The UK-US Data Bridge: Where GDPR Adequacy Actually Stands in 2026
If you send a UK data subject's personal data to a US vendor, there isn't one adequacy decision underneath that transfer. There are at least three, stacked on top of each other, each with its own legal life and its own point of failure. The European Commission has a decision saying the UK itself is adequate. The UK has its own regulations saying certain US organisations are adequate, via the UK-US Data Bridge. And underneath both of those sits the EU's adequacy decision for the US, which the UK Bridge borrows its entire evidentiary basis from without formally depending on it. Pull on any one of these threads and it is genuinely unclear, even now, how far the others unravel.
None of this is broken today. But two things happened in 2025 that put visible cracks in the load-bearing wall, and it is worth knowing exactly where they are before you rely on this mechanism for anything that matters.
What the UK-US Data Bridge actually does
The Bridge came into force on 12 October 2023 as an adequacy regulation under section 17A of the Data Protection Act 2018. It does not create a new transfer mechanism from scratch. It piggybacks on the EU-US Data Privacy Framework (DPF), the mechanism the European Commission adopted in July 2023 to replace the arrangement the Court of Justice struck down in Schrems II. A US organisation wanting to receive UK personal data under the Bridge has to do two things, not one. First, self-certify to the base DPF with the US Department of Commerce, committing to the DPF Principles on notice, choice, accountability and so on. Second, separately extend that certification to cover the UK, which layers on extra obligations: UK data subjects have to be named explicitly in the certification, the definition of sensitive data has to be widened to match the UK GDPR's broader category (which includes criminal offence data, something the US definition doesn't cover), and the arrangement extends to Gibraltar as well as the UK.
Practically, this means checking a company against two lists, not one, on the official Data Privacy Framework programme site: the base DPF participant list, and the separate UK Extension list. A vendor on the first but not the second is not a valid recipient under the Bridge, whatever their marketing page claims.
The load-bearing wall underneath it all
The reason any of this satisfies the "essentially equivalent" standard from Schrems II is Executive Order 14086, signed in October 2022. It requires US signals intelligence collection to be "necessary and proportionate," and it creates a redress mechanism: an EU or UK individual who thinks they've been surveilled unlawfully can complain to the Civil Liberties Protection Officer at the Office of the Director of National Intelligence, and appeal that officer's decision to a new body called the Data Protection Review Court (DPRC). Two things keep this apparatus honest on paper. The DPRC is meant to function with enough independence from the executive branch that its decisions are more than a formality. And the Privacy and Civil Liberties Oversight Board (PCLOB) is meant to conduct an annual review of how EO 14086 is actually being implemented, a report the European Commission leans on heavily when it periodically reassesses whether the DPF still holds up.
PCLOB lost its quorum, and the fix hasn't stuck
On 27 January 2025, the Trump administration removed three of PCLOB's five members, including its chair. That took the board below quorum, meaning it could no longer open investigations or publish findings, including the annual EO 14086 review the Commission's oversight process depends on. A federal court ruled in May 2025 that the removals were unlawful and ordered two of the three members reinstated. The administration appealed, and as things stand the board still doesn't have a working quorum in practice. The annual report that was supposedly in preparation at the time of the firings has not surfaced. None of this has, by itself, invalidated the DPF or the Bridge. Nothing in EU or UK law says an adequacy decision falls the moment its underlying oversight body stops functioning; it falls when a court says so, or when the Commission withdraws it. But it does mean the Commission's next periodic review of the DPF will have a visible gap where PCLOB's evidence used to sit, and that is exactly the kind of gap a legal challenge is built to exploit.
Latombe's challenge, and the CJEU appeal that's now pending
Someone did exploit it, or tried to. French MP Philippe Latombe brought a direct challenge to the DPF adequacy decision before the General Court (Case T-553/23), arguing that the DPRC lacks genuine independence from the US executive and that US intelligence agencies collect data in bulk without prior authorisation from a court or independent authority. The General Court dismissed the challenge on 3 September 2025, holding that the DPRC provides sufficient guarantees of independence and impartiality under Article 47 of the EU Charter, and that bulk collection can satisfy the "essentially equivalent" standard provided it is subject to ex post judicial review rather than prior authorisation. Latombe appealed to the Court of Justice on 31 October 2025 (Case C-703/25 P). A CJEU appeal is limited to points of law rather than a fresh look at the facts, which narrows what it can actually overturn, and no hearing date had been set as of mid-2026. So the DPF remains valid law, upheld once already, with a further appeal working its way through a court that moves on its own schedule.
Meanwhile, the UK's own adequacy got renewed too, separately
Layer three, and the one people forget exists: the EU's adequacy decision for the UK itself, covering ordinary transfers from the EEA to the UK, not anything to do with the US. That decision was adopted in June 2021 with a built-in four-year sunset clause, meaning it needed active renewal by June 2025. The Commission didn't rush it. It wanted to see the effect of the UK's Data (Use and Access) Act 2025 (DUAA) before deciding whether the UK's data protection regime had drifted too far from the GDPR to remain adequate. That meant a short bridging extension to keep the existing decision alive to 27 December 2025 while the assessment ran. The European Data Protection Board gave its opinion on 20 October 2025, and the Commission formally renewed both UK adequacy decisions (the general GDPR one and the law enforcement one) on 19 December 2025, with a new sunset date of 27 December 2031. So the UK cleared its own adequacy review in the same year that PCLOB lost its quorum and Latombe's appeal was filed against the framework the UK Bridge depends on. Three separate clocks, none of them running on the same schedule.
"Independent" is a legal fact, not a practical one
Since July 2026, the position has been clarified: the UK Extension is treated as legally independent of the EU's adequacy decision for the US. If the CJEU eventually strikes down the EU-US DPF on Latombe's appeal, the UK Bridge does not fall automatically with it, because it's a separate UK statutory instrument, made under UK law, based on the UK's own assessment. The same goes in reverse. That independence is real, but it's worth being honest about what it actually buys you. The UK's own assessment when it made the Bridge regulation rested on the same EO 14086 safeguards, the same DPRC, and the same PCLOB oversight structure that the CJEU is now being asked to re-examine. If the CJEU decides those safeguards are inadequate as a matter of law, the ICO and DSIT would be under enormous pressure to revisit the UK's own regulation on the same evidence, even though nothing would legally compel them to do it on any particular timetable. Independence on paper and independence in practice are not the same thing, and I wouldn't build a compliance programme on the gap between them.
What to actually check if you're relying on this today
- Confirm the recipient is on the UK Extension list specifically, not just the base DPF list, on dataprivacyframework.gov. The two lists are not the same set of companies.
- For anything you'd genuinely mind seeing in a regulator's enforcement notice, keep the UK International Data Transfer Agreement (or the UK Addendum to the EU SCCs) as a fallback mechanism rather than relying on the Bridge alone, particularly for special category data or large-scale processing.
- Watch the CJEU docket for C-703/25 P if this matters to your organisation's risk register; a points-of-law appeal narrows the odds of a near-term reversal, but it isn't zero.
- Keep an eye on whether PCLOB regains a functioning quorum. It doesn't change the law on its own, but the Commission's next scheduled review of the DPF will care a great deal about whether that report exists.
None of this is a reason to panic about any specific transfer you're running right now under the Bridge; it's still valid law, upheld once already at the General Court. But it is a reason not to treat "we checked the list in 2023" as a permanent state of compliance. The entire structure rests on an executive order a US president can amend unilaterally, reviewed by a board that currently can't muster a quorum, feeding a court appeal that's still open. It's holding up. It's just worth noticing how much of the weight is currently resting on the fact that nobody has knocked the wall down yet, rather than on the wall being especially solid.