The EU-US Data Privacy Framework has been the primary transfer mechanism for US vendors since the Commission’s adequacy decision of 10 July 2023. It was challenged almost immediately. On 3 September 2025 the General Court dismissed the action in Latombe v Commission, and on 31 October 2025 the applicant lodged an appeal with the Court of Justice as Case C-703/25 P. Until that appeal is decided, every vendor review that relies on a DPF listing carries a known legal risk with a known history: Safe Harbor fell in 2015 and Privacy Shield in 2020. This is what to do about it now, in the order that costs least.
- 10 Jul 2023
- Adequacy decision
- Commission Implementing Decision (EU) 2023/1795
- 3 Sep 2025
- General Court judgment
- Case T-553/23, action dismissed
- 31 Oct 2025
- Appeal lodged
- Case C-703/25 P; no hearing date at the time of writing
Where the case stands
The General Court rejected all of the applicant’s pleas, including the arguments about the Data Protection Review Court and bulk collection safeguards, and confirmed the adequacy decision. The appeal raises four grounds of law. Commentators expect no judgment before late 2026 or 2027, and the Court of Justice’s record in Schrems I and II, both of which annulled Commission decisions, is why the risk is taken seriously even after a first-instance win.
Latombe appealed the judgment to the Court of Justice on 31 October 2025 (Case C-703/25 P), raising four grounds of law. As of this writing, no hearing date has been scheduled.
| Date | Event | Effect on transfers |
|---|---|---|
| 6 October 2015 | Schrems I annuls Safe Harbor | Immediate loss of legal basis; move to SCCs |
| 16 July 2020 | Schrems II annuls Privacy Shield | Immediate loss of legal basis; SCCs plus transfer impact assessments |
| 10 July 2023 | DPF adequacy decision adopted | Transfers to listed participants without further safeguards |
| 3 September 2025 | General Court dismisses Latombe (T-553/23) | DPF confirmed at first instance |
| 31 October 2025 | Appeal lodged (C-703/25 P) | DPF remains in force pending judgment |
What the DPF proves today
An active DPF listing is a verifiable, dated fact: the organisation self-certified to the Department of Commerce, named a recourse mechanism and is current on recertification. CertReports mirrors the participant list daily and records the status, the usage end date and the EU, UK and Swiss coverage on the vendor page. The DPF explainer covers each field; in the index, 1,562 linked listings are active and 3,111 are past their usage end date.
What to do while the appeal runs
- 1
Accept the DPF as the primary basis, and keep the SCCs
Check that the vendor’s DPA incorporates the 2021 standard contractual clauses as a fallback. If the DPF falls, the SCCs carry the transfer the next morning without a new signature.
- 2
Confirm the listed entity
The listed organisation must be the entity that receives your data or a covered affiliate of it. Group listings are common; a mismatch is a finding.
- 3
Check the UK and Swiss boxes separately
UK data needs the UK Extension, the IDTA or the UK Addendum. A vendor active for the EU only cannot rely on the DPF for UK transfers.
- 4
Watch the usage end date
Certifications lapse annually. CertReports marks a row expired when the date passes without recertification; follow the vendor to get the alert.
- 5
Keep a transfer impact assessment on file
The SCCs require one anyway, and it is the document you will be asked for if the mechanism changes.
- 6
Build the exposure list now
Put your US vendors side by side on Compare and note which have SCCs in the DPA and which rely on the DPF alone.
What a fall would change
If the Court of Justice annuls the decision, transfers would not stop; the legal basis would move to the SCCs and the accompanying assessments overnight, as in 2020. Vendors that already carry SCCs in their DPA need nothing new from you. Vendors that rely on the DPF alone would need an amended DPA, and that is the list worth building now. Supervisory authorities in 2020 gave no grace period, and there is no reason to expect one.
| Vendor position | Risk if the DPF is annulled | Action now |
|---|---|---|
| Active DPF and SCCs in the DPA | Low | None beyond monitoring |
| Active DPF, no SCCs | High | Request a DPA amendment |
| Inactive or lapsed DPF, SCCs in the DPA | Medium | Rely on SCCs; note the lapse |
| No DPF, no SCCs | Transfers unsupported today | Escalate |
Signals to watch
- A hearing date at the Court of Justice, then an Advocate General opinion some months before judgment.
- Any change to the US executive order underpinning the DPF safeguards, which the appeal grounds reference.
- Enforcement activity by the FTC under the DPF, which supports the adequacy finding.
- Your vendors’ usage end dates, which arrive regardless of the case.
Vocabulary
People also ask
Is the EU-US Data Privacy Framework still valid?
Yes. The General Court upheld the adequacy decision on 3 September 2025 and it remains in force while the appeal in Case C-703/25 P is pending at the Court of Justice.
When will the Court of Justice rule on the DPF appeal?
No hearing date had been set at the time of writing. Commentators expect a judgment no earlier than late 2026 or 2027.
What happens to data transfers if the DPF is struck down?
Transfers would move to the standard contractual clauses with transfer impact assessments, as after Privacy Shield in 2020. Vendors with SCCs in their DPA need nothing new; vendors relying on the DPF alone need an amended DPA.
Should I still rely on the DPF for new vendors?
Yes, as the primary basis, provided the DPA also incorporates the SCCs. That combination has carried transfers through both previous annulments.
Does the appeal affect the UK Extension?
The UK data bridge is a UK decision and is not before the Court of Justice, but it depends on the underlying US framework. Treat it with the same fallback: the IDTA or UK Addendum.
How do I know if a vendor’s DPF listing has lapsed?
Check the usage end date on the participant list or the CertReports DPF row; the index marks a row expired the day after the date passes without recertification, and following the vendor sends an alert.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read