EU-U.S. Data Privacy Framework
The EU-U.S. Data Privacy Framework is a voluntary arrangement that lets participating U.S. organizations receive personal data transferred from the European Economic Area while committing to a set of privacy protections. It was created to make it easier for data to flow safely across the Atlantic and it replaced the earlier Privacy Shield program. U.S. companies must self-certify and adhere to the framework's privacy principles to rely on it.
The EU-U.S. Data Privacy Framework is a transatlantic data transfer mechanism established in the context of the GDPR to facilitate lawful transfers of personal data from the European Economic Area to certified U.S. organizations. It replaces the former Privacy Shield program and requires participating U.S. organizations to self-certify and adhere to a defined set of privacy principles; the framework entered into force on July 11, 2023. Participation is voluntary, and reliance on the framework as a transfer mechanism is generally available only to organizations that maintain an active certification and comply with the applicable principles. This entry addresses the framework's function as an EU-to-U.S. transfer mechanism; the separate UK Extension, the Swiss-U.S. component, enforcement details, and the framework's ongoing legal durability are outside the scope of this definition and are not covered by the evidence provided.
Why it matters
Transfers of personal data from the European Economic Area to the United States sit at the center of a long-running compliance challenge. Under the GDPR, personal data may generally only be transferred outside the EEA where an appropriate safeguard or transfer mechanism applies. The EU-U.S. Data Privacy Framework, which entered into force on July 11, 2023, provides one such mechanism, allowing participating U.S. organizations that self-certify and adhere to its privacy principles to receive EEA personal data. For businesses operating across the Atlantic, this matters because it offers a route to lawful data flows without relying solely on other mechanisms such as standard contractual clauses.
The framework replaced the earlier Privacy Shield program, and its arrival was intended to restore a more predictable basis for transatlantic commerce that depends on the movement of personal data. In the cookie and tracking context, this is relevant because analytics providers, advertising platforms, and other vendors that process personal data collected through cookies and similar technologies are frequently based in the United States. Where such processing involves transferring EEA personal data to a U.S. vendor, the availability of a certified transfer mechanism can be a material factor in a controller's compliance assessment.
It is important to keep the framework's scope in perspective. Reliance on it is generally available only to organizations that maintain an active certification and comply with the applicable principles, so a vendor's participation cannot be assumed. The framework's ongoing legal durability, enforcement practices, and the separate UK and Swiss components are outside the scope of this entry and are not addressed by the evidence here. Organizations should treat the framework as one option to evaluate rather than a settled guarantee, and should confirm a given vendor's certification status independently.
Who it's relevant to
Inside EU-U.S. DPF
Common questions
Answers to the questions practitioners most commonly ask about EU-U.S. DPF.

