EU-US Data Privacy Framework FAQ for European businesses
Adopted EU - U.S. DATA PRIVACY FRAMEWORK F.A.Q. FOR EUROPEAN BUSINESSES 1 Adopted on 16 July 2024 1 In this context, European businesses refer to businesses in the EEA, which transfer or may transfer personal data to companies in the U.S. certified under the DPF. Adopted 2 Adopted 3 Q1. WHAT IS THE EU - U.S . DATA PRIVACY F RAMEWORK? The EU - U.S. Data Privacy Framework (“DPF”) is a self - certification mechanism for companies in the U.S. Companies that have self - certified under the DPF must…
How it connects
Related across sources
Full text 5 sections
S. Q. S. certified under the DPF. Adopted 2 Adopted 3 Q1. S . DATA PRIVACY F RAMEWORK? S. S. Companies that have self - certified under the DPF must comply with its principles, rules and obligations related to the processing of personal data of EEA individuals. For more information about these commitments, see the Data Privacy Framework Principles . 2 The European Commission considered that transfers of personal data from the EEA to companies certified under the DPF enjoy an adequate level of protection . S. certified companies, without the need to put in place further safeguards or obtain an authorisation. S. S. S. is self - certified under the DPF to process those types of data. 7 Q2. S . S. DATA PRIVACY F RAMEWORK? S. S. S. Department of Transportation (“DoT”). S. statutory bod ies may be included in the future. 8 This means that, for example, non - profit organizations, banks, insurance companies and telecommunication service providers (with regard to common carrier activities) which do not fall under the jurisdiction of the FTC or DoT cannot self - certify under the D PF.
gov/program - articles/Participation - Requirements - Data - Privacy - Framework - (DPF) - Principles 3 The decision on the adequacy of the Data Privacy Framework was adopted by the European Commission on July 10, 2023. S. Department of Commerce to replace the Privacy Shield Decision (EU) 2016/1250 which was declared invalid by the European Court of Justice in 16 July 2020 in Case C - 311/18, Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems (Schrems II) . pdf 7 Note that not all DPF self - certifications cover HR Data. It is therefore important to check whether this is the case, if relevant. See also Q3. S. S. 2. Adopted 4 Q3. S . S. DATA PRIVACY F RAMEWORK? S. S. holds an active self - certification (certifications must be renewed annually) and that this certification covers the data in question (in particular if it covers HR Data, respectively, non - HR Data).
S. S. Department of Commerce’s website. This list also includes a register of companies that have been removed from the List (“inactive participants”), stating the reasons for their removal. An EEA data exporter cannot rely on the DPF for transfers of personal data to such companies. Please note that companies that have been removed from the Data Privacy Framework List must continue to apply the Data Privacy Framework Principles to personal data received while participating in the DPF for a s long as they retain these data. S. that are not (or no longer) self - certified under the DPF, other grounds for transfer in Chapter V of the GDPR may be used, such as Binding Corporate Rules or Standard Contractual Clauses. S. is self - certified under the DPF will enable data exporters in the EEA to comply with Chapter V of the GDPR, but all other requirements in the GDPR and any other national data protection law remain applicable.
1. S. S. S. that are subsidiaries of a DPF - certified parent company, EEA data exporters must check if the certification of the parent company also covers the subsidiary company concerned. S. S. subsidiaries are covered by it, here . 2. S. , an EEA data exporter must ensure the transfer complies with all relevant provisions of the GDPR. S. if th ere is a legal basis for the processing (Article 6 of the GDPR). g. purpose limitation, proportionality, accuracy and information obligations towards data subjects). , the EEA data exporter, in accordance with Articles 13 and 14 GDPR, must inform data subjects about the identity of the recipients of their data 9 See definition of HR Data in Q1 . S. Data Privacy Framework adequacy decision. 3. S. , the controller and processor are obliged to conclude a data processing agreement under Article 28 GDPR (hereafter: Data processing agreement), regardless of whether the processor is self - certified under the DPF.
S. here . S. gov/program - articles/Contract - Requirements - for - Data - Transfers - to - a - Processor Adopted 6 by the controller. With regard to this last point, the processor shall immediately inform the controller if, in its opinion, an instruction infringes the DPF. S. B DPF are fulfilled. This includes ensuring that the sub - processor provides the same level of protection of personal data as required in the DPF and the same data protection obligations as set out in the data processing agreement. S. processor shall remain fully liable to the controller for the performance of that sub - processor's obligations. Q4. S. SUBSIDIARY COMPANIES OF E UROPEAN BUSINESSES? S. S. Department of Transportation (DoT). You can find more information on the eligibility requirements here , 13 and a guide to the self - certification process here . gov/program - articles/How - to - Join - the - Data - Privacy - Framework - (DPF) - Program - (part%E2%80%931)