Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Data Privacy Framework TIA: when a certified US recipient still needs a transfer impact assessment

Data Privacy Framework TIA: When You Still Need One (The Essential 2026 Guide)

The Data Privacy Framework TIA question comes up with almost every US supplier: if the recipient is certified to the EU-US Data Privacy Framework, do you still need a transfer impact assessment? For the transfer to that certified recipient, no. But the answer changes quickly once you look at what the certification covers, who else sees the data, and what happens if the framework falls. This guide sets out when a TIA is still needed, what to check before relying on the framework, and how to keep a fallback ready.

Data Privacy Framework TIA: when a certified US recipient still needs a transfer impact assessment

The Short Answer: Data Privacy Framework TIA Rules

The European Commission adopted its adequacy decision for the EU-US Data Privacy Framework on 10 July 2023. A transfer to a US organization that is actively certified under the framework, for the data concerned, rests on adequacy. Adequacy needs no transfer tool and so no TIA; the EDPB’s FAQ for European businesses says personal data can then flow to the certified company without further safeguards, though the rest of the GDPR still applies.

A transfer to a US organization that is not certified, or whose certification does not cover the data, relies on the Standard Contractual Clauses or another Article 46 tool. That transfer needs a TIA.

What to Check Before Relying on the Framework

The EDPB’s FAQ lists what an exporter must verify:

  1. The certification is active. Certifications must be renewed every year. Check the recipient on the Data Privacy Framework List kept by the US Department of Commerce, not only its privacy policy.
  2. It covers the data you send. A company can certify for some kinds of data and not others.
  3. HR data is covered separately. For employee data, the recipient needs a certification that covers HR data, and you should tell it that HR data is included.
  4. Onward transfers are protected. Sub-processors must give the same level of protection the framework requires.

Record these checks. They are what an authority will ask for in place of a TIA.

When You Still Need a Data Privacy Framework TIA

SituationTransfer relies onTIA needed?
US recipient actively certified, for this dataAdequacy (DPF)No; record the certification check
US recipient not certifiedSCCsYes
Certified, but not for HR data, and you send employee dataSCCs for the HR dataYes, for that data
Certified US provider with support staff in India or the PhilippinesDPF, with its onward transfer principleNo TIA, but check the onward transfer contract and what the access means for your data
UK data to a US recipient certified only to the EU frameworkIDTA or UK AddendumYes, a UK transfer risk assessment
UK data to a recipient certified to the UK ExtensionUK adequacy regulations (the “data bridge”)No

The fourth row is the one most often missed. A certified US provider with a support team elsewhere is sending your data onward. The framework’s onward transfer principle requires a contract giving the same protection, so ask to see it, and treat the destination as part of your due diligence. Where the provider is not certified, that onward access belongs in your TIA; our transfer impact assessment example works through exactly that case.

The UK: The Data Bridge and the Transfer Risk Assessment

Since 12 October 2023, UK organizations can send personal data to US organizations certified to the UK Extension to the Data Privacy Framework under the UK’s own adequacy regulations. The recipient must be certified to the UK Extension, not only to the EU framework, and the same checks apply: active certification, the right data, and HR data if you send it.

For US recipients outside the data bridge, a UK transfer risk assessment is needed before relying on the IDTA or the UK Addendum. The ICO points to the UK government’s own analysis of US law as one source you can use in it, which does much of the country research for you. The ICO’s guidance on completing a transfer risk assessment explains the options.

A Data Privacy Framework TIA Is Easier Than It Used to Be

The framework also helps transfers that do not use it. The European Commission has said that the safeguards the US introduced for it, including the limits on signals intelligence in Executive Order 14086 and the Data Protection Review Court, apply to all transfers to US companies, whatever the transfer tool. A TIA for SCCs to a US recipient can take those safeguards into account, which is why many US TIAs now conclude that the SCCs are effective with modest supplementary measures.

That does not make a Data Privacy Framework TIA for SCCs a formality. The importer still has to answer for its own position: whether it falls within the laws that allow access, whether it has received requests, and whether it can keep its promises under the SCCs.

How to Record the Decision

Whichever way the Data Privacy Framework TIA question comes out, write the decision down for each US recipient. A short record per supplier is enough:

FieldWhat to record
Recipient and roleName, whether it acts as a processor or a controller, and the service it provides
Data and peopleCategories of data, and whether HR data is included
RouteDPF (EU), UK Extension, SCCs, IDTA or UK Addendum, for each regime
Certification checkDate checked on the Data Privacy Framework List, scope, and HR coverage
Onward transfersSub-processors and their countries, and the contract that protects the data
TIANot needed (adequacy), or the date and outcome of the TIA
FallbackWhether SCCs are signed alongside the certification
Next checkWhen the certification and the decision are checked again

This record is the evidence that the Data Privacy Framework TIA decision was made on facts, not assumptions. It also makes the annual certification check a ten-minute job, and it is the list you will need on the day the framework’s status changes. Keep it with your record of processing activities, so that a new US supplier cannot be added without passing through it.

Keep a Fallback Ready

The framework has held so far. The Commission’s first periodic review, published on 9 October 2024, found it functioning, and the EU General Court dismissed the Latombe challenge to the adequacy decision in September 2025. That judgment has been appealed to the Court of Justice, and the framework’s predecessors, Safe Harbor and the Privacy Shield, were both struck down there.

A sensible fallback costs little:

  • sign the SCCs (and for UK data, the Addendum) with key US suppliers alongside their certification, so there is a tool to switch to;
  • keep a short Data Privacy Framework TIA on file for your most important US transfers, so the switch does not start from nothing;
  • put the framework’s status on your list of things that trigger a re-evaluation.

Frequently Asked Questions

Does a Data Privacy Framework certification replace a TIA?

For the transfer to the certified recipient, for the data its certification covers, yes: that transfer relies on adequacy. It does not cover data outside the certification, onward access from other countries, or UK data unless the recipient is certified to the UK Extension.

Do I need a DPIA as well?

Possibly. A DPIA depends on whether the processing is high risk, not on where the data goes. Our guide to when a DPIA is required covers that test.

What if the framework is struck down?

Transfers relying on it would need another tool, in practice the SCCs with a TIA. Exporters with a fallback already signed and a TIA on file can switch without stopping the transfer.

Does the framework cover Switzerland?

There is a separate Swiss-US framework for data from Switzerland, with its own certification.

For transfers that need one, our free transfer impact assessment tool covers the EU SCCs and the UK IDTA and Addendum in one assessment, including the adequacy check at the start. For the transfer procedure and records around it, see the GDPR Toolkit, and for the rules in full, our guide to international data transfers.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.