A controller plans to transfer EU customer data to a US vendor “because they are on the Data Privacy Framework,” but nobody verifies the vendor’s active participation status. What verification step is required?
Select an answer to reveal the explanation.
Short Explanation
The EU–US Data Privacy Framework is a guest list, not a vibe. You check that the vendor is actually on it and still in good standing before you lean on DPF for the transfer. Assuming participation from a glossy website or a Schrems II name-drop is how gaps appear.
Full Explanation
Reliance on the EU–US Data Privacy Framework depends on transferring to an organisation that is eligible and actively self-certified under the Framework’s requirements. Controllers should verify current participation rather than assume status from marketing materials. Website domains, subcontractor-only listings, or vague Schrems II references do not substitute for confirming the recipient’s Framework status.