Legal jurisdiction

EU-US Data Privacy Framework

The EU-US Data Privacy Framework is the current agreement that lets data flow from Europe to US companies that sign up to it.

The EU-US Data Privacy Framework, active since 2023, is the replacement for the Privacy Shield agreement that Schrems II is a 2020 EU court ruling. It found that standard tools for sending data to the US did not protect Europeans enough from US surveillance laws. Learn more → struck down. US companies can self-certify that they meet certain privacy standards, which then allows European data to flow to them. It is meant to address the surveillance concerns raised in Schrems II. Privacy advocates, including Max Schrems, have already challenged it in EU courts, arguing the underlying US surveillance laws have not changed. Its long-term survival is not guaranteed.

Frequently asked questions

What is the EU-US Data Privacy Framework?

The EU-US Data Privacy Framework is an agreement between the EU and the US. It lets personal data flow from Europe to US companies that join the program. It has been active since 2023.

A US company must self-certify that it follows the framework's privacy rules. Once certified, it can receive EU data without needing separate contracts like SCCs. The framework replaced the earlier Privacy Shield agreement, which EU courts struck down.

Is the EU-US Data Privacy Framework legally valid right now?

Yes, at present. The European Commission issued an official adequacy decision for the framework in 2023. This means EU-US data transfers under it are currently considered legal.

But its status is not fully settled long-term. Privacy groups, including noyb, have already challenged it in EU courts. Its predecessor, Privacy Shield, was also valid for years before being struck down. So companies should watch for updates rather than assume the current status is permanent.

How is the Data Privacy Framework different from the old Privacy Shield?

Privacy Shield was the previous agreement, active from 2016 to 2020. EU courts struck it down in the Schrems II ruling. The court said it didn't protect Europeans enough from US surveillance.

The new framework adds things Privacy Shield lacked. It includes new limits on how much data US intelligence agencies can collect. It also creates a new complaint process, called the Data Protection Review Court, for Europeans to challenge misuse of their data.

Which companies are certified under the Data Privacy Framework?

Only US companies that actively join the program are certified. A company must apply, agree to the framework's privacy rules, and be listed on the official Data Privacy Framework registry.

Certification is not automatic. A large US tech company is not covered by the framework just because it operates in the US. You can check if a specific company has joined by searching the public registry.

Could the Data Privacy Framework be struck down like Privacy Shield was?

It's possible, though not certain. The framework has already faced legal challenges in EU courts. Its critics argue that US surveillance laws haven't actually changed enough to fix the problems Schrems II identified.

So far, the framework has survived these early challenges. But its predecessor also survived challenges for years before being struck down. Its long-term future depends on how future court cases in the EU are decided.