Compliance Briefing — EU adopts Data Privacy Framework adequacy decision
The European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework on 10 July 2023, reinstating a legal basis for transatlantic personal data flows to certified U.S. companies.
On 10 July 2023 the European Commission issued an adequacy decision for the EU-U.S. Data Privacy Framework (DPF), enabling personal data transfers to participating U.S. organizations that commit to the framework’s privacy principles. The decision followed U.S. executive actions establishing a Data Protection Review Court and limits on signals intelligence, addressing Schrems II concerns.
Controllers relying on the DPF must verify vendor certification via the U.S. Department of Commerce list and update contracts and privacy notices accordingly. Non-certified transfers still require alternative safeguards such as standard contractual clauses with supplementary measures.
- European Commission press release announces the adequacy decision and oversight mechanisms.
- Official Journal decision provides the legal text and requirements for certified organizations.
Continue in the Compliance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Third-Party Risk Oversight Playbook — Zeph Tech
Operationalize OCC, Federal Reserve, EBA, and MAS outsourcing expectations with lifecycle controls, continuous monitoring, and board reporting.
-
Compliance Operations Control Room — Zeph Tech
Implement cross-border compliance operations that satisfy Sarbanes-Oxley, DOJ guidance, EU DORA, and MAS TRM requirements with verifiable evidence flows.
-
SOX Modernization Control Playbook — Zeph Tech
Modernize Sarbanes-Oxley (SOX) compliance by aligning PCAOB AS 2201, SEC management guidance, and COSO 2013 controls with data-driven testing, automation, and board reporting.




