Pillar guide

EU-US Data Privacy Framework: what universities need to know (2026)

Most universities rely on US software, and for many US vendors the EU-US Data Privacy Framework is the transfer route. This guide explains what the adequacy decision covers, how to check a vendor's entry on the DPF List properly, where the legal challenges stand on 7 October 2026, how the Commission reviews the framework, and what to put in contracts in case it stops applying.

Published 7 October 2026 · Sources checked 7 October 2026

The short version

Contents

  1. What the Data Privacy Framework is
  2. What it covers, and what it does not
  3. How to check a vendor on the DPF List
  4. HR data: why coverage matters for staff data
  5. Legal challenges: Latombe and the appeal
  6. Reviews and monitoring by the Commission
  7. What to put in contracts as a fallback
  8. Practical checklist
  9. Sources
  10. About this page

1. What the Data Privacy Framework is

Article 1 of Commission Implementing Decision (EU) 2023/1795 states that, for the purpose of Article 45 GDPR, the United States ensures an adequate level of protection for personal data transferred from the Union to organisations in the US "that are included in the 'Data Privacy Framework List'", maintained and published by the US Department of Commerce [1]. The EDPB confirms that, since 10 July 2023, transfers to listed organisations may be based on the decision without an Article 46 tool, and do not need supplementary measures [2].

The framework is a self-certification scheme. US organisations publicly commit to the DPF Principles, publish a privacy policy that reflects them, and must re-certify every year [1]. The decision followed US Executive Order 14086, which introduced new safeguards for signals intelligence and a redress mechanism that includes the Data Protection Review Court. The Commission says these national security safeguards apply to all transfers to US companies under the GDPR, whatever transfer tool is used [3]. The decision also covers the EEA states [1].

The DPF is the third attempt at a general EU-US arrangement. The Court of Justice invalidated Safe Harbour in 2015 and the Privacy Shield in Schrems II on 16 July 2020 [4]. That history is why universities should treat the DPF as reliable today but not permanent.

2. What it covers, and what it does not

SituationDPF applies?Why
US vendor's own entity is on the List with an active EU-U.S. DPF certification covering the dataYesArticle 1 of the decision.
US subsidiary of a certified parentOnly if coveredThe EDPB says exporters must check that the parent's certification also covers the subsidiary concerned [5].
Staff data (employment context) sent to a vendor certified for non-HR data onlyOnly with a commitmentSee section 4.
Organisation removed from the List or whose certification lapsedNoThe EDPB says exporters cannot rely on the DPF for companies without an active self-certification [5].
US universities and other non-profits outside FTC jurisdictionGenerally noOnly organisations subject to the FTC or the Department of Transportation can certify; the EDPB names non-profits, banks, insurers and telecoms common carriers as examples that cannot [5].
Non-US sub-processors of a US vendorNoThe DPF covers transfers to the US. Onward transfers elsewhere need their own route.

Two further points are easy to miss. First, the DPF answers only the Chapter V question. The EDPB stresses that all other GDPR requirements remain, including an Article 28 agreement with a US processor "regardless of whether the processor is self-certified" [5]. Second, the EDPB says the decision does not cover transfers by entities outside the EU that are subject to the GDPR only through Article 3(2) [2]. The DPF List also shows the separate UK Extension and the Swiss-U.S. DPF; for an EU university, the line that matters is "EU-U.S. Data Privacy Framework" [6].

Validemic's analysis The non-profit point matters for research. A data sharing agreement with a US university partner will usually need SCCs (or another Chapter V tool) and a transfer impact assessment, even if every commercial tool in the project is DPF certified. Our TIA template covers that case.

3. How to check a vendor on the DPF List

The EDPB says that before transferring under the DPF, an exporter "must ascertain" that the US company holds an active self-certification and that it covers the data in question, by checking the DPF List [5]. A statement in a privacy policy is not enough. On the List (dataprivacyframework.gov/list), each participant's full profile shows, per framework, the participation status, the original certification date, the next certification due date, and whether HR data, non-HR data or both are covered. Profiles also list other covered US entities, the purpose of data collection, the privacy policy, the verification method and the recourse mechanisms [6].

  1. Identify the receiving entity. Take the legal name from the DPA or subprocessor list, not the brand. A European contracting entity is often not the US entity that processes the data.
  2. Search the List and open the full profile. Confirm the entity, or check that it appears under "Other Covered Entities" of a certified parent.
  3. Check the EU-U.S. line. The status must be active for the EU-U.S. Data Privacy Framework specifically.
  4. Check the data covered. Non-HR data, HR data or both. Match it to what you will send.
  5. Note the next certification due date. Certifications must be renewed annually; diarise a re-check.
  6. Check the inactive list if the vendor is missing. The EDPB notes the List includes removed companies and the reasons for removal [5].
  7. Record the check. Screenshot or save the profile, with the date, in the vendor file and the ROPA.

Validemic's analysis Some profiles on the check date showed the status "Active - Re-certification under Review". We did not find an official definition of that label. We read it as an active certification whose annual renewal is being processed, but record it as shown and re-check later. Our transfer mechanism tool walks through the DPF question alongside adequacy and SCC modules, and our vendor fact sheets, for example ChatGPT, Zoom and Microsoft Copilot, record the DPF position we found for each vendor.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

4. HR data: why coverage matters for staff data

The DPF can cover any type of personal data, including human resources data collected in the context of an employment relationship, "as long as" the US company is certified to process that type of data [5]. Organisations that want HR data covered must commit to cooperate with EU data protection authorities and comply with their advice for that data [1]. In the Commission's first review, 60% of certified companies were certified only for non-HR data, 2.5% only for HR data and 37.5% for both [7].

The EDPB's FAQ for European businesses (version 2.0, adopted 15 January 2026) says that when an exporter intends to transfer HR data, it must ensure that the US company either holds an active certification covering it as HR data, or holds an active certification covering it as another type of personal data and has committed in its privacy policy to cooperate with, and follow the advice of, EU data protection authorities for that data. The exporter must also tell the US company that the transfer includes HR data [5].

Validemic's analysis For universities this affects more tools than payroll. Staff evaluations in a learning platform, an HR survey, recruitment software, staff accounts in a collaboration tool and occupational health systems can all involve employment-context data. When the processing involves staff data, check the HR column, not just the green "Active" label. If coverage is missing and the vendor has made no commitment to cooperate with EU authorities, use SCCs for that data.

5. Legal challenges: Latombe and the appeal

General Court, 3 September 2025 (T-553/23)

Philippe Latombe, a French citizen, asked the General Court to annul the decision, arguing that the Data Protection Review Court is not independent of the executive and that bulk collection of data in transit from the EU without prior authorisation is unlawful. The General Court dismissed the action. It found that appointment and functioning of DPRC judges are accompanied by safeguards ensuring independence, and that Schrems II does not require bulk collection to be authorised in advance by an independent authority; ex post judicial review by the DPRC was sufficient. It also noted that the Commission must monitor the US framework continuously and may suspend, amend or repeal the decision if it changes [8].

Court of Justice appeal (C-703/25 P): pending

Mr Latombe lodged an appeal on 31 October 2025. He asks the Court of Justice to set aside the judgment and annul the decision, or in the alternative to refer the case back to the General Court. The published summary lists four grounds of appeal, including the independence of the DPRC, whether the DPRC is a tribunal "previously established by law", and the absence of prior authorisation for bulk collection. The other parties named are the Commission, Ireland and the United States [9].

On 7 October 2026 the Court's InfoCuria case page shows the case as pending. The documents listed are the published appeal (22 December 2025) and an order of the President of the Court of 4 June 2026 (ECLI:EU:C:2026:465) [10]. That order, available in French, admitted Microsoft Corporation to intervene in support of the Commission, and lists Germany, Ireland and the United States as interveners at first instance supporting the Commission. It also notes that the General Court, having dismissed the action on the merits, did not rule on whether Mr Latombe's action was admissible [11]. We found no Advocate General's opinion or judgment listed on the check date.

The outcome is not predictable, and nothing in the pending appeal suspends the decision. Until the Court rules otherwise, the adequacy decision applies. We will update this page when the case moves.

Other developments to watch

On 31 July 2026 the EDPB wrote to Commissioner McGrath about the US Supreme Court's judgment of 29 June 2026 in Trump v. Slaughter, which overruled Humphrey's Executor and held that FTC Commissioners are subject to the President's power of removal. The EDPB pointed out that the adequacy decision refers explicitly to the independence of the FTC, and asked the Commission to "closely assess" whether the judgment affects the decision [12]. We did not find a published Commission response on the check date.

6. Reviews and monitoring by the Commission

Article 3 of the decision requires the Commission to monitor the US framework continuously, including onward transfers, individual rights and access by US public authorities. The first review was due one year after notification, with later reviews at a periodicity decided with the EDPB and the Article 93 committee. Where the Commission has indications that adequate protection is no longer ensured, it can suspend, amend or repeal the decision, or limit its scope [1].

The first review report (COM(2024) 451, 9 October 2024) concluded that the US had put in place the structures and procedures needed for the framework to function effectively. It said the Commission would watch reports of the Privacy and Civil Liberties Oversight Board, further changes to Section 702 FISA and appointments to the PCLOB, and asked the Department of Commerce, the FTC and EU authorities to develop common guidance, for example on HR data and onward transfers. It considered it appropriate to carry out the next periodic review after three years [7].

Validemic's analysis That timetable points to a second review around late 2027, but the Commission can act earlier. Treat any Commission announcement on the DPF, and the judgment in C-703/25 P, as triggers to re-check your US transfers.

7. What to put in contracts as a fallback

The decision itself shows what happens when an organisation withdraws or fails to re-certify: it must delete or return the data, or keep it only if it affirms annually that it continues to apply the Principles or provides adequate protection by another authorised means, such as a contract reflecting the Commission's standard contractual clauses [1]. A university does not need to wait for that. Common contract clauses are:

Validemic's analysis With SCCs already in place, the work left if the DPF falls is the transfer impact assessment. The EDPB has said that, when assessing an Article 46 tool for the US, exporters should take into account the Commission's assessment in the adequacy decision, since the US national security safeguards apply regardless of the tool [2]. How far that would still hold after an annulment would depend on the Court's reasons. Our DPA checker helps confirm whether a vendor's DPA already contains the clauses.

8. Practical checklist

  1. List every US recipient of personal data, including sub-processors and support locations.
  2. For each one, check the DPF List for the exact entity: active EU-U.S. status, HR or non-HR coverage, next certification due date. Save the evidence.
  3. For staff data, confirm HR coverage or a privacy policy commitment to cooperate with EU authorities, and tell the vendor the transfer includes HR data.
  4. For non-certified recipients (including US universities), put SCCs in place and complete a transfer impact assessment.
  5. Make sure every US processor has signed an Article 28 DPA, certified or not.
  6. Add SCCs as a fallback in each DPA that relies on the DPF, plus a duty to notify loss of certification.
  7. Update privacy notices: controllers must tell data subjects about the recipients and that the transfer relies on the adequacy decision [5].
  8. Record the transfer route in the ROPA (Article 30(1)(e)); see our ROPA template.
  9. Diarise re-checks: each vendor's certification due date, the C-703/25 P judgment, and the Commission's next review.
  10. Fold all of this into your vendor assessment process, so the check happens at intake and renewal.

Sources

  1. Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework, Articles 1 and 3, recitals and Annex I (retrieved 7 October 2026).
  2. EDPB Information note on data transfers under the GDPR to the United States after the adoption of the adequacy decision on 10 July 2023 (retrieved 7 October 2026).
  3. European Commission: EU-US data transfers (retrieved 7 October 2026).
  4. Court of Justice, Judgment of 16 July 2020, Case C-311/18, Facebook Ireland and Schrems (retrieved 7 October 2026).
  5. EDPB: EU-U.S. Data Privacy Framework F.A.Q. for European businesses, version 2.0, adopted 15 January 2026 (retrieved 7 October 2026).
  6. US Department of Commerce: Data Privacy Framework List, including participant profiles (retrieved 7 October 2026).
  7. Report from the Commission on the first periodic review of the functioning of the adequacy decision on the EU-US Data Privacy Framework, COM(2024) 451, 9 October 2024 (retrieved 7 October 2026).
  8. Court of Justice of the European Union, Press release No 106/25: Judgment of the General Court in Case T-553/23, Latombe v Commission, 3 September 2025 (retrieved 7 October 2026).
  9. Appeal brought on 31 October 2025 by Philippe Latombe against the judgment of the General Court in Case T-553/23 (Case C-703/25 P), OJ C/2025/6610, 22 December 2025 (retrieved 7 October 2026).
  10. InfoCuria: Case C-703/25 P, Latombe v Commission, case overview (retrieved 7 October 2026).
  11. Ordonnance du président de la Cour du 4 juin 2026, Latombe / Commission, C-703/25 P, ECLI:EU:C:2026:465, read in French on InfoCuria (retrieved 7 October 2026).
  12. EDPB letter to the European Commission on US Supreme Court judgment Trump v. Slaughter, 31 July 2026 (retrieved 7 October 2026).
  13. Commission Implementing Decision (EU) 2021/914 on standard contractual clauses, Clauses 14 to 16 (retrieved 7 October 2026).
  14. European Commission: Adequacy decisions (retrieved 7 October 2026).

About this page

Sources checked on 7 October 2026. The adequacy decision and the published appeal were read in their Official Journal versions; the case status was read on the Court's InfoCuria site, where the 4 June 2026 order was available in French only; EDPB and Commission documents were read on their own sites; the DPF List was read on dataprivacyframework.gov. That the decision is in force was confirmed on the Commission's adequacy list [14]. Statements labelled as Validemic's analysis are our interpretation. This page is not legal advice. Court cases and adequacy decisions change: if you spot an error or a development we have missed, please contact us and we will correct it.

Frequently asked questions

Is the EU-US Data Privacy Framework still valid in 2026?

Yes. On 7 October 2026 Commission Implementing Decision (EU) 2023/1795 is in force and appears on the Commission's list of adequacy decisions. The General Court dismissed an action to annul it on 3 September 2025 (T-553/23). An appeal to the Court of Justice, Case C-703/25 P, is pending.

How do I check whether a US vendor is DPF certified?

Search the Data Privacy Framework List on dataprivacyframework.gov for the exact legal entity that will receive the data. Check that its EU-U.S. DPF participation is active, that the covered data includes the type you will send (HR or non-HR), that any subsidiary involved is listed as a covered entity, and record the date of your check.

What does HR data mean in the DPF?

Human resources data collected in the context of an employment relationship. Not every certification covers it. The EDPB says that for staff data the US company must hold an active certification covering HR data, or a certification for other data plus a commitment in its privacy policy to cooperate with EU data protection authorities for that data.

Can a US university join the Data Privacy Framework?

Usually not. Only organisations subject to the investigatory and enforcement powers of the FTC or the US Department of Transportation can self-certify, and the EDPB notes that non-profit organisations outside the FTC's jurisdiction cannot. Transfers to most US universities, for example in research collaborations, therefore need SCCs or another Chapter V tool.

Do we still need a DPA with a DPF-certified vendor?

Yes. The EDPB says an Article 28 data processing agreement is required whether or not the US processor is certified. The DPF only addresses the Chapter V transfer question.

What happens if the Court of Justice annuls the DPF?

Transfers that rely only on the adequacy decision would need another Chapter V tool, usually standard contractual clauses with a transfer impact assessment. That is why many institutions keep SCCs in the contract as a fallback that applies if the vendor's certification or the decision stops applying.

When will the Commission next review the DPF?

In its first review report of 9 October 2024 the Commission said it considered it appropriate to carry out the next periodic review after three years. It also monitors the framework continuously and can suspend, amend or repeal the decision.