What Is DPF (EU-U.S. Data Privacy Framework)?

Also called: EU-US Data Privacy Framework, EU-US DPF

Related problems: Our US SaaS vendor says it is DPF certified and we don't know what that covers; Need a lawful way to send European personal data to US providers; Worried the EU-US transfer rules will be struck down again; A European customer asked how we transfer their data to the US

The EU-U.S. Data Privacy Framework (DPF) is a program that lets US organizations receive personal data from the European Union without additional transfer tools, provided they self-certify to the US Department of Commerce that they follow a set of privacy principles. It grew out of the Trans-Atlantic Data Privacy Framework, the agreement in principle announced by the EU and the US in 2022, and rests on an adequacy decision the European Commission adopted in July 2023, finding that the US ensures adequate protection for data sent to participating companies. Related arrangements cover transfers from the UK and Switzerland. This entry is an overview for buyers, not legal advice.

At a glance

  • US companies join by self-certifying to the Department of Commerce and must recertify every year to stay on the official list.
  • Participation is limited to organizations under the jurisdiction of the US Federal Trade Commission or Department of Transportation, the bodies currently recognized.
  • It replaced Privacy Shield, which the EU’s top court invalidated in 2020, as Safe Harbor had been before it.
  • The EU General Court upheld the framework at first instance in 2025; an appeal is pending.
  • It governs commercial transfers, not whether US authorities can compel access to data.

What problem it solves

GDPR allows personal data to leave the European Economic Area only with a recognized mechanism. Without an adequacy decision for the US, European organizations sending data to US cloud, SaaS, contact center and support providers had to rely on standard contractual clauses and transfer impact assessments, which take time and legal effort for every vendor.

The DPF gives a simpler route for participating US companies: once a company is on the list, transfers to it are covered by the adequacy decision. For US providers it reduces friction with European customers; for European buyers it reduces paperwork for each US vendor.

How it works

Principles. Participating companies commit to principles covering notice, choice, accountability for onward transfers, security, data integrity and purpose limitation, access, and recourse, enforcement and liability.

Self-certification. A company submits its certification to the International Trade Administration of the Department of Commerce, publishes a compliant privacy policy and names an independent recourse mechanism for complaints. It must recertify annually or be removed from the list. Companies that receive human resources data must say so and cooperate with EU data protection authorities on HR complaints.

Enforcement. Commitments are enforceable by the FTC or Department of Transportation. Companies that leave the list are generally expected to keep protecting data they received while participating, or to return or delete it.

US government access safeguards. A US executive order on signals intelligence limits collection to what is necessary and proportionate for defined national security purposes and created a two-step redress mechanism for EU individuals, including a Data Protection Review Court. The European Commission states these safeguards apply to all transfers to US companies, whatever transfer mechanism is used.

Review and challenge. The Commission reviews the framework periodically, and its validity can be challenged before EU courts, as earlier frameworks were.

Participation and what to verify

The DPF has no tiers; its structure is a set of participation options, each of which a buyer can verify on the official DPF List.

Element Who it applies to How it is achieved What to check as evidence
EU-U.S. DPF US organizations under FTC or DOT jurisdiction receiving EU personal data Self-certification to the Department of Commerce, renewed annually Active status on the DPF List for the correct legal entity
HR data coverage Participants receiving employee data from the EU Declared in the certification, with an HR privacy policy and cooperation with EU authorities List entry shows HR data covered
UK Extension Participants receiving personal data from the UK Opt-in alongside the EU-U.S. DPF List entry shows the UK Extension
Swiss-U.S. DPF Participants receiving personal data from Switzerland Separate self-certification under the Swiss framework List entry shows the Swiss-U.S. DPF

Requirements and coverage can change; confirm the current details on the official program site and with counsel.

When it matters for buyers

  • When a US vendor will process EU, UK or Swiss personal data. Confirm the DPF entry before relying on it.
  • When negotiating data processing agreements. Agree which transfer mechanism applies and the fallback if the DPF is invalidated.
  • When assessing government access risk. The DPF does not answer which governments can compel access; that is a data sovereignty question.
  • When customers ask how you transfer their data. Be ready to name your mechanism for each vendor.

Our governance, risk and compliance overview covers how to track transfer mechanisms across vendors.

Questions to ask vendors

  • Which legal entity is on the DPF List, and does its entry cover HR or non-HR data, the UK Extension and the Swiss framework?
  • Do your subprocessors that receive our data also participate, or which mechanism do they use?
  • What fallback transfer mechanism, such as standard contractual clauses, is in our contract?
  • Where is our data stored, and who can be compelled to disclose it under US or other law?
  • How do you handle and report government requests for our data?

How it differs from data residency

Data residency is about where data is stored and processed. The DPF is about whether personal data may lawfully be transferred to a US company at all. A US provider on the DPF List may still store your data in Europe, and a provider storing data in Europe may still be subject to US legal process such as the US CLOUD Act, which the DPF does not prevent. Law-enforcement access within the EU is a separate topic covered by the e-Evidence Regulation. Under GDPR, the data in question is personal data, a broader idea than PII in many US uses, and transfers are one part of wider data security compliance.

Frequently Asked Questions

How do we check whether a US company is in the DPF?
Search the Data Privacy Framework List on the US program's official website. Check that the company's status is active, that it covers the right legal entity, that it lists the type of data you send (HR or non-HR) and, if relevant, that it covers the UK Extension or the Swiss-U.S. framework.
What happened to Privacy Shield and Safe Harbor?
They were earlier EU-US transfer frameworks, and the Court of Justice of the EU invalidated both, Safe Harbor in 2015 and Privacy Shield in 2020, mainly over US government surveillance and the lack of effective redress for Europeans. The DPF was built to address those findings with new US safeguards and a redress mechanism.
Could the DPF be struck down too?
It is possible. The EU General Court dismissed a challenge to the DPF in 2025, and an appeal to the Court of Justice is pending. Many organizations keep standard contractual clauses or another mechanism ready as a fallback; check with counsel, as this is not legal advice.
Does DPF certification mean a vendor is GDPR compliant?
No. The DPF covers one issue, the lawful transfer of personal data from the EU to a participating US company. The vendor still needs a data processing agreement, security measures and other GDPR obligations, and you still need a lawful basis for your own processing.
Does the DPF stop the US government from accessing our data?
No. US law, including surveillance authorities and the US CLOUD Act, still applies to US companies. The DPF relies on US commitments limiting signals intelligence to what is necessary and proportionate and on a redress route for EU individuals, not on blocking access.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.