EU-US Data Privacy Framework
The EU-US Data Privacy Framework is a voluntary program that allows eligible U.S. organizations to receive personal data transferred from the European Union in a way the EU recognizes as offering adequate protection. U.S. companies self-certify their compliance to participate, and doing so provides a lawful basis under EU data protection law for those transfers. It is not a general privacy law and does not by itself impose obligations on organizations that choose not to participate.
The EU-U.S. Data Privacy Framework (DPF) is a transatlantic data transfer mechanism established in connection with the EU General Data Protection Regulation (GDPR). On July 10, 2023, the European Commission's adequacy decision for the EU-U.S. DPF entered into force, which is also the effective date of the framework's principles; personal data may then be transferred from the EU to participating U.S. organizations without additional transfer safeguards under the GDPR. Participation is voluntary: U.S. organizations subject to the jurisdiction of the U.S. Federal Trade Commission (or other designated authority) self-certify adherence to the DPF Principles through the U.S. Department of Commerce, whose self-certification website launched on July 17, 2023. The DPF is a self-certification-based adequacy mechanism, not a certification scheme audited by an independent body, and not a statute imposing direct obligations; its continued availability depends on the validity of the Commission's adequacy decision, which may be subject to review, amendment, or legal challenge. Practitioners should verify current participation requirements, eligibility, and the status of the adequacy decision against the official Data Privacy Framework program and the European Commission's authoritative texts.
Why it matters
Cross-border transfers of personal data from the European Union to the United States have been a persistent source of legal uncertainty. Two earlier arrangements intended to enable such transfers—the Safe Harbor framework and its successor, Privacy Shield—were each invalidated by the Court of Justice of the European Union, leaving organizations scrambling for alternative transfer mechanisms. The EU-US Data Privacy Framework was established to provide a renewed adequacy-based route for these transfers, and its availability matters to any organization that moves EU personal data to participating recipients in the United States.
For U.S. companies, self-certifying under the DPF can supply a lawful basis under the GDPR for receiving EU personal data without having to layer on additional transfer safeguards such as standard contractual clauses. For EU-based controllers and processors, confirming that a U.S. counterparty is an active DPF participant can simplify due diligence on international transfers. However, the framework's continued utility rests on the validity of the European Commission's adequacy decision, which may be subject to review, amendment, or legal challenge. Given the litigation history of its predecessors, practitioners should treat the DPF's stability as contingent rather than settled, and monitor the status of the adequacy decision as part of ongoing transfer risk management.
It is also important to keep the DPF's limits in view. It is a voluntary program, not a general privacy law, and it imposes no obligations on U.S. organizations that choose not to participate. Nor is it the only lawful route for EU-US transfers; other GDPR transfer mechanisms remain available. Organizations relying on the DPF should verify a recipient's current participation status and the scope of its self-certification against the official program listing rather than assuming coverage.
Who it's relevant to
Inside DPF
Common questions
Answers to the questions practitioners most commonly ask about DPF.
