Skip to content
← All terms

Glossary · Privacy & regulation

EU-US Data Privacy Framework

The EU-US Data Privacy Framework (DPF) is a 2023 adequacy decision permitting personal-data transfers to US companies that self-certify to its principles — successor to the invalidated Privacy Shield and Safe Harbor.

US companies aren’t covered by an EU adequacy decision by default, since US law lacks a GDPR-equivalent federal privacy statute and has broader government surveillance powers than the EU considers acceptable. The DPF, which the European Commission adopted on 10 July 2023, addresses this for companies that opt in: a US organization self-certifies to the Department of Commerce that it will follow DPF principles — purpose limitation, data minimization, individual rights, onward-transfer accountability — and, once certified, can receive personal data from the EU/EEA as if the destination were adequate.

The DPF is the third iteration of this mechanism. Its predecessor, Privacy Shield, was struck down by the Court of Justice of the EU in the 2020 Schrems II ruling over concerns that US surveillance law gave intelligence agencies disproportionate access to transferred data without adequate redress for EU citizens; Safe Harbor, the version before that, was invalidated in 2015 for similar reasons. The DPF tries to address the Schrems II concerns with new limits on US signals-intelligence collection and a redress mechanism — a Data Protection Review Court — for EU individuals, though its durability against a future legal challenge is not settled.

Because certification is company-specific and voluntary, a DPF-transfer path only exists if the specific US recipient is on the certified list; otherwise, exporters fall back to SCCs or another safeguard.

See also

Related terms