The European Commission adopted the EU-U.S. Data Privacy Framework on July 10, 2023. This framework requires U.S. companies to self-certify before they can lawfully receive EU personal data. Unlike typical adequacy decisions that automatically apply to all businesses in a country, this framework demands active participation. If you're handling EU data subjects' personal data, you need a systematic approach to certification.
Purpose of the Checklist
This checklist guides U.S. companies through the self-certification process under the EU-U.S. Data Privacy Framework. It covers initial certification for companies new to the framework and re-certification for former Privacy Shield participants. The checklist ensures you've addressed each technical and policy requirement before submitting your certification through the official DPF website.
Use this checklist when:
- Your company processes EU personal data and needs a lawful transfer mechanism under GDPR Chapter 5
- You're transitioning from Privacy Shield to the new framework
- You're establishing your first cross-border data transfer program with EU partners
- You need to document your compliance posture for internal audit or external verification
Prerequisites
Before starting this checklist, confirm:
Organizational Readiness
- Identify all systems and processes that handle EU personal data
- Secure executive sponsorship for framework participation
- Commit to annual re-certification
- Allocate budget for independent recourse mechanisms (typically required for consumer-facing data processing)
Technical Prerequisites
- Access your Privacy Policy and data processing documentation
- Authority to update public-facing privacy disclosures
- Administrative access to the DPF website (dataprivacyframework.gov)
- Document your data flows from EU to U.S. systems
Legal Basis Confirmation
- Verify that the DPF is appropriate for your data transfers (it's one mechanism under GDPR Chapter 5, not the only option)
- Understand that non-participating companies must use Standard Contractual Clauses, Binding Corporate Rules, or another lawful transfer mechanism
- Prepare to adhere to the Framework Principles, which differ from Privacy Shield requirements
The Checklist
Phase 1: Pre-Certification Audit
☐ Map Your EU Data Flows
Document every system, vendor, and process that receives EU personal data. Include data categories processed, purposes of processing, retention periods, and onward transfer recipients.
☐ Review Framework Principles Against Current Practices
Compare your existing data handling to the DPF Principles. Flag gaps in notice requirements, choice mechanisms, accountability for onward transfers, security measures, data integrity practices, access procedures, recourse mechanisms, and enforcement.
☐ Select and Contract with Independent Recourse Mechanism
If you process consumer data, identify an approved dispute resolution provider. Verify they're listed on the DPF website. Establish your agreement before certification.
☐ Update Internal Policies
Revise data protection policies, vendor agreements, and employee training materials to reflect Framework commitments. Document how you'll handle data subject access requests, complaints, and withdrawal of consent under the Principles.
Phase 2: Privacy Policy Updates
☐ Draft Framework-Specific Disclosure Language
Your Privacy Policy must state your participation in the EU-U.S. Data Privacy Framework. Include commitment to the Principles, independent recourse mechanism details, Federal Trade Commission enforcement jurisdiction, and contact information for Framework-related inquiries.
☐ Remove Outdated Privacy Shield References
If you're transitioning from Privacy Shield, replace all mentions with DPF language. Former Privacy Shield participants must complete this update by Oct. 10, 2023.
☐ Add UK and Swiss Extensions (if applicable)
If you plan to certify for the UK Extension or Swiss-U.S. DPF, include separate statements for each. Note: you can't rely on these extensions until those countries issue their own adequacy decisions.
☐ Publish Updated Privacy Policy
Make the updated policy live on your website before submitting certification. The DPF program will verify your public commitments during review.
Phase 3: Self-Certification Submission
☐ Create Account on dataprivacyframework.gov
Register your organization. You'll need the legal entity name, primary business address, contact details for your privacy officer or compliance lead, and EIN or other tax identifier.
☐ Complete Certification Questionnaire
Answer all questions about your data processing activities, types of personal data handled, and adherence to each Framework Principle. Be specific, vague answers delay approval.
☐ Upload Supporting Documentation
Provide your current Privacy Policy, independent recourse mechanism agreement, organizational chart showing privacy governance, and description of security measures.
☐ Pay Certification Fee
Budget for the annual fee, which varies by organization size and revenue. Former Privacy Shield participants should verify their fee tier hasn't changed.
☐ Submit for Review
The Department of Commerce reviews submissions for completeness and consistency with the Principles. Expect follow-up questions if your documentation is unclear.
Phase 4: Post-Certification Compliance
☐ Monitor for Framework Updates
Subscribe to DPF program announcements. The Principles may evolve based on EDPB guidance or enforcement actions.
☐ Establish Annual Re-Certification Calendar
Set a reminder 60 days before your re-certification date. Former Privacy Shield participants re-certify according to their previous schedule; new participants re-certify one year from approval.
☐ Document Ongoing Compliance
Maintain records of Framework-related complaints and resolutions, changes to data processing activities, vendor due diligence for onward transfers, and internal audits of Principle adherence.
☐ Update Certification if Business Changes
Material changes to your data processing, corporate structure, or Privacy Policy require an amended certification. Don't wait until annual re-certification if your practices diverge from your submission.
Customization Options
For Former Privacy Shield Participants:
You were automatically enrolled in the DPF on July 17, 2023. Skip Phase 3 (you're already certified) but complete Phases 1, 2, and 4 immediately. Your Oct. 10, 2023 deadline for Privacy Policy updates is firm.
For Companies with Limited EU Data Processing:
If you handle only employee data or business contact information, you may not need an independent recourse mechanism. Clarify this during Phase 1 by reviewing the Principles' applicability to your data categories.
For Companies Planning UK or Swiss Certification:
Complete the EU-U.S. DPF certification first. Add UK Extension and Swiss-U.S. DPF certifications once those adequacy decisions are announced. You'll use the same DPF website to register additional commitments.
For Multi-Entity Organizations:
Each legal entity processing EU data must self-certify separately. If you have subsidiaries or affiliates handling EU personal data, they need individual certifications even if they follow group-wide policies.
Validation Steps
Before Submitting Certification:
- Confirm your Privacy Policy is live and includes all required DPF language
- Verify your independent recourse mechanism agreement is signed and the provider is DPF-approved
- Test that your documented data flows match what you've described in the certification questionnaire
- Review your submission with legal counsel familiar with GDPR Chapter 5 transfer mechanisms
After Certification Approval:
- Search the DPF List on dataprivacyframework.gov to confirm your organization appears
- Notify EU data transfer partners that you're now certified (provide your DPF List entry as proof)
- Update vendor contracts to reference your DPF certification as the lawful transfer mechanism
- Brief your privacy team on Framework-specific complaint handling procedures
Ongoing Validation:
- Quarterly: Review new data processing activities for Framework implications
- Semi-annually: Audit vendor onward transfers for continued DPF participation or adequate safeguards
- Annually: Complete full compliance review before re-certification deadline
- As needed: Monitor EDPB guidance on adequacy decisions for signals that the DPF may face legal challenge (previous frameworks were invalidated; defensible records matter)
The qualified nature of this adequacy decision means your certification status directly affects the lawfulness of your EU data transfers. Treat this checklist as a living document, update it when the Principles change, when your business evolves, or when enforcement guidance clarifies expectations.





