The EU-US Data Privacy Framework (DPF) is the third transfer mechanism between the European Union and the United States, after Safe Harbor was invalidated in 2015 and Privacy Shield in 2020. The European Commission adopted its adequacy decision on 10 July 2023. For a vendor review it is the one transfer artefact you can verify without asking anyone: the participant list is public, every entry has a status, and every status has a date. This article explains what a listing proves, what it does not, and how to use the DPF row on a vendor page.
- 10 Jul 2023
- EU adequacy decision
- Commission Implementing Decision (EU) 2023/1795
- 4,673
- DPF rows linked to vendors in the CertReports index
- 1,562 active, 3,111 past their usage end date, 18 September 2026
- C-703/25 P
- Appeal pending at the Court of Justice
- Lodged 31 October 2025; no hearing date
What the DPF is
The DPF is a self-certification programme run by the US Department of Commerce. A US organisation commits publicly to the DPF Principles (notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, recourse and enforcement), names an independent recourse mechanism, and certifies annually. The Federal Trade Commission or the Department of Transportation enforces the commitment. The Commission’s adequacy decision then allows EU organisations to transfer personal data to listed participants without further safeguards.
The EU-U.S. Data Privacy Framework (DPF) Program enables participating organizations to self-certify their compliance with the DPF Principles.
What a listing proves, and what it does not
A listing proves that the organisation self-certified, paid the fee, named a recourse mechanism and is current on recertification. It is verified in the sense that a government registry publishes it, which is why CertReports records an active listing as verified by registry. It is not an audit of the organisation’s practices. The verification method field tells you whether the organisation self-assessed or engaged an outside compliance review, and the latter is the stronger of the two.
| Field on the list | What it means | What to check |
|---|---|---|
| Status | Active, Inactive or Withdrawn | Only Active supports transfers; Inactive organisations still owe obligations for data received while active |
| Certification framework | EU-US DPF, UK Extension, Swiss-US DPF | A vendor may be listed for the EU but not the UK extension |
| HR data and non-HR data | Which categories the certification covers | Employee data transfers need the HR box |
| Verification method | Self-assessment or outside compliance review | Outside review is stronger |
| Usage end date | When the current certification lapses without recertification | CertReports uses it as the expiry of the row |
| Covered entities | US subsidiaries and affiliates covered by the parent’s certification | Check the entity you contract with is listed |
| Recourse mechanism | Where an EU individual complains | Named and reachable |
Two thirds of DPF rows in the index are lapsed
The participant list includes every organisation that ever self-certified, with inactive and withdrawn entries kept for accountability. Of the DPF rows the CertReports index links to a vendor, 3,111 are past their usage end date without a visible recertification, against 1,562 active. That is why a DPF badge on a privacy page proves nothing on its own: the list decides, and it changes daily.
- Past usage end date (expired)3,111
- Active1,562
The UK and Swiss extensions
The UK Extension to the EU-US DPF (the "data bridge") took effect on 12 October 2023. The Swiss-US DPF took effect on 15 September 2024 when the Swiss Federal Council recognised it. Both are separate boxes on the same list. A vendor active for the EU-US DPF but not the UK extension cannot rely on the DPF for UK transfers; it needs the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses instead.
| Transfer | Mechanism | What to look for on the list |
|---|---|---|
| EU to US | EU-US DPF | Active, EU-US framework ticked |
| UK to US | UK Extension | Active, UK Extension ticked; otherwise IDTA or UK Addendum |
| Switzerland to US | Swiss-US DPF | Active, Swiss framework ticked |
| Any of the above, fallback | Standard contractual clauses in the DPA | Not on the list; read the DPA |
The legal risk in 2026
The adequacy decision was challenged almost immediately. On 3 September 2025 the General Court dismissed the action in Latombe v Commission (T-553/23). The applicant lodged an appeal with the Court of Justice on 31 October 2025 (C-703/25 P), and no hearing date had been set at the time of writing; commentators expect no judgment before late 2026 or 2027. Schrems II shows what happens when a mechanism falls: transfers do not stop, but the legal basis disappears overnight. The practical advice is unchanged since 2020: accept the DPF as the primary basis and keep the standard contractual clauses in the DPA as the fallback. The appeal article sets out the steps.
Latombe appealed the judgment to the Court of Justice on 31 October 2025 (Case C-703/25 P), raising four grounds of law.
How to use the DPF row on CertReports
- 1
Check the state and the date
A verified DPF row shows the status and the usage end date from the list. Expired means the usage end date passed without a recertification appearing.
- 2
Check the extensions you need
The row detail shows EU, UK and Swiss coverage separately.
- 3
Read the DPA for SCCs
The vendor page lists public legal documents. Look for the DPA and whether it incorporates the 2021 SCCs; see the GDPR and DPA hub. - 4
Note the entity
The listed organisation must be the entity that receives your data, or a covered affiliate of it.
- 5
Follow the vendor
The usage end date arrives once a year. Following the vendor on CertReports sends an alert when the row expires or renews.
Vocabulary
CertReports never writes "GDPR certified". There is no GDPR certification in general use. A GDPR row records public artefacts, a DPA, SCCs, an EU representative, a DPF listing, each with a date and a source.
People also ask
Is the EU-US Data Privacy Framework still valid in 2026?
Yes. The General Court upheld the adequacy decision on 3 September 2025 and the decision remains in force while the appeal (C-703/25 P) is pending at the Court of Justice.
How do I check if a company is DPF certified?
Search the participant list at dataprivacyframework.gov or the CertReports DPF registry mirror. Check the status is Active, the frameworks ticked, the usage end date, and that the listed entity is the one you contract with.
What is the usage end date on the DPF list?
The date the current annual certification lapses unless the organisation recertifies. CertReports treats a row whose usage end date has passed without renewal as expired.
Does the DPF cover UK data?
Only where the organisation is also listed under the UK Extension. Without it, UK transfers need the IDTA or the UK Addendum to the standard contractual clauses.
Do I still need standard contractual clauses if a vendor is DPF listed?
They are not required for the transfer while the DPF stands, but keeping them in the DPA means the transfer keeps a legal basis if the adequacy decision is annulled, as happened with Privacy Shield in 2020.
What happens if the DPF is struck down?
Transfers would move to the standard contractual clauses and a transfer impact assessment overnight. Vendors with SCCs already in their DPA need nothing new; vendors relying on the DPF alone need an amended DPA.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
The Data Privacy Framework survived the General Court. What buyers should do while the appeal runs
Solomon Amos · 8 Sep 2026 · 9 min read
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read