Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Laws and Regulations

EU-U.S. Data Privacy Framework

Also known as: EU-U.S. DPF, Data Privacy Framework, DPF
Simply put

The EU-U.S. Data Privacy Framework is a voluntary arrangement that lets participating U.S. organizations receive personal data transferred from the European Economic Area while committing to a set of privacy protections. It was created to make it easier for data to flow safely across the Atlantic and it replaced the earlier Privacy Shield program. U.S. companies must self-certify and adhere to the framework's privacy principles to rely on it.

Formal definition

The EU-U.S. Data Privacy Framework is a transatlantic data transfer mechanism established in the context of the GDPR to facilitate lawful transfers of personal data from the European Economic Area to certified U.S. organizations. It replaces the former Privacy Shield program and requires participating U.S. organizations to self-certify and adhere to a defined set of privacy principles; the framework entered into force on July 11, 2023. Participation is voluntary, and reliance on the framework as a transfer mechanism is generally available only to organizations that maintain an active certification and comply with the applicable principles. This entry addresses the framework's function as an EU-to-U.S. transfer mechanism; the separate UK Extension, the Swiss-U.S. component, enforcement details, and the framework's ongoing legal durability are outside the scope of this definition and are not covered by the evidence provided.

Why it matters

Transfers of personal data from the European Economic Area to the United States sit at the center of a long-running compliance challenge. Under the GDPR, personal data may generally only be transferred outside the EEA where an appropriate safeguard or transfer mechanism applies. The EU-U.S. Data Privacy Framework, which entered into force on July 11, 2023, provides one such mechanism, allowing participating U.S. organizations that self-certify and adhere to its privacy principles to receive EEA personal data. For businesses operating across the Atlantic, this matters because it offers a route to lawful data flows without relying solely on other mechanisms such as standard contractual clauses.

The framework replaced the earlier Privacy Shield program, and its arrival was intended to restore a more predictable basis for transatlantic commerce that depends on the movement of personal data. In the cookie and tracking context, this is relevant because analytics providers, advertising platforms, and other vendors that process personal data collected through cookies and similar technologies are frequently based in the United States. Where such processing involves transferring EEA personal data to a U.S. vendor, the availability of a certified transfer mechanism can be a material factor in a controller's compliance assessment.

It is important to keep the framework's scope in perspective. Reliance on it is generally available only to organizations that maintain an active certification and comply with the applicable principles, so a vendor's participation cannot be assumed. The framework's ongoing legal durability, enforcement practices, and the separate UK and Swiss components are outside the scope of this entry and are not addressed by the evidence here. Organizations should treat the framework as one option to evaluate rather than a settled guarantee, and should confirm a given vendor's certification status independently.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for assessing international data transfers need to determine whether the EU-U.S. Data Privacy Framework is an appropriate mechanism for a given transfer of EEA personal data to the United States. This includes verifying whether a specific U.S. vendor maintains an active certification, rather than assuming participation, and considering the framework alongside other transfer mechanisms as part of a broader compliance judgment.
Legal counsel and compliance teams
Advisers evaluating the lawful basis for transatlantic data flows should understand that the framework replaced the earlier Privacy Shield program and entered into force on July 11, 2023. Counsel may need to weigh reliance on the framework against alternatives, and to note that its ongoing legal durability and enforcement details are matters beyond the scope of this definition that warrant separate assessment.
Marketing compliance teams and vendor managers
Teams that engage U.S.-based analytics, advertising, and tracking vendors that process personal data collected through cookies and similar technologies should consider whether those vendors are certified under the framework as part of due diligence. Certification status is not permanent and depends on the vendor maintaining compliance, so it should be confirmed rather than presumed.
Web developers and technical implementers
Those integrating third-party scripts, pixels, SDKs, and analytics tools from U.S. providers benefit from understanding that the movement of EEA personal data to these providers can implicate international transfer rules. While technical staff do not make the legal determination, awareness of the framework helps them collaborate with privacy and legal colleagues on vendor selection and data flow mapping.

Inside EU-U.S. DPF

Adequacy-based transfer mechanism
The EU-U.S. Data Privacy Framework (DPF) provides a lawful basis for transferring personal data from the EU to participating organizations in the United States, based on an adequacy decision adopted by the European Commission. It addresses the cross-border transfer requirements under Chapter V of the GDPR rather than the placing of cookies itself.
Self-certification for U.S. organizations
U.S.-based organizations may participate by self-certifying their adherence to a set of privacy principles and publicly committing to them. Certification is administered on the U.S. side and must generally be maintained and re-affirmed to remain valid; lapses can affect the availability of the mechanism for continued transfers.
Privacy principles and obligations
Participating organizations commit to principles covering areas such as notice, choice, onward transfer, security, data integrity, access, and accountability. These commitments are enforceable against the certified organization.
Redress and oversight components
The Framework includes redress avenues intended to give EU individuals mechanisms to raise complaints, alongside oversight arrangements addressing government access to data. The precise scope and effectiveness of these mechanisms have been the subject of ongoing legal and regulatory attention.
Relationship to cookie and tracking data
Where cookies, pixels, SDKs, or similar technologies result in personal data being transferred to a certified U.S. organization, the DPF may serve as the transfer mechanism for that data. It does not, however, provide a legal basis for setting cookies or for the underlying processing, which remain governed by the ePrivacy rules and the GDPR respectively.
UK and Swiss extensions
Separate but related arrangements extend comparable transfer mechanisms for personal data originating in the UK and Switzerland. These operate under their own respective legal determinations and should not be assumed to be identical in scope to the EU decision.

Common questions

Answers to the questions practitioners most commonly ask about EU-U.S. DPF.

Does certifying under the EU-U.S. Data Privacy Framework mean my cookie consent obligations are satisfied?
No. The Data Privacy Framework addresses the lawfulness of transferring personal data from the EU to certified organizations in the United States; it is a transfer mechanism under the GDPR. It does not address whether you may place or access cookies and similar technologies on a user's device, which is governed separately by the ePrivacy Directive and its national implementations, nor does it substitute for obtaining valid consent for non-essential cookies where that is required. You generally still need an appropriate consent or exemption for the cookies themselves, and a lawful basis for any subsequent processing, in addition to a valid transfer mechanism.
Is the Data Privacy Framework a global solution that covers all my international data flows?
No. The framework is specific to transfers of personal data from the EU (and, through related arrangements, from the UK and Switzerland) to organizations in the United States that have self-certified. It does not govern transfers to other countries, and the UK and Swiss components operate as distinct extensions rather than a single worldwide regime. For flows to other jurisdictions you would generally need to consider other transfer tools, and the availability and status of these arrangements can change following legal challenges or regulatory review, so scope should be confirmed against current guidance.
How do I confirm whether a U.S. vendor is actually covered by the Data Privacy Framework?
Certification is organization-specific and self-declared, so you should verify that the particular entity you are transferring data to is listed as active under the framework and that the certification covers the relevant category of data (for example, HR versus non-HR data). Confirm the certification is current rather than lapsed or withdrawn. Beyond checking the listing, most organizations also carry out their own due diligence and reflect the arrangement in contractual terms, because reliance on a vendor's certification is a factual matter that you may need to document.
If a vendor is certified, do I still need a data processing agreement or other contractual terms?
Generally yes. A transfer mechanism such as the framework addresses the international transfer, but it does not remove the GDPR's broader requirements governing controller-processor relationships and the allocation of responsibilities. In most cases you would still put appropriate contractual terms in place covering matters such as processing instructions, security, and onward transfers. The framework and your contracts serve different functions and are typically used together rather than as alternatives.
How should the Data Privacy Framework be reflected in my privacy notice or cookie disclosures?
Where you rely on the framework for transfers to a certified recipient, it is common practice to identify the transfer mechanism in your privacy information so that users are informed about how their data is transferred and safeguarded. This is separate from the consent-focused information you provide about cookies and similar technologies. The precise disclosure expectations can differ between EU jurisdictions and under UK guidance, so the wording should be reviewed against applicable requirements rather than copied generically.
What happens to my transfers if the framework is challenged or invalidated?
The framework's status can be affected by legal challenges and regulatory review, as adequacy-based arrangements have been before. Because of this, many organizations maintain contingency planning, such as being prepared to fall back on alternative transfer tools, and monitor developments rather than treating the arrangement as permanent. This entry does not predict the outcome of any specific challenge; whether and how to prepare fallback measures is a matter for legal judgment based on current guidance and your particular data flows.

Common misconceptions

If an organization is DPF-certified, it can lawfully set analytics and advertising cookies on EU users' devices.
The DPF concerns the lawfulness of transferring personal data to the U.S.; it is a transfer mechanism, not a consent mechanism. The placing of non-essential cookies still generally requires prior consent under the ePrivacy rules as implemented in EU member states, and the associated processing still requires a valid GDPR legal basis. Certification does not substitute for either.
The Data Privacy Framework guarantees that any transatlantic transfer of tracking data is beyond legal challenge.
The Framework rests on an adequacy decision and related arrangements whose durability has been questioned in past legal proceedings involving predecessor mechanisms. Practitioners should treat its continued availability as something to monitor rather than as a permanent guarantee, and consider that regulatory and judicial positions may evolve.
Any U.S. company can automatically rely on the DPF.
Only organizations that have actively self-certified, and that maintain their certification and public commitments, fall within the Framework. Reliance on the DPF for a given data importer should be verified rather than assumed, and it applies to organizations that are eligible to certify under the applicable U.S. administration of the program.

Best practices

Verify that a specific U.S. data importer is actively and currently self-certified under the DPF before relying on it as a transfer mechanism, and re-check periodically since certification status can lapse.
Treat the DPF strictly as a transfer mechanism: continue to obtain valid prior consent for non-essential cookies and similar technologies where required under national ePrivacy rules, and maintain a separate, appropriate GDPR legal basis for the underlying processing.
Map which cookies, pixels, SDKs, and other technologies actually result in personal data flowing to U.S. recipients, so you know where a transfer mechanism such as the DPF is engaged and where it is not.
Confirm which arrangement applies to each data flow, since transfers originating in the UK or Switzerland rely on their own respective extensions rather than the EU decision.
Monitor guidance from data protection authorities and any legal developments affecting the Framework's status, and maintain a fallback transfer approach in case its availability changes.
Document your reliance on the DPF, including the certification checks performed, as part of your broader records of transfer safeguards and consent decisions.
Application Security Isn’t Optional Anymore.