No history yet

EU-US DPF Foundations

From Safe Harbor to a New Framework

For decades, moving personal data from the European Union to the United States has been a complex legal puzzle. Because the EU and US have different approaches to data privacy, a special agreement is needed to ensure that EU citizens' data remains protected when it crosses the Atlantic. The first attempts to solve this were the Safe Harbor and Privacy Shield agreements. Both aimed to create a streamlined way for US companies to meet EU data protection standards.

However, both frameworks were eventually struck down by the Court of Justice of the European Union (CJEU). The court found that US surveillance laws did not provide adequate protection for EU data, leaving personal information vulnerable to access by US intelligence agencies. The ruling that invalidated the Privacy Shield, known as the decision, created significant uncertainty for thousands of companies that relied on it for daily business operations, from cloud computing to payroll.

The DPF's Legal Bedrock

In response to the Schrems II ruling, the EU and US negotiated a new agreement: the EU-US Data Privacy Framework (DPF). To avoid the pitfalls of its predecessors, the DPF is built on a dual legal foundation designed to address the court's concerns head-on.

Lesson image

First, the European Commission issued an , declaring that the US now provides a level of data protection comparable to that in the EU. This decision is the green light from the EU's side, making the framework legally valid for transferring data.

Second, the US issued Executive Order 14086. This order introduces new, binding safeguards. It limits US intelligence agencies' access to EU data to what is necessary and proportionate, and it establishes a new two-tier redress mechanism. This includes an independent Data Protection Review Court (DPRC) where EU individuals can bring claims, directly addressing the core issue raised in Schrems II.

The Seven Core Principles

For a US organisation to participate in the DPF, it must publicly commit to complying with seven core principles. These principles are the practical rules of the road for handling EU personal data. While they share the same spirit as the GDPR's principles, they have their own specific requirements.

PrincipleDescription
NoticeOrganisations must inform individuals about the data they collect, the purpose of collection, and who it will be shared with.
ChoiceIndividuals must be given the option to opt out of having their data disclosed to a third party or used for a new purpose.
Accountability for Onward TransferWhen transferring data to a third party, the original organisation remains responsible for ensuring the data is protected.
SecurityOrganisations must take reasonable and appropriate measures to protect data from loss, misuse, and unauthorised access.
Data Integrity & Purpose LimitationData must be relevant for the purposes for which it is to be used. It shouldn't be processed in a way that is incompatible with those purposes.
AccessIndividuals must have the right to access the personal data an organisation holds about them and be able to correct or delete it if inaccurate.
Recourse, Enforcement & LiabilityThere must be robust mechanisms for ensuring compliance and providing recourse for individuals whose rights have been violated.

Let's consider a practical example of 'Accountability for Onward Transfer'. Suppose a US-based software company uses the DPF to receive customer data from its German office. If this company then hires a separate US-based marketing firm to analyse that customer data, the software company is still liable for how the marketing firm handles it. It must have a contract in place that ensures the marketing firm provides the same level of protection as the DPF requires.

This principle ensures that data protection doesn't end once the data is passed along to another company. The responsibility travels with the data.

Similarly, the 'Data Integrity and Purpose Limitation' principle prevents scope creep. If a customer provides their data to a US e-commerce site to process an order, the company cannot then start using that same data to train a new, unrelated AI model without obtaining new consent. The data can only be used for the specific, relevant purpose for which it was originally collected. This mirrors the GDPR's purpose limitation principle, but it is explicitly laid out as a core commitment under the DPF.

Ready to test your knowledge?

Quiz Questions 1/5

What was the primary reason the Court of Justice of the European Union (CJEU) invalidated the Privacy Shield framework in the 'Schrems II' decision?

Quiz Questions 2/5

Under the EU-US Data Privacy Framework (DPF), what two key legal components form its foundation?

Understanding these foundations is the first step in navigating the landscape of transatlantic data privacy. The DPF provides a critical, albeit complex, pathway for data to flow, underpinning countless digital services.