Don’t do SECURITY. Do business SECURELY.

EU–US Data Privacy Framework adopted

The European Commission has adopted an adequacy decision for the EU–US Data Privacy Framework, three years after Schrems II.

The European Commission has today adopted its adequacy decision for the EU–US Data Privacy Framework (DPF).

How it works

  • US organisations self-certify to the US Department of Commerce and commit to the DPF Principles, enforced by the FTC and Department of Transportation.
  • New safeguards on US intelligence access under Executive Order 14086, including necessity and proportionality requirements.
  • A new Data Protection Review Court for EU individuals.

Transfers from the EEA to DPF-certified US organisations no longer need additional safeguards such as SCCs.

The UK is expected to introduce its own “data bridge” extension shortly. Given the history of Safe Harbor and Privacy Shield, legal challenges are likely, so keep fallback transfer mechanisms in your supplier contracts.

Source: Implementing Decision (EU) 2023/1795, EU–US Data Privacy Framework (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights