The DPF is the third attempt at the same bargain, Safe Harbor fell in 2015, Privacy Shield in 2020, and each collapse taught the same lesson: the framework’s survival depends on US surveillance safeguards no certifier controls. What a certifying company does control is its own paperwork, and that is where the real enforcement lives: the FTC’s DPF docket is mostly companies that let certifications lapse while their privacy policies kept claiming participation, plus notice and onward-transfer failures that a competent annual review would have caught. Certify if you are eligible, run the recertification calendar like a compliance deadline rather than a renewal notice, and keep SCCs warm underneath, because transatlantic transfer law has never stayed settled for a full decade.
| Mechanism | Adequacy decision (July 10, 2023) + self-certification |
|---|---|
| Eligible | FTC/DOT-jurisdiction entities only |
| Core duties | 7 Principles + 16 supplemental; conforming privacy policy; free recourse mechanism |
| Enforcement | FTC Section 5; List removal; binding arbitration; DPRC for intelligence access |
| Sticky rule | Principles follow DPF data even after withdrawal |
| Portal | dataprivacyframework.gov |
Making certification stick
Write the policy before the application. The conforming privacy policy is a prerequisite, and its claims are the FTC’s evidence; the annual recertification cycle starts from what it says.
Paper the onward transfers. Every processor and third party receiving DPF data needs Principle-level contract terms, the same discipline as GDPR controller-processor agreements.
Track the litigation weather. Schrems III-style risk is structural; keep SCCs as fallback and know which flows switch to what.
Extend deliberately. The UK Extension and Swiss-US DPF are separate elections with their own policy language.
DPF notice obligations start with what your site actually collects: verify your data flows with a free scan.