Cybersecurity Policy Report, Netherlands Responds to Questions on Sustainability of EU-U.S. DPF, (Mar 18, 2025)
By Tony Foley
The Dutch Ministry of Interior and Kingdom Relations has published its cabinet response on the sustainability of the European Union-U.S. Data Privacy Framework (DPF) and its possible consequences for sensitive data transfers to U.S. companies.
The response was released yesterday but is available only in Dutch. A machine translation of the document reveals that it seeks to address concerns that have been raised in the Netherlands and elsewhere concerning recent dismissals of members the U.S. Privacy and Civil Liberties Oversight Board (PCLOB).
The cabinet response notes that these dismissals do not necessarily detract from an evaluation of the DPF conducted in July 2024 in which the European Commission (EC) found that the U.S. had established procedures, processes, and structures required to sustain the adequacy decision (CPR, July 19, 2024).
Specifically, the response notes that the role of the PCLOB in regard to the DPF is to monitor the functioning of Executive Order 14086, which established the parameters that the U.S. must meet to establish adequate levels of personal data protection. The dismissal of members of the body, even if it results in the lack of a quorum, does not impede the performance of this task by the PCLOB, the ministry said.
In addition, however, the ministry said that if the structural transfer of personal data to the U.S. under the DPF no longer provided an adequate level of protection as required by the EU’s General Data Protection Regulation (GDPR), the EC would be required to withdraw or suspend the DPF’s adequacy decision. Where appropriate, the EC would be required to discuss the suspension or withdrawal of the DPF with EU member states, including the Netherlands. In the absence of an adequacy decision, the GDPR provides that transfers may only take place if appropriate safeguards, as provided in GDPR article 46(2), are implemented, including standard contractual clauses (SCCs) or binding corporate rules (BCRs).
News: InternationalLegislation DataPrivacy GDPR