adequate level of protection.
Unsurprisingly, this third decision turned out, again, to be highly contested. The Commission adopted it against the (non-binding) advice of the European Parliament, and much scholarly commentary (for example here) considers it unlawful from the outset, on the ground that the remaining scope of intelligence access is disproportionate and the available redress mechanisms too weak. The General Court, however, recently upheld the decision on the facts as they stood in 2023 (General Court, Latombe, 2025). These questions remain open for now, and may ultimately be resolved in the pending appeal before the ECJ or in other proceedings before that court.
Trump v Slaughter and the End of FTC Independence
Trump v Slaughter now adds a new and serious complication to this already long list of concerns. The issue has attracted considerable attention, ignited by Schrems’ NGO noyb. Blogs and law firms have since weighed in (for example, here, here, and here).
Under the current framework for EU-US data transfers, the FTC serves as the supervisory authority overseeing private entities’ handling of European personal data (EU-US Data Privacy Framework, 2023, paras. 58-64) – that is the functional equivalent to the European data protection authorities.
European law attaches great importance to the independence of data protection authorities. This principle is rooted in the European Treaties themselves (Article 16(2) TFEU and Article 8(3) of the Charter of Fundamental Rights) and reiterated in the GDPR (Article 52). The European Court of Justice, ruling on the insofar materially similar predecessor instrument to the GDPR, explicitly required supervisory authorities to be independent from government even where they supervise only the private sector rather than public bodies (Commission/Germany – Deutsche Kontrollstellen, 2011, para. 30). In the Court’s view, supervisory authorities can discharge their duty to protect data-related fundamental rights only if they act “objectively and impartially” – that is, free from any external, and in particular political, influence (ECJ, Deutsche Kontrollstellen, paras. 23–25).
Now, all of this applies directly only to European data protection authorities. However, an adequacy decision under Article 45 GDPR requires the third country, “by reason of its domestic law or international commitments,” to offer “a level of protection of fundamental rights and freedoms essentially equivalent to that guaranteed within the European Union” (ECJ, Schrems II, para. 94). To that end, the GDPR expressly instructs the Commission to consider the existence of an “independent” supervisory authority in the third country (Article 45(2)(b) GDPR). Against this background, such independence can only be understood as a substantive precondition for an adequacy decision.
Before Trump v Slaughter, the FTC seems to have satisfied this requirement. Under the FTC Act of 1914, a US President could remove FTC Commissioners only “for inefficiency, neglect of duty, or malfeasance in office” (15 U.S.C. § 41). Precedent had confirmed this restriction to be compatible with the US Constitution and suggested that it also shielded FTC Commissioners from presidential orders (US Supreme Court, Humphrey’s Executor v United States). In substance, this created an institutional arrangement comparable to the one the GDPR prescribes for European data protection authorities (cf. Article 52 on independence; Article 53(4) on protection against removal).
In Trump v Slaughter, the court divided along partisan lines to hold that a US president need not to show cause to remove an FTC Commissioner (the decision has drawn sharp criticism, for example here). This alone undermines the FTC’s independence measured by the European standard. The Court did not squarely decide whether the FTC remains independent from direct presidential orders, though its reasoning seems open to the view that the FTC must follow presidential instructions (cf. Trump v Slaughter, slip op. at 24–25). But even if that independence survives, the President’s newly confirmed power to remove Commissioners without cause forecloses any oversight remotely comparable to the European standard.
A Way Out? Fixing the FTC Problem
There may be a straightforward fix. Under the current adequacy framework, oversight of and redress against US intelligence agencies’ access to Europeans’ personal data is governed by a mere Executive Order of former President Biden (EO 14086). It establishes independent bodies and court-like review mechanisms. The compatibility of that arrangement with the European requirements for an adequacy decision is itself contested, among other things, because it is established by Executive Order rather than law. The General Court recently held that it is compatible, though that ruling is now on appeal to the ECJ (see above Latombe, on the law requirement paras. 64-82).
Accordingly, the US President could restore the FTC’s independence – or at least the independence of the part responsible for European data protection – by way of a comparable Executive Order. Under US law, such an order could bind the executive unless and until publicly repealed (possibly the construction would need to include the Attorney General, as is the case for the intelligence oversight, cf. US-EU Data Privacy Framework, 2023, para. 176; on such executive self-binding US Supreme Court, United States v Nixon, p. 683-84). This would place the FTC’s independence, from the European perspective, on the same footing as the notorious question of intelligence oversight. That footing is admittedly precarious – but it would at least avoid creating an entirely new vulnerability.
Good Faith Across the Atlantic
Of course, this solution presupposes good faith on both sides of the Atlantic – for the moment, there seems little of that. President Trump has already removed the Democratic members of the relevant intelligence oversight bodies, in what those members maintain was a violation of the very Executive Order meant to bind him. That dispute, too, is now under judicial review: a Court of Appeals has stayed proceedings pending the outcome in Slaughter. Yet Slaughter does not speak to this (Trump v Slaughter slip op. at 27-28) – self-binding executive norms raise no separation-of-powers issue of the kind at stake there.
Despite their differing traditions and approaches to data protection, the United States and the European Union have worked hard to keep personal data flowing across the Atlantic. With good faith, that effort has succeeded, and will likely continue to succeed. Without it, even minor and easily resolvable problems can trigger major disruption.
For now, the adequacy decision on the US remains in force. Yet the Commission is obliged to review it should circumstances materially change (Article 45(4) GDPR) – and changed they have. Judicial review, too, is announced. The next major disruption in EU-US relations may not be far off.



