The Data Privacy Framework is a self-certification programme administered by the US Department of Commerce under the EU adequacy decision of July 2023. A listing lets an EU controller transfer personal data to the participant without standard contractual clauses for that transfer.
What a listing proves
That the organisation has self-certified, pays the annual fee, has a public privacy policy referencing the framework and is subject to FTC enforcement. It is not a security attestation. The "Outside Compliance Review" verification method is a stronger signal than self-assessment.
Usage end date and inactive status
Every certification carries a usage end date under annual recertification. Inactive and withdrawn participants remain on the list with their status; CertReports shows Inactive as Expired with the date.
UK and Swiss extensions
Participants can add the UK extension (for UK GDPR transfers) and the Swiss-US DPF. CertReports records EU, UK and Swiss coverage separately.
Legal status
The General Court dismissed the challenge to the adequacy decision on 3 September 2025 (T-553/23). An appeal is pending at the Court of Justice (C-703/25 P, lodged 31 October 2025). Reviewers relying on the DPF should keep standard contractual clauses in reserve.