International data transfers after the EU-US Data Privacy Framework
How EU-to-US data transfers work under the Data Privacy Framework, what EU exporters should actually do, and why keeping your transfer safeguards in place is still the prudent call.
By Magdalena Goralczyk·Data Protection Partner, White Label Consultancy
Transferring personal data from the EU to the United States has been one of the most unsettled questions in data protection for a decade. The EU-US Data Privacy Framework (DPF) brought welcome certainty, but it did not make transfer governance go away. This guide explains how transfers work under the DPF and what a careful EU exporter should do, written to stay useful even if the legal ground shifts again.
The rules behind transfers, briefly
Under the GDPR, you may only send personal data outside the EU and EEA if the destination offers an essentially equivalent level of protection. That can come from three places: an adequacy decision by the European Commission, appropriate safeguards such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), or a narrow derogation for specific situations.
For transfers to the US, adequacy has had a turbulent history. The Commission's earlier Safe Harbor (2000) and Privacy Shield (2016) frameworks were both invalidated by the Court of Justice, in the Schrems and Schrems II judgments, because US surveillance law was found to undercut the protection EU data was supposed to enjoy. After Schrems II in 2020, US transfers had to lean on SCCs or BCRs, each requiring a case-by-case transfer impact assessment.
What the DPF changed
Following new US commitments, including limits on intelligence access and a redress mechanism for EU individuals, the Commission adopted an adequacy decision for the EU-US Data Privacy Framework. In practice that means personal data can flow to a US organisation without additional safeguards, provided that organisation has self-certified to the DPF and appears on the official DPF list.
This is a narrower adequacy than usual: it does not cover the whole country, only the self-certified organisations. So the exporter's job shifts from "negotiate SCCs with every US recipient" to "check whether this recipient is actually on the list."
What an EU exporter should do
The workflow is simple once your records are in order:
- Identify the transfer. Know which processing activities send personal data to the US, and to which recipients. This is just your records of processing and your supplier register doing their job.
- Check the DPF list. If the recipient is self-certified and listed, you can rely on the adequacy decision. Enter into a data processing agreement and carry out your normal third-party due diligence.
- If they are not listed, treat the transfer as you would have before the DPF: SCCs, a transfer impact assessment, and technical and organisational supplementary measures such as encryption and access controls.
Why you should keep your safeguards anyway
It is unusual to plan for a law being struck down, but the history here is specific: two materially similar frameworks were invalidated within a few years of each other, and the DPF is already being tested. The pragmatic response is not to dismantle what you built after Schrems II.
Concretely, that means: keep your processing and transfer mapping current, keep your supplier and contract register organised, keep documenting the safeguards that reduce risk regardless of the legal basis, and where practical keep SCCs attached to your data processing agreements as a high-assurance backstop. Teams that kept good records found re-papering transfers straightforward; teams with incomplete records found it painful. If the framework is ever annulled, the difference between those two states is weeks of scramble.
The takeaway
The DPF made the common case easier: listed US recipients, free flow, light touch. It did not remove the need for transfer governance, and it did not make records optional. The organisations in the best position are the ones treating the DPF as one more tool in a maintained transfer programme, not as a reason to stop maintaining it.
Keep transfers, supplier vetting, and transfer impact assessments on one record in the Pritect data protection suite.
