EU-U.S. Data Privacy Framework

The U.S. certification program that can let a listed American company receive personal data from the EU without separate transfer clauses.

the EU to US data transfer listthe US privacy certification for Europecan we send EU customer data to Americathe replacement for Privacy ShieldPrivacy Shield replacementis this US vendor allowed to hold EU dataDPF certificationdata privacy framwork

What it is

The EU-U.S. Data Privacy Framework is a transfer mechanism for sending personal data from the European Economic Area to participating U.S. organizations. An eligible U.S. organization self-certifies to the Department of Commerce, publishes promises based on the Framework Principles, and renews that certification annually. The European Commission's adequacy decision is what lets an active participant receive covered data without Standard Contractual Clauses. It is the third arrangement of its kind: the Court of Justice struck down Safe Harbor in 2015 and Privacy Shield in 2020, both in cases brought by Max Schrems, and the current adequacy decision dates from July 2023.

Reach for it when a U.S. vendor appears on the official Data Privacy Framework List and the listed organization, covered entities, and data types match the transfer you are making. The UK Extension and the Swiss-U.S. Data Privacy Framework are separate participation choices, so an EU listing does not silently cover UK or Swiss transfers.

Gotcha: a logo in a vendor's footer is not evidence. Check that the certification is active, that the exact legal entity is listed, and that the entry covers the relevant data. Keep a fallback such as Standard Contractual Clauses ready, because a lapsed certification stops being a usable basis for new transfers.

Ask AI for it

Build a vendor-transfer assessment for the EU-U.S. Data Privacy Framework using the official Data Privacy Framework List. For every U.S. recipient below, record the exact legal entity, active or inactive status, certification date, next recertification date, covered data categories, independent recourse mechanism, and whether the UK Extension or Swiss-U.S. Data Privacy Framework is also listed. Add a monthly recheck procedure, evidence snapshots, an owner, and a fallback workflow that executes the European Commission's 2021 Standard Contractual Clauses when certification is missing, mismatched, or lapses. Do not treat a vendor logo or privacy-policy claim as proof.

You might have meant

cross border data transferstandard contractual clausesgdprdata processing agreementsubprocessor