Commission Implementing Decision (EU) 2023/1795 of 10 July 2023
- Document
- 10 July 2023
- Event
- 10 July 2023
- Retrieved
- 16 September 2026
The workload
A US company that wants a lawful basis for receiving personal data from the EU has, since 10 July 2023, had a second path beside negotiating and executing the Standard Contractual Clauses this site already covers. The European Commission's own page on EU-US data transfers, retrieved 16 September 2026, states that on 10 July the Commission adopted its adequacy decision for the EU-US Data Privacy Framework, after which personal data can flow to a US company that participates in it. The work is self-certification to the US Department of Commerce, not a Brussels filing: the company declares its commitment to the Framework's Principles, publishes a conforming privacy policy, and waits to be placed on the public Data Privacy Framework List before it may rely on the decision.
What the documents show
Verified, from Commission Implementing Decision (EU) 2023/1795 of 10 July 2023: an organization may only receive personal data on the basis of the Framework from the date it is placed on the DPF list by the Department of Commerce, must be subject to the FTC's or the Department of Transportation's enforcement jurisdiction, and must re-certify its adherence annually. Verified: the Commission's own transfers page frames the Framework as an addition alongside SCCs, not a replacement; a company remains free to use SCCs instead, including for a US recipient not on the DPF list. Editorial note this entry must carry rather than assume: this Framework's two predecessors, Safe Harbor and Privacy Shield, were each invalidated by the Court of Justice of the EU after legal challenge, and a challenge to this Framework's own adequacy decision has been lodged before the EU courts; this entry does not state a current outcome of that litigation because the court's own case record was not reachable when this entry was retrieved.
The operating cost
The decision itself states no certification fee; the Department of Commerce's own program, not the Commission's decision, sets any enrollment cost, and this entry does not restate a figure it has not independently verified here. The recurring cost the decision does verify is annual re-certification of adherence to the Principles, for as long as the company wants to keep relying on the Framework rather than SCCs.
The stop condition
Editorial: reliance on the Framework stops, on the Decision's own terms, if the company is removed from the DPF list for failing to re-certify or for a compliance finding, at which point it would need SCCs or another mechanism to keep the same transfers lawful.
- Is the receiving US entity actually listed on the current Data Privacy Framework List, not merely claiming to have applied?
- Has the annual re-certification deadline been calendared, given that lapsing removes the legal basis for transfers already underway?
- Given the predecessors' history, is a fallback SCC arrangement ready if this Framework's own adequacy decision is later set aside?
The Commission's decision gives a US-side company a Brussels-facing shortcut; it does not retire the clauses-based path the site already documents, and the two mechanisms' histories argue for keeping both options live rather than assuming either is permanent.
Sources & reading trail
The adequacy decision's own text: DPF List placement, FTC/DoT jurisdiction requirement, and annual re-certification.
Source published: 10 July 2023 · Retrieved: 16 September 2026
The Commission's own confirmation of the 10 July 2023 adoption date and that participation is by self-certification.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.