The EU-US Data Privacy Framework (DPF) is a data protection agreement between the European Union and the United States that provides a legally sound basis for the transfer of personal data from the EU to certified US organisations. It is based on an adequacy decision by the European Commission dated 10 July 2023, which certifies that the US – for organisations certified under the Framework – an adequate level of data protection within the meaning of Article 45 of the GDPR. For companies in the EU that use US services such as cloud platforms, analytics tools or AI services, the DPF is therefore one of the key instruments for legitimising data transfers to the US.
In practice, this means that if an EU-based company transfers personal data to a US provider certified under the DPF, this transfer is permitted without the need for additional instruments – comparable to a data transfer within the EU. If the provider is not certified, the DPF does not apply, and another transfer mechanism is required, usually the Standard Contractual Clauses (SCCs).
How the DPF came about: from Safe Harbour to Privacy Shield
The DPF is already the third attempt to regulate transatlantic data transfers in a legally compliant manner – and this is no coincidence, but rather the result of years of legal dispute. Both of the previous agreements were struck down by the European Court of Justice (ECJ):
- Safe Harbour (2000) was declared invalid in the 2015 Schrems I judgement because it did not offer sufficient protection against access by US intelligence agencies.
- The EU-US Privacy Shield (2016) was struck down in 2020 in the Schrems II judgement for the same reasons – the CJEU once again criticised the access rights of US authorities and the lack of effective legal remedies for EU citizens.
The DPF (2023) is intended to remedy these weaknesses. On the US side, it is based on President Biden’s Executive Order 14086, which limits the intelligence services’ access to data to what is “necessary and proportionate” and establishes the Data Protection Review Court (DPRC) as an independent appeals body for EU citizens. Due to this background, the DPF is unofficially known among experts as “Privacy Shield 2.0”.
How does the DPF work?
The DPF is a self-certification scheme. US companies that fall under the jurisdiction of the Department of Commerce’s data protection authority can commit to complying with a defined set of data protection principles and are then included in a public list. In practice, this has three consequences:
- Verifiability: You can check whether a provider is certified in the official list at dataprivacyframework.gov.
- Scope: Certification may be limited to specific categories of data (e.g. HR data only or non-HR data only). The status is therefore not blanket; it must be checked in detail.
- Enforcement: If a certified organisation fails to comply with the principles, it faces enforcement action by the US Federal Trade Commission (FTC) and removal from the list.
Important: The DPF only legitimises the “destination” of the transfer. If the US provider processes data on behalf of another party, a Data Processing Agreement (DPA) is also required, which governs the ‘how’ of the processing. Both instruments complement one another.
Current status 2026
Like its predecessors, the DPF is also under legal scrutiny. An action for annulment brought by the French MEP Philippe Latombe against the adequacy decision was dismissed by the General Court of the European Union (GCEU) on 3 September 2025 (Case T-553/23). At the time of the decision, the Court considered that an adequate level of protection was in place. The adequacy decision therefore remains in force.
However, at the end of October 2025, an appeal was lodged with the Court of Justice of the European Union (CJEU) (Case C-703/25 P). The DPF is therefore undergoing review by the highest court. Added to this is a political risk: the US basis of the framework – in particular Executive Order 14086 – is dependent on the respective US administration and is under scrutiny. A ‘Schrems III’ scenario – i.e. the decision being overturned once again by the highest court – cannot be ruled out. For businesses, this means that the DPF is currently a valid, but not definitively secure, basis for data transfers.
| Agreement | In force | Status |
|---|---|---|
| Safe Harbour | 2000 | Overturned in 2015 (Schrems I) |
| EU-US Privacy Shield | 2016 | Overturned in 2020 (Schrems II) |
| EU-US Data Privacy Framework | 2023 | in force; appeal pending before the ECJ (C-703/25 P) |
What companies should do now
Based on the current situation, there are two specific recommendations for dealing with data transfers to the US:
- Check and specify certification. Before using a US service, verify whether the provider is actually DPF-certified (and for the relevant data category), and specify this basis in the data protection documentation.
- Prepare a Plan B. As the possibility of the DPF being withdrawn cannot be ruled out, Standard Contractual Clauses (SCCs) should be kept ready as an alternative basis for data transfers. The basis for data transfers in the privacy policy should also be worded in such a way that it withstands any changes in the legal situation.
A concrete real-world example: OpenAI offers both DPF certification and SCCs, as well as EU data residency, for its business products. A company using ChatGPT Enterprise can therefore base the transfer on the DPF – whilst at the same time having the SCCs as a fallback in case the adequacy decision is revoked. This dual safeguard will be the pragmatic standard for the use of US services in 2026.
The DPF’s data protection principles
A US company that obtains DPF certification commits to complying with a fixed set of data protection principles, the structure of which is modelled on the principles of the GDPR. They form the core of the framework and are the reason why the European Commission certifies that the US provides an adequate level of protection for certified organisations:
- Notice: The company must disclose what data it processes, for what purpose, and to whom it discloses it.
- Choice: Data subjects may object to the transfer of data to third parties or to its use for purposes other than those for which it was collected.
- Accountability for onward transfer: If data is transferred to other service providers, the level of protection must be maintained by contract.
- Security: Appropriate technical and organisational safeguards are mandatory.
- Data Integrity & Purpose Limitation): Data may only be processed for the specified purpose and only for as long as necessary.
- Right of Access: Data subjects have the right to access their data and to have it corrected or erased.
- Remedies, enforcement and liability: There must be effective complaint mechanisms and independent supervision – for EU citizens via the specially established Data Protection Review Court.
Comparison of the DPF, Standard Contractual Clauses and BCRs
The DPF is just one of several instruments that can be used to justify a transfer to a third country under Chapter V of the GDPR. Which one is appropriate depends on the provider and the scenario.
| Mechanism | When applicable |
|---|---|
| EU-US Data Privacy Framework (DPF) | The recipient is a DPF-certified US company – no additional instrument required |
| Standard Contractual Clauses (SCCs) | The recipient is not (DPF-)certified or is based in another third country – supplemented by a risk assessment (Transfer Impact Assessment) |
| Binding Corporate Rules (BCR) | Intra-group transfers within a corporate group, authorised by the supervisory authority |
In practice, DPF and SCC are the two relevant options for most small and medium-sized enterprises. Often, both are combined: the transfer is based on the DPF, but SCC is kept as a fallback option in case the adequacy decision is revoked. Given the experience with Safe Harbour and the Privacy Shield, this dual safeguard is the pragmatic response to the ongoing legal uncertainty.
Significance for SMEs
For small and medium-sized enterprises, the DPF is particularly important because a large proportion of the standard software landscape consists of US services – from cloud hosting and collaboration and marketing tools to AI services. Without a viable data transfer mechanism, the use of these services would be vulnerable to challenges under data protection law. The DPF significantly lowers this hurdle, as it eliminates the otherwise necessary effort involved in SCCs and risk assessments for certified providers. At the same time, responsibility remains with the data controller: It must verify the certification, specify the transfer in its data protection documentation and be prepared for any potential changes to the legal situation.
Common misconceptions about the DPF
There are a number of misconceptions surrounding the DPF which, in practice, lead to legal loopholes. Three of these are particularly common.
The first misconception is: “A US provider is automatically DPF-compliant.” This is incorrect – only explicitly certified companies fall under the framework, and certification may be limited to specific data categories. It is therefore essential to check the official list. The second misconception is the assumption that the DPF renders any further measures superfluous. In fact, it merely legitimises the transfer; a data processing agreement (DPA), accurate information in the privacy policy and, where applicable, consent for the underlying processing purpose remain necessary. The third misconception concerns its permanence: as two previous agreements have already been overturned by the ECJ, it is reckless to treat the DPF as definitively secure. Anyone who writes in their privacy policy in general terms that it is „legally compliant on the basis of the DPF“ in their privacy policy risks having an invalid document as soon as the legal situation changes. The change-resistant wording – specifying the concrete legal basis and retaining the SCCs as a fallback – is the safe choice.
Frequently Asked Questions (FAQ)
What is the EU-US Data Privacy Framework?
It is an adequacy decision by the European Commission from 2023, which permits the transfer of personal data to US companies certified under the Framework without the need for additional safeguards. It is the successor to Safe Harbour and the Privacy Shield.
Is the DPF still valid in 2026?
Yes. An action challenging it was dismissed by the General Court on 3 September 2025 (T-553/23, Latombe); the decision remains in force. However, an appeal to the Court of Justice of the European Union is pending (C-703/25 P), and a further overturning (“Schrems III”) cannot be ruled out.
How do I know if a US provider is certified?
Certification can be checked against the official, publicly available list on dataprivacyframework.gov. When doing so, also check whether the certification covers the relevant data category.
What happens if the DPF is overturned?
In that case, the legal basis for DPF-based data transfers would cease to apply. Companies would have to switch to Standard Contractual Clauses (SCCs), including a risk assessment, at short notice. It is therefore advisable to have SCCs in place now as a fallback option.
Is the DPF alone sufficient for using a US tool?
No. The DPF only legitimises the transfer of data to the US. If the provider processes data on behalf of the controller, a data processing agreement is also required, and the privacy policy must specify the purpose, recipients and legal basis for the transfer.