← All articles

consultant

US DPF: adequacy adopted, EDPB caution and CNPD guidance

On 10 July 2023, the Commission adopted the EU‑US DPF adequacy decision (GDPR art. 45). The EDPB urges caution and the CNPD sets practical checks: verify certification and scope (incl. HR) and keep a fallback plan.

Verified fact — On 10 July 2023, the European Commission adopted the EU‑US Data Privacy Framework adequacy decision (GDPR art. 45). The EDPB took note but flagged points of attention in 2023 and in its first 2025 report. For Luxembourg groups, these must be reconciled with the CNPD’s 2025 guidance.

The case

On 10 July 2023, the Commission adopted Implementing Decision (EU) 2023/1795 finding that transfers to US organisations certified under the Data Privacy Framework (DPF) ensure an adequate level of protection under GDPR Article 45. The decision relies on Executive Order 14086 and the redress mechanism (Data Protection Review Court). Official sources: Commission Decision 2023/1795, 10/07/2023 and additional extracts (incl. urgency clauses, recitals (220) et seq.) on EUR‑Lex.

In April 2025, the CNPD updated its “International transfers” guidelines, including a dedicated factsheet on “Transfers to the United States under the DPF” stating that transfers to entities on the DPF List may rely on Article 45 GDPR without additional Article 46 measures, while reminding controllers of required checks (HR coverage, certification scope, Article 28 contract if processor). See the CNPD news 04/2025 and the thematic page CNPD — DPF USA.

The EDPB, in Opinion 5/2023, welcomed progress but raised concerns (US authorities’ access, independence and effectiveness of redress). After adoption, it issued an information note and, in 2025, a first follow‑up report, stressing vigilance on the practical implementation of safeguards.

Legal reasoning

  • Legal basis: GDPR Article 45 permits transfers to third countries covered by an adequacy decision. Decision 2023/1795 concludes that US organisations certified under the DPF ensure an “adequate” level of protection. DPF principles and safeguards (EO 14086, necessity/proportionality, Data Protection Review Court) are central. EUR‑Lex, 2023/1795. For a refresher on the legal basis, see GDPR Article 45.
  • EDPB view: before adoption, the EDPB (Opinion 5/2023) highlighted uncertainties (scope of “necessity and proportionality” under US law, independence/effectiveness of redress, deletion). After adoption, the EDPB did not challenge adequacy but issued an info note (07/2023) and a first report (2025) urging verification of certification, scope (notably HR data coverage), and the operational reality of safeguards and redress. Refs: Opinion 5/2023; Information note; 2025 report.
  • CNPD view: the CNPD aligns with Article 45 and provides a practical checklist: confirm presence on the DPF List, assess scope (including HR data, not always included), keep an Article 28 processor agreement where applicable, and do not apply adequacy to non‑certified entities (then rely on Article 46 SCC/BCR and, if needed, supplementary measures). See CNPD — DPF factsheet and news 04/2025.
  • Practical divergence: the Commission recognises compliance “in principle” (Art. 45), while the EDPB, as GDPR guardian and coordinator, calls for strengthened oversight of implementation. This does not block DPF use, but requires added diligence for Luxembourg controllers.

What this changes in Luxembourg

  • US DPF‑certified SaaS: for CRM, helpdesk or analytics on the DPF List, a Luxembourg controller may rely on Article 45 without a TIA or “EDPB 01/2020” supplementary measures. They must evidence: certification check (legal entity, covered services), validity/date, HR data coverage if relevant, and an Article 28 contract if the provider is a processor. See CNPD — DPF USA. To operationalise these checks, a certified DPO mandate can strengthen day‑to‑day governance.
  • Recipient not on the List: if the US recipient is not on the DPF List, adequacy does not apply: use an Article 46 tool (SCC 2021/914, BCR) and, if needed, supplementary measures (encryption, data splitting), consistent with the “post‑Schrems II” approach. The EDPB stresses that DPF does not “cascade” to non‑certified sub‑processors. Information note 07/2023.
  • Governance: keep your record (Art. 30) updated with the transfer tool (Art. 45 vs 46), DPF status, and the legal relationship (Art. 28 if processor). Retain dated proof of DPF List checks and certification scope. For local alignment, see GDPR Luxembourg compliance.
  • Plan for reversibility: Decision 2023/1795 includes an urgency clause allowing the Commission to suspend or repeal adequacy if US safeguards are weakened (recital 220). Keep SCC “plan B” ready for critical services. Ref.: EUR‑Lex, 2023/1795, recital (220).

Frequent pitfalls

  1. “DPF covers all US flows” — False. Adequacy applies only to the listed entity and declared scope. Unlisted affiliates or uncertified downstream processors require Art. 46 (SCC/BCR). Ref.: EDPB, Information note 07/2023.
  2. Forgetting HR data — Many self‑certifications exclude “HR data”. An external HRIS, ATS or US payroll tool often processes HR data: without HR coverage, no Art. 45; revert to SCCs. CNPD and EDPB explicitly recall this. Refs: CNPD — DPF USA; EDPB FAQ 2024/2025.
  3. Overlooking Article 28 — Even under DPF, if the US provider acts as processor, a GDPR‑compliant Data Processing Agreement remains mandatory (purpose, duration, security, onward processing, audits). Ref.: CNPD — international transfers guidelines (PDF).
  4. No evidence of checks — In a CNPD audit, you must show when/how you verified the DPF List, certification scope and redress commitments. Document and timestamp (screenshot, URL, version). Ref.: CNPD — DPF USA.
  5. Ignoring reversibility — Adequacy may change (review, suspension). Prepare fallback clauses (pre‑negotiated SCCs), an exact flow inventory and strong encryption for sensitive data in transit and at rest. Ref.: EUR‑Lex, 2023/1795, recital (220).

In short

Managed divergence: the Commission reopened a direct path (Art. 45) to US DPF‑certified providers; the EDPB and CNPD emphasise precise documentary controls (certification and scope), ongoing vigilance and fallback plans.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →