Skip to content
    August 19, 2026| Top Floor Team| 13 min read

    Data Privacy Framework vs SCCs: Which Transfer Mechanism Do You Need?

    If your US company is self-certified under the EU-US Data Privacy Framework, you do not need standard contractual clauses for the transfers your certification covers, and the certification itself is cheap: the International Trade Administration's final revised DPF fee schedule, published 30 August 2024 and effective 1 October 2024, charges an organisation with annual revenue of $0 to $5 million a flat $260 a year for a single framework, or $390 for both. If you are not certified, you need the 2021 standard contractual clauses plus a transfer impact assessment, and the pre-2021 clauses are no longer valid for anything. The complication as of August 2026 is durability rather than cost: the General Court upheld the adequacy decision in September 2025 and that judgment is under appeal, and on 29 June 2026 the US Supreme Court held in Trump v. Slaughter that FTC commissioners can be removed at will, which goes directly at the independent supervision the adequacy decision is built on.

    This article prices both routes, names what DPF certification does not cover, and sets out the posture we think survives whichever way the durability question goes.

    Key takeaways

    • DPF certification is genuinely cheap: $260 a year for a single framework at the smallest revenue tier, rising to $5,530 at the largest, per the ITA fee schedule effective 1 October 2024.
    • Certification removes the SCC requirement only for transfers your certification actually covers, and only from the countries whose framework you certified to.
    • SCCs cost nothing to license but carry real work: the 2021 clauses plus a documented transfer impact assessment.
    • The DPF survived Latombe v Commission at the General Court on 3 September 2025; the appeal, C-703/25 P, was lodged on 31 October 2025 and is still pending.
    • Trump v. Slaughter, decided 29 June 2026, removed the for-cause protection insulating FTC commissioners, and the FTC is the DPF's primary enforcement body. Keep SCC documentation maintained in parallel.

    The two mechanisms, briefly

    Chapter V of the GDPR says personal data can leave the European Economic Area only under a recognised transfer route. Two of those routes matter to a normal US company.

    An adequacy decision means the Commission has determined that a destination provides an essentially equivalent level of protection, so transfers to it need no additional safeguard. The EU-US Data Privacy Framework is an adequacy decision of a particular shape: it covers the United States, but only for US organisations that have self-certified to the Department of Commerce and appear on the Data Privacy Framework List. Adequacy attaches to the certified organisation, not to the country as a whole.

    Standard contractual clauses are the alternative. Commission Implementing Decision (EU) 2021/914 published four modules covering controller to controller, controller to processor, processor to processor and processor to controller transfers. You sign the right module, you complete a transfer impact assessment considering the destination's law and any supplementary measures you need, and you keep both on file. The clauses themselves are free.

    What DPF certification actually costs

    The fee schedule is a published US government document and the tiers are worth stating exactly, out of the notice rather than out of a secondary write-up. Note also which notice: the ITA published a schedule on 9 July 2024 that requested comment and set no effective date, then published the final schedule on 30 August 2024 after receiving no comments. The figures below are the final ones.

    The ITA's final revised annual fee schedule, published on 30 August 2024 and effective 1 October 2024, sets fees by the organisation's annual revenue. At $0 to $5 million in revenue, a single framework costs $260 and both frameworks cost $390. Over $5 million to $25 million, it is $750 and $1,125. Over $25 million to $500 million, $1,600 and $2,400. Over $500 million to $5 billion, $4,130 and $6,195. Over $5 billion, $5,530 and $8,295. An organisation that withdraws but keeps applying the Principles to data it already received pays a fixed annual affirmation fee of $260 per applicable framework, or $520 for both.

    "Single framework" means the EU-US DPF alone, or the EU-US DPF plus its UK Extension, or the Swiss-US DPF alone. Participating in the UK Extension requires participating in the EU-US DPF, so the UK does not cost extra on its own. Certifying to an additional framework costs 50 percent more rather than double, which the notice explains as an efficiency saving in administering multi-part participants.

    The fee is not the cost. Certification requires a conforming privacy policy, an independent recourse mechanism available to individuals at no cost to them, contributions toward the arbitration model in Annex I of the Principles, and annual recertification with the same review. The recourse mechanism is the line most first-time certifiers underestimate, because it means either paying a dispute resolution provider or committing to a European data protection authority panel.

    One more thing worth knowing about the source: the ITA's own notice argues that the DPF gives participants "a more effective and efficient service... at a lower cost than other options, including standard contractual clauses or binding corporate rules." That is the agency that runs and is funded by the programme, making the case for the programme. It is also, on the fee arithmetic alone, probably right for a small company.

    What SCCs actually cost

    Nothing to license and quite a lot to operate.

    You need the correct module for each transfer relationship, which requires knowing whether each party is a controller or a processor for that flow. You need a transfer impact assessment documenting the destination country's law, the practical likelihood of government access, and the supplementary measures you rely on. You need to repeat that per destination, not once. And you need to keep it current, because the assessment rests on a legal landscape that moves.

    For a small US company with a handful of EU customers and one data destination, that is a day or two of work plus a review each year. For a company with a subprocessor chain running through several countries, it becomes an ongoing programme. This is the real argument for certifying: the DPF replaces a recurring assessment obligation with a recurring fee and a recertification.

    What certification does not cover

    This is where "do I still need SCCs" gets its real answer, and the answer is usually a qualified yes.

    Scope of your own certification. A DPF certification covers the categories of personal data you declared and, importantly, whether you certified for HR data. Transfers outside what you certified are not covered.

    Onward transfers. Your certification does not certify your subprocessors, and the Principles handle that leg by contract rather than by a second Chapter V mechanism. The Accountability for Onward Transfer Principle requires you:

    • to transfer such data only for limited and specified purposes;
    • to ascertain that the agent is obligated to provide at least the same level of privacy protection as the Principles require;
    • to take reasonable and appropriate steps to ensure it processes the data consistently with your obligations;
    • to stop and remediate unauthorised processing when the agent tells you it can no longer meet them;
    • and to hand the Department of Commerce a summary or representative copy of those contract provisions on request.

    You also remain liable for the agent. So a subprocessor that is not itself certified does not by itself put you back on standard contractual clauses; what does is a transfer that falls outside what you certified, or one from a country whose framework you did not join.

    Countries outside the frameworks you joined. Certifying for the EU-US DPF does nothing for a transfer from, say, Brazil or India, and the Swiss-US DPF is a separate certification.

    Your customers' contractual demands. Plenty of European enterprise buyers require SCCs in the data processing agreement regardless of your certification, because their own counsel wants a contractual remedy rather than reliance on an adequacy decision that has been struck down twice before. That is a commercial fact, not a legal one, and arguing it usually costs more than signing.

    So in practice most certified US companies still have SCCs in some contracts. Certification reduces the assessment burden and simplifies the default; it does not empty the folder.

    The durability question, and why 2026 sharpened it

    Two data points, and they point in opposite directions.

    On 3 September 2025, the General Court dismissed Latombe v Commission (T-553/23), the direct challenge to the adequacy decision, finding among other things that the Data Protection Review Court was sufficiently independent and that US law adequately limited bulk collection. Latombe appealed on 31 October 2025; the appeal is registered as C-703/25 P and, as of August 2026, remains pending before the Court of Justice with no ruling.

    Then on 29 June 2026 the US Supreme Court decided Trump v. Slaughter (No. 25-332) by six votes to three, holding that statutory restrictions on the President's power to remove FTC commissioners are unconstitutional and displacing the 1935 precedent in Humphrey's Executor. The FTC is the primary enforcement authority for DPF commitments; a US organisation must be subject to FTC or Department of Transportation jurisdiction to participate at all. activeMind.legal, which describes itself as a law firm specialising in data protection law, and noyb, which wrote to the Commission on 30 June 2026 asking for an orderly withdrawal from the adequacy decision, both argue the ruling undermines the independent supervision that the adequacy analysis assumes.

    We are not going to predict the outcome, and anyone who tells you they can is guessing. What we will say is that the two previous transatlantic frameworks, Safe Harbor and Privacy Shield, were both invalidated by the Court of Justice, and both invalidations left companies scrambling for an alternative on short notice. The base rate is not comforting.

    The posture that survives either outcome

    Certify if the fee arithmetic favours it, which for a small company it clearly does. Then keep the SCC route warm rather than dismantling it.

    Concretely, that means three things. Keep a signed set of the 2021 clauses with your key EU counterparties, even where the DPF would cover the transfer, because papering them under time pressure after an adverse ruling is how companies end up signing bad terms. Keep the transfer impact assessment written and dated, refreshed annually, because the assessment is the part that takes real time and it does not expire when the mechanism changes. And keep your data map current enough that you can answer, in an afternoon, which flows would need a new basis if the adequacy decision fell.

    That is not double work. The assessment and the map are things a Chapter V programme needs anyway; the only genuinely duplicated item is the signature page.

    When you need neither

    Two cases where this whole article is a distraction.

    The receiving entity is itself established in the EEA. What decides whether Chapter V is engaged is where the importer is established, not where the server sits. If the entity receiving the data is your EU subsidiary or an EU-established vendor, and the data stays with it, there may be no transfer to authorise. If the receiving entity is your US company, an EU hosting region does not change that: the importer is the US legal entity, so the disclosure is still a transfer and still needs a mechanism, whatever the data centre map says. Remote access from the US by a support engineer is a transfer for the same reason, and so is a US-hosted analytics tool receiving Union visitor identifiers. EU data residency is a legitimate way to make the problem smaller and a bad way to make it disappear on paper.

    You are a processor whose customer has already papered it. If your European customer is the controller and its data processing agreement with you already incorporates the correct SCC module, that leg is covered. Certifying under the DPF may still be commercially useful because it shortens procurement, but it is not adding a legal basis you lack. Buy it for the sales cycle if you want, and say that is why.

    Where Top Floor fits

    Transfer mechanism selection is one decision inside a Chapter V programme, and the decision is usually the easy part. The work is knowing which flows exist, which are controller flows and which are processor flows, and what your subprocessors do with the data after they get it. That is GDPR work and it is what we do.

    Where the same company is also facing the US state privacy laws, treating both as one programme is materially cheaper than running them separately, which is what global privacy is for. Where several regimes stack up at once, across the EU, the UK and elsewhere, international compliance is the framing. The budget side of all of this is worked line by line in How much does GDPR compliance cost a US company.

    How to decide this week

    List your transfers first. Every flow of EU personal data to the United States, with the exporter, the importer, the role each plays, and the systems involved. Most companies have between four and fifteen. You cannot pick a mechanism for flows you have not enumerated.

    Check your revenue tier against the fee schedule. If you are under $5 million in annual revenue, DPF self-certification is $260 a year for a single framework and the decision is close to automatic on cost alone, provided you can stand up the recourse mechanism.

    Price the recourse mechanism before you commit, because it is the line that surprises people. Get a quote from a dispute resolution provider or confirm the EU data protection authority panel route, and add it to the fee.

    Whichever route you pick, write the transfer impact assessment anyway and date it. It is the artefact your enterprise customers ask for, it is the artefact that keeps its value if the adequacy decision changes, and it is the one thing here that no fee schedule can buy for you.

    Frequently asked questions

    Do I still need SCCs if I am DPF certified?

    For transfers covered by your certification, from the countries whose framework you joined, no: the adequacy decision is the transfer basis and no additional safeguard is required. In practice most certified companies still keep standard contractual clauses in place for three reasons. Transfers that fall outside the scope you certified, including data categories or HR data you did not declare, are not covered. Transfers from countries outside the framework you certified to are not covered. And many European enterprise buyers require SCCs in the data processing agreement regardless of certification, which is a commercial requirement rather than a legal one. Onward transfers to a subprocessor that is not itself certified are not on that list: the Accountability for Onward Transfer Principle covers them by contract, so what you owe there is the contract and the ongoing responsibility for the agent, not a second transfer mechanism.

    How much does EU-US Data Privacy Framework certification cost?

    The International Trade Administration's final revised fee schedule, published 30 August 2024 and effective 1 October 2024, charges by annual revenue: $260 a year for a single framework at organisations with $0 to $5 million in revenue and $390 for both frameworks, $750 and $1,125 for revenue over $5 million to $25 million, rising to $5,530 and $8,295 above $5 billion in revenue. Beyond the fee, certification requires a conforming privacy policy, an independent recourse mechanism free to individuals, contributions to the arbitration model in Annex I of the Principles, and annual recertification. The recourse mechanism is the cost most first-time certifiers underestimate.

    Is the EU-US Data Privacy Framework still valid in 2026?

    Yes. The Commission's adequacy decision of 10 July 2023 remains in force, and the General Court dismissed the direct challenge to it in Latombe v Commission (T-553/23) on 3 September 2025. Two things keep the durability question open. The appeal against that judgment, lodged on 31 October 2025 and registered as C-703/25 P, is still pending before the Court of Justice as of August 2026. And on 29 June 2026 the US Supreme Court held in Trump v. Slaughter that FTC commissioners can be removed at will, which several European commentators argue undermines the independent supervision the adequacy analysis relies on, since the FTC is the DPF's primary enforcement body.

    What happens to my transfers if the DPF is struck down?

    The two previous frameworks, Safe Harbor and Privacy Shield, were both invalidated by the Court of Justice, and in each case companies had to fall back to standard contractual clauses under time pressure. The practical protection is to keep the fallback maintained rather than dismantled: a signed set of the 2021 clauses with your key EU counterparties, a written and dated transfer impact assessment refreshed annually, and a data map current enough to tell you within an afternoon which flows would need a new basis. The clauses cost nothing to license, so the only duplicated work is the signature.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.