EU-US Data Privacy Framework: certification, redress and reviews
Decision (EU) 2023/1795 finds that the United States ensures an adequate level of protection for personal data sent to certified organisations. Here is how certification, oversight and individual redress work under the Framework.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
Only organisations on the DPF List
Article 1 of the decision covers transfers from the Union to organisations in the United States included in the Data Privacy Framework List kept public by the US Department of Commerce. As Article 45(1) GDPR provides for any adequacy decision, such transfers require no specific authorisation.
To be eligible, an organisation must fall under the investigatory and enforcement powers of the Federal Trade Commission or the Department of Transportation. It commits to the EU-US DPF Principles, publishes a privacy policy and must re-certify every year.
Organisations that persistently fail to comply are removed from the List and must return or delete the data received under the Framework.
Redress for individuals in the EU
For commercial practices, a person can complain to the organisation, which must reply within 45 days, to an independent dispute resolution body, to a national data protection authority, to the Department of Commerce or to the FTC. Binding arbitration by the EU-US DPF Panel is a last resort.
For access by US intelligence agencies, Executive Order 14086 created a dedicated mechanism. The complaint is lodged with an EU data protection authority, which channels it through the EDPB secretariat; the complainant does not have to prove that their data were actually collected.
The Civil Liberties Protection Officer of the ODNI investigates first. Their decision can be appealed within 60 days to the Data Protection Review Court, which sits in panels of three judges assisted by a Special Advocate.
Frequently asked questions
Why was a new framework needed?
The Court of Justice invalidated the Commission's adequacy decision on the Privacy Shield. After talks with the EU, the United States adopted Executive Order 14086 on 7 October 2022, complemented by a Regulation on the Data Protection Review Court issued by the US Attorney General.
When is the decision reviewed?
The decision provides for a first review within one year of its entry into force, to verify that all new elements are fully implemented and work effectively in practice. Following that review, the Commission decides on the periodicity of future reviews in consultation with the Article 93 Committee and the European Data Protection Board.
Can a US company advertise its participation before it is listed?
No. Organisations certifying for the first time may not publicly refer to their adherence before the Department of Commerce has found the submission complete and added them to the List. The Department also monitors false claims of participation.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfersClaude Code, Cursor and other clients
claude mcp add --transport http kopik-eu-gdpr-official-texts-data-transfers "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-eu-gdpr-official-texts-data-transfers": {
"url": "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/eu-gdpr-official-texts-data-transfers/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_…with your key. - Full details (responses, errors, JS and Python examples): developer docs.