The Trump administration in the USA is currently having many effects inside and outside the United States. The future of many institutions and agreements is uncertain. This includes the Data Privacy Framework (DPF).
The DPF is a mechanism for facilitating the transfer of personal data from the EU to the USA, intended to ensure that US companies offer a level of data protection comparable to the GDPR. Many companies in the EU rely on this adequacy decision when using digital services from US companies.
For software manufacturers, the loss of the Data Privacy Framework would create legal uncertainty with regard to the GDPR:
- Continuing to transfer data to the USA would risk fines from European data protection authorities.
- If the affected services continue to be used, considerable organisational effort could arise, for example from implementing alternative legal bases such as standard contractual clauses (SCCs) or case-by-case assessments via transfer impact assessments (TIAs).
- Alternatively, switching to European providers with GDPR-compliant data processing would be an option.
As early as the end of January this year, the international law firm CMS recommended that EU companies take the following measures to prepare for a possible invalidation of the DPF:

This would allow companies to protect themselves in advance against the collapse of the Data Privacy Framework.
Read the original English article here: Is the EU-U.S. Data Privacy Framework in danger?