The EU-U.S. Data Privacy Framework (DPF) is a program that lets US organizations receive personal data from the European Union without additional transfer tools, provided they self-certify to the US Department of Commerce that they follow a set of privacy principles. It grew out of the Trans-Atlantic Data Privacy Framework, the agreement in principle announced by the EU and the US in 2022, and rests on an adequacy decision the European Commission adopted in July 2023, finding that the US ensures adequate protection for data sent to participating companies. Related arrangements cover transfers from the UK and Switzerland. This entry is an overview for buyers, not legal advice.
At a glance
- US companies join by self-certifying to the Department of Commerce and must recertify every year to stay on the official list.
- Participation is limited to organizations under the jurisdiction of the US Federal Trade Commission or Department of Transportation, the bodies currently recognized.
- It replaced Privacy Shield, which the EU’s top court invalidated in 2020, as Safe Harbor had been before it.
- The EU General Court upheld the framework at first instance in 2025; an appeal is pending.
- It governs commercial transfers, not whether US authorities can compel access to data.
What problem it solves
GDPR allows personal data to leave the European Economic Area only with a recognized mechanism. Without an adequacy decision for the US, European organizations sending data to US cloud, SaaS, contact center and support providers had to rely on standard contractual clauses and transfer impact assessments, which take time and legal effort for every vendor.
The DPF gives a simpler route for participating US companies: once a company is on the list, transfers to it are covered by the adequacy decision. For US providers it reduces friction with European customers; for European buyers it reduces paperwork for each US vendor.
How it works
Principles. Participating companies commit to principles covering notice, choice, accountability for onward transfers, security, data integrity and purpose limitation, access, and recourse, enforcement and liability.
Self-certification. A company submits its certification to the International Trade Administration of the Department of Commerce, publishes a compliant privacy policy and names an independent recourse mechanism for complaints. It must recertify annually or be removed from the list. Companies that receive human resources data must say so and cooperate with EU data protection authorities on HR complaints.
Enforcement. Commitments are enforceable by the FTC or Department of Transportation. Companies that leave the list are generally expected to keep protecting data they received while participating, or to return or delete it.
US government access safeguards. A US executive order on signals intelligence limits collection to what is necessary and proportionate for defined national security purposes and created a two-step redress mechanism for EU individuals, including a Data Protection Review Court. The European Commission states these safeguards apply to all transfers to US companies, whatever transfer mechanism is used.
Review and challenge. The Commission reviews the framework periodically, and its validity can be challenged before EU courts, as earlier frameworks were.
Participation and what to verify
The DPF has no tiers; its structure is a set of participation options, each of which a buyer can verify on the official DPF List.
| Element | Who it applies to | How it is achieved | What to check as evidence |
|---|---|---|---|
| EU-U.S. DPF | US organizations under FTC or DOT jurisdiction receiving EU personal data | Self-certification to the Department of Commerce, renewed annually | Active status on the DPF List for the correct legal entity |
| HR data coverage | Participants receiving employee data from the EU | Declared in the certification, with an HR privacy policy and cooperation with EU authorities | List entry shows HR data covered |
| UK Extension | Participants receiving personal data from the UK | Opt-in alongside the EU-U.S. DPF | List entry shows the UK Extension |
| Swiss-U.S. DPF | Participants receiving personal data from Switzerland | Separate self-certification under the Swiss framework | List entry shows the Swiss-U.S. DPF |
Requirements and coverage can change; confirm the current details on the official program site and with counsel.
When it matters for buyers
- When a US vendor will process EU, UK or Swiss personal data. Confirm the DPF entry before relying on it.
- When negotiating data processing agreements. Agree which transfer mechanism applies and the fallback if the DPF is invalidated.
- When assessing government access risk. The DPF does not answer which governments can compel access; that is a data sovereignty question.
- When customers ask how you transfer their data. Be ready to name your mechanism for each vendor.
Our governance, risk and compliance overview covers how to track transfer mechanisms across vendors.
Questions to ask vendors
- Which legal entity is on the DPF List, and does its entry cover HR or non-HR data, the UK Extension and the Swiss framework?
- Do your subprocessors that receive our data also participate, or which mechanism do they use?
- What fallback transfer mechanism, such as standard contractual clauses, is in our contract?
- Where is our data stored, and who can be compelled to disclose it under US or other law?
- How do you handle and report government requests for our data?
How it differs from data residency
Data residency is about where data is stored and processed. The DPF is about whether personal data may lawfully be transferred to a US company at all. A US provider on the DPF List may still store your data in Europe, and a provider storing data in Europe may still be subject to US legal process such as the US CLOUD Act, which the DPF does not prevent. Law-enforcement access within the EU is a separate topic covered by the e-Evidence Regulation. Under GDPR, the data in question is personal data, a broader idea than PII in many US uses, and transfers are one part of wider data security compliance.
