惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
The Last Watchdog
The Last Watchdog
P
Proofpoint News Feed
C
Cybersecurity and Infrastructure Security Agency CISA
L
LINUX DO - 热门话题
Cyberwarzone
Cyberwarzone
S
Schneier on Security
C
CERT Recently Published Vulnerability Notes
Latest news
Latest news
I
Intezer
A
Arctic Wolf
IT之家
IT之家
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cisco Blogs
AWS News Blog
AWS News Blog
博客园 - 三生石上(FineUI控件)
C
CXSECURITY Database RSS Feed - CXSecurity.com
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
The Exploit Database - CXSecurity.com
Google DeepMind News
Google DeepMind News
M
MIT News - Artificial intelligence
D
Docker
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
Cyber Attacks, Cyber Crime and Cyber Security
MongoDB | Blog
MongoDB | Blog
B
Blog
博客园 - 叶小钗
V2EX - 技术
V2EX - 技术
Simon Willison's Weblog
Simon Willison's Weblog
MyScale Blog
MyScale Blog
Hugging Face - Blog
Hugging Face - Blog
Engineering at Meta
Engineering at Meta
NISL@THU
NISL@THU
WordPress大学
WordPress大学
人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
N
Netflix TechBlog - Medium
The GitHub Blog
The GitHub Blog
V
V2EX
PCI Perspectives
PCI Perspectives
N
News | PayPal Newsroom
V
Visual Studio Blog
Vercel News
Vercel News
P
Proofpoint News Feed
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
J
Java Code Geeks
O
OpenAI News
爱范儿
爱范儿

Open Rights Group

Wanted: Government to fix the ICO Joint Letter: Protect VPNs Open letter for an investigation into the ICO over eVisas Civil society organisations call for ICO to be investigated over eVisas How AI in asylum decision-making drives failure and cost Dear Andy, we need a complete reset on digital policy John Edwards resignation is opportunity to appoint a regulator with teeth AI in Asylum Decisions: Transparency and Accountability Failures Stop Killing the Internet: New global movement launches MPs urged to vote for a Digital Sovereignty strategy The social media policy ratchet Starmer’s social media ban fails to address root causes of online harms This refugee week, take courage! The rise of copyright trolling Growing up in an online world: ORG Consultation Response Reset the ICO The ICO isn’t doing its job – why the data watchdog needs an overhaul The ICO isn’t doing its job – why the data watchdog needs to be reset ORG response to ICO call for views on our approach to regulating online advertising ORG response to Consultation on the ICO’s approach to data protection complaint handling Companies and civil society warn that UK is undermining open web Papers Please! MPs back mass online digital ID checkpoints MPs call for publication of secret documents that outline chronic risks from UK’s dependence on Big Tech New report: UK needs digital sovereignty strategy to address threats from reliance on big tech The case for Digital Sovereignty and the Digital Commons After the LA Court verdict, the UK must disrupt surveillance capitalism business models 13 year olds could be compelled to use unregulated age verification Children’s Wellbeing and Schools Bill: Analysis of Amendment 38b ICO must investigate Reform ‘competition’ for data protection breaches Break privacy to make privacy? Age verification isn’t the answer Home Office use of AI in asylum cases likely to be unlawful, legal opinion finds Legal Opinion: The use of Artificial Intelligence tools in asylum cases MPs give ministers powers to restrict entire Internet Board Election Results Palestine Action ruling: Human rights organisations call for Ofcom to issue guidance on content takedowns
The end is nigh for US data transfers
02 Jul 2026 Mariano delli Santi · 2026-07-02 · via Open Rights Group

Digital Privacy

The Supreme Court held that President of the United States can remove members of public offices at will. The judgment overturns well-established case-law that protected the independence of federal agencies, and has serious consequences for personal data transfers, digital rights, and the digital economy at large.

Personal data transfers between the EU and the US are made possible by the EU-US Data Privacy Framework (EU-US DPF), under which the US committed to protect personal data transferred to the US from its mass surveillance programmes. Data flows between the UK and the US depend on this scheme as well. The oversight of the framework rested on a number of US federal agencies, whose independence has now been gutted by the Supreme Court ruling.

The practical implications of this judgment are hard to understate for a country such as the UK, whose government and digital economy are highly dependent on US tech firms. It doesn’t only undermine the EU-US DPF, whose judicial invalidation is now guaranteed. US federal agencies have become structurally unable to act as meaningful legal guardians, making any future agreement with the US unworkable. Short-term fixes that were relied on in previous crises, such as Standard Contractual Clauses, would now prove ineffective: contracts are no solution against arbitrary State power, and there is no realistic prospect of a structural agreement being reached.

Likewise, the UK has recently reformed its data protection law to, potentially, allow personal data transfers to take place even if such protections are missing. If the UK were to pursue this path, however, it would lose adequacy status with the EU, and the consequences would be dramatic. In 2020, it was estimated “that the aggregate cost to UK firms of no adequacy decision would likely be between £1 billion and £1.6 billion” in legal and compliance costs alone. This does not account for the impact loss of adequacy would have on the EU-UK Trade and Cooperation Agreement, nor for its incompatibility with the non-diminution principle which Northern Ireland enjoys under the Good Friday Agreement and the Windsor Framework.

Hard truths require real solutions. The UK needs to depart from the failed path of technological dependency from the US and appeasement to US corporate interests. The new Labour leadership will have a difficult task at hand: charting a clear roadmap to digital sovereignty.

The Supreme Court Judgment Explained

In 2025, the Trump administration proceeded to replace democratic-affiliated members of several federal agencies with their own political allies. This purge reached both the US Federal Trade Commission (FTC) and the Privacy and Civil Liberties Oversight Board (PCLOB). Rebecca Slaughter, one of the FTC members who were fired, sued the US government, on the basis of well-established case-law that protected the independence of federal agencies. The case reached the US Supreme Court, which overturned such precedents and gave the President unfettered power to remove officials from public offices.

In the words of the US Office for Legal Counsel, independence is a means to “maintaining the separation of powers”, and a shield against legal decisions being reflective of partisan political agenda rather than the preservation of Justice. Sonia Sotomayor, a dissenting Justice within the Supreme Court, pointed out that the unfettered Presidential authority handed over by this judgment will “destroy the structure of government and […] take away from Congress its ability to protect” independent agencies. She continued by noting that, even under colonial rule, “Neither the king, nor parliament nor prime ministers in England at the time of the founding [of the United States] ever had an unqualified removal power”.

Thus, the Supreme Court has just undermined the integrity of the US regulatory environment as a whole. Tech companies who are based or operate in the US are now exposed to a new reality, where their legal obligations can be manipulated arbitrarily by the US administration.

A Death Warrant for Data Transfers to the US

Transfers of personal data to the US are at the centre of a decades-long legal controversy over the impact of US mass surveillance programmes on the security of European personal data. In 2022, the Biden administration signed an Executive Order that established a mechanism to protect personal data transfers to the US, and restrictions to the President’s authority to conduct surveillance programmes. This was the culmination of a long political process, started with the Data Free Flow with Trust initiative and the OECD declaration on government access to data, which sought to create baseline rule of law safeguards for the secure transfer of personal data among democratic countries.

On the basis of these commitments, the European Commission adopted the an adequacy decision for the so-called EU-US Data Privacy Framework (EU-US DPF), which legalises transfers of personal data between the EU and the US. However, the oversight of this framework rested on the FTC, the PCLOB, and the Data Protection Review Court. Article 8 of the Charter of Fundamental Rights of the EU requires oversight to be independent, to protect the overseers’ ability to enforce legal standards. By empowering the Trump administration to remove their members at will, the US Supreme Court undermined oversight, and thus the workability of the framework as a whole.

Max Schrems, a renowned privacy activist, has already pointed out that the invalidation of the US adequacy decision is not a matter of if but when, and called “on the European Commission to orderly withdraw the adequacy decision on the US”. Max Schrems already obtained the judicial invalidation of the previous US adequacy decisions twice, and the letter states that he is ready to seek a third judicial invalidation if the Commission does not act.

The UK is in a Tough Spot

In the UK, transfers of personal data to and from the US are underpinned by a so-called UK extension of the EU-US DPF: if or when the EU framework goes down, the “UK extension” will follow, making transfers of personal data to the US unlawful. To cope with the disruption this will cause, there are a few “easy fixes” that organisations and the UK government may try to pursue. Such options would, at best, be short-sighted and inadequate responses to the upcoming crisis. At worst, they would risk invalidating the UK adequacy decision.

UK organisations may try to rely on alternative mechanisms, such as Standard Contractual Clauses, that allow international data transfers to countries that lack acceptable data protection standards. However, the Schrems II judgment has already established that contractual arrangements are useless against US surveillance powers, and thus inadequate in this instance. This would leave UK organisations with the option to rely on encryption and key management. This is a technically-complex workaround that may work for some, but will be unfeasible for many.

The UK government could be tempted to use the new powers, introduced by the Data Use and Access Act (DUAA) 2025, to re-legalise transfers to the US. Contrary to the EU GDPR, the new UK international data transfers regime allows the Secretary of State to authorise personal data transfers to country that do not have independent or judicial oversight of data protection rules. Also, the DUAA lowered the standards that alternative transfer mechanisms, such as contractual clauses, need to reach in order to adequately protect personal data abroad.

If, however, the UK government were to take this path, the UK’s own adequacy decision would face repeal or judicial invalidation. The European Data Protection Board has already pointed out that adequacy “cannot be interpreted as not including the need for an independent supervisory authority and effective and enforceable data subjects’ rights”. Likewise, the UK adequacy decision sits on the commitment, made by UK authorities, to abide by these norms even if not listed in UK law. Notably, UK adequacy also establishes an unprecedented monitoring mechanism, where the Commission could require UK authorities to address any developments that undermine the level of protection afforded to EU personal data within three months – or else, face the repeal, suspension or amendment of the UK adequacy determination.

We need UK Digital Sovereignty

As it turns out, the General Data Protection Regulation deems transfers to the US to be unsafe not because of legal abstractions. It does, instead, capture the unsafe nature of these data transfers, and the high risk posed by technological infrastructure that can be weaponised by an unaccountable government.

The United Kingdom is highly dependent on US technology products and services. Its Invest2035 strategy has been centred around attracting foreign investments and firms. Its AI opportunities action plan encourages fast and loose adoption of AI products by the public sector, and heavy reliance on private (and, often, US based) companies for access to computing power. Peter Mandelson’s Tech Prosperity Deal aims to make the United States the principal technology partner for the UK.

This status quo now sits within the harsh reality that emerges from the US and its collapsing institutional environment, bringing up tough questions. How do you trust a “partner” which systematically evades constitutional check and balances? How reliable are US tech companies and service providers, when regulatory standards and contractual agreements have lost their meaning and enforceability? What will you do when you end up being locked you out of your email account or AI service, due to petty political motives pursued by the US administration of the day?

With ORG’s digital sovereignty report, we detailed how the UK needs a roadmap to de-risk its technological dependency: we must embrace open source and digital commons; strengthen competition and regulation in digital markets; and foster relationships with like-minded partners like the EU. The upcoming new Labour leadership will need to lay out a clear pathway to achieve this.

Demand UK Digital Sovereignty

Related Blogs

Digital Privacy

15 Jun 2026 By Jim Killock

The social media policy ratchet

For more than a decade, UK governments have introduced successive child safety measures, responding to public concern about the availability of content that is either unsuitable or harmful to children, or due to harmful interactions ranging from bullying.

Find Out More

Digital Privacy

11 Feb 2026 By Open Rights Group

To consent or pay?

If you live in the UK and have a Facebook or Instagram account, you have probably received a message when you’ve logged in asking you if you “Want to subscribe or continue to use our Products for free with ads?

Find Out More

Digital Privacy

14 Jan 2026 By Jim Killock

Techno-Permacrisis

Musk’s latest venture, image generation in Grok that until Wednesday lacked sufficient guardrails to prevent the easy production of non-consensual sexual images and even child abuse images, provoked an Ofcom investigation and further EU Commission action as well as the promise of UK emergency legislation against apps that provide such images in less than a week.

Find Out More

Digital Privacy

18 Sep 2024 By Jim Killock

e-Visas: The Next Digital Windrush Scandal

Our report, “Hostile and Broken” released today, explains why e-Visas risk creating tens or hundreds of thousands of errors, with people potentially turned down for jobs, or unable to enter the country, as the result of electronic failures of the new online, real time re-checking inherent in the UK e-Visa scheme.

Find Out More

Digital Privacy

16 Jul 2024 By Mariano delli Santi

Meta Wants to Make Us its AI Guinea Pigs

Meta, the company that runs Facebook and Instagram, has announced plans to repurpose most of the personal data that they ever collected about you, to train their “artificial intelligence (AI) technologies” — without, of course, asking your permission to do so.

Find Out More

Digital Privacy

20 Mar 2024 By Mariano delli Santi

The ICO Must Toughen Up

As the House of Lords finally begins scrutiny of the UK data protection reform, Open Rights Group urges peers to support amendments that would strengthen the independence and effectiveness of the UK data protection authority, and bolster the public’s right of seeking a remedy against an infringement of their rights.

Find Out More

Digital Privacy

01 Aug 2013 By Jim Killock

Diane Abbott responds on web forum blocking

On a cycling forum, members who are rightly worried that their forum may be blocked by default filters, Skydancer posted a response he was given by Diane Abbott: I do not believe that the arrangements to protect children from hard core porn online will affect a forum to discuss cycling!

Find Out More

Digital Privacy

13 Jun 2013 By Jim Killock

Website filtering problems are a ‘load of cock’

The motion laid down by Labour says: That this House deplores the growth in child abuse images online; deeply regrets that up to one and a half million people have seen such images; notes with alarm the lack of resources available to the police to tackle this problem; further notes the correlation between viewing such images and further child abuse; notes with concern the Government’s failure to implement the recommendations of the Bailey Review and the Independent Parliamentary Inquiry into Online Child Protection on ensuring children’s safe access to the internet; and calls on the Government to set a timetable for the introduction of safe search as a default, effective age verification and splash page warnings and to bring forward legislative proposals to ensure these changes are speedily implemented.

Find Out More

Digital Privacy

26 Apr 2013 By Claudia Mateus

Digital Surveillance video

The Digital Surveillance report – to be launched at a public event on Monday – gives a history of surveillance policy, looks at the current state of the law, examines why technology poses a problem and offers alternative, more targeted and more accountable approaches.

Find Out More

Digital Privacy

28 May 2012 By Peter Bradwell

Reporting ‘over-blocking’ to mobile operators

Since we published our report ‘Mobile Internet censorship: what’s happening and what to do about it‘, jointly with LSE Media Policy project, a number of people have been in touch with us asking what to do if they discover their site is blocked incorrectly by mobile networks’ child protection filters.

Find Out More

Digital Privacy

23 Jan 2012 By Peter Bradwell

UK Mobile operators censor privacy tool ‘Tor’

Open Rights Group and Tor have established that UK mobile networks such as Vodafone, O2 and 3 are filtering UK users’ access to Tor’s primary website (meaning the HTTP version of the Tor Project website, rather than connections to the Tor network) on pre-paid contractless accounts.

Find Out More

Digital Privacy

01 Nov 2011 By Peter Bradwell

Joint letter to the Foreign Secretary

To coincide with the start of the London Conference on Cyberspace, eleven organisations and experts on freedom of expression and privacy online have today written to the Foreign Secretary stating that Britain’s desire to promote these ideals internationally is being hampered by domestic policy.

Find Out More

Digital Privacy

20 May 2010 By Jason Kitcat

Changing the way we vote

In the sixth of our series on the challenges facing the new government, Jason Kitcat looks at proposals for changes to the way our elections are run, including dangerous calls for e-voting.

Find Out More

Digital Privacy

17 Apr 2009 By Jim Killock

Wikipedia blocks Phorm

Wikipedia have announced that they are blocking Phorm as they consider the scanning and profiling of our visitors’ behavior by a third party to be an infringement on their privacy.

Find Out More

Digital Privacy

17 Mar 2008 By Becky Hogge

Phorm update

It’s difficult to tell which of today’s developments the UK’s major ISPs should be more worried about – the fact that Sir Tim Berners-Lee has publicly stated that he would change his ISP if it started employing systems, like Phorm, which could track his activity on the internet, or the news that UK digital rights gurus the Foundation for Information Policy Research (FIPR) have today written an open letter to the Information Commissioner, urging him to look at the legality of Phorm.

Find Out More

Digital Privacy

24 Oct 2007 By Jason Kitcat

Gould Review on Scottish Elections Published

The Electoral Commission and the separate review by Ron Gould that the Commission instituted have published their reports on the Scottish elections of May 2007 The Gould Review in particular identifies a number of important issues, many of which ORG addressed in our own report on the elections published this June.

Find Out More

Digital Privacy

03 Sep 2007 By Becky Hogge

Gordon Brown at the NCVO: e-Voting off the agenda?

In a speech to the National Council of Voluntary Organisations this morning, Gordon Brown announced he would be convening a Speaker’s conference on voting reform: Today I am proposing to the Speaker that he calls a conference to consider, against the backdrop of a decline in turnout, a number of important issues, such as electoral registration, weekend voting, and the representation of women and ethnic minorities in the House of Commons.

Find Out More

Digital Privacy

16 Jan 2007 By Michael Holloway

Taking the lid off e-voting

While the Department for Constitutional Affairs have left us in the dark with no news at all about the e-voting pilots due for May 2007, The Open Rights Group and FIPR have been hard at work.

Find Out More