Law / European Union

EU-US Data Privacy Framework Adequacy Decision, Commission Implementing Decision (EU) 2023/1795

Commission Implementing Decision (EU) 2023/1795

In force since .

A cross border transfer rule binding public and private bodies.

Criminal exposure
No
Private right of action
No
Obligation class
Transfer
Audit expectation
periodic
Who audits it
Regulator

As of .

What it requires

  • A transfer of personal data from the Union to an organization in the United States that is included in the Data Privacy Framework List may take place on the basis of Article 1 of the Decision, without any specific authorization (Article 45(1) of Regulation (EU) 2016/679).
  • A transfer to an organization in the United States that is not included in the Data Privacy Framework List is outside the finding in Article 1.

Who enforces it

Enforcement body

The competent authorities of the Member States, which exercise their powers under Article 58 of Regulation (EU) 2016/679 over transfers covered by Article 1 and inform the Commission (Article 2), and the Commission, which monitors the application of the legal framework and may suspend, amend or repeal the Decision (Article 3).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 1 provides that, for the purpose of Article 45 of Regulation (EU) 2016/679, the United States ensures an adequate level of protection for personal data transferred from the Union to organizations in the United States that are included in the Data Privacy Framework List maintained and made publicly available by the United States Department of Commerce.

Article 2 requires a Member State whose competent authorities exercise their powers under Article 58 of Regulation (EU) 2016/679 over data transfers referred to in Article 1 to inform the Commission without delay.

Article 3(1) requires the Commission to monitor continuously the application of the legal framework that is the object of the Decision, including the conditions under which onward transfers are carried out, individual rights are exercised and public authorities in the United States have access to data transferred on the basis of the Decision.

Article 3(4) requires the Commission to evaluate the finding in Article 1(1) after one year from the date of the notification of the Decision to the Member States, and subsequently at a periodicity decided in close consultation with the committee established under Article 93(1) of Regulation (EU) 2016/679 and the European Data Protection Board.

Article 3(5) provides that, where the Commission has indications that an adequate level of protection is no longer ensured, it informs the competent authorities of the United States and, if necessary, decides to suspend, amend or repeal the Decision, or limit its scope, in accordance with Article 45(5) of Regulation (EU) 2016/679. Article 4 provides that the Decision is addressed to the Member States.

The Commission published its report on the first review of the functioning of the Decision on . The General Court dismissed an action for annulment of the Decision in Latombe v Commission (Case T-553/23, ). An appeal against that judgment is pending before the Court of Justice as Case C-703/25 P.

When LexLint raises it

When your app profile says your app crawls the web, trains models, deploys a chatbot, sends automated outreach, processes voice recordings or processes biometric data.

Back to the example  ·  Lint your app