Privacy & Data · European Union · International Transfers

Where Does Your Data Go? How to Audit an EU–U.S. Data Privacy Framework Transfer

A US company can process EU personal data lawfully under the EU-US Data Privacy Framework only if it is a certified organisation covered by the framework. Otherwise, the controller needs another valid transfer mechanism or an applicable derogation.

The EU-US Data Privacy Framework Is Still the Current Adequacy Mechanism

As of August 2026, the European Commission's July 2023 adequacy decision remains the legal basis allowing personal-data transfers from the EEA to certified US organisations participating in the EU-US Data Privacy Framework.

This is important: the adequacy decision is not a blanket finding that every US company provides adequate protection. It applies to organisations certified under the framework and within its scope.

How to Verify a Company

  1. Open the official US Department of Commerce Data Privacy Framework participant list.
  2. Search the exact legal entity name, not only the brand name.
  3. Check that the EU-U.S. Data Privacy Framework status is Active.
  4. Check the scope of covered information, such as HR and/or non-HR data.
  5. Read the participant's privacy policy and dispute-resolution information.
  6. Check whether the service provider named in the contract is the certified entity.

Certification Is Not the Only Possible Transfer Mechanism

If a US company is not covered by the DPF, a transfer can still be lawful under another GDPR Chapter V mechanism, such as Standard Contractual Clauses or Binding Corporate Rules, provided the requirements are satisfied.

The controller or processor should also assess whether the transfer and the recipient's legal environment provide the protections required by the GDPR and relevant CJEU case law. A company simply saying "our servers are in the US" does not answer the legal question.

Do Not Mix Up the DPF and the Old Privacy Shield

The EU-U.S. Data Privacy Framework replaced the invalidated Privacy Shield framework. The European Commission's adequacy decision expressly states that the DPF was assessed in light of the CJEU's Schrems II judgment and the updated US safeguards.

The Commission continues to monitor the framework. In July 2026, the Commission stated that it continued to treat the adequacy decision as operative while monitoring developments.

What Can a Consumer Actually Do?

A consumer generally cannot "revoke the DPF" themselves. Instead, they can exercise GDPR rights against the controller, object or request erasure where applicable, ask what transfer mechanism is being relied upon, and raise a complaint with the controller or the competent supervisory authority.

If the US participant violates its DPF commitments, the framework includes complaint and enforcement mechanisms involving the US Department of Commerce, independent recourse mechanisms and, for certain covered organisations, the FTC.

Build a Transfer Audit File

What This Means Practically

Related Kibbo Tools

Sources