























Personal data transfers between the EU and the US are made possible by the EU-US Data Privacy Framework (EU-US DPF), under which the US committed to protect personal data transferred to the US from its mass surveillance programmes. Data flows between the UK and the US depend on this scheme as well. The oversight of the framework rested on a number of US federal agencies, whose independence has now been gutted by the Supreme Court ruling.
The practical implications of this judgment are hard to understate for a country such as the UK, whose government and digital economy are highly dependent on US tech firms. It doesn’t only undermine the EU-US DPF, whose judicial invalidation is now guaranteed. US federal agencies have become structurally unable to act as meaningful legal guardians, making any future agreement with the US unworkable. Short-term fixes that were relied on in previous crises, such as Standard Contractual Clauses, would now prove ineffective: contracts are no solution against arbitrary State power, and there is no realistic prospect of a structural agreement being reached.
Likewise, the UK has recently reformed its data protection law to, potentially, allow personal data transfers to take place even if such protections are missing. If the UK were to pursue this path, however, it would lose adequacy status with the EU, and the consequences would be dramatic. In 2020, it was estimated “that the aggregate cost to UK firms of no adequacy decision would likely be between £1 billion and £1.6 billion” in legal and compliance costs alone. This does not account for the impact loss of adequacy would have on the EU-UK Trade and Cooperation Agreement, nor for its incompatibility with the non-diminution principle which Northern Ireland enjoys under the Good Friday Agreement and the Windsor Framework.
Hard truths require real solutions. The UK needs to depart from the failed path of technological dependency from the US and appeasement to US corporate interests. The new Labour leadership will have a difficult task at hand: charting a clear roadmap to digital sovereignty.
In 2025, the Trump administration proceeded to replace democratic-affiliated members of several federal agencies with their own political allies. This purge reached both the US Federal Trade Commission (FTC) and the Privacy and Civil Liberties Oversight Board (PCLOB). Rebecca Slaughter, one of the FTC members who were fired, sued the US government, on the basis of well-established case-law that protected the independence of federal agencies. The case reached the US Supreme Court, which overturned such precedents and gave the President unfettered power to remove officials from public offices.
In the words of the US Office for Legal Counsel, independence is a means to “maintaining the separation of powers”, and a shield against legal decisions being reflective of partisan political agenda rather than the preservation of Justice. Sonia Sotomayor, a dissenting Justice within the Supreme Court, pointed out that the unfettered Presidential authority handed over by this judgment will “destroy the structure of government and […] take away from Congress its ability to protect” independent agencies. She continued by noting that, even under colonial rule, “Neither the king, nor parliament nor prime ministers in England at the time of the founding [of the United States] ever had an unqualified removal power”.
Thus, the Supreme Court has just undermined the integrity of the US regulatory environment as a whole. Tech companies who are based or operate in the US are now exposed to a new reality, where their legal obligations can be manipulated arbitrarily by the US administration.
Transfers of personal data to the US are at the centre of a decades-long legal controversy over the impact of US mass surveillance programmes on the security of European personal data. In 2022, the Biden administration signed an Executive Order that established a mechanism to protect personal data transfers to the US, and restrictions to the President’s authority to conduct surveillance programmes. This was the culmination of a long political process, started with the Data Free Flow with Trust initiative and the OECD declaration on government access to data, which sought to create baseline rule of law safeguards for the secure transfer of personal data among democratic countries.
On the basis of these commitments, the European Commission adopted the an adequacy decision for the so-called EU-US Data Privacy Framework (EU-US DPF), which legalises transfers of personal data between the EU and the US. However, the oversight of this framework rested on the FTC, the PCLOB, and the Data Protection Review Court. Article 8 of the Charter of Fundamental Rights of the EU requires oversight to be independent, to protect the overseers’ ability to enforce legal standards. By empowering the Trump administration to remove their members at will, the US Supreme Court undermined oversight, and thus the workability of the framework as a whole.
Max Schrems, a renowned privacy activist, has already pointed out that the invalidation of the US adequacy decision is not a matter of if but when, and called “on the European Commission to orderly withdraw the adequacy decision on the US”. Max Schrems already obtained the judicial invalidation of the previous US adequacy decisions twice, and the letter states that he is ready to seek a third judicial invalidation if the Commission does not act.
In the UK, transfers of personal data to and from the US are underpinned by a so-called UK extension of the EU-US DPF: if or when the EU framework goes down, the “UK extension” will follow, making transfers of personal data to the US unlawful. To cope with the disruption this will cause, there are a few “easy fixes” that organisations and the UK government may try to pursue. Such options would, at best, be short-sighted and inadequate responses to the upcoming crisis. At worst, they would risk invalidating the UK adequacy decision.
UK organisations may try to rely on alternative mechanisms, such as Standard Contractual Clauses, that allow international data transfers to countries that lack acceptable data protection standards. However, the Schrems II judgment has already established that contractual arrangements are useless against US surveillance powers, and thus inadequate in this instance. This would leave UK organisations with the option to rely on encryption and key management. This is a technically-complex workaround that may work for some, but will be unfeasible for many.
The UK government could be tempted to use the new powers, introduced by the Data Use and Access Act (DUAA) 2025, to re-legalise transfers to the US. Contrary to the EU GDPR, the new UK international data transfers regime allows the Secretary of State to authorise personal data transfers to country that do not have independent or judicial oversight of data protection rules. Also, the DUAA lowered the standards that alternative transfer mechanisms, such as contractual clauses, need to reach in order to adequately protect personal data abroad.
If, however, the UK government were to take this path, the UK’s own adequacy decision would face repeal or judicial invalidation. The European Data Protection Board has already pointed out that adequacy “cannot be interpreted as not including the need for an independent supervisory authority and effective and enforceable data subjects’ rights”. Likewise, the UK adequacy decision sits on the commitment, made by UK authorities, to abide by these norms even if not listed in UK law. Notably, UK adequacy also establishes an unprecedented monitoring mechanism, where the Commission could require UK authorities to address any developments that undermine the level of protection afforded to EU personal data within three months – or else, face the repeal, suspension or amendment of the UK adequacy determination.
As it turns out, the General Data Protection Regulation deems transfers to the US to be unsafe not because of legal abstractions. It does, instead, capture the unsafe nature of these data transfers, and the high risk posed by technological infrastructure that can be weaponised by an unaccountable government.
The United Kingdom is highly dependent on US technology products and services. Its Invest2035 strategy has been centred around attracting foreign investments and firms. Its AI opportunities action plan encourages fast and loose adoption of AI products by the public sector, and heavy reliance on private (and, often, US based) companies for access to computing power. Peter Mandelson’s Tech Prosperity Deal aims to make the United States the principal technology partner for the UK.
This status quo now sits within the harsh reality that emerges from the US and its collapsing institutional environment, bringing up tough questions. How do you trust a “partner” which systematically evades constitutional check and balances? How reliable are US tech companies and service providers, when regulatory standards and contractual agreements have lost their meaning and enforceability? What will you do when you end up being locked you out of your email account or AI service, due to petty political motives pursued by the US administration of the day?
With ORG’s digital sovereignty report, we detailed how the UK needs a roadmap to de-risk its technological dependency: we must embrace open source and digital commons; strengthen competition and regulation in digital markets; and foster relationships with like-minded partners like the EU. The upcoming new Labour leadership will need to lay out a clear pathway to achieve this.

For more than a decade, UK governments have introduced successive child safety measures, responding to public concern about the availability of content that is either unsuitable or harmful to children, or due to harmful interactions ranging from bullying.
If you live in the UK and have a Facebook or Instagram account, you have probably received a message when you’ve logged in asking you if you “Want to subscribe or continue to use our Products for free with ads?
Musk’s latest venture, image generation in Grok that until Wednesday lacked sufficient guardrails to prevent the easy production of non-consensual sexual images and even child abuse images, provoked an Ofcom investigation and further EU Commission action as well as the promise of UK emergency legislation against apps that provide such images in less than a week.
Our report, “Hostile and Broken” released today, explains why e-Visas risk creating tens or hundreds of thousands of errors, with people potentially turned down for jobs, or unable to enter the country, as the result of electronic failures of the new online, real time re-checking inherent in the UK e-Visa scheme.
Meta, the company that runs Facebook and Instagram, has announced plans to repurpose most of the personal data that they ever collected about you, to train their “artificial intelligence (AI) technologies” — without, of course, asking your permission to do so.
As the House of Lords finally begins scrutiny of the UK data protection reform, Open Rights Group urges peers to support amendments that would strengthen the independence and effectiveness of the UK data protection authority, and bolster the public’s right of seeking a remedy against an infringement of their rights.
On a cycling forum, members who are rightly worried that their forum may be blocked by default filters, Skydancer posted a response he was given by Diane Abbott: I do not believe that the arrangements to protect children from hard core porn online will affect a forum to discuss cycling!
The motion laid down by Labour says: That this House deplores the growth in child abuse images online; deeply regrets that up to one and a half million people have seen such images; notes with alarm the lack of resources available to the police to tackle this problem; further notes the correlation between viewing such images and further child abuse; notes with concern the Government’s failure to implement the recommendations of the Bailey Review and the Independent Parliamentary Inquiry into Online Child Protection on ensuring children’s safe access to the internet; and calls on the Government to set a timetable for the introduction of safe search as a default, effective age verification and splash page warnings and to bring forward legislative proposals to ensure these changes are speedily implemented.
The Digital Surveillance report – to be launched at a public event on Monday – gives a history of surveillance policy, looks at the current state of the law, examines why technology poses a problem and offers alternative, more targeted and more accountable approaches.
Since we published our report ‘Mobile Internet censorship: what’s happening and what to do about it‘, jointly with LSE Media Policy project, a number of people have been in touch with us asking what to do if they discover their site is blocked incorrectly by mobile networks’ child protection filters.
Open Rights Group and Tor have established that UK mobile networks such as Vodafone, O2 and 3 are filtering UK users’ access to Tor’s primary website (meaning the HTTP version of the Tor Project website, rather than connections to the Tor network) on pre-paid contractless accounts.
To coincide with the start of the London Conference on Cyberspace, eleven organisations and experts on freedom of expression and privacy online have today written to the Foreign Secretary stating that Britain’s desire to promote these ideals internationally is being hampered by domestic policy.
In the sixth of our series on the challenges facing the new government, Jason Kitcat looks at proposals for changes to the way our elections are run, including dangerous calls for e-voting.
Wikipedia have announced that they are blocking Phorm as they consider the scanning and profiling of our visitors’ behavior by a third party to be an infringement on their privacy.
It’s difficult to tell which of today’s developments the UK’s major ISPs should be more worried about – the fact that Sir Tim Berners-Lee has publicly stated that he would change his ISP if it started employing systems, like Phorm, which could track his activity on the internet, or the news that UK digital rights gurus the Foundation for Information Policy Research (FIPR) have today written an open letter to the Information Commissioner, urging him to look at the legality of Phorm.
The Electoral Commission and the separate review by Ron Gould that the Commission instituted have published their reports on the Scottish elections of May 2007 The Gould Review in particular identifies a number of important issues, many of which ORG addressed in our own report on the elections published this June.
In a speech to the National Council of Voluntary Organisations this morning, Gordon Brown announced he would be convening a Speaker’s conference on voting reform: Today I am proposing to the Speaker that he calls a conference to consider, against the backdrop of a decline in turnout, a number of important issues, such as electoral registration, weekend voting, and the representation of women and ethnic minorities in the House of Commons.
While the Department for Constitutional Affairs have left us in the dark with no news at all about the e-voting pilots due for May 2007, The Open Rights Group and FIPR have been hard at work.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。