
Insights · Clarius Group
Data Privacy Framework (DPF): new adequacy decision for secure data transfers between the EU and the US
The new adequacy decision on the EU-US Data Privacy Framework makes data transfers to the United States easier.
- Published
- 11 July 2023
- Reading time
- 2 min read
On 10 July 2023 the European Commission adopted, at the third attempt, an adequacy decision for the EU-US Data Privacy Framework (DPF). EU companies can therefore now transfer personal data to data importers in the United States that certify compliance with the DPF principles, without further authorisations or additional measures (for example Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs)) being required.
Background
If the Commission decides that a third country (territory or sector) provides an adequate level of protection, then the third-country transfer is permissible without further ado.
For the United States, the Commission issued two adequacy decisions before the GDPR entered into force: the Safe Harbor decision of 26 June 2000, which was declared invalid by the Court of Justice of the European Union on 6 October 2015 (Schrems I), and the Privacy Shield of 12 June 2016, which was also declared invalid by the Court of Justice of the European Union on 16 July 2020 (Schrems II).
In both cases the Court of Justice of the European Union found that surveillance by the US authorities of EU citizens whose personal data had been transferred to the United States was not compatible with EU law. A further problem was the lack of effective enforcement mechanisms for EU citizens in the United States.
Since July 2020, companies have had to transfer data to the United States subject to appropriate safeguards.
The Data Privacy Framework (DPF)
On 23 May 2022 the European Commission and the United States announced that they had in principle agreed on a new Trans-Atlantic Data Privacy Framework and had also ensured that the concerns expressed by the Court of Justice of the European Union in the Schrems II case would be taken into account.
Yesterday the adequacy decision finally entered into force.
Implications for companies
- This is still a self-certification mechanism: data importers in the United States must certify their own compliance with the DPF principles.
- It remains unclear what will happen to companies that are already certified under the Privacy Shield – whether a new certification is necessary or whether recertification will be possible.
- Necessary information is made available at https://www.dataprivacyframework.gov/s/. At present the website is still under construction and visitors are redirected to the Privacy Shield website.
- Data exporters in the EU must first ensure that the data recipient in the United States is already DPF-certified before a data transfer takes place on the basis of the new adequacy decision.
- A transfer impact assessment is no longer required for third-country transfers on the basis of the DPF. If, however, the data importer is not DPF-certified, a transfer impact assessment remains necessary.
- Privacy notices are to be updated.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


