2026-10853NoticeWallet

Commerce Seeks Renewal of EU Data Privacy Certifications

Published Date: 6/1/2026

Notice

Summary

The Department of Commerce is asking for approval to keep collecting self-certification info from U.S. companies that handle personal data from the EU, UK, and Switzerland. This helps make sure data privacy rules are followed while allowing smooth data flow across borders. About 4,575 companies will spend around 40 minutes each on this, with a total time cost of nearly 3,000 hours.

Analyzed Economic Effects

5 provisions identified: 1 benefits, 4 costs, 0 mixed.

Must Self-Certify To Rely On DPF

If your U.S. organization wants to rely on the EU-U.S., UK Extension, or Swiss-U.S. Data Privacy Frameworks for personal data transfers, it must self-certify its adherence to the Principles to the Department of Commerce and be placed on the Data Privacy Framework List. The information must be submitted via the DOC website by an authorized individual; the respondent's obligation is voluntary but required to rely on the Framework.

Participation Compliance Requirements

To participate, your organization must (a) be subject to investigatory/enforcement powers of the FTC, DOT, or other statutory body, (b) publicly declare commitment to the Principles, (c) publicly disclose privacy policies aligned with the Principles, and (d) fully implement those policies. Submissions must include the information specified in the Principles and an authorized individual must make the submission.

Annual Re‑certification and Removal Rules

Your organization must re-certify annually to remain on the Data Privacy Framework List; the DOC will remove organizations that voluntarily withdraw, fail to complete annual re-certification, or are found to persistently fail to comply. DOC will also require questionnaires and verifications for lapsed or withdrawing organizations.

Enforcement Exposure for Noncompliance

If your organization fails to comply with the Principles after self-certification, enforcement may be taken by the FTC under Section 5 of the FTC Act (15 U.S.C. 45), by the DOT under 49 U.S.C. 41712, or under other laws or regulations prohibiting unfair or deceptive acts. The DOC will maintain a public record of organizations removed from the Data Privacy Framework List and the reason for removal.

Annual Time Burden on U.S. Firms

If your company self-certifies under the Data Privacy Framework, the Department of Commerce expects 4,575 organizations to respond, with each response taking about 40 minutes and a total annual burden of 2,977 hours. The submission is filed via the DOC's Data Privacy Framework website and is estimated as an annual and periodic requirement.

Your PRIA Score

Score Hidden

Personalized for You

How does this regulation affect your finances?

Sign up for a PRIA Policy Scan to see your personalized alignment score for this federal register document and every other regulation we track. We analyze your financial profile against policy provisions to show you exactly what matters to your wallet.

Free to start

Key Dates

Published Date
6/1/2026

Department and Agencies

Department
Independent Agency
Agency
Commerce Department
International Trade Administration
Source: View HTML

Related Federal Register Documents

Previous / Next Documents

Back to Federal Register