Data Sovereignty / Source date:

EU-US Data Privacy Framework: Third Time's the Charm?

In June 2023, the proposed EU-US Data Privacy Framework was approaching an adoption decision. This dated commentary examines transfer controls and the risks of relying on a single mechanism.

Illustration of a privacy architect reviewing a sample transfer map and mechanism register.

Historical context. The source date is 13 June 2023. The opening discussion reflects the period before adoption. The European Commission adopted the framework's adequacy decision on 10 July 2023. Corrections below do not establish the framework's future legal status or provide legal clearance for a particular transfer.

The third attempt at a transatlantic data transfer framework is now in its final procedural stretch. The Commission published its draft adequacy decision in December. The European Data Protection Board gave its opinion in February, acknowledging real improvements while listing concerns it considered unresolved. Last month the European Parliament passed a resolution urging the Commission not to adopt the decision at all. The member state committee vote is still to come, and adoption is widely expected this summer. Three weeks ago, the Irish regulator issued a fine of 1.2 billion euro against Meta and ordered the suspension of its transfers. That decision, more than any legal analysis, explains why the framework will be adopted.

The temptation for anyone who has managed two rounds of this is cynicism: another framework, another challenge, another few years of paperwork. The temptation for anyone who has not is relief: a decision is coming, so the problem is solved. Both are wrong in the same way. They treat the framework as the thing that determines your exposure. What actually determines it is whether your architecture can change transfer mechanism without an engineering project.

What genuinely changed this time

It is worth being fair about the improvements, because dismissing them makes it harder to assess the risk accurately. The United States executive order signed last October introduced necessity and proportionality as binding constraints on signals intelligence activity, language drawn deliberately from European jurisprudence and absent from the previous arrangement. It also created a two-stage redress path: an initial review by an intelligence community civil liberties officer, and an appeal to a newly constituted review body with members drawn from outside government and protections against removal. These are not cosmetic. They address, in form, the two failures the Court identified when it struck down the previous framework.

Three objections raised ahead of adoption

Bulk collection remains permitted without prior authorisation by an independent body, subject to the new proportionality language. Critics argue that a standard applied internally by the collecting agencies is not the independent prior review European law requires. The redress body is an executive creation. It is established by executive action rather than by statute, its members are appointed within the executive branch, and a complainant receives a standardised response that neither confirms nor denies that any collection occurred. Whether that constitutes an effective remedy before a tribunal is precisely the question a court will be asked. It is reversible by the same instrument that created it. An executive order can be amended or revoked by a subsequent administration without any legislative process. Permanence is not a legal requirement for adequacy, but it is a durability question for anyone building on it. The Parliament's resolution is not binding and the Commission is not obliged to follow it. It does, however, tell you how contested the adoption will be, and it will be cited in the challenge.

Why it will be adopted anyway

Standard contractual clauses and transfer assessments can be demanding to implement, including for smaller organisations. Their suitability depends on the actual transfer, not an organisation's size alone. The Meta decision concerned transfers made using the 2021 standard contractual clauses and supplementary measures, not the absence of a transfer mechanism. The DPC found that those arrangements did not address the risks identified by the CJEU. Its May 2023 announcement records a €1.2 billion fine and a suspension order with a deadline attached. The Commission has a strong institutional interest in adopting, and it has built a defensible record to adopt on. Expect it in weeks.

What to do between now and then

Do not dismantle anything. The clauses, the assessments and the supplementary measures you built over the past three years may provide an alternative if the framework ceases to apply, but only if they satisfy the relevant requirements for the transfer, and rebuilding them under time pressure after an adverse ruling is considerably more expensive than maintaining them. Understand the coverage limits. The framework will cover transfers to United States organisations that certify to it. It will not cover your vendors who do not certify, your transfers to other third countries, or your intra-group flows outside the United States. For many organisations the framework resolves a minority of the transfer map. Keep the data map current, because every mechanism decision depends on knowing what goes where, and that map decays continuously as teams adopt new tools. Keep the technical measures. Encryption with keys held in the European Economic Area, pseudonymisation before transfer and regional processing are the controls that reduce actual exposure rather than documenting it. Their effectiveness depends on the data, access arrangements and key management. These controls do not, by themselves, guarantee a lawful transfer.

Make the transfer mechanism a configuration, not an architecture

The organisations that suffered least in 2020 were those that could change legal basis without changing systems. That is a design property, and it can be specified. In contracts, require the vendor to support an alternative transfer mechanism on request and to offer a regional processing option, with a defined period to implement. Internally, record the transfer basis as an attribute of each data flow rather than as a paragraph in a policy, so that a change of basis is an update to a register rather than an archaeology exercise. Where a flow could not survive suspension, know that now and price the remediation, because that is the list you will work from on the day a court rules.

Practical Guidance for Cross-Border Data Transfer Compliance Review

  • Maintain your standard clauses and assessments through the transition.
  • Record the transfer basis per data flow, not per policy document.
  • List vendors that will and will not certify to the new framework.
  • Keep encryption keys and pseudonymisation in the originating region.
  • Write the assessment for inbound transfers to your own jurisdiction.
  • Check which law applies per legal entity, including financial free zones.
  • Assess support, telemetry and recovery flows for personal data, recipient roles and applicable transfer requirements.
  • Negotiate the right to switch mechanism into every new contract.

The Regional Angle

Three points matter for groups headquartered in the Gulf, and the first is that this framework does almost nothing for you. A regional group with a European subsidiary is a third country from the European perspective, and nothing in the transatlantic arrangement changes the basis on which a Frankfurt or Paris entity sends personnel, customer or supplier data to a head office in Dubai or Riyadh. That flow needs clauses and a transfer impact assessment addressing government access in your jurisdiction, and in practice most regional groups have never written one. The reason is understandable: these assessments are published as templates aimed at United States transfers, and nobody produces the equivalent analysis for a Gulf recipient. Somebody has to, and it is better for it to be your counsel than your customer's. The assessment needs to address lawful access powers in your jurisdiction, the protections available to a data subject, and the measures you apply on top. Binding corporate rules are the more durable answer for groups with substantial intra-group flows, and they take long enough to approve that starting now is not premature. The second point is that many regional groups are subject to more than one data protection law at once, and routinely forget it. An entity in a financial free zone operates under that zone's own regime, with its own regulator, its own adequacy determinations and its own transfer rules, while an affiliate on the mainland operates under the federal law. A transfer between the two is a cross-border transfer under the zone's law, regardless of the fact that both offices are in the same city and share a chief financial officer. Intra-group service arrangements, shared human resources systems and consolidated reporting all cross that boundary constantly. Map which regime applies entity by entity before assuming the group operates under one rulebook, because it almost certainly does not. The third is the transfer nobody documents. Regional cloud regions mean data can genuinely be kept in-country, and groups here have moved faster on that than most European organisations. But residency of stored data is not the whole flow. Vendor support staff access production systems from wherever their follow-the-sun rota places them, diagnostic telemetry is exported to a central platform, and backups and disaster recovery may replicate to a region on another continent. Each may involve a personal-data transfer, depending on the data, recipient roles and locations. Whether it falls outside a residency commitment depends on that contract. The EDPB's February 2023 guidance sets out the criteria; processing abroad can also require safeguards even when it is not a Chapter V transfer. Get the support access model, the telemetry destinations and the recovery region in writing for every material system this quarter. It is a short list of questions, and the answers determine whether your residency position is accurate or merely asserted.

The objection worth taking seriously

The strongest objection is that fifteen years of this have produced no observable change in anyone's privacy. Two frameworks were struck down, transatlantic data continued to flow throughout without interruption, and the compliance apparatus that grew in the gaps generated assessments that nobody read and clauses that nobody enforced. Organisations that ignored the entire debate and kept using their software experienced precisely the same outcomes as those that spent heavily on advice. On that record, the rational response to a third framework is to use it when it arrives and stop funding a parallel mechanism against the possibility that a court in Luxembourg disagrees in 2027. That objection does not establish that ignoring transfer requirements produces the same outcome as complying with them. Documentation alone is insufficient, but the validity of the transfer mechanism and the effectiveness of safeguards still matter. What has changed is the tail. Three weeks ago a regulator issued a fine of 1.2 billion euro and ordered transfers to stop within months. That is no longer a theoretical exposure, and it landed on an organisation whose legal resources are not the constraint. The cost of maintaining alternatives and regional controls depends on the systems and flows. Those measures may improve preparedness, but they do not guarantee continued lawful operation after an adverse decision. Reassess the transfer and stop or change it where the required protection cannot be maintained. Treat it as insurance priced against the new tail, not as compliance theatre priced against the old one.

Common Questions

Should we wait for adoption before signing new United States vendors?

At the source date, the proposed framework was not yet an available transfer mechanism. Before signing, assess whether an existing lawful route supports the intended transfers. Certification eligibility and any future certification commitment need to be checked with the vendor; do not assume agreement or coverage.

Does certification cover the vendor's subprocessors?

Not automatically. Onward transfer obligations apply, but the practical answer requires looking at the subprocessor list, which is where most transfer maps break.

Is the United Kingdom covered by the same arrangement?

No, it is a separate matter proceeding on a parallel track, and organisations with both flows need both answers.

What should we expect over the next twelve months?

Expect adoption this summer, following the member state committee vote. Legal challenges were a risk to consider at the source date. Neither their timing nor the outcome or continued validity of the framework could be guaranteed. Expect national regulators to continue enforcing against transfers made without any valid basis in the interim, the Irish decision concerned the adequacy of the safeguards offered by the 2021 standard contractual clauses and supplementary measures, not the absence of a mechanism. And expect the durable differentiator to be architectural reversibility, because the organisations that will struggle in 2025 or 2026 are the ones that spend the intervening period quietly dismantling the alternative.


Cross-Border Data Transfer Compliance Review — we map your flows by legal entity and applicable regime, write the assessments nobody templates for Gulf recipients, and make your transfer basis something you can change without an engineering project.

Continue reading

Talk to OPS

Start with the operating problem.