Skip to main content

GDPR

The EU-US Data Privacy Framework, explained for vendor reviews

What a DPF listing proves, the usage end date, the UK and Swiss extensions, and the pending Court of Justice appeal.

Last updated 17 Sep 2026

The Data Privacy Framework is a self-certification programme administered by the US Department of Commerce under the EU adequacy decision of July 2023. A listing lets an EU controller transfer personal data to the participant without standard contractual clauses for that transfer.

What a listing proves

That the organisation has self-certified, pays the annual fee, has a public privacy policy referencing the framework and is subject to FTC enforcement. It is not a security attestation. The "Outside Compliance Review" verification method is a stronger signal than self-assessment.

Usage end date and inactive status

Every certification carries a usage end date under annual recertification. Inactive and withdrawn participants remain on the list with their status; CertReports shows Inactive as Expired with the date.

UK and Swiss extensions

Participants can add the UK extension (for UK GDPR transfers) and the Swiss-US DPF. CertReports records EU, UK and Swiss coverage separately.

The General Court dismissed the challenge to the adequacy decision on 3 September 2025 (T-553/23). An appeal is pending at the Court of Justice (C-703/25 P, lodged 31 October 2025). Reviewers relying on the DPF should keep standard contractual clauses in reserve.