Skip to main content
Promotional banner for the pentest readiness checklist
Category: Cross-Border Transfers

EU-US Data Privacy Framework

Also known as: DPF, EU-U.S. Data Privacy Framework, EU–US Data Privacy Framework, Data Privacy Framework
Simply put

The EU-US Data Privacy Framework is a voluntary program that allows eligible U.S. organizations to receive personal data transferred from the European Union in a way the EU recognizes as offering adequate protection. U.S. companies self-certify their compliance to participate, and doing so provides a lawful basis under EU data protection law for those transfers. It is not a general privacy law and does not by itself impose obligations on organizations that choose not to participate.

Formal definition

The EU-U.S. Data Privacy Framework (DPF) is a transatlantic data transfer mechanism established in connection with the EU General Data Protection Regulation (GDPR). On July 10, 2023, the European Commission's adequacy decision for the EU-U.S. DPF entered into force, which is also the effective date of the framework's principles; personal data may then be transferred from the EU to participating U.S. organizations without additional transfer safeguards under the GDPR. Participation is voluntary: U.S. organizations subject to the jurisdiction of the U.S. Federal Trade Commission (or other designated authority) self-certify adherence to the DPF Principles through the U.S. Department of Commerce, whose self-certification website launched on July 17, 2023. The DPF is a self-certification-based adequacy mechanism, not a certification scheme audited by an independent body, and not a statute imposing direct obligations; its continued availability depends on the validity of the Commission's adequacy decision, which may be subject to review, amendment, or legal challenge. Practitioners should verify current participation requirements, eligibility, and the status of the adequacy decision against the official Data Privacy Framework program and the European Commission's authoritative texts.

Why it matters

Cross-border transfers of personal data from the European Union to the United States have been a persistent source of legal uncertainty. Two earlier arrangements intended to enable such transfers—the Safe Harbor framework and its successor, Privacy Shield—were each invalidated by the Court of Justice of the European Union, leaving organizations scrambling for alternative transfer mechanisms. The EU-US Data Privacy Framework was established to provide a renewed adequacy-based route for these transfers, and its availability matters to any organization that moves EU personal data to participating recipients in the United States.

For U.S. companies, self-certifying under the DPF can supply a lawful basis under the GDPR for receiving EU personal data without having to layer on additional transfer safeguards such as standard contractual clauses. For EU-based controllers and processors, confirming that a U.S. counterparty is an active DPF participant can simplify due diligence on international transfers. However, the framework's continued utility rests on the validity of the European Commission's adequacy decision, which may be subject to review, amendment, or legal challenge. Given the litigation history of its predecessors, practitioners should treat the DPF's stability as contingent rather than settled, and monitor the status of the adequacy decision as part of ongoing transfer risk management.

It is also important to keep the DPF's limits in view. It is a voluntary program, not a general privacy law, and it imposes no obligations on U.S. organizations that choose not to participate. Nor is it the only lawful route for EU-US transfers; other GDPR transfer mechanisms remain available. Organizations relying on the DPF should verify a recipient's current participation status and the scope of its self-certification against the official program listing rather than assuming coverage.

Who it's relevant to

U.S. organizations receiving EU personal data
Companies subject to FTC (or other designated authority) jurisdiction that wish to receive personal data from the EU may self-certify through the U.S. Department of Commerce to obtain a lawful transfer basis under the GDPR. They should assess eligibility and the scope of the DPF Principles before committing, and recognize that self-certification is a voluntary undertaking rather than an independently audited certification.
EU controllers and processors transferring data to the U.S.
Organizations in the EU exporting personal data to U.S. recipients can use a counterparty's active DPF participation as a transfer basis, but should verify the recipient's current status on the official program list and confirm that the intended data falls within the scope of that participation. They should also weigh the DPF against other available GDPR transfer mechanisms.
Data protection officers and privacy counsel
Those advising on international data transfers need to track the validity of the European Commission's adequacy decision, which may be subject to review, amendment, or legal challenge, and to maintain contingency plans given the litigation history of the DPF's predecessor arrangements. Application to specific transfers requires professional judgment against the current official texts.
Compliance and vendor-management teams
Teams performing due diligence on service providers and sub-processors should incorporate verification of DPF participation status into their onboarding and periodic review processes, understanding that a listing reflects a self-declared commitment rather than third-party assurance, and that participation status can change.

Inside DPF

Adequacy Decision Basis
The DPF operates under a European Commission adequacy decision that recognizes the United States as providing an adequate level of protection for personal data transferred to certified U.S. organizations. Such a decision permits transfers without additional safeguards for participating entities, but its continued validity depends on periodic review by the Commission and may be subject to legal challenge, as prior transatlantic mechanisms were. Verify the current status of the decision against the latest official European Commission publications.
Self-Certification Mechanism
Participation is voluntary and depends on eligible U.S. organizations self-certifying their adherence to the framework's principles, administered through the U.S. Department of Commerce. Self-certification is not the same as a formal certification against a technical standard; it is an attestation of commitment that must generally be renewed periodically to remain valid.
Privacy Principles
Certified organizations commit to a set of privacy principles governing the handling of personal data, which generally address matters such as notice, choice, accountability for onward transfers, security, data integrity and purpose limitation, access, and recourse. Organizations should consult the official principles text for the authoritative and current wording.
Redress and Oversight Layers
The framework contemplates mechanisms intended to give EU individuals avenues for complaint and redress regarding U.S. handling of their data, including independent recourse and oversight components. The precise design and effectiveness of these mechanisms are subject to ongoing scrutiny and potential legal review.
Scope of Application
The framework facilitates personal data transfers from the EU to participating U.S. organizations. It does not itself replace other lawful transfer mechanisms, and it applies only to organizations that have validly self-certified and that fall within the applicable U.S. regulatory oversight. Transfers to non-participating recipients require a separate lawful basis.

Common questions

Answers to the questions practitioners most commonly ask about DPF.

Does self-certifying under the EU-US Data Privacy Framework guarantee that our transfers are permanently compliant?
No. Self-certification to the DPF, administered by the U.S. Department of Commerce, provides a lawful basis for transfers of personal data from the EU to participating U.S. organizations only while several conditions hold. The organization must remain actively certified, re-certify on the required periodic basis, and continue to meet the Framework's principles in practice. Equally important, the underlying European Commission adequacy decision that makes the DPF a valid transfer mechanism can be reviewed, suspended, or invalidated. Prior EU-US arrangements were struck down by the Court of Justice of the European Union, and the current decision may likewise be subject to legal challenge or periodic review. Certification is therefore a continuing obligation and a conditional basis, not a permanent guarantee. Readers should verify current status against the official DPF program list and the latest Commission position.
Is the Data Privacy Framework the same as the GDPR, or does it replace GDPR obligations for participating companies?
No. The DPF is not a substitute for the GDPR, and the two operate at different levels. The GDPR is binding EU law governing the processing of personal data. The DPF is a mechanism that addresses one specific GDPR requirement: providing an adequate basis for transferring personal data from the EU to the United States, supported by a European Commission adequacy decision. A U.S. organization's participation in the DPF does not exempt an EU-based controller or processor from its broader GDPR duties, nor does it convert the DPF principles into EU law. The DPF principles are commitments enforced primarily under U.S. law and oversight. Organizations remain responsible for meeting all applicable GDPR obligations independently of, and in addition to, any DPF participation.
How does a U.S. organization begin participating in the DPF, and who is eligible?
Participation is through self-certification with the U.S. Department of Commerce, which administers the program and maintains the public list of participants. Eligibility is generally limited to U.S. organizations subject to the investigatory and enforcement powers of a designated U.S. authority (such as the Federal Trade Commission or the Department of Transportation, depending on sector), because that oversight underpins the Framework's enforceability. Organizations outside the scope of those authorities may not be eligible. Certification generally requires publicly committing to the Framework's principles, having a conforming privacy policy, and meeting the program's procedural conditions. Prospective participants should confirm current eligibility criteria and process against the official DPF program materials, as details may change.
Can our EU organization rely on a U.S. vendor's DPF certification as the transfer mechanism, and what should we check first?
In many cases an EU controller or processor can rely on a recipient's active DPF participation as the basis for the specific transfer, provided the recipient is genuinely certified for the relevant category of data. Before relying on it, verify that the organization appears as active on the official Data Privacy Framework list, that its certification covers the type of data involved (certain frameworks distinguish, for example, HR data), and that the certification has not lapsed. Relying on a listed but expired or non-covering certification would not provide a valid basis. Because status can change, this should be checked at onboarding and monitored over time, and organizations often maintain an alternative transfer mechanism as a contingency.
What ongoing obligations does a participating organization have after certifying, and what happens if it stops participating?
Participation carries continuing obligations rather than a one-time step. These generally include periodic re-certification, keeping the privacy policy and public commitments accurate, honoring individual rights and complaint-handling mechanisms provided under the Framework, and cooperating with the relevant oversight and dispute-resolution processes. If an organization withdraws or fails to re-certify, it must still address personal data it received while certified in the manner the Framework requires, and it can no longer rely on the DPF as a transfer basis for new transfers. Specific retention and continued-protection requirements are set out in the program's principles, which readers should consult directly, as procedural details are subject to change.
Does DPF participation cover transfers to jurisdictions other than the EU, such as the United Kingdom or Switzerland?
Not automatically. The core DPF adequacy decision concerns transfers from the EU. Separate arrangements or extensions address transfers from other jurisdictions, and their availability, scope, and status differ. The United Kingdom and Switzerland have historically operated their own mechanisms tied to but distinct from the EU arrangement, each depending on that jurisdiction's own determination. An organization intending to receive data from the UK or Switzerland should confirm whether it has certified under the applicable extension and whether that jurisdiction's authorities currently recognize it. Because these determinations are made separately and may be reviewed independently, coverage should be verified per jurisdiction against the current official sources rather than assumed from EU participation alone.

Common misconceptions

Any U.S. company can automatically rely on the DPF to receive EU personal data.
Only organizations that have validly self-certified and that fall within the applicable U.S. oversight can rely on the framework. A data exporter should confirm the recipient's active participation before relying on the mechanism, and transfers to non-participating recipients require a separate lawful transfer basis.
The DPF is a permanent, settled legal arrangement.
The framework rests on a European Commission adequacy decision that is subject to periodic review and may be challenged in court, as prior transatlantic transfer mechanisms were. Its continued availability should not be assumed, and practitioners should monitor its current status against authoritative sources.
DPF self-certification is equivalent to a formal certification against a technical standard.
Self-certification under the DPF is a voluntary attestation of adherence to the framework's privacy principles administered through the U.S. Department of Commerce. It is not the same as certification against a voluntary technical standard, and it does not by itself demonstrate conformity with any such standard.

Best practices

Before relying on the DPF for a transfer, verify that the specific recipient organization holds an active, current self-certification rather than assuming eligibility.
Maintain a contingency plan and consider alternative lawful transfer mechanisms so that transfers remain compliant if the adequacy decision is reviewed, suspended, or invalidated.
Monitor official European Commission and U.S. Department of Commerce sources for changes to the framework's status, principles, and participation requirements.
Track self-certification renewal obligations for participating organizations, as lapses may affect the lawful basis for ongoing transfers.
Document your transfer analysis and the basis for reliance on the DPF to support accountability obligations and internal audits.
Seek qualified professional advice when applying the framework to specific transfers, since obligations are fact-specific and interpretations continue to evolve.
Promotional banner for the Penetration Report Template Kit