EU-US Data Privacy Framework (Adequacy Decision)
The EU-US Data Privacy Framework (DPF) is the European Commission adequacy decision that has, since July 2023, allowed transfers of personal data to certified US companies without extra safeguards such as standard contractual clauses. It succeeded the Privacy Shield, which fell away in 2020. A central element is a redress route for people in the EU that is meant to be independent of the US authorities; that independence was the precondition for EU recognition. The decision is in force. Its future is still being contested, in the courts and politically, and we do not predict here how that ends.
In practice
Companies transferring personal data to the United States through cloud, CRM or marketing tools can rely on the DPF for now, and should still prepare. Three things need no legal advice. First: check whether the specific recipient appears on the certification list of the US Department of Commerce, and record that with a date. Certification covers a company, not an industry. Second: keep your own overview of transfers current, so that nobody has to work out what flows where at the worst possible moment. Third: prepare standard contractual clauses with additional measures as a fallback for the critical data flows, rather than looking for them once they are needed. Whether a particular transfer is lawful, and which basis carries it, is a legal question. The calmest route is still the one that never raises it: a service that processes the data inside the EU.