What the EU-US Data Privacy Framework means
The EU-US Data Privacy Framework is an adequacy decision the European Commission adopted on 10 July 2023, under Article 45(3) of the GDPR. With it, the Commission declares that the United States offers, for companies that join the framework, a level of personal data protection that is essentially equivalent to that of the European Union. The decision covers any US company that completes the self-certification process described below, regardless of its sector.
That declaration has a direct practical effect. When a European company transfers data to a certified US organization under the framework, it needs no additional safeguard and does not need prior authorization from its data protection authority. Neither Standard Contractual Clauses (SCC) nor a transfer impact assessment are required, because the Commission's decision already covers the transfer as if the recipient were located within the European Union.
SCC remain in place as an alternative mechanism, used to transfer data to providers that are not certified under the framework, or to third countries without their own adequacy decision. The difference lies in origin: the adequacy decision comes from the Commission and covers an entire country for a specific purpose, while SCC are a contract between the two parties transferring the data, with obligations each company must negotiate and document on its own. The framework does not replace SCC, it gives a simpler alternative for data traffic with the United States.