International data transfers and AI: SCCs and the Data Privacy Framework in 2026
Almost no AI vendor worth using processes data exclusively inside the European Economic Area. The moment you send personal data to a model hosted in the US, GDPR Chapter V kicks in — and in 2026, relying solely on the Data Privacy Framework is more fragile than it looks.

The two legal routes, and why they aren't interchangeable
GDPR allows personal data to leave the European Economic Area through two main routes. The first is a European Commission adequacy decision: if the destination country (or, as with the US, a certified framework within that country) offers an "essentially equivalent" protection level, no additional safeguards are needed. Fifteen jurisdictions currently hold adequacy status, including the UK, Canada, Japan, South Korea — and the United States, but only for organizations enrolled in the EU-US Data Privacy Framework (DPF).
The second route, for transfers without adequacy, is the 2021 Standard Contractual Clauses (SCCs) — the version that incorporates the accountability principles required after the Schrems II ruling. SCCs aren't a rubber stamp: they require the exporter to carry out a transfer impact assessment (TIA), analyzing whether the destination country's law or practice could undermine the agreed protection level, and what supplementary measures are needed if it does.
Why "my vendor is DPF-certified" doesn't close the question in 2026
The DPF remains a valid adequacy decision — the EU General Court dismissed the first annulment challenge (the Latombe case, September 2025), finding that the US Data Protection Review Court (DPRC) was, at the time the decision was adopted, sufficiently independent. But that assessment concerns 2023, not current conditions, and three developments have weakened the ground under the framework since then:
- A pending CJEU appeal. Latombe appealed to the Court of Justice of the EU in October 2025 — the same court that already struck down both Safe Harbor and Privacy Shield, the DPF's two predecessors.
- The PCLOB lost its quorum. In January 2025, the Privacy and Civil Liberties Oversight Board lost three of its five members — the board can no longer conduct the annual surveillance-compliance reviews the Commission cited as a safeguard when approving the framework.
- FISA Section 702 runs on short-term extensions — 45-day increments as of June 2026 — creating ongoing uncertainty about whether the underlying US protections remain intact.
None of this invalidates the DPF today. But if your company depends on a single US-based AI vendor and the DPF as your sole legal basis, a reversal at the CJEU — and there's ample precedent for one — leaves you without cover overnight.
The practical recommendation: SCCs as a backstop, not an improvised plan B
The way to avoid depending on a single thread is to include SCCs as an additional contractual safeguard with your AI vendor, even when it's already DPF-certified — many large vendors' contracts already allow this as a "fallback" clause. If the DPF falls, the contract doesn't need renegotiating from scratch.
For vendors with no adequacy basis at all (most AI startups outside the US, or infrastructure hosted in jurisdictions without an adequacy decision), SCCs aren't optional — they're the only route, and the accompanying TIA needs to be documented, not assumed.
What to ask an AI vendor before signing
Three concrete questions before sending the first piece of personal data to an AI vendor outside the EEA: where exactly is the data processed and stored (including sub-processors)? Is the vendor DPF-certified, or are we signing SCCs? And what supplementary measures exist if the destination country's law allows government access to the data? If a vendor can't answer all three precisely, your due diligence isn't done.
The due diligence checklist, already structured
AI Vendor Due Diligence + DPA: what to ask before signing, sub-processor clauses, and a ready-to-adapt Data Processing Agreement template.