Data Privacy Framework List: Lookup, Certification, Enforcement

The Data Privacy Framework List is the public directory, hosted at dataprivacyframework.gov, of U.S. organizations that have self-certified their compliance with the privacy standards required to receive personal data from the European Union, the United Kingdom, and Switzerland. It is administered by the International Trade Administration (ITA) within the U.S. Department of Commerce.1Data Privacy Framework. EU-U.S. Data Privacy Framework (DPF) If you are a European company deciding whether you can lawfully send data to a U.S. partner, or a U.S. company trying to join, the list is the verification point.

How to Check a Company on the List

The list is searchable by organization name at dataprivacyframework.gov. You can filter by framework (EU-U.S., UK Extension, or Swiss-U.S.) and by participation status, and you can export the results if you need to audit several organizations at once.2Data Privacy Framework. Data Privacy Framework List

Status is the first thing to read. “Active” means the organization has completed its most recent annual re-certification and remains in good standing. “Inactive” typically signals that the organization has not completed re-certification on time.2Data Privacy Framework. Data Privacy Framework List A verbal assurance from a vendor is not a substitute for an active entry. If an organization tells you it participates and the list does not confirm that, treat the discrepancy as the answer.

What Each Listing Shows

Each entry displays the organization’s legal name, the specific frameworks it has joined (EU-U.S., UK Extension, Swiss-U.S., or a combination), and the types of personal data it processes.2Data Privacy Framework. Data Privacy Framework List The listing distinguishes between human resources data (employee information) and non-human resources data (customer or consumer information). That distinction governs how the data can be used and which individual rights apply, so check that the category you care about is actually covered.

Every profile also identifies the enforcement body with jurisdiction: either the Federal Trade Commission (FTC) or the Department of Transportation (DOT).2Data Privacy Framework. Data Privacy Framework List Most commercial entities fall under the FTC. Air carriers and ticket agents fall under the DOT. Only organizations under one of these two agencies can participate at all, so nonprofits, banks regulated solely by banking authorities, and other entities outside FTC or DOT reach are not on the list and cannot join.3Data Privacy Framework. How to Join the Data Privacy Framework (DPF) Program (Part 1)

How to Get Your Company on the List

Joining is a self-certification process, but the preparation matters more than the submission form.

Eligibility and Privacy Policy

Only U.S. legal entities subject to FTC or DOT jurisdiction can participate. The organization must publish a privacy policy that specifically references its adherence to the DPF Principles and includes a hyperlink to the DPF program website.3Data Privacy Framework. How to Join the Data Privacy Framework (DPF) Program (Part 1) If the company covers both employee data and consumer data, it needs a separate applicable privacy policy identified for each type. Participation in the UK Extension requires participation in the EU-U.S. DPF first.1Data Privacy Framework. EU-U.S. Data Privacy Framework (DPF)

Independent Recourse Mechanism

Before self-certifying, the organization must designate an Independent Recourse Mechanism (IRM) to handle complaints from individuals whose data it processes. The IRM investigates unresolved complaints at no cost to the individual.4International Centre for Dispute Resolution. IRM Services for the Data Privacy Framework Program You can choose between a private-sector dispute resolution provider or the relevant European data protection authorities. The privacy policy must name your choice and, for a private-sector provider, link to the complaint submission form.3Data Privacy Framework. How to Join the Data Privacy Framework (DPF) Program (Part 1)

Self-Certification, Fees, and Annual Re-Certification

Once the privacy policy is finalized and the IRM is in place, the organization submits its self-certification through the DPF program website. The submission includes organizational details, the categories of personal data covered, and the location of the published privacy policy. The ITA reviews it before adding the organization to the list.

Self-certification requires payment of an annual fee based on the organization’s revenue. The Department of Commerce revised the fee schedule in 2024, so check the current tiers on the DPF program website rather than relying on older figures.5Federal Register. Revisions to the Fee Schedule for the Data Privacy Framework Program

Certification is not a one-time event. Organizations must re-certify with the ITA annually, confirming that their privacy practices and policies still conform to the DPF Principles. If certification lapses, the ITA removes the organization from the active list and requires it to complete a questionnaire indicating whether it intends to withdraw or re-certify. Even during a lapsed period, the organization must continue to apply the DPF Principles to any personal data it previously received under the program.6Data Privacy Framework. How to Re-Certify Under the Data Privacy Framework (DPF) Program Letting the listing go inactive does not erase the obligations attached to data already held.

What Listed Companies Have Committed To

An entry on the list represents a commitment to seven principles. Failure to honor them can trigger enforcement action, so the principles function as concrete obligations rather than statements of intent.7Federal Trade Commission. Data Privacy Framework

  • Notice: tell individuals what data is collected, why, how to complain, which types of third parties receive the data, and their right to access their own information.8Data Privacy Framework. Notice
  • Choice: allow individuals to opt out before data is shared with third parties or used for a new purpose.
  • Accountability for Onward Transfer: bind third-party recipients contractually to equivalent privacy protection.
  • Security: take reasonable precautions against loss, misuse, and unauthorized access.
  • Data Integrity and Purpose Limitation: limit collection to what is relevant to the stated purpose and do not use data in incompatible ways.
  • Access: let individuals see, correct, or delete their personal data.
  • Recourse, Enforcement, and Liability: provide free independent dispute resolution and remain subject to FTC or DOT enforcement.

The Notice Principle alone requires disclosure of roughly a dozen specific items, including the availability of binding arbitration, the organization’s liability when data moves to third parties, and the fact that personal data may be disclosed in response to lawful government requests for national security or law enforcement purposes.8Data Privacy Framework. Notice The privacy policy must also state that the organization is subject to FTC or DOT investigatory and enforcement powers.

Sensitive Data Requires Opt-In

The framework draws a hard line around sensitive personal information: data about medical conditions, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and sex life.9Data Privacy Framework. Choice Before sharing this data with a third party or using it for any new purpose, the organization must obtain explicit opt-in consent. The standard opt-out that applies to ordinary data is not enough. If a third party identified data as sensitive when transferring it, the receiving organization must treat it as sensitive too. Data does not lose its sensitive status by passing through an intermediary.

Onward Transfer Rules

Passing data along to another company is where participating organizations most often stumble. The Accountability for Onward Transfer Principle sets different contract requirements depending on whether the recipient acts as an agent (processing on your behalf) or as an independent controller (making its own decisions about the data).

Transfers to a third-party agent require a contract that limits the transfer to specified purposes, requires the agent to provide protection at least equivalent to the DPF Principles, and obligates the agent to notify the organization if it can no longer meet that standard. On receiving such notice, the organization must take reasonable steps to stop and remedy any unauthorized processing. The Department of Commerce can request a summary or representative copy of the relevant contract provisions at any time.10Data Privacy Framework. Accountability for Onward Transfer

Transfers to third-party controllers require a contract ensuring the data is used only for purposes consistent with the individual’s original consent, that the controller provides DPF-level protection, and that the controller will stop processing if it cannot maintain that protection.10Data Privacy Framework. Accountability for Onward Transfer

Enforcement and Binding Arbitration

Self-certification is not an honor system. Once an organization commits publicly to the DPF Principles through its privacy policy and listing, that commitment is legally enforceable. For companies under FTC jurisdiction, failing to comply with principles they claim to follow can violate Section 5 of the FTC Act, which prohibits unfair and deceptive practices.7Federal Trade Commission. Data Privacy Framework

Individuals in the EU, UK, Gibraltar, or Switzerland who believe a listed organization has violated the DPF Principles have a last-resort option after exhausting the organization’s IRM and other channels: binding arbitration under Annex I of the DPF Principles. Every participating organization, regardless of which IRM it selected, must contribute to the Annex I Arbitral Fund managed by the International Centre for Dispute Resolution, which covers arbitration costs including capped arbitrator fees.11International Centre for Dispute Resolution. DPF Annex I Binding Arbitration Mechanism Services – Arbitral Fund Contributions