The EU-US Data Privacy Framework (DPF) adequacy decision, adopted by the European Commission on 10 July 2023, establishes a legal basis for transferring personal data from the European Union to certified US organisations. What it does not do, and what its text cannot do, is remove the authority of US intelligence agencies and law enforcement to compel access to that data under domestic US statutes. For compliance officers, CISOs and data protection officers in regulated sectors, this distinction is not a technicality: it is the central operational sovereignty risk that must be assessed, documented and mitigated independently of DPF certification status.
Transfer Legality Versus Operational Control: Two Separate Legal Dimensions
GDPR Chapter V governs the conditions under which personal data may leave the EU. An adequacy decision under Article 45 satisfies that condition by confirming that the destination country provides essentially equivalent protection. A fallback transfer mechanism under GDPR Article 46, such as Standard Contractual Clauses, serves the same purpose through contractual rather than systemic equivalence. Neither instrument, however, governs what happens to data once it arrives in the hands of a US provider.
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) empowers US federal agencies to compel US-based electronic communications service providers to produce data stored anywhere in the world, regardless of the data subject’s nationality or the data’s physical location. FISA Section 702 (Foreign Intelligence Surveillance Act) separately authorises collection of communications from non-US persons located outside the United States, directed at US providers. Executive Order 12333 provides a further authority for signals intelligence collection that operates largely outside judicial oversight.
None of these statutes is addressed, amended or constrained by the DPF adequacy decision. The DPF creates obligations for certified US companies toward EU data subjects and establishes a redress mechanism through the Data Protection Review Court. It does not bind the National Security Agency, the FBI or the Department of Justice when those agencies invoke FISA 702 or the CLOUD Act. A US provider that is DPF-certified remains legally obligated to comply with a lawfully issued CLOUD Act order, and that obligation will override any contractual commitment to EU customers.
The Structural Weaknesses That Make Schrems III Foreseeable
The Court of Justice of the European Union invalidated the predecessor Privacy Shield adequacy decision in Schrems II (Case C-311/18) in July 2020 on two grounds: US surveillance law did not meet EU standards of proportionality, and EU data subjects had no effective judicial redress against US intelligence activity. The DPF attempts to address both points, primarily through Presidential Policy Directive 28 (PPD-28) limitations on bulk collection and the creation of the Data Protection Review Court.
Max Schrems, privacy activist and chair of NOYB, stated directly after the DPF adoption: “The Data Privacy Framework does not address the fundamental problem: US intelligence agencies can still compel US-based providers to hand over data under FISA 702, regardless of where that data is stored.” NOYB filed a legal challenge immediately and a referral to the CJEU is widely expected. The core structural problem is that PPD-28 is an executive order, not a statute: a future US administration can revoke or modify it without Congressional action. The Data Protection Review Court is also an executive body, not an Article III court with full judicial independence. These are precisely the proportionality and redress deficits that the CJEU found fatal in Privacy Shield.
The European Data Protection Board noted in its 2023 statement on the DPF that “adequacy decisions facilitate transfers but do not confer immunity from the national security laws of the recipient country. Organisations must still assess whether those laws undermine the protection the GDPR requires.” This framing makes clear that even under a valid adequacy decision, a residual risk analysis remains a compliance obligation, not an optional exercise.
Documenting Residual Sovereignty Risk in a Transfer Impact Assessment
A Transfer Impact Assessment (TIA) under GDPR Article 46, required when Standard Contractual Clauses or other Article 46 mechanisms are used, must evaluate the laws and practices of the destination country that could impinge on the effectiveness of the transfer tool. Under the DPF, where no Article 46 mechanism is formally required, many organisations mistakenly omit the TIA entirely. This is a significant compliance gap for regulated sectors.
A TIA for data processed by a DPF-certified US provider should explicitly document: the scope of FISA 702 and CLOUD Act authority as it applies to the specific provider; whether the provider is an “electronic communications service provider” within the meaning of FISA (which covers virtually all major US cloud and software-as-a-service companies); the absence of advance notification to data subjects when compelled disclosure occurs; and the provider’s published transparency reports as evidence of the frequency of government requests.
Microsoft alone reported receiving over 3,700 US government data requests in the first half of 2023, according to its law enforcement requests report. IBM’s Cost of a Data Breach Report 2023 found the global average breach cost at USD 4.45 million, with healthcare reaching USD 10.93 million per incident, illustrating the financial stakes when access controls fail regardless of their legal basis.
Supplementary technical measures that can genuinely reduce the residual risk include: end-to-end encryption where the encryption keys are held exclusively by the data exporter and are not accessible to the US provider; zero-knowledge architecture for stored data; and routing all access through a non-US legal entity that is not subject to CLOUD Act or FISA jurisdiction. The EDPB has been explicit that contractual supplementary measures alone cannot close this gap because no contract can override a lawful national security order.
| Legal instrument | What it addresses | What it leaves open |
|---|---|---|
| DPF adequacy decision (2023) | GDPR Chapter V transfer legality to DPF-certified US organisations | CLOUD Act, FISA 702, EO 12333 compelled-access authority; Schrems III invalidation risk |
| Standard Contractual Clauses (GDPR Art. 46) | Contractual basis for transfer when no adequacy decision applies | Same compelled-access exposure; cannot override US national security law |
| End-to-end encryption with exporter-held keys | Technical barrier to provider access and therefore to compelled disclosure of plaintext | Metadata, traffic analysis, key escrow demands in some jurisdictions |
| Sovereign hosting (non-US jurisdiction, non-US entity) | Structural removal of CLOUD Act and FISA 702 jurisdictional hook | Must verify no US parent, no US-incorporated subsidiaries, no US-listed personnel with access |
The Swiss nFADP Dimension: A Separate and Parallel Gap
Switzerland is not an EU member state and the DPF is not applicable to Swiss data transfers. The revised Federal Act on Data Protection (Swiss nFADP) entered into force on 1 September 2023 and governs international transfers from Switzerland. Switzerland maintains its own adequacy list and has recognised the United States under the Swiss-US Data Privacy Framework, a parallel instrument negotiated separately from the EU-US DPF.
The Swiss-US Data Privacy Framework has the same structural vulnerabilities as its EU counterpart: it does not amend FISA 702 or the CLOUD Act, and it relies on the same executive-order-based limitations on US intelligence activity. Swiss organisations transferring sensitive data to DPF-certified US providers therefore face an equivalent sovereignty gap. Critically, if the CJEU invalidates the EU-US DPF in a Schrems III ruling, that judgment does not automatically invalidate the Swiss instrument, but it will create significant political and regulatory pressure on Swiss authorities to revisit their own adequacy assessment. Swiss compliance officers should not assume that Swiss-specific certification insulates them from the structural problem.
Procurement Due Diligence: Distinguishing Genuine Independence from Certification Theatre
DPF certification is self-certification maintained on a Department of Commerce registry. It signals a commitment to specific data handling principles but does not verify operational independence from US jurisdiction. Procurement teams evaluating cloud, software-as-a-service or AI providers for regulated-sector data should apply a structured diligence framework that goes beyond checking the DPF registry.
The key questions are structural rather than contractual. First, is the provider incorporated under US law or does it have a US parent company? If so, it is subject to CLOUD Act orders regardless of where its servers are located. Second, does the provider operate under a US-incorporated holding structure even if its operational entity is European? US ownership creates jurisdictional exposure that server location cannot cure. Third, does the provider’s architecture allow it to access plaintext customer data? A provider that cannot produce intelligible data cannot comply with a compelled-access order in a meaningful way. Fourth, what do the provider’s transparency reports show about the frequency and scope of government requests, and does the provider commit to notify customers of requests to the extent legally permitted?
Providers that offer genuine operational independence typically demonstrate: non-US incorporation at every level of the corporate structure; physical infrastructure located in jurisdictions without mutual legal assistance treaties that routinely serve US compelled-access orders; zero-knowledge or customer-key-management encryption for stored data; and published legal response policies that commit to challenge overbroad government requests. Swiss-hosted infrastructure under the nFADP, operated by a non-US legal entity with no US parent, currently represents one of the more structurally robust alternatives available to European regulated-sector organisations.
Fallback Positions for a Legally Fragile Adequacy Decision
Organisations that depend exclusively on the DPF as their transfer basis are exposed to operational disruption if the CJEU invalidates it. After Schrems II, organisations that had relied solely on Privacy Shield had to scramble to implement Standard Contractual Clauses retroactively, often under regulatory scrutiny. A sensible fallback strategy has three layers: maintain documented Standard Contractual Clauses alongside DPF reliance so that the Article 46 mechanism is already in place if adequacy is withdrawn; complete a TIA now that honestly documents the residual sovereignty risk, both as a compliance record and as an input to infrastructure planning; and establish a credible migration path toward sovereign infrastructure that does not depend on any US adequacy determination, so that a Schrems III ruling triggers a planned transition rather than an emergency.
For regulated sectors subject to NIS-2, DORA or sector-specific supervisory expectations, the ability to demonstrate that data sovereignty has been actively managed, not merely assumed through a certification registry check, is increasingly a supervisory expectation rather than a differentiator. Documenting the gap and the measures taken to close it is both a legal obligation and an audit-readiness investment.
FAQ
Does a DPF adequacy decision mean that transfers to US providers are fully GDPR-compliant?
A valid adequacy decision under GDPR Article 45 removes the need for additional transfer mechanisms such as Standard Contractual Clauses, but it does not address whether US surveillance laws such as FISA 702 and the CLOUD Act can override the data protection commitments of the US provider. Transfer legality and operational sovereignty are separate legal questions, and the DPF only resolves the first.
What is the practical difference between CLOUD Act exposure and GDPR adequacy?
An adequacy decision determines whether the legal framework of the destination country provides essentially equivalent protection to EU law. The CLOUD Act is a US statute that allows US law enforcement to compel US providers to produce data stored anywhere in the world. The DPF does not amend or limit the CLOUD Act, so compelled-access risk persists independently of adequacy status. The two operate on entirely different legal tracks.
Is Switzerland covered by the EU-US Data Privacy Framework?
No. Switzerland is not an EU member state and the DPF is an EU instrument. Switzerland operates the Swiss-US Data Privacy Framework under the revised nFADP, which entered into force on 1 September 2023. Swiss organisations face the same FISA 702 and CLOUD Act exposure as EU counterparts, and a CJEU invalidation of the EU-US DPF would create pressure on Swiss authorities to revisit their parallel adequacy assessment.
What supplementary measures can genuinely close the sovereignty gap?
The EDPB has indicated that only technical measures preventing the provider from accessing plaintext data, specifically end-to-end encryption with keys held exclusively by the data exporter, can genuinely close this gap. Contractual measures cannot override US national security law. Hosting on infrastructure operated by non-US legal entities outside US jurisdiction provides an additional structural layer by removing the jurisdictional hook that makes CLOUD Act and FISA 702 orders applicable.
How likely is a Schrems III invalidation, and what should organisations do now?
NOYB filed a legal challenge immediately after DPF adoption and a CJEU referral is widely anticipated. The structural deficits that caused Schrems II, namely FISA 702 mass surveillance and the absence of effective judicial redress for non-US persons, remain present under the DPF. Organisations should treat the DPF as legally fragile, maintain Standard Contractual Clauses as a documented fallback, complete a Transfer Impact Assessment that honestly records residual risk, and develop a credible migration path to sovereign infrastructure that does not depend on US adequacy decisions.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
