A US company can process EU personal data lawfully under the EU-US Data Privacy Framework only if it is a certified organisation covered by the framework. Otherwise, the controller needs another valid transfer mechanism or an applicable derogation.
The EU-US Data Privacy Framework Is Still the Current Adequacy Mechanism
As of August 2026, the European Commission's July 2023 adequacy decision remains the legal basis allowing personal-data transfers from the EEA to certified US organisations participating in the EU-US Data Privacy Framework.
This is important: the adequacy decision is not a blanket finding that every US company provides adequate protection. It applies to organisations certified under the framework and within its scope.
How to Verify a Company
- Open the official US Department of Commerce Data Privacy Framework participant list.
- Search the exact legal entity name, not only the brand name.
- Check that the EU-U.S. Data Privacy Framework status is Active.
- Check the scope of covered information, such as HR and/or non-HR data.
- Read the participant's privacy policy and dispute-resolution information.
- Check whether the service provider named in the contract is the certified entity.
Certification Is Not the Only Possible Transfer Mechanism
If a US company is not covered by the DPF, a transfer can still be lawful under another GDPR Chapter V mechanism, such as Standard Contractual Clauses or Binding Corporate Rules, provided the requirements are satisfied.
The controller or processor should also assess whether the transfer and the recipient's legal environment provide the protections required by the GDPR and relevant CJEU case law. A company simply saying "our servers are in the US" does not answer the legal question.
Do Not Mix Up the DPF and the Old Privacy Shield
The EU-U.S. Data Privacy Framework replaced the invalidated Privacy Shield framework. The European Commission's adequacy decision expressly states that the DPF was assessed in light of the CJEU's Schrems II judgment and the updated US safeguards.
The Commission continues to monitor the framework. In July 2026, the Commission stated that it continued to treat the adequacy decision as operative while monitoring developments.
What Can a Consumer Actually Do?
A consumer generally cannot "revoke the DPF" themselves. Instead, they can exercise GDPR rights against the controller, object or request erasure where applicable, ask what transfer mechanism is being relied upon, and raise a complaint with the controller or the competent supervisory authority.
If the US participant violates its DPF commitments, the framework includes complaint and enforcement mechanisms involving the US Department of Commerce, independent recourse mechanisms and, for certain covered organisations, the FTC.
Build a Transfer Audit File
- Company legal name and service.
- Privacy policy date.
- Country of the controller and processor.
- DPF participant record and certification scope.
- Stated transfer mechanism if no DPF certification exists.
- Relevant data categories.
- Your requests and the company's response.
What This Means Practically
- The DPF is currently valid for qualifying transfers to certified US organisations.
- Check the exact legal entity on the official participant list.
- No active certification does not automatically mean an unlawful transfer; another Chapter V mechanism may apply.
- Do not confuse DPF status with a consumer's right to erase or object to processing.
- Use the controller, DPO and supervisory-authority channels when the transfer cannot be explained or appears unlawful.
Related Kibbo Tools
Sources
- European Commission / EUR-Lex — EU-US Data Privacy Framework adequacy decision, Commission Implementing Decision (EU) 2023/1795. eur-lex.europa.eu
- U.S. Department of Commerce — Data Privacy Framework participant search. dataprivacyframework.gov
- U.S. Department of Commerce — DPF participants list information for European individuals. dataprivacyframework.gov
- European Commission — July 2026 statement on the EU-US Data Privacy Framework. audiovisual.ec.europa.eu