EU-US Data Privacy Framework (DPF)
The adequacy decision for the United States applies only to recipients certified under the EU-US Data Privacy Framework. How the certification is verified, what consequences it has, why no transfer impact assessment is required and how the transfer can be safeguarded contractually.
The United States is not a safe third country across the board. For data transfers to the United States, however, an adequacy decision of the European Commission does exist where the specific recipient is certified under the EU-US Data Privacy Framework (DPF) (Implementing Decision (EU) 2023/1795 of 10 July 2023). Where the recipient is certified and the certification covers the data transferred, the transfer is to be treated like a domestic transfer.
Key takeaways
- The adequacy decision applies only to certified US recipients, not to the United States as a whole. Transfers to non-certified recipients remain transfers to an unsafe third country.
- For certified recipients, neither standard contractual clauses nor a transfer impact assessment are required.
- Two points must be examined: whether the company holds an active certification and whether the certification covers the specific data being transferred.
- The decision does not establish a legal basis; a legal basis under Article 6 GDPR must additionally be in place.
1. When the Data Privacy Framework applies
The adequacy decision does not attach to the country but to the individual recipient. What matters is whether the US company has certified under the Data Privacy Framework and whether the certification covers the data transferred. Companies that were previously certified under the Privacy Shield continue to be covered under the Data Privacy Framework.
2. Verifying the certification
The certification can be verified through the official list. Two points need to be clarified:
If the review shows that the recipient is not certified, or is not certified for the data in question, there is a transfer to an unsafe third country. In that case, standard contractual clauses together with a transfer impact assessment are required.
3. Consequences and contractual safeguards
Where the recipient holds a valid certification, no additional safeguards are required for the transfer. In particular, no standard contractual clauses need to be concluded and no transfer impact assessment needs to be carried out.
As a precaution, it is advisable to agree contractually with the data recipient that it will maintain the certification for the entire term of the contract. This is not mandatory. It is also conceivable to conclude the standard contractual clauses in addition, as a fallback solution. The background is that the CJEU declared the predecessor arrangements Safe Harbor and Privacy Shield invalid and could review the Data Privacy Framework as well. Unless and until there is a decision to the contrary, the adequacy decision remains valid.
The data protection guarantees introduced with the Data Privacy Framework are based on an Executive Order of 7 October 2022 (including a redress mechanism and restricted access by US security authorities). These guarantees apply irrespective of whether the individual recipient is certified and can therefore be taken into account as a positive factor in a transfer impact assessment where the recipient is not certified.
4. Background: from Safe Harbor to the Data Privacy Framework
The Data Privacy Framework is the third attempt to base data transfers to the United States on an adequacy decision. Both predecessors failed because of access by US security authorities and the lack of legal protection for EU citizens.
- Safe Harbor (2000 to 2015). On the basis of a self-certification, the European Commission declared transfers to participating US companies permissible. In 2015, the CJEU declared the Safe Harbor decision invalid, because the principles were subordinate to US security requirements and effective legal protection was lacking (CJEU, judgment of 6 October 2015, C-362/14, Schrems).
- Privacy Shield (2016 to 2020). The successor program introduced, among other things, an ombudsperson mechanism and assurances from the US authorities. The CJEU declared this decision invalid as well, because the surveillance programs were not limited to what is strictly necessary and the ombudsperson did not have the required independence and powers of enforcement (CJEU, judgment of 16 July 2020, C-311/18, Schrems II).
- Data Privacy Framework (since 2023). The improvements are based on Executive Order 14086 of 7 October 2022. It ties access by the US intelligence services to the principles of necessity and proportionality and creates a two-tier redress system including a Data Protection Review Court. On that basis, the European Commission adopted the adequacy decision on 10 July 2023 (Implementing Decision (EU) 2023/1795).
Both the European Data Protection Board and the European Parliament have followed the decision critically and expressed doubts on individual points (among other things on data subject rights and on the effectiveness of the redress system). A further judicial review has been announced. Unless and until there is a decision to the contrary, the adequacy decision remains valid; many companies therefore additionally safeguard transfers by way of standard contractual clauses (see section 3).
5. Transparency towards data subjects
Under the Data Privacy Framework as well, the transfer must be stated in the privacy notice (Article 13(1)(f) GDPR). A notice may read, for example:
We transfer your data to the United States. Under an adequacy decision of the European Commission, companies in the United States that are certified under the EU-US Data Privacy Framework provide an adequate level of protection for personal data. The data recipient is certified under the EU-US Data Privacy Framework.
Data Privacy Framework List
Official list of certified US companies for verifying the certification and its scope.
Implementing Decision (EU) 2023/1795
Adequacy decision on the EU-US Data Privacy Framework of 10 July 2023.
CJEU, Schrems II (C-311/18)
Invalidity of the predecessor Privacy Shield; background to the risks regarding its continued validity.
CJEU, Schrems I (C-362/14)
Invalidity of the Safe Harbor agreement; the start of the chain of US adequacy decisions.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
EU Standard Contractual Clauses and Transfer Impact Assessment
The EU standard contractual clauses (SCCs) as an appropriate safeguard for transfers to third countries: the four modules, the constellations, the delegation model and how the clauses are concluded. Plus the mandatory transfer impact assessment (TIA) in three stages, with risk-based considerations, periodic review and the treatment of the chain of processors.
Binding Corporate Rules (BCR)
Binding Corporate Rules as an appropriate safeguard for intra-group transfers to third countries under Article 47 GDPR: binding internal data protection rules, scope, approval by the supervisory authority, minimum content and liability, as well as the relationship to the Schrems II case law. Distinction between controller and processor BCR, reach and limits.