Skip to content

Glossary EU-US Data Privacy Framework

What is the EU-US Data Privacy Framework?

Definition

The EU-US Data Privacy Framework is the adequacy decision through which the European Commission recognizes that the United States offers a level of data protection comparable to the EU's, allowing personal data transfers to certified US companies without additional contractual safeguards.

On this page 5
  1. What the EU-US Data Privacy Framework means
  2. How it works
  3. Why it matters
  4. Buenas prácticas
  5. Errores frecuentes
In brief

It is the adequacy decision that allows personal data to move from the EU to certified US companies without additional safeguards.

What the EU-US Data Privacy Framework means

The EU-US Data Privacy Framework is an adequacy decision the European Commission adopted on 10 July 2023, under Article 45(3) of the GDPR. With it, the Commission declares that the United States offers, for companies that join the framework, a level of personal data protection that is essentially equivalent to that of the European Union. The decision covers any US company that completes the self-certification process described below, regardless of its sector.

That declaration has a direct practical effect. When a European company transfers data to a certified US organization under the framework, it needs no additional safeguard and does not need prior authorization from its data protection authority. Neither Standard Contractual Clauses (SCC) nor a transfer impact assessment are required, because the Commission's decision already covers the transfer as if the recipient were located within the European Union.

SCC remain in place as an alternative mechanism, used to transfer data to providers that are not certified under the framework, or to third countries without their own adequacy decision. The difference lies in origin: the adequacy decision comes from the Commission and covers an entire country for a specific purpose, while SCC are a contract between the two parties transferring the data, with obligations each company must negotiate and document on its own. The framework does not replace SCC, it gives a simpler alternative for data traffic with the United States.

How it works

The mechanism relies on a public register, the Data Privacy Framework List, maintained by the US Department of Commerce. A US company that wants to receive personal data from the EU under this framework must self-certify with the Department of Commerce, committing in writing to a set of data protection principles: clear notice about the processing, choice for the data subject, purpose limitation and data minimization, security and data integrity, access and rectification rights, and complaint and accountability mechanisms for European citizens.

Once self-certification is complete, the company appears on the public list, together with the date it joined and the specific scope of data it covers. From that point, any EU company can transfer it personal data by relying directly on the Commission's adequacy decision, without needing to sign SCC or justify the transfer case by case before any authority.

The critical point is verification: certification is a self-declaration by the US company, not a prior audit by a European body. Oversight happens afterward, through the US Federal Trade Commission (FTC), which can sanction companies that fail to meet their stated commitments, and through the complaint mechanisms built into the framework itself, including an independent review court, the Data Protection Review Court, for cases involving access by intelligence services.

For a European company, the practical check before sending data to a US provider is simple: look up whether that specific provider, under that exact legal name, is listed as active on the Data Privacy Framework List. Being certified for one type of data does not mean being certified for all of them: the list specifies the scope of each certification, and it is worth keeping a dated screenshot or note of that check to be able to demonstrate it later.

Why it matters

A very concrete decision depends on this framework for anyone running a website or online store in Europe: whether tools like GA4, Google Ads or the Meta Pixel can be used without additional safeguards, because the data they collect travels to servers in the United States for processing.

That question has already been answered twice before, and both times the answer changed. The Court of Justice of the EU struck down the Safe Harbor agreement in 2015 (the Schrems I ruling) and its successor, the Privacy Shield, in 2020 (the Schrems II ruling, Case C-311/18), in both cases over US authorities' access to the data without safeguards equivalent to the European ones. The Data Privacy Framework is the third attempt, designed specifically to fix the problems the Court identified regarding US intelligence services' access to European data.

That history is why the current framework has already gone through its own judicial review. The General Court of the European Union, in a ruling of 3 September 2025 (Case T-553/23, Latombe v Commission), fully dismissed the action brought against the adequacy decision and confirmed that the level of protection in the United States is essentially equivalent to the European one. The ruling is a first-instance decision and can still be appealed, so the framework remains, by design, subject to review, and anyone relying on it to run analytics or advertising tools does well to keep following how it develops.

Buenas prácticas

  • Check whether each tool's provider (Google, Meta, HubSpot, etc.) is listed as active on the Data Privacy Framework List, under the exact legal name of the entity receiving the data.
  • Review the scope of that provider's certification: it covers specific data types, not automatically every product the company offers.
  • Document in the record of processing activities which transfers rely on the framework and which still need SCC.
  • Monitor whether the provider keeps its certification active: removal from the list is not always communicated clearly to customers.
  • Keep an alternative (SCC) ready for tools or providers that are not certified under the framework.
  • Follow the Court of Justice of the EU's case law on the framework, since an appeal against the September 2025 ruling could change the situation.

Errores frecuentes

  • Assuming every US company is covered by the framework: only those that have self-certified and remain active on the list are.
  • Confusing the framework with a technical security certification: it is a legal compliance commitment, not a cybersecurity audit.
  • Treating the current framework as final because its two predecessors, Safe Harbor and Privacy Shield, were struck down by the Court of Justice of the EU.
  • Forgetting that certification has a limited scope by data type and does not automatically cover every service from the same provider.
  • Not recording the date a certification was checked: the list changes, and a check from a year ago is no proof of the current status.
Manuel Riveiro Rodriguez CEO & Digital Strategist

A technical audit covers this and everything else in one pass.

Request an audit

Frequently asked

Does the EU-US Data Privacy Framework replace the GDPR?

No. The GDPR is the European regulation that governs data protection in general and applies across the whole Union. The Data Privacy Framework is an adequacy decision issued under Article 45 of the GDPR, which facilitates one specific type of international transfer: from the EU to the United States.

What happens if a provider is not on the Data Privacy Framework List?

Then the transfer cannot rely on this adequacy decision. Another mechanism is needed, usually Standard Contractual Clauses (SCC), together with a transfer impact assessment if the provider receives personal data from European users. It is worth recording in writing which mechanism was applied and when.

Could the framework be struck down again, like Safe Harbor and Privacy Shield?

It is possible. The General Court of the EU confirmed the framework on 3 September 2025 (Case T-553/23), but the ruling is a first-instance decision and can be appealed. Both earlier mechanisms were also considered settled for years before falling, so the situation is worth continuing to watch.

Do GA4 and Google Ads need anything beyond the framework?

It depends on the specific provider and the type of data processed. If Google keeps the certification active for that product, the transfer relies on the framework. Worth checking in each tool's privacy settings and in the provider's published data processing policy.

Who checks that US companies meet what they certify?

The US Federal Trade Commission (FTC), which can sanction violations of the self-certification with fines or compliance orders. The framework also adds complaint mechanisms for European citizens, including an independent review court for cases involving access by intelligence services, whose decisions are binding on the US authorities involved.