pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework | 32023D1795 — European Union law | Esheria

pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework

The decision says personal data may be transferred from EU controllers and processors to certified U.S. organisations without further authorisation, but certified organisations must follow the Framework’s rules.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
European Union
Instrument
Decision
Citation
32023D1795
Status
In force
Version
Undated source snapshot
Language
en
Official source
View official record ↗
EU-U.S. DPF compliance access requests adequacy decision arbitration administration certification complaints and redress complaints handling compliance monitoring cross-border data transfer cross-border data transfers dispute resolution government data requests internal compliance investigations oversight personal data processing privacy compliance recordkeeping redress regulatory cooperation regulatory enforcement search warrants self-certification signals intelligence +5 more

Statute overview

About this statute

The decision says personal data may be transferred from EU controllers and processors to certified U.S. organisations without further authorisation, but certified organisations must follow the Framework’s rules. Organisations must cooperate with a DPA complaint process in certain HR-data or voluntary-oversight cases, and must answer DPA inquiries, follow the DPA’s advice, and confirm in writing what they did. This provision sets rules for U.S. signals intelligence collection, including prioritising less intrusive methods, targeting and tailoring requirements, safeguards for bulk collection, and complaint/redress procedures. This Decision says the Commission must keep monitoring the U.S. data-protection framework and, if protection is no longer adequate, inform U.S. authorities and consider suspending, amending, repealing, or limiting the Decision. The FBI must notify the DoJ if the Guidelines are not followed, and anyone departing from the Guidelines must first get prior approval from specified FBI officials unless there is an urgent threat or national security reason.