Under the GDPR, when can an EU startup rely on the EU-US Data Privacy Framework to send personal data to a US-headquartered cloud provider?
answer
- adequacy, but only for some
- a list kept by the US side
- annual re-certification
- HR data needs its own opt-in
- keep a fallback ready
basics
~20 sUnder Decision (EU) 2023/1795, only US organisations on the Data Privacy Framework List are adequate. The startup checks that the recipient is listed, current and covers the data type; otherwise it needs SCCs or another Art. 46 route.
solid answer
~40 sThe Commission's **Decision (EU) 2023/1795** of 10 July 2023 is an **Art. 45 adequacy decision** with a limit. Under its **Art. 1**, the United States is adequate only for transfers to organisations included in the **Data Privacy Framework List** kept by the US Department of Commerce. Organisations get onto the list by **self-certifying**. Only those subject to the FTC's or the Department of Transportation's powers are eligible, and they must **re-certify annually** or be removed. Removed organisations lose the benefit. **HR data** is covered only if the organisation says so in its self-certification and commits to cooperate with EU data protection authorities. So the startup checks that the **specific US entity** receiving data is on the list, active and covering the right data type. If not, it uses **SCCs** (Art. 46).
go deeper
Recall that the DPF is an adequacy decision that covers only US organisations on the Data Privacy Framework List, not the United States as a whole.
Explain self-certification: FTC or DoT eligibility, annual re-certification, removal, and the separate HR-data commitment. Say what to check before relying on a listing.
Plan for the DPF's fragility after Schrems II: keep SCCs as a contractual fallback and know which flows would move if the decision were suspended.
Decide how much of a data architecture may depend on one partial adequacy decision, and what a switch-over must cost, given the Privacy Shield precedent.
## What kind of instrument the DPF is The EU-US Data Privacy Framework (DPF) is an **adequacy decision under Art. 45**: Commission Implementing Decision (EU) 2023/1795, adopted **10 July 2023**. Where it applies, a transfer *"shall not require any specific authorisation"* (Art. 45(1)). There are no SCCs to sign and no Clause 14 assessment to run for that transfer. It is also a **partial** adequacy decision. **Art. 1** of the Decision says the United States ensures an adequate level of protection for personal data transferred *"to organisations in the United States that are included in the 'Data Privacy Framework List', maintained and made publicly available by the U.S. Department of Commerce."* The rest of the United States is not covered. ## The self-certification limit The list is built by **self-certification**. The Decision and its annexes set conditions: - **Eligibility.** Only organisations subject to the investigatory and enforcement powers of the **Federal Trade Commission** or the **US Department of Transportation** can certify. Sectors outside those powers, which the Decision notes include banks and most non-profits, cannot use the DPF. - **Start date.** DPF benefits are assured from the date the organisation is placed on the list. - **Annual re-certification.** An organisation that fails to re-certify is removed. A removed organisation *"is no longer entitled to benefit from the Commission's adequacy decision."* The Department also keeps a public record of removed organisations. - **HR data.** To cover **human resources data** transferred in the employment context, the organisation must indicate this in its self-certification and commit to cooperate with the EU data protection authorities. A listing without that commitment does not cover employee data. ## The checklist for the startup | Check | Why it matters | |---|---| | The **exact legal entity** receiving the data is on the list | the parent's listing may not cover a sister company that actually runs the service | | The listing is **active**, not in the removed record | removal ends the adequacy benefit | | It covers the **data type** sent (non-HR, HR, or both) | HR data needs the separate commitment | | **Onward transfers** by that entity follow the Principles | adequacy protects the first hop; the entity's own obligations govern what it passes on | If a check fails, the transfer needs another route, usually the **2021 SCCs** under Art. 46(2)(c), with their Clause 14 assessment. ## Why it may not be permanent The DPF follows **Schrems II** (case C-311/18). In 2020 that judgment **invalidated** the previous framework, the EU-US Privacy Shield. The Court found that US law on public-authority access for national-security purposes was not limited in a way essentially equivalent to EU law, and that individuals lacked an effective remedy. The DPF decision rests on changes made since, notably **Executive Order 14086** and a **Data Protection Review Court** for redress. The Decision builds in monitoring: 1. The Commission **continuously monitors** the framework (Art. 3(1) of the Decision). 2. A first **review after one year**, then at a periodicity set with the Art. 93 committee and the EDPB (Art. 3(4)). 3. If protection is no longer adequate, the Commission may **suspend, amend, repeal or limit** the decision under Art. 45(5) GDPR (Art. 3(5)). A suspension would not have retroactive effect, and Arts. 46-49 would stay available (Art. 45(7) GDPR). But every DPF-based flow would then need another route. Many architects keep **SCCs in the contract as a fallback** so the switch is contractual rather than an emergency. ## Where this leaf stops Whether data in an EU region is ever reached from the US, and how residency and operator-access architecture limit that, is an architecture question owned elsewhere. The regime question here is narrower: when a US organisation *receives* the data, is it covered by the DPF, and if not, what replaces it?
- Under the EU-US Data Privacy Framework, what must a US organisation do with EU data after it withdraws or is removed?Under the Principles in the Decision's annex, it must either keep applying the Principles to data received under the DPF and affirm that annually, protect the data by another authorised means such as contracts reflecting the Commission's SCCs, or return or delete it. Persistent non-compliers must return or delete the data.
- Under the GDPR, does an adequacy decision remove every other obligation for the transfer?No. Art. 44 makes Chapter V apply subject to the other provisions of the Regulation. The startup still needs a lawful basis, an Art. 28 processor contract if the provider is a processor, security under Art. 32 and transparency under Art. 13(1)(f), which must mention the adequacy decision.
saying these in an interview costs you the question
- The DPF makes every US company an adequate destination.
- A US parent's listing automatically covers all of its subsidiaries.
- Once certified, a US organisation stays covered with no annual renewal.
- A DPF listing covers employee HR data with no extra commitment.
- Since the DPF, SCCs for US transfers are pointless and can be dropped.