EU-US Data Privacy Framework (DPF)
· About EU-US Data Privacy Framework (DPF)
Key Takeaways
- The EU-U.S. Data Privacy Framework (DPF) is the European Commission’s adequacy mechanism for transfers of personal data from the EU to U.S. organizations that self-certify to the DPF Principles and are listed by the U.S. Department of Commerce.[1][9]
- The framework currently remains in force; the Commission adopted its adequacy decision on 10 July 2023, and the decision took effect on 11 July 2023.[1][2]
- It applies only to U.S. organizations that are subject to the jurisdiction of the U.S. Department of Commerce and are actively included on the public DPF List; organizations that fall off the list or miss annual recertification lose the ability to rely on the framework for incoming EU transfers.[9][15]
- Certified organizations must comply with the DPF Principles, including notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, enforcement, and liability.[1][14]
- The DPF is enforced through a combination of U.S. administrative oversight, private and public complaint handling, and FTC or Department of Transportation enforcement where applicable; violations can also trigger removal from the DPF List and loss of transfer eligibility.[9][15]
- The Commission’s first review in 2024 found the framework adequate and indicated the next periodic review should occur after three years, so there was no 2025–2026 amendment replacing the adequacy decision as of this date.[3][9]
What It Is
The EU-U.S. Data Privacy Framework is the European Union’s adequacy decision for transfers of personal data to participating U.S. commercial organizations under Chapter V of the GDPR.[1][9] It replaced the former Privacy Shield arrangement after the Court of Justice of the European Union invalidated that regime in Schrems II.
The framework is enforced on the EU side by the European Commission, which adopted the adequacy decision on 10 July 2023 and made it effective on 11 July 2023.[1][2] On the U.S. side, the U.S. Department of Commerce administers the certification and public list, while the Federal Trade Commission and, for certain transport-related entities, the Department of Transportation enforce compliance with the privacy commitments.[9][15]
The Commission published its first review report on 9 October 2024 and concluded that the framework continued to provide an adequate level of protection.[3] That review also indicated the next periodic review should occur after three years, so there is no later amendment or delay that has displaced the framework itself as of 6 September 2026.[3][9]
Who Must Comply
The DPF applies to U.S.-based commercial organizations that receive personal data from the EU and choose to self-certify adherence to the DPF Principles.[1][9] In practice, the organization must be subject to the jurisdiction of the U.S. Department of Commerce and must appear on the official DPF List to rely on the adequacy decision for EU-to-U.S. transfers.[9][15]
The framework has extraterritorial transfer effect in the sense that it governs incoming EU personal data transferred to a qualifying U.S. recipient, even if the sender is in the EU and the recipient processes the data in the United States.[1][9] It is not a general U.S. privacy law applying to all U.S. companies; it is a voluntary certification regime with legal consequences once a company opts in and makes public commitments.[1][15]
The DPF does not cover every organization or every transfer. It is limited to commercial organizations, and organizations outside U.S. jurisdiction, or U.S. organizations that are not listed or no longer certified, cannot rely on the adequacy finding for their transfers.[9][15] The framework also contains specific exclusions and sectoral limitations, including that certain public-sector and non-participating entities fall outside the regime.[1][9]
Core Requirements
- Notice and transparency: Certified organizations must publish privacy information covering the categories of data collected, purposes of use, choices available, recourse mechanisms, and the organization’s commitment to comply with the DPF Principles.[1][14]
- Choice: Organizations must offer individuals a meaningful opportunity to opt out of disclosure to third parties and use for materially different purposes, and they need explicit consent for certain sensitive-data uses.[1][14]
- Accountability for onward transfer: A certified organization remains responsible for third-party transfers unless it can ensure the recipient will provide the same level of protection through contractual or equivalent safeguards.[1][14]
- Security and data integrity: Organizations must implement reasonable and appropriate security measures and ensure data is relevant, reliable for its intended use, and retained only as long as needed for the stated purpose.[1][14]
- Purpose limitation and access: Personal data must be processed only for the purposes disclosed, and individuals must be able to access, correct, or delete data where appropriate, subject to limited exceptions.[1][14]
- Recourse, enforcement, and liability: Organizations must provide independent dispute-resolution mechanisms, cooperate with authorities, and remain liable for the noncompliance of certain onward recipients unless they prove they were not responsible for the event giving rise to damage.[1][9][14]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Commission adequacy decision adopted | 10 July 2023 | The EU recognized the DPF as providing adequate protection for transfers to certified U.S. organizations.[1][2] | | Adequacy decision effective | 11 July 2023 | EU-to-U.S. transfers could rely on the DPF for organizations on the official list.[1][14] | | First Commission review published | 9 October 2024 | The Commission reported the framework remained adequate and set the next review horizon at about three years.[3] | | DPF List updated through annual recertification cycle | ongoing, including 2026 | Participating organizations must recertify annually or risk removal from the list and loss of reliance on the framework.[15] |
Maximum fines and sanctions: The DPF itself does not create a single standalone fine schedule in the way a statute does. The main sanction is loss of certification and removal from the DPF List, which ends the ability to rely on the framework for EU transfers.[15] In addition, the FTC or Department of Transportation may bring enforcement actions for deceptive or unfair practices tied to the certification commitments, and EU data exporters may need to suspend transfers or switch to another Chapter V transfer mechanism if a recipient is no longer certified.[9][15]
How to Comply
- Confirm eligibility and jurisdiction: Verify the organization is a U.S. commercial entity within the Commerce Department’s scope and that the data flows are EU-to-U.S. transfers covered by the DPF.[9][15]
- Map data flows and vendors: Inventory what EU personal data is received, where it goes, which subprocessors or third parties receive it, and whether onward transfers require separate safeguards under the DPF.[1][14]
- Build the DPF notice set: Update privacy notices, internal records, and public commitments so they accurately describe purposes, choices, complaint routes, retention, access rights, and independent recourse.[1][14]
- Implement governance controls: Use an information-security management baseline such as ISO 27001 for policy, risk treatment, access control, incident management, and supplier oversight; these controls map directly to DPF security and accountability obligations.
- Operationalize privacy-by-design controls: Use NIST CSF 2.0 to structure identification, protection, detection, response, and recovery around personal-data processing and incident handling; this supports the DPF security, integrity, and enforcement expectations.
- Manage AI and automated processing carefully: If the organization uses personal data in AI systems, align governance with ISO 42001 so data lineage, purpose limitation, model access, retention, and human oversight support DPF transparency and minimization obligations.
- Set annual recertification and audit cadence: Calendar annual re-certification well in advance, review all statements and contracts for accuracy, and test that the DPF List entry remains current because lapse means transfer reliance is lost.[15]
- Prepare complaint and escalation workflows: Maintain a documented process for receiving and resolving EU individual complaints, DPA referrals, and regulator inquiries, including deadlines, ownership, and evidence preservation.[4][9]
Related Regulations
GDPR: The DPF is a transfer mechanism under Chapter V of the GDPR, so it does not replace GDPR obligations on the EU exporter or on processing that remains within the EU.
Schrems II: The CJEU’s 2020 Schrems II decision invalidated Privacy Shield and raised the bar for transfer assessments, which is why the DPF is designed as a successor adequacy regime.
Standard Contractual Clauses (SCCs): SCCs remain a separate transfer tool; they are often used as a fallback if a recipient is not DPF-certified or loses certification.
UK Extension / UK Addendum regime: The United Kingdom has its own transatlantic transfer arrangements, so a DPF-certified U.S. recipient may still need separate UK transfer coverage for UK-origin data.
EU AI Act: The DPF is not an AI law, but AI systems processing imported EU personal data still need governance that respects data minimization, transparency, retention, and security obligations.
FAQ
Does the DPF apply to companies outside the United States?
No. The framework is built for U.S. organizations that self-certify and come under the Department of Commerce’s jurisdiction.[9][15] Non-U.S. entities cannot use DPF certification as such, although they may still use other transfer mechanisms for EU data.
Does a company have to certify every year?
Yes. Annual recertification is part of maintaining an active listing, and the public DPF List is updated based on those submissions.[15] Missing recertification can result in removal from the list, which ends DPF reliance for EU transfers.
Does the DPF replace SCCs and other transfer tools?
No. The DPF is one transfer mechanism among several under EU law.[1][9] SCCs, binding corporate rules, and derogations remain relevant when DPF coverage is unavailable or unsuitable.
What happens if a certified company is removed from the DPF List?
Once removed, the company can no longer rely on the adequacy decision for new transfers, and EU exporters may need to suspend transfers or move to another lawful transfer tool.[9][15] Existing contractual and security obligations may still apply, but the adequacy basis is gone.
Is the DPF still valid after the 2025 court challenge?
Yes. A 2025 General Court ruling upheld the Commission’s adequacy decision, which strengthened legal certainty for certified transfers.[8] The Commission’s adequacy decision and the 2024 review also remained in place through 2026.[3][9]
Sources
- European Commission adequacy decisions overview
- EUR-Lex, Commission Implementing Decision on the EU-U.S. Data Privacy Framework (CELEX 32023D1795)
- European Commission press release on adopting the adequacy decision
- European Commission report on the first review of the DPF adequacy decision
- U.S. Department of Commerce Data Privacy Framework program
- EU-U.S. DPF FAQ for European individuals, European Data Protection Board
- EU-U.S. DPF FAQ for European businesses, European Data Protection Board
- Department of Commerce final rule / Federal Register notice on DPF administration
- Jones Day analysis of the 2025 General Court ruling
Put it into practice
- Generate the policy: GDPR policy generator (generatepolicy.com)
- Buy the policy pack: GDPR Complete Bundle (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)