Skip to main content

Explainers

The EU-US Data Privacy Framework, explained for vendor reviews

What a DPF listing proves, the usage end date, the UK and Swiss extensions, the pending Court of Justice appeal, and how to read a DPF row before you sign a DPA.

Solomon AmosPublished 7 Sep 2026Updated 18 Sep 202610 min read

The European Union flag against a blue sky
Photo by Christian Lue on Unsplash

The EU-US Data Privacy Framework (DPF) is the third transfer mechanism between the European Union and the United States, after Safe Harbor was invalidated in 2015 and Privacy Shield in 2020. The European Commission adopted its adequacy decision on 10 July 2023. For a vendor review it is the one transfer artefact you can verify without asking anyone: the participant list is public, every entry has a status, and every status has a date. This article explains what a listing proves, what it does not, and how to use the DPF row on a vendor page.

10 Jul 2023
EU adequacy decision
Commission Implementing Decision (EU) 2023/1795
4,673
DPF rows linked to vendors in the CertReports index
1,562 active, 3,111 past their usage end date, 18 September 2026
C-703/25 P
Appeal pending at the Court of Justice
Lodged 31 October 2025; no hearing date

What the DPF is

The DPF is a self-certification programme run by the US Department of Commerce. A US organisation commits publicly to the DPF Principles (notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, recourse and enforcement), names an independent recourse mechanism, and certifies annually. The Federal Trade Commission or the Department of Transportation enforces the commitment. The Commission’s adequacy decision then allows EU organisations to transfer personal data to listed participants without further safeguards.

The EU-U.S. Data Privacy Framework (DPF) Program enables participating organizations to self-certify their compliance with the DPF Principles.

What a listing proves, and what it does not

A listing proves that the organisation self-certified, paid the fee, named a recourse mechanism and is current on recertification. It is verified in the sense that a government registry publishes it, which is why CertReports records an active listing as verified by registry. It is not an audit of the organisation’s practices. The verification method field tells you whether the organisation self-assessed or engaged an outside compliance review, and the latter is the stronger of the two.

Field on the listWhat it meansWhat to check
StatusActive, Inactive or WithdrawnOnly Active supports transfers; Inactive organisations still owe obligations for data received while active
Certification frameworkEU-US DPF, UK Extension, Swiss-US DPFA vendor may be listed for the EU but not the UK extension
HR data and non-HR dataWhich categories the certification coversEmployee data transfers need the HR box
Verification methodSelf-assessment or outside compliance reviewOutside review is stronger
Usage end dateWhen the current certification lapses without recertificationCertReports uses it as the expiry of the row
Covered entitiesUS subsidiaries and affiliates covered by the parent’s certificationCheck the entity you contract with is listed
Recourse mechanismWhere an EU individual complainsNamed and reachable
A glass office tower against the sky
A listing names a legal entity. Group companies are covered only where the parent’s certification lists them. · Photo by Sean Pollock on Unsplash

Two thirds of DPF rows in the index are lapsed

The participant list includes every organisation that ever self-certified, with inactive and withdrawn entries kept for accountability. Of the DPF rows the CertReports index links to a vendor, 3,111 are past their usage end date without a visible recertification, against 1,562 active. That is why a DPF badge on a privacy page proves nothing on its own: the list decides, and it changes daily.

DPF rows linked to indexed vendors, by status
  • Past usage end date (expired)3,111
  • Active1,562

The UK and Swiss extensions

The UK Extension to the EU-US DPF (the "data bridge") took effect on 12 October 2023. The Swiss-US DPF took effect on 15 September 2024 when the Swiss Federal Council recognised it. Both are separate boxes on the same list. A vendor active for the EU-US DPF but not the UK extension cannot rely on the DPF for UK transfers; it needs the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses instead.

TransferMechanismWhat to look for on the list
EU to USEU-US DPFActive, EU-US framework ticked
UK to USUK ExtensionActive, UK Extension ticked; otherwise IDTA or UK Addendum
Switzerland to USSwiss-US DPFActive, Swiss framework ticked
Any of the above, fallbackStandard contractual clauses in the DPANot on the list; read the DPA

The adequacy decision was challenged almost immediately. On 3 September 2025 the General Court dismissed the action in Latombe v Commission (T-553/23). The applicant lodged an appeal with the Court of Justice on 31 October 2025 (C-703/25 P), and no hearing date had been set at the time of writing; commentators expect no judgment before late 2026 or 2027. Schrems II shows what happens when a mechanism falls: transfers do not stop, but the legal basis disappears overnight. The practical advice is unchanged since 2020: accept the DPF as the primary basis and keep the standard contractual clauses in the DPA as the fallback. The appeal article sets out the steps.

Latombe appealed the judgment to the Court of Justice on 31 October 2025 (Case C-703/25 P), raising four grounds of law.

How to use the DPF row on CertReports

  1. 1

    Check the state and the date

    A verified DPF row shows the status and the usage end date from the list. Expired means the usage end date passed without a recertification appearing.

  2. 2

    Check the extensions you need

    The row detail shows EU, UK and Swiss coverage separately.

  3. 3

    Read the DPA for SCCs

    The vendor page lists public legal documents. Look for the DPA and whether it incorporates the 2021 SCCs; see the GDPR and DPA hub.
  4. 4

    Note the entity

    The listed organisation must be the entity that receives your data, or a covered affiliate of it.

  5. 5

    Follow the vendor

    The usage end date arrives once a year. Following the vendor on CertReports sends an alert when the row expires or renews.

Code on a laptop screen in a dark room
CertReports mirrors the participant list daily by record id, so a lapse appears the day after the usage end date. · Photo by Ilya Pavlov on Unsplash

Vocabulary

CertReports never writes "GDPR certified". There is no GDPR certification in general use. A GDPR row records public artefacts, a DPA, SCCs, an EU representative, a DPF listing, each with a date and a source.

People also ask

Is the EU-US Data Privacy Framework still valid in 2026?

Yes. The General Court upheld the adequacy decision on 3 September 2025 and the decision remains in force while the appeal (C-703/25 P) is pending at the Court of Justice.

How do I check if a company is DPF certified?

Search the participant list at dataprivacyframework.gov or the CertReports DPF registry mirror. Check the status is Active, the frameworks ticked, the usage end date, and that the listed entity is the one you contract with.

What is the usage end date on the DPF list?

The date the current annual certification lapses unless the organisation recertifies. CertReports treats a row whose usage end date has passed without renewal as expired.

Does the DPF cover UK data?

Only where the organisation is also listed under the UK Extension. Without it, UK transfers need the IDTA or the UK Addendum to the standard contractual clauses.

Do I still need standard contractual clauses if a vendor is DPF listed?

They are not required for the transfer while the DPF stands, but keeping them in the DPA means the transfer keeps a legal basis if the adequacy decision is annulled, as happened with Privacy Shield in 2020.

What happens if the DPF is struck down?

Transfers would move to the standard contractual clauses and a transfer impact assessment overnight. Vendors with SCCs already in their DPA need nothing new; vendors relying on the DPF alone need an amended DPA.

DPFGDPRtransfersSCCsprivacy
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

You might also like