Certification · Last verified

EU-US Data Privacy Framework

The EU-US Data Privacy Framework is a self-certification program for personal-data transfers, run and verified by the U.S. International Trade Administration. Organizations must, in the ITA's words, publicly declare their commitment to comply with the Principles and remain subject to FTC or DOT enforcement.

Class
Certification
Owner
International Trade Administration (ITA), U.S. Department of Commerce
Public register
Not confirmed at our last check
Last verified

What it is

The U.S. International Trade Administration describes the program's purpose in the Federal Register: "the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF" — "provide U.S. organizations with reliable mechanisms for personal data transfers to the United States from the EU, UK, and Switzerland."

This is a self-certification program, not a third-party audit: an organization must "(1) be subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC), the Department of Transportation (DOT), or another statutory body that will effectively ensure compliance with the Principles; (2) publicly declare its commitment to comply with the Principles."

The ITA's own role is to maintain the list and check the paperwork, not to audit the organization's practices: its duties include to "Maintain, upgrade, and update a DPF program website, including maintaining the Data Privacy Framework List" and to "Verify self-certification requirements submitted by organizations to participate in the DPF program."

Who owns it

The program is run by the International Trade Administration (ITA), U.S. Department of Commerce, per the Federal Register notice on DPF program fees (Doc. 2024-14983, 9 July 2024).

Who assesses it

No independent conformity-assessment body was identified in the source reviewed: the ITA itself verifies the self-certification paperwork, and enforcement of the Principles once an organization is listed runs through "the Federal Trade Commission (FTC), the Department of Transportation (DOT), or another statutory body."

Who asks for it

The program exists for "U.S. organizations" that need "reliable mechanisms for personal data transfers to the United States from the EU, UK, and Switzerland" — i.e., U.S. companies receiving personal data from those three jurisdictions.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"EU-US Data Privacy Framework." Certifidex, FutureTechnologies. Last verified 1 September 2026. https://certifidex.com/frameworks/eu-us-dpf

All frameworks & audits →