Recertification is where DPF programs quietly die. The initial certification gets counsel, attention, and a project plan; the anniversary gets a portal reminder forwarded to someone who left the company. The stakes are asymmetric: renewing costs a policy review and a fee, while lapsing costs the adequacy basis for your EU flows and, if the privacy policy keeps claiming participation, hands the FTC its favorite deception case, one where the violation is provable from your own website and the List’s public records. The fix is administrative discipline: a named owner, a 90-day runway, a verification signed before the attestation, and a policy diff that treats every sentence about the DPF as a claim someone will eventually test.
| Cycle | Annual, by certification anniversary |
|---|---|
| Prerequisite | Signed verification (self-assessment or outside review) |
| Re-check | Policy accuracy, covered entities, recourse registration, UK/Swiss elections |
| Lapse cost | List removal + sticky Principles + misrepresentation exposure |
| FTC pattern | Lapsed certifier, live participation claim |
| Portal | dataprivacyframework.gov |
Running the annual cycle
Assign an owner and a runway. Sixty to ninety days out: policy diff, entity reconciliation, recourse renewal; the certification requirements define what must still be true.
Sign the verification first. The officer’s attestation certifies present compliance; the self-assessment or outside review is the evidence behind it.
Reconcile the framework trio. EU, UK Extension, and Swiss elections each need matching policy language and entity mapping.
Pre-plan the exit you may never take. If lapse or withdrawal ever becomes strategy, the claim-scrubbing and SCC fallback work is a same-week job, not an afterthought.
Policy-to-practice reconciliation starts with knowing your actual data flows: map what your site collects with a free scan.