Certification · Last verified
EU-US Data Privacy Framework
The EU-US Data Privacy Framework is a self-certification program for personal-data transfers, run and verified by the U.S. International Trade Administration. Organizations must, in the ITA's words, publicly declare their commitment to comply with the Principles and remain subject to FTC or DOT enforcement.
- Class
- Certification
- Owner
- International Trade Administration (ITA), U.S. Department of Commerce
- Public register
- Not confirmed at our last check
- Last verified
What it is
The U.S. International Trade Administration describes the program's purpose in the Federal Register: "the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF" — "provide U.S. organizations with reliable mechanisms for personal data transfers to the United States from the EU, UK, and Switzerland."
This is a self-certification program, not a third-party audit: an organization must "(1) be subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC), the Department of Transportation (DOT), or another statutory body that will effectively ensure compliance with the Principles; (2) publicly declare its commitment to comply with the Principles."
The ITA's own role is to maintain the list and check the paperwork, not to audit the organization's practices: its duties include to "Maintain, upgrade, and update a DPF program website, including maintaining the Data Privacy Framework List" and to "Verify self-certification requirements submitted by organizations to participate in the DPF program."
Who owns it
The program is run by the International Trade Administration (ITA), U.S. Department of Commerce, per the Federal Register notice on DPF program fees (Doc. 2024-14983, 9 July 2024).
Who assesses it
No independent conformity-assessment body was identified in the source reviewed: the ITA itself verifies the self-certification paperwork, and enforcement of the Principles once an organization is listed runs through "the Federal Trade Commission (FTC), the Department of Transportation (DOT), or another statutory body."
Who asks for it
The program exists for "U.S. organizations" that need "reliable mechanisms for personal data transfers to the United States from the EU, UK, and Switzerland" — i.e., U.S. companies receiving personal data from those three jurisdictions.
Sources
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.