legal247

Transferring personal data to the US: how safe is the Data Privacy Framework?

In brief

The Data Privacy Framework makes it lawful to transfer personal data to US companies certified under it. The adequacy decision applies in Norway and was upheld by the EU General Court in 2025, but the case has been appealed and US oversight bodies have been weakened. Businesses should use the framework, but keep standard contractual clauses and an exit plan in reserve.

A great many Norwegian businesses transfer personal data to the US, often without giving it much thought. It happens when you use US cloud services, CRM systems, AI tools and analytics tools. Since 2023, the EU-US Data Privacy Framework has been the simplest basis for such transfers. The question is how long it will last.

What is the EU-US Data Privacy Framework?

The Data Privacy Framework is a scheme under which US companies self-certify with the US Department of Commerce and commit to complying with European data protection principles. In Implementing Decision (EU) 2023/1795 of 10 July 2023, the European Commission concluded that such companies provide an adequate level of protection under GDPR Art. 45.

The decision was incorporated into the EEA Agreement by EEA Joint Committee Decision No 169/2024, with effect from 6 July 2024. The Norwegian Data Protection Authority (Datatilsynet) had already taken the position from July 2023 that Norwegian businesses could rely on it.

The framework is based on a presidential order from October 2022 (Executive Order 14086). It limits US intelligence access to what is necessary and proportionate, and establishes a redress mechanism with a dedicated court, the Data Protection Review Court, for individuals in the EU and the EEA.

Which transfers does the Data Privacy Framework cover?

The framework only covers transfers to US companies that appear on the official Data Privacy Framework List with active status. If the recipient is listed, no standard contractual clauses or transfer impact assessment are needed. All other obligations under the GDPR still apply, including the legal basis for processing, the duty to inform and the data processing agreement.

Three points should be checked. First, the certification must be active, because it must be renewed annually. Second, it must cover the right type of data, since HR data requires the company to have certified specifically for HR data. Third, it must be the right legal entity, not just a company in the same group.

If data is transferred to a US company that is not certified, you must use another mechanism in GDPR Chapter V, typically standard contractual clauses.

Why is the Data Privacy Framework uncertain?

The framework is the third attempt at an arrangement for the US. The Court of Justice of the EU struck down Safe Harbor in 2015 and Privacy Shield in Schrems II, Case C-311/18, on 16 July 2020. On both occasions, the reasoning was that US surveillance legislation went further than was strictly necessary and that Europeans lacked effective judicial redress.

The Data Privacy Framework is lawful to use today, but it is not a basis you should rely on alone.

The risk today relates in particular to four factors.

Factor Status as of October 2026 Significance
The Latombe case The General Court ruled in the Commission’s favour on 3 September 2025 (T-553/23). The appeal (C-703/25 P) is pending before the Court of Justice A final answer may come in 2027 or later
PCLOB Three members were removed in January 2025, and the body has lacked a quorum since Weakens one of the oversight bodies the Commission relied on
FTC On 29 June 2026, the Supreme Court held in Trump v. Slaughter that the President may remove FTC commissioners at will The FTC enforces the companies’ commitments, and its independence was a premise
The executive order Can be amended or revoked by the President The basis is not enacted in legislation by Congress

The Latombe case

On 3 September 2025, the EU General Court dismissed the action brought by the French member of parliament Philippe Latombe in Case T-553/23. The court found that the Data Protection Review Court is sufficiently independent, and that the collection of data by US intelligence did not render the decision invalid. Datatilsynet pointed out at the same time that the judgment is based on the circumstances in 2023.

Latombe appealed to the Court of Justice in October 2025, and the appeal is registered as Case C-703/25 P. As of October 2026, the case has not been decided, and we have found no information that a hearing has been scheduled. An appeal is limited to points of law, but the Court of Justice is not bound by the General Court’s assessment.

PCLOB and FTC

The Privacy and Civil Liberties Oversight Board (PCLOB) oversees US intelligence and was part of the basis for the adequacy decision. Since three members were removed in January 2025, the body has lacked a quorum. We have found no information that new members had been confirmed as of October 2026.

Following the judgment in Trump v. Slaughter, the EDPB asked the Commission in a letter of 31 July 2026 to assess whether the ruling affects the adequacy decision. The EDPB did not ask for the decision to be suspended. Datatilsynet has updated its information on transfers to the US and states that the adequacy decision applies until it is set aside by the Commission or the Court of Justice.

The framework can therefore fall in two ways. The Court of Justice can declare the decision invalid, as it did with Privacy Shield. The Commission can also itself repeal, amend or suspend the decision under GDPR Art. 45(5) if the US no longer ensures an adequate level of protection. The Commission carried out the first periodic review in October 2024 and concluded that the framework was working. The next review is expected by October 2027, and both the PCLOB and the FTC will then be central.

What happens if the Data Privacy Framework falls?

If the adequacy decision falls, the transfer mechanism falls with immediate effect. In Schrems II, the Court of Justice granted no transition period, and businesses that had relied solely on Privacy Shield were left without a lawful basis the day after the judgment.

The fallback is the Commission’s standard contractual clauses in Implementing Decision (EU) 2021/914, under GDPR Art. 46(2)(c). They require a transfer impact assessment of whether the law of the recipient country undermines the protection, and any supplementary measures, as described by the EDPB in Recommendations 01/2020. If the framework falls because US surveillance law is not sufficiently limited, the same weakness will feed into the transfer impact assessment. Technical measures such as encryption with keys that only you control may then become decisive.

The derogations in GDPR Art. 49, such as consent or necessity for the performance of a contract, are intended for occasional transfers. They are not suitable as a basis for ongoing use of a cloud service.

Mechanism Requires transfer impact assessment Robustness
Data Privacy Framework No Depends on the adequacy decision
Standard contractual clauses Yes Survives if the framework falls, but the assessment becomes demanding
Derogations in Art. 49 No Only for occasional cases

What does this mean for your supplier agreements?

Many large SaaS suppliers have already built the standard contractual clauses into the data processing agreement, with a clause stating that they apply if the Data Privacy Framework ceases to apply. Check that this is included. Also check which sub-processors in the US are used and which mechanism applies to each of them. See data processing agreements for SaaS.

Datatilsynet recommends that businesses have an exit strategy in case transfers to the US can no longer take place as they do today. The agreement should therefore give a right to retrieve data and terminate without unreasonable cost if the transfer becomes unlawful. See cloud exit. US standard terms often provide for state law and US jurisdiction, which can make such rights difficult to enforce, see choice of law and jurisdiction.

If the service processes large volumes of data or particularly sensitive data, or uses AI, the transfer should be assessed in a data protection impact assessment, see DPIA for AI tools. Analytics and marketing tools on your website also often transfer data to the US, see cookies and consent.

What should the business do?

  1. Map all transfers to the US, including via sub-processors and support.
  2. Check each recipient on the Data Privacy Framework List, for active status, the right entity and HR data where relevant.
  3. Make sure standard contractual clauses are in reserve in the data processing agreements with US suppliers.
  4. Carry out a simplified transfer impact assessment now for the most important services, so that it can be used quickly.
  5. Choose EEA storage and encryption with your own keys where possible for sensitive data.
  6. Prepare an exit plan for the most critical services, with an alternative supplier and a timetable.
  7. Follow the Latombe appeal and the Commission’s assessment after Trump v. Slaughter.

The Data Privacy Framework can be used with a clear conscience today. The risk does not lie in using the framework, but in having nothing else to fall back on. See also the data protection topic page.

Questions and answers

What happens to our transfers if the Court of Justice strikes down the Data Privacy Framework?

The transfer mechanism falls away immediately. In Schrems II, the Court of Justice of the EU granted no transition period. Transfers to the US must then rely on standard contractual clauses with a transfer impact assessment and any supplementary measures, or be stopped. If you already have the standard contractual clauses in place as a fallback, the transition is far easier.

Does the Data Privacy Framework apply when a European supplier uses a US sub-processor?

Yes, if the US sub-processor is certified. The transfer from the European supplier to the sub-processor can then rely on the adequacy decision. You should nevertheless require the data processing agreement to show which sub-processors in the US are used and which transfer mechanism applies to each of them.

Is it enough that the supplier stores the data in a data centre in the EEA?

Not always. If a US entity has access to the data, for example for support or operations, that counts as a transfer. In addition, US law may give the authorities access to data controlled by US companies, even when it is stored in Europe. Storage in the EEA reduces the risk, but does not remove it.

Next legal review: 31 December 2026