We keep running into the same mix-up with startup clients: a vendor has a DPA, calls itself GDPR compliant, and everyone assumes the data transfer to the US is therefore covered too. It isn't—those are two separate legal questions.
A Data Processing Agreement covers how a vendor handles your data—security measures, sub-processors, what happens if there's a breach. It says nothing about whether you're legally allowed to send that data to the US in the first place. That's a separate legal basis under GDPR, and you need one for every transfer, every vendor.
The ARC Test
Every time personal data leaves the EU, check these three things in order: Adequacy, Registration, Clauses.
A - Adequacy: Does the Destination Country Have an Adequacy Decision?
The EU Commission has already decided some countries offer adequate protection—Switzerland, Japan, South Korea, and a few others. If yes, you're done; no further paperwork.
The US doesn't have a general adequacy decision.
R—Registration: Is Your Specific Vendor Certified Under the EU-US Data Privacy Framework?
This is the one people get wrong most often. The DPF is not a blanket US adequacy decision. It's a self-certification scheme—individual companies opt in and get listed on a public register. If your vendor is actually on that register, the transfer is covered. If they're not, the DPF does nothing for you, regardless of what their compliance page says.
C - Clauses: Do You Need Standard Contractual Clauses?
If neither of the above applies, you need Standard Contractual Clauses—and one more step most people skip.
SCCs alone aren't enough. Since the 2020 Schrems II decision, you're also required to do a Transfer Impact Assessment: checking whether the destination country's surveillance laws could undermine what the SCCs promise on paper. A lot of companies sign the SCCs and never do this part, even though it's been a requirement since 2020 - years before this year's DPF news.
The R in ARC Has a Shaky History
The DPF has a history of not lasting. Its two predecessors, Safe Harbor and Privacy Shield, were both struck down by the CJEU, in 2015 and 2020.
In June 2026, the US Supreme Court ruled in Trump v. Slaughter that federal agencies like the FTC have less protection from presidential removal than before. Max Schrems and noyb have already written to the European Commission arguing this undermines one of the DPF's core requirements—independent oversight of EU data. People are calling the expected case "Schrems III."
The DPF hasn't been struck down. If it's your only transfer mechanism for a given vendor though, worth knowing that letter of ARC has failed twice before, and there's already movement toward a third round.
What Should Companies Do in Practice?
If you're covered by adequacy, there's nothing to do. If you're relying on clauses, check whether anyone actually did the Transfer Impact Assessment—if not, that's a gap sitting in your files right now, not a hypothetical one. If you're relying on DPF registration, check the vendor is actually on the current register, and don't assume that status is permanent for the life of the contract.
Run the ARC test on your vendor list and you'll usually find you're not sitting on just one letter—most companies have a mix, vendor by vendor.
Get Help Reviewing Your International Data Transfers
Happy to help if you want a Transfer Impact Assessment done properly, or just want a second pair of eyes on where your vendors land on ARC.
- A vendor being GDPR compliant via a Data Processing Agreement is a separate legal question from whether transferring personal data to that vendor's country is itself lawful.
- The article proposes an ARC test for every cross-border transfer: check Adequacy (EU adequacy decision for the destination), Registration (is the specific vendor DPF-certified), and Clauses (do you need Standard Contractual Clauses).
- The EU-US Data Privacy Framework is a self-certification scheme, not a blanket adequacy decision for the US, so it only covers a transfer if the specific vendor is actually listed on the public register.
- Companies relying on Standard Contractual Clauses are also required to complete a Transfer Impact Assessment checking the destination country's surveillance laws, a requirement since the 2020 Schrems II decision that many companies skip.
- The Data Privacy Framework's predecessors, Safe Harbor and Privacy Shield, were both struck down by EU courts, and a 2026 US Supreme Court ruling has already prompted advocates to argue the DPF's oversight requirement is now undermined.
- In practice, most companies rely on a mix of all three ARC mechanisms across their different vendors rather than a single blanket approach.
| The core mix-up | A vendor's GDPR-compliant Data Processing Agreement covers how they handle your data, not whether transferring that data to their country is legally permitted; those are separate questions. |
|---|---|
| The ARC test | For every cross-border transfer, check Adequacy (EU adequacy decision for the country), Registration (is the vendor DPF-certified), and Clauses (do you need SCCs), in that order. |
| The US has no blanket adequacy | Unlike Switzerland, Japan, or South Korea, the US has no general EU adequacy decision, so transfers there require one of the other two mechanisms. |
| DPF is per-vendor, not per-country | The Data Privacy Framework is a self-certification scheme; it only covers a transfer if your specific vendor is actually listed on the public register. |
| SCCs need a Transfer Impact Assessment too | Since the 2020 Schrems II ruling, signing SCCs alone isn't enough; companies must also assess whether the destination country's surveillance laws could undermine those clauses, a step many skip. |
| A shaky track record | The DPF's two predecessors, Safe Harbor and Privacy Shield, were both struck down by EU courts, and a 2026 US Supreme Court ruling has already fueled arguments the DPF's oversight safeguard is compromised. |
| What to actually do | Run the ARC test vendor by vendor: confirm DPF registration, complete any missing Transfer Impact Assessments, and don't assume a vendor's compliance page settles the question. |
If my vendor says they're GDPR compliant, does that mean my data transfer to them is legal?
Not necessarily. A Data Processing Agreement covers how the vendor handles your data, but the legality of transferring that data across borders is a separate legal question requiring its own basis.
What is the ARC test?
A three-step check for every cross-border data transfer: Adequacy (does the destination country have an EU adequacy decision), Registration (is the specific vendor DPF-certified), and Clauses (do you need SCCs).
Does the EU-US Data Privacy Framework cover all transfers to the US?
No. It's a self-certification scheme that only covers a transfer if the specific vendor is actually registered on the public DPF list, not simply because the framework exists.
What is a Transfer Impact Assessment, and do I need one?
An assessment of whether the destination country's surveillance laws could undermine SCC protections; it's been required since the 2020 Schrems II decision, and many companies that signed SCCs never completed it.
Is the Data Privacy Framework at risk of being struck down like its predecessors?
It hasn't been struck down, but its two predecessors were, and a 2026 US Supreme Court ruling has already led privacy advocates to argue its independent-oversight requirement is undermined, with a 'Schrems III' challenge anticipated.
- “Anonymized” Doesn’t Mean What You Think It Means: A Guide to Data Privacy ComplianceSame data, five legal definitions of "anonymous." GDPR, HIPAA, CCPA, LGPD, and PIPL compared.
- Synthetic Data: The Most Exciting Privacy-Enhancing Technology, and the Most OversoldSynthetic doesn't mean private. Generative models can leak real records—here's what testing catches.
- Your Sub-Processor List Is Probably Wrong [Explained]Ask most startups for a sub-processor list, get a vendor list instead—that gap is where GDPR exposure quietly sits.
