The EU-US Data Privacy Framework and AI Vendors
9 min read · updated August 11, 2026
A vendor telling you it is “DPF certified” has told you something narrower than it sounds. The certification covers one named legal entity, for the categories of data it declared, under the jurisdiction of one US regulator — and an AI stack routinely produces transfers that fall outside all three.
What the framework actually is
On 10 July 2023 the European Commission adopted Implementing Decision (EU) 2023/1795, finding that the United States ensures an adequate level of protection for personal data transferred from the Union to organisations self-certified under the EU-U.S. Data Privacy Framework. The decision is at EUR-Lex, Decision (EU) 2023/1795. Its effect is that a transfer to a certified organisation travels on Article 45 of the GDPR — an adequacy decision — rather than on an Article 46 tool. No standard contractual clauses, and no Clause 14 transfer impact assessment, for the transfers it covers.
The framework is administered by the US Department of Commerce, which maintains the authoritative list of certified organisations at dataprivacyframework.gov. Certification is a self-certification: the organisation publicly commits to the framework’s principles, and those commitments are then enforceable by the Federal Trade Commission or the Department of Transportation under their respective powers over deceptive practices. Enforcement runs against the commitment, which is why a lapsed certification is a genuine problem rather than a paperwork one.
Two adjacent instruments travel with it. The UK Extension to the EU-U.S. Data Privacy Framework — the “data bridge” — took effect in October 2023 for transfers from the United Kingdom, and requires a separate election by the organisation. The Swiss-U.S. Data Privacy Framework is a separate arrangement again, recognised by the Swiss authorities. An organisation certified for the EU is not thereby certified for the UK or Switzerland.
What a certification covers
The certification binds the organisation to seven principles — notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, enforcement and liability — together with a set of supplemental principles. Three features of how it is scoped matter more than the principles themselves.
- It covers one legal entity. Certification is by entity, and it may or may not extend to named US subsidiaries. A group structure where the contracting entity is Irish, the certified entity is the US parent, and the inference is served by a third company is common, and only the middle one is covered.
- It covers declared data categories. The certification record states which categories the organisation covers. Human resources data collected in the employment context is a separate election with additional obligations; an organisation certified only for non-HR data cannot receive HR data on the framework.
- It requires FTC or DOT jurisdiction. Organisations outside the jurisdiction of one of those regulators cannot certify, which historically excluded banks, insurers and telecommunications common carriers among others.
The accountability for onward transfer principle is the one that does the most work in an AI context. A certified organisation transferring personal data to a third party acting as its agent must enter a contract limiting processing to the specified purposes, and — critically — remains liable for the agent’s processing unless it proves it was not responsible for the event giving rise to the damage. That is how the framework reaches an upstream model provider that is not itself certified.
The transfers it does not cover
Here is where an AI stack leaks out of the certification, and each of these is a case where an Article 46 tool and an assessment are still required:
- An uncertified upstream provider. If your vendor routes to a model provider that has not certified, the onward transfer from your vendor is governed by the accountability principle, but your own position depends on how the chain is contracted. Where the upstream provider is your sub-processor rather than your vendor’s agent, you need a transfer tool for it.
- A non-US third country in the chain. An adequacy decision for the United States says nothing about a support team in a fourth country, or an inference region outside both.
- Transfers to an entity in the group that is not on the list. Verify the exact legal name on the Commerce list against the exact legal name on your contract. They differ more often than you would expect.
- Data categories outside the certification. If your prompts routinely carry employment data and the vendor certified only for customer data, the framework does not reach that flow.
- Everything after a certification lapses. Certification must be renewed annually. An organisation that fails to re-certify is moved off the active list, and transfers to it stop being covered on that date even though nothing about the relationship changed.
This is why the common advice to keep standard contractual clauses in place alongside a DPF certification is not belt-and-braces over-caution. It is a fallback that becomes the operative instrument the moment any of the above is true — including, in the limiting case, the annulment of the adequacy decision itself. Which module to keep in place is covered in which SCC modules apply to an AI processor.
Legal status and challenge
The framework’s two predecessors were annulled. Safe Harbour fell in Case C-362/14, Schrems, in October 2015; the Privacy Shield fell in Case C-311/18, Schrems II, in July 2020. That history is the reason the current decision is treated as contingent by careful practitioners rather than as settled.
An action for annulment of the 2023 decision was brought before the General Court by a French member of parliament, Philippe Latombe, in September 2023, registered as Case T-553/23. The General Court dismissed the action in 2025. A judgment of the General Court can be appealed to the Court of Justice on points of law, and a separate reference from a national court remains possible at any time; the docket is at curia.europa.eu for T-553/23.
Two structural criticisms are worth understanding because they are what any future challenge will be built on, and because they are what a cautious assessment should record as residual risk. The first is that the redress mechanism — the Data Protection Review Court — is created by executive order rather than by statute, and is described by its critics as an executive body rather than a tribunal within the meaning of Article 47 of the Charter. The second is that the oversight architecture depends on bodies whose composition is politically determined; the Privacy and Civil Liberties Oversight Board lost its quorum in early 2025, which was raised in the Union as a question about the durability of the safeguards the adequacy finding rests on. Neither criticism has been accepted by a court, and neither has been dismissed as unfounded either. What would settle them is a reasoned judgment on the merits from the Court of Justice, and there is not one.
What to check before relying on it
Four checks, all of which take minutes and none of which is usually done. Look up the exact contracting entity on the Commerce list and confirm it is active rather than inactive. Read the certification record for the declared data categories and confirm your data is within them. Confirm whether the UK extension has been elected if you transfer from the United Kingdom. And ask the vendor which upstream providers receive the data and whether each of those is certified — because the answer determines whether your reliance on Article 45 ends at the first hop.
The result of those checks belongs in your record of processing under Article 30, in the transfers field, with the date the list was checked; see records of processing activities for an AI system. Where a flow falls outside the certification, it needs the SCC and assessment route instead — the method for which is in transfer impact assessments for a US-hosted AI provider.