This FAQ includes information about the EU-U.S. Data Privacy Framework for European businesses. The document outlines eligibility criteria for U.S. companies, specifying that they must fall under the jurisdiction of the FTC or DoT. Before transferring data, European businesses must verify U.S. companies' active certifications and coverage of relevant data types. Guidance is provided on handling transfers to U.S. subsidiaries and the necessary data processing agreements under GDPR. Lastly, it directs businesses to resources for verifying certifications and the self-certification process.
Author: European Commission
Status: Adopted / Published
Adoption date: 2024-07-16
Last updated: 08 Aug 2025
Category: Miscellaneous
Subcategory: Information note