Skip to content
DPAFlow

schrems-ii

How to Verify a US Vendor's Data Privacy Framework Certification

A certification claim can remove the need for Standard Contractual Clauses, or be true in general and inapplicable to your transfer. Five checks: the entity, currency, scope, the receiving party, and whether a fallback exists.

If a United States vendor tells you it is certified under the EU-US Data Privacy Framework, that statement can remove the need for Standard Contractual Clauses and for a transfer assessment. It can also be true in general and inapplicable to your specific transfer. The difference is worth ten minutes of checking, because getting it wrong means operating without a valid transfer mechanism while believing you have one.

This article sets out the checks to run, in order, and what to record. The broader transfer sequence is in our international data transfer checklist, and the Schrems II background is in Schrems II transfers for smaller organizations.

What the framework actually provides

In Implementing Decision (EU) 2023/1795, adopted on 10 July 2023, the European Commission found that the United States ensures an adequate level of protection for personal data transferred to organizations certified under the EU-US Data Privacy Framework.

The consequence is narrow and precise. Transfers to a certified organization, for data within the scope of its certification, rest on an adequacy decision under Article 45 of the General Data Protection Regulation (GDPR). They do not require Article 46 safeguards, and the assessment obligation attached to those safeguards is not triggered.

Everything outside that scope is unchanged. Transfers to United States organizations that are not certified, and transfers to every other third country, still need a mechanism from the ordinary toolbox.

The five checks

1. Is the organization actually on the list?

Certification is verifiable on the public list maintained by the United States Department of Commerce. Check the entity, not the brand. Corporate groups frequently certify one legal entity while contracting through another, and the certification follows the entity.

Match the name on the list against the name on your contract. A mismatch is not necessarily fatal, but it needs explaining before you rely on it.

2. Is the certification current?

Certifications must be maintained and can lapse or be withdrawn. An organization that has allowed its certification to expire, or has withdrawn from the framework, is no longer covered, and transfers relying on it lose their basis at that point.

Record the date you checked. That date is what makes your position defensible if the status changes later.

3. Does the scope cover your data?

This is the check most often skipped. A certification covers specified categories of data, and human-resources data is treated separately: an organization that has not extended its certification to human-resources data cannot receive it under the framework.

If you are sending employee data to a vendor certified only for non-human-resources data, the framework does not cover that transfer.

4. Does it cover the entity that actually receives the data?

Your contracting party may be an Irish or other European entity that then transfers onward to a United States parent or affiliate. In that case the relevant question is what covers the onward leg, and whether that recipient is itself certified.

The same applies to the vendor's sub-processors. A certified vendor using a non-certified United States sub-processor has an onward transfer that needs its own basis, as our article on Standard Contractual Clauses and sub-processors explains.

5. Is there a fallback if the position changes?

Many Data Processing Agreements layer Standard Contractual Clauses beneath the framework so that a lapse in certification, or a change in the adequacy decision, does not leave the transfer unsupported. Check whether yours does. Where it does not, knowing which vendors would need an assessment at short notice converts a possible future problem into a list.

Status, and why it warrants monitoring

As of July 2026 the adequacy decision remains in force. It has, however, been contested: the EU General Court dismissed an action seeking its annulment in September 2025, and an appeal against that ruling is pending before the Court of Justice.

Separately, in June 2026 the United States Supreme Court held that statutory removal protections for Federal Trade Commission commissioners are unconstitutional. The Commission's adequacy analysis referred to the Federal Trade Commission as an independent enforcement authority, so the ruling has prompted scrutiny of whether the conditions underpinning the finding continue to hold.

Neither development changes the legal position by itself. An adequacy decision stands until the European Commission repeals it or the Court of Justice annuls it. What both establish is that this is a mechanism whose status should be re-verified periodically rather than recorded once, and that vendors relying solely on it are worth identifying in advance.

What to record

For each vendor you clear on this basis, retain:

  • The certified entity name as it appears on the public list.
  • The certification status and the date you verified it.
  • The data categories covered, including whether human-resources data is in scope.
  • Confirmation that the contracting entity and the receiving entity align.
  • The fallback mechanism, if the contract provides one.
  • The date for the next re-verification.

Capture the evidence rather than linking to it, since the underlying pages change. Our article on audit-ready vendor evidence covers the standard.

Frequently asked questions

Do we still need a transfer assessment for a certified vendor?

Not for transfers genuinely covered by the adequacy decision, because adequacy-based transfers do not rest on Article 46 and the associated assessment warranty is not engaged. You should still track whether the decision remains in force.

What about United Kingdom transfers?

The United Kingdom operates its own regime, which includes an extension arrangement covering framework-certified United States organizations. Transfers from the United Kingdom rely on United Kingdom mechanisms and should be checked under that regime separately, using guidance from the Information Commissioner's Office on international transfers.

How often should we re-verify?

At least at each scheduled vendor review, and whenever the vendor changes its corporate structure or its published disclosures. Certification status is a fact that can change without any notice to you.

What if a vendor's certification lapses?

The framework no longer supports the transfer from that point. You would need another mechanism, typically Standard Contractual Clauses with an assessment, which is why the fallback question is worth settling before it happens.

Where DPAFlow fits in

Certification status, corporate structure, and sub-processor chains all change on the vendor's side and generate no signal in yours. DPAFlow checks vendor sub-processor lists, Data Processing Agreement pages, and trust-center pages on a scheduled, recurring basis, records what changed with dated evidence including captured page text and change differences, and sends email alerts. Detected changes enter a review workflow where your team decides whether the transfer basis needs revisiting.

DPAFlow does not verify certifications on your behalf and does not provide legal advice. The transfer assessment module is described on the transfer impact assessment page.

This article describes verification steps, not legal advice. The transfer conclusions belong to your privacy function and counsel, and the framework's status should be confirmed at the time you rely on it.

DPAFlow · 2026-07-25

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow