Matias Cañibe argues that the UK-US data Bridge is not necessarily doomed if the latest challenge from NOYB succeeds
On 29 June 2026, the US Supreme Court decided Trump v Slaughter, holding 6-3 that Congress cannot shield Federal Trade Commission commissioners from at-will presidential removal. The Court overturned Humphrey’s Executor, a 1935 precedent that had underpinned the independence of the FTC for ninety years. Within a day, Max Schrems, the Austrian privacy lawyer whose earlier challenges produced the Schrems I and II rulings striking down Safe Harbor and Privacy Shield, and his organisation NOYB had written to the European Commission arguing that the commercial pillar of the EU-US Data Privacy Framework had collapsed, pointing out that the Commission’s 2023 adequacy decision cites FTC independence 259 times. NOYB has signalled it will file a CJEU challenge within weeks, and commentators are already referring to it as a potential “Schrems III“.
Most of the UK commentary published since has treated the UK-US Data Bridge as an afterthought to this story: if the EU framework goes, the Bridge goes with it. That is too quick. The Bridge shares the DPF’s underlying US architecture, but it does not share its legal foundation, and a change made eighteen months ago to UK domestic law may matter more than anything happening in Washington.
Two frameworks, one US architecture
The Data Bridge is not a standalone UK-US agreement. It is a UK extension, brought into force by the Data Protection (Adequacy) (United States of America) Regulations 2023, that allows UK-to-US transfers where the receiving US organisation has certified to both the core DPF and the UK Extension specifically. Strip away the extension mechanics and the underlying enforcement architecture is identical: the same FTC self-certification regime, the same Data Protection Review Court sitting inside the US Department of Justice by virtue of an executive order rather than legislation. If Slaughter genuinely removes FTC independence, it removes it for UK transfers exactly as it does for EU ones. On that point, the commentary is right.
Where it stops short is in assuming that shared architecture means shared legal fate. The EU’s adequacy framework and the UK’s are no longer running the same test.
The EU argument NOYB is relying on
Part of Schrems’s argument rests on Article 16(2) TFEU and Article 8(3) of the Charter of Fundamental Rights, which require that data protection oversight be carried out by a body that is independent in a specific, justiciable sense, not merely well-run, but structurally insulated from executive direction, alongside broader Charter and GDPR adequacy arguments. That independence requirement is the standard the CJEU applied in Schrems I against Safe Harbor and in Schrems II against Privacy Shield, and it is the standard the Commission’s adequacy decision was built to satisfy, hence the 259 citations to FTC independence. Slaughter is a direct hit against that specific requirement, because it holds that the kind of insulation the Charter demands is now constitutionally unavailable in the US system.
The UK left this framework at the end of the Brexit transition period. The Charter of Fundamental Rights does not apply in UK domestic law, and while UK courts are no longer bound by CJEU jurisprudence, Schrems II is likely to remain highly persuasive when a UK court or the ICO comes to interpret the international transfer regime. Persuasive is not binding, though, and that means the specific legal lever NOYB is pulling in Brussels, a Charter provision the UK is not party to, has no direct equivalent in London.
The DUAA changed the UK’s own test
The more significant point is that the UK’s transfer standard has itself moved. The Data (Use and Access) Act 2025, in force since 5 February 2026, replaced the UK’s prior standard, which the ICO itself called “sufficiently similar” and which was shaped by the EU’s “essentially equivalent” test inherited via retained EU case law after Brexit, with a new statutory “data protection test”: whether protection in the receiving country is “not materially lower” than the UK GDPR standard. The ICO’s updated guidance, published 15 January 2026, frames this as a shift toward a more structured, proportionate and risk-based assessment, weighing the nature, volume and sensitivity of the data actually being transferred rather than requiring a point-by-point comparison of foreign oversight architecture.
This is not a cosmetic rewording. “Essentially equivalent” carries two decades of CJEU case law behind it, oriented around structural and institutional comparison: is the foreign regulator independent in the way ours is required to be. “Not materially lower” is a different kind of question, closer to an outcomes-based test: does the data end up meaningfully less protected. A finding that the FTC’s statutory independence has been constitutionally invalidated is significant evidence under either test. It is not obviously dispositive under the second one, particularly for lower-risk, lower-volume transfers, in the way it is close to dispositive under the first.
Nobody, including the ICO, has yet said whether a CJEU annulment of the DPF would automatically trigger UK divergence. That is precisely the point: it is a live, open, and genuinely separate legal question, not an automatic consequence of what happens in Luxembourg.
There is already a precedent, of sorts, for the EU accepting this exact gap. When the European Commission reviewed the DUAA reforms as part of renewing the UK’s own adequacy status in late 2025, the EDPB’s own opinion noted that the UK’s new “not materially lower” test does not refer to the risk of government access, the existence of redress for individuals, or the need for an independent supervisory authority, precisely the elements NOYB is now relying on against the US. The Commission renewed UK adequacy anyway, for six years, on 19 December 2025. The EU has, in other words, already renewed UK adequacy despite a transfer test that does not ask the independence question the way its own case law demands elsewhere. That is not proof the UK will diverge on the US question, but it undercuts any assumption that EU institutions would treat UK divergence as self-evidently unacceptable if it happened.
What this does not mean
It does not mean the Bridge is safe, and it is not an argument that UK organisations should sit still. The Secretary of State retains the power to revoke the 2023 Adequacy Regulations at any time, and any such review would treat a CJEU annulment of the DPF as highly persuasive evidence, whatever its formal non-binding status in UK law. Sustained political pressure from Brussels, particularly if the Commission itself moves toward an orderly withdrawal, as NOYB has demanded, would be difficult for the UK to ignore indefinitely for both diplomatic and commercial reasons. Nor does divergence insulate any given transfer from EU exposure: a UK subsidiary of an EU group, or any transfer that also touches EU personal data, remains subject to the EU test regardless of what the UK decides to do with its own.
What it does mean is that UK organisations should stop treating the Bridge and the Framework as a single point of failure, and start treating them as two related but analytically distinct compliance questions.
Practical steps
Map the dependency separately for UK and EU flows. Where a transfer is purely UK-to-US, with no EU nexus, it will fall to be assessed under the DUAA’s “not materially lower” test, not the EU’s “essentially equivalent” one, regardless of what the CJEU eventually decides about the DPF.
Refresh transfer risk assessments under the new statutory language, not the old one. A TRA that still reasons in “essentially equivalent” terms is arguing the wrong legal test. The ICO’s TRA tool and updated guidance are built around the DUAA standard; assessments completed before 5 February 2026 remain valid if compliant with the prior regime, but new or refreshed assessments should be conducted under the current test.
Keep the IDTA and UK Addendum current as a fallback, independent of whichever way the Bridge goes. The ICO has indicated it intends to update both instruments in the course of the year to reflect the DUAA changes; organisations relying on contractual safeguards rather than adequacy should watch for that update rather than assuming existing templates are final.
Watch the Secretary of State, not just Brussels. The decision that actually revokes or preserves the Bridge sits with the UK government under the 2023 Regulations. Commission and CJEU developments are relevant evidence for that decision, but they are not the decision itself.
Do not assume group-wide uniformity. Multinational groups with both UK and EU entities transferring to the same US recipient may find themselves relying on two different legal tests for what looks, operationally, like a single data flow. That is worth flagging to the business now, before it becomes a live incident response problem.
The real question
“Schrems III”, if it proceeds, will take the CJEU somewhere between eighteen months and several years to resolve; Schrems I and II both took roughly that long. The more useful question for UK counsel in the meantime is not whether “Schrems III” kills the Bridge, but whether the UK’s own adequacy test gives it room to reach a different answer than the EU eventually does. The honest answer, on the current statutory text, is that it might, and that possibility, not the shared US architecture, is what UK organisations and their advisers should be tracking most closely over the next year.

Matías Cañibe is Associate General Counsel and Assistant Corporate Secretary at a NASDAQ-listed multinational, based in Luxembourg. He writes on cross-border data protection, AI regulation, and corporate governance.