Insight

Using US software under the GDPR: the EU-US Data Privacy Framework and what still needs checking

Since July 2023, personal data can flow from the EU to US companies certified under the EU-US Data Privacy Framework without additional transfer tools. That simplified the use of many US software providers, but it covers only certified organisations and does not replace the other GDPR obligations.

Published by Somnium Digital

A wireframe of the Insight page: headline, supporting sections and a single call to action. Insight US software and the Data Privacy… Get in touch 01 Why transfers to the… 02 The Data Privacy Fram… 03 What certification co…

Why transfers to the US became difficult

The GDPR restricts transfers of personal data to countries outside the European Economic Area unless the destination provides adequate protection or appropriate safeguards are in place. For years, transfers to the United States relied on frameworks negotiated between the EU and the US.

The Court of Justice of the EU invalidated the Safe Harbor framework in 2015 in the Schrems I judgment and the Privacy Shield in 2020 in the Schrems II judgment, largely because of concerns about access to data by US intelligence services and the lack of effective redress for Europeans. After Schrems II, companies relied mainly on standard contractual clauses combined with transfer impact assessments, and several European data protection authorities found specific uses of US analytics tools unlawful.

The Data Privacy Framework

On 10 July 2023 the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework. It followed a US executive order that introduced limits on signals intelligence activities and a redress mechanism, including a Data Protection Review Court.

Under the decision, personal data can be transferred from the EU to US organisations that have self-certified to the framework with the US Department of Commerce, without standard contractual clauses or other transfer tools. Organisations commit to privacy principles, and certification is listed publicly on the Data Privacy Framework website.

The UK adopted a comparable arrangement, the UK Extension to the Data Privacy Framework, from October 2023, and Switzerland recognised the Swiss-US Data Privacy Framework in 2024. The framework has been challenged in the EU courts. In September 2025 the EU General Court dismissed an action seeking its annulment, but further legal challenges remain possible, so companies should keep watching developments.

What certification covers and what it does not

The adequacy decision only applies to US organisations actively certified under the framework, and only for the types of data covered by their certification. Certification can cover non-HR data, HR data or both. A provider’s parent company being certified does not automatically mean every subsidiary or service is covered.

The framework also concerns transfers only. Using a certified US CRM, email platform or analytics tool still requires a lawful basis for processing, transparent privacy information, a data processing agreement where the provider acts as a processor, appropriate security, data minimisation and respect for data subject rights. Cookie and tracking consent rules also continue to apply separately.

Check certification
Search the official Data Privacy Framework list for the provider’s exact legal entity and confirm the status is active.
Check scope
Confirm the certification covers the type of data you transfer, such as customer data or employee data.
Check subprocessors
Review where the provider’s own subprocessors are located and which safeguards apply to them.
Keep contracts
Maintain data processing agreements and, as a fallback, standard contractual clauses where providers include them.

When other safeguards are still needed

Transfers to US companies that are not certified still need another transfer mechanism, typically the European Commission’s standard contractual clauses from 2021, with an assessment of the transfer. Transfers to other countries without adequacy decisions also still need safeguards.

Many large providers keep standard contractual clauses in their data processing agreements alongside certification. This provides continuity if the framework were ever invalidated, as its predecessors were. Businesses should know which mechanism each important provider relies on and what would change if one fell away.

Practical steps for marketing and sales teams

Start with an inventory of tools that process personal data: CRM, email marketing, marketing automation, analytics, advertising platforms, customer support, scheduling, video conferencing, form builders and AI tools. For each, record the provider entity, where data is stored, whether data is transferred outside the EEA, and the transfer mechanism.

Update the privacy notice to describe transfers accurately, including the use of the Data Privacy Framework or other safeguards. Configure tools to minimise data, for example by avoiding unnecessary personal data in analytics and removing old contacts from marketing systems.

Where data is especially sensitive, such as health, legal or financial information, consider whether EU data residency options, EU providers or additional encryption reduce risk. The framework makes transfers lawful where it applies, but it does not change how sensitive the data is or how carefully it should be handled. This article is a general overview and not legal advice.

Questions

When was the EU-US Data Privacy Framework adopted?

The European Commission adopted the adequacy decision on 10 July 2023.

Can we use any US software now without extra safeguards?

Only for transfers to US organisations actively certified under the framework, within the scope of their certification.

How do we check whether a provider is certified?

Search the official Data Privacy Framework list for the provider’s legal entity and confirm the certification is active and covers the relevant data.

Does certification make a tool GDPR-compliant?

No. It addresses transfers only. Lawful basis, transparency, processor agreements, security and consent rules still apply.

What about providers that are not certified?

Transfers to them need another mechanism, usually standard contractual clauses with a transfer assessment.

Does the framework cover the UK and Switzerland?

The UK and Switzerland have their own arrangements linked to the framework: the UK Extension and the Swiss-US Data Privacy Framework.

Could the framework be invalidated?

Legal challenges remain possible, which is why many companies keep standard contractual clauses as a fallback.

Where this sits in what we do

This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.

Not sure where your customer data goes?

We map the tools in your marketing and sales stack, document transfers and data locations, and reconfigure systems to collect only what you need.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp