Data adequacy is the European Union's formal finding that a country outside the European Economic Area (EEA), a territory, a specified sector within a country, or an international organisation protects personal data to a standard "essentially equivalent" to EU law. Once the European Commission adopts such a finding, personal data can leave the EEA for that destination as though it were moving between two member states: no contract, no authorisation from a regulator, no case-by-case risk assessment. It exists because the General Data Protection Regulation (GDPR) treats every export of personal data as a potential escape from its protections, and adequacy lifts that presumption for a whole jurisdiction.

In advertising the term usually points to a single decision. The EU-US Data Privacy Framework (DPF) is an adequacy finding, and it is the legal basis on which much of the European ad stack sends identifiers, bid data and conversion events to American servers.

How a finding is made

Article 45 of the GDPR sets the test. Paragraph 2 lists three groups of elements the Commission must weigh: the destination's rule of law, human rights protection and legislation, including rules on access to data by public authorities and the redress open to individuals; the existence and effective functioning of one or more independent supervisory authorities; and the international commitments the country has made. Equivalence is judged on effect rather than wording.

The procedure runs in four stages. The Commission publishes a draft. The European Data Protection Board (EDPB), which brings together the EEA's national data protection authorities, issues a non-binding opinion. Member state representatives then vote in a comitology committee under Article 93(2). Adoption as an implementing act follows. Brazil shows the pace: the Commission sought the Board's view on 5 September 2025 and received a 145-page opinion on 4 November. Implementing Decision (EU) 2026/179 was adopted on 26 January 2026, according to Kennedys.

Each decision must define its territorial and sectoral scope and build in a periodic review at least every four years. Article 45(5) lets the Commission repeal, amend or suspend a finding when protection lapses. Scope can be narrow: Canada's decision reaches only commercial organisations subject to its private-sector privacy law, and the American finding covers only companies certified to the DPF.

As of September 2026, the Commission's list comprises Andorra, Argentina, Brazil, Canada, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States and Uruguay, plus the European Patent Organisation. Only the UK decisions extend to law enforcement exchanges governed by the separate Law Enforcement Directive.

Where it sits in an ad transaction

transfer occurs whenever personal data held under the GDPR is disclosed or made available to a recipient in a third country. In programmatic terms that includes a bid request carrying an IP address or device identifier sent to a demand-side platform (DSP) bidding from Virginia, or a conversion tag reporting to an American analytics server.

Every such flow needs a transfer tool on top of a lawful basis for processing. Adequacy does not replace consent or legitimate interest; it settles only the export question. Without it, the exporter falls back on Article 46 safeguards, most often the standard contractual clauses (SCCs) the Commission modernised on 4 June 2021, paired with a transfer impact assessment and, where American surveillance law applies, supplementary technical measures. Article 49 derogations exist but are designed for occasional transfers, not an ad server's continuous traffic.

For American recipients, the DPF turns the question into a registry check. A company self-certifies to the International Trade Administration within the Department of Commerce, commits publicly to the DPF Principles and must re-certify every year. Its promises then become enforceable under Section 5 of the FTC Act, according to the Federal Trade Commission (FTC). Google began relying on the framework for certain EU transfers in its advertising services on 1 September 2023, then extended the approach to Swiss and UK data in September 2024. The DSP StackAdapt certified in February 2026, citing the removal of any need for SCCs across delivery, reporting and measurement.

From Directive to three transatlantic attempts

The concept predates the GDPR. Article 25 of Directive 95/46/EC, adopted in 1995, barred transfers to countries lacking "adequate" protection, and the first decisions, covering Switzerland and the US Safe Harbor scheme, were adopted on 26 July 2000. Eleven Directive-era findings carried over into the GDPR, and on 15 January 2024 the Commission reported that all eleven remained adequate, according to Covington's Inside Privacy.

The transatlantic arrangement has been rebuilt three times. The Court of Justice struck down Safe Harbor on 6 October 2015 in the case known as Schrems I. Privacy Shield replaced it on 12 July 2016 and fell on 16 July 2020 in Schrems II, Case C-311/18, where the court found American surveillance powers disproportionate and redress for Europeans insufficient. Washington responded with Executive Order 14086 on 7 October 2022, limiting signals intelligence and creating a Data Protection Review Court. The Commission adopted the DPF as Implementing Decision (EU) 2023/1795 on 10 July 2023.

Japan's reciprocal arrangement took effect in January 2019. The United Kingdom received two decisions on 28 June 2021 after leaving the EU, and Korea followed in December 2021. In July 2025 the European Patent Organisation became the first international organisation to obtain a finding. Brazil's decision in January 2026 was matched by its own regulator recognising the EU, producing what the Commission called the largest area of free data flows in the world, covering 670 million consumers, according to PrivacyLaws.

Why the marketing community watches it

Adequacy is cheap compliance, and its absence is expensive. The Dutch Data Protection Authority's case against Takeaway.com limited its Google Analytics findings to the period ending 1 September 2023, the date a valid adequacy basis resumed. Before then, SCCs plus a proxy server had not sufficed. Meta is still contesting a 1.2 billion euro Irish fine over transfers to the United States made under SCCs, one of the largest penalties under appeal.

Destinations without a finding show the other side of the ledger. China has none. Ireland's regulator fined TikTok 530 million euros in 2025, 485 million euros of it for breaching Article 46(1), and the High Court later allowed transfers to continue while the appeal proceeds. The transfer chapter's place in the wider regulation is set out in the GDPR explainer.

Criticism and open disputes

Objections fall into four groups.

The first is durability. The American finding rests on executive instruments that a later administration can revise. Reports in January 2025 that Democratic members of the Privacy and Civil Liberties Oversight Board had been asked to resignraised early doubts about the framework's oversight.

The second is the judicial record. The General Court dismissed Philippe Latombe's annulment action on 3 September 2025 in Case T-553/23, but it assessed the framework only as it stood in 2023. Latombe appealed on 31 October 2025, and the case is pending as C-703/25 P, according to the Court's InfoCuria database.

The third is the oversight anchor. On 29 June 2026, in Trump v. Slaughter, the US Supreme Court removed for-cause protection from FTC commissioners. noyb asked the Commission the next day to begin an orderly withdrawal, counting more than 250 references to FTC independence in the decision. The group also argues, according to Privado, that SCC risk assessments lean on the same American bodies.

The fourth is politics. The Brazil decision followed the EU-Mercosur agreement signed on 17 January 2026, and the Commission presented it as a geopolitical signal. The UK renewal came after the Data (Use and Access) Act 2025 introduced new UK standards for adequacy, and the EDPB asked for its implementation to be monitored, according to Shepherd and Wedderburn.

Not the same as

Appropriate safeguards. Article 46 tools, including SCCs, binding corporate rules and approved certifications, attach to specific transfers rather than a destination. The EDPB's approval of the Europrivacy seal as a transfer tool on 15 April 2026 added a certification route, but each tool still requires a transfer impact assessment.

UK data bridges. Since Brexit the UK has issued its own adequacy regulations, which the government calls data bridges. The UK Extension to the DPF took effect on 12 October 2023. According to the Information Commissioner's Office, it is a separate arrangement that would not automatically fall with the EU framework.

Adequate data. Article 5(1)(c) GDPR requires personal data to be adequate, relevant and limited to what is necessary. That is data minimisation: how much is processed, not where it goes.

Data localisation. Adequacy lets data move; localisation keeps it in place. Products such as the AWS European Sovereign Cloud are commercial responses to transfer risk rather than a legal status.

Recent developments

The Commission renewed both UK decisions on 19 December 2025, adding a six-year sunset clause running to 27 December 2031 and a review after four years. Henna Virkkunen, executive vice-president for tech sovereignty, said the renewal "benefits businesses and citizens alike on both sides of the Channel", according to Research Live.

On 31 July 2026, EDPB chair Anu Talus asked Commissioner Michael McGrath to assess whether the Supreme Court judgment affects the DPF, citing Article 45(2)(b) and paragraphs 58 to 60 of the decision. It did not seek suspension. A separate reference on tax data sent under FATCA, Case C-804/25, also touches the decision's scope. As of September 2026 the framework remains in force, and it stays so until the Commission repeals it or the Court of Justice annuls it.

Timeline

  • 24 October 1995: Directive 95/46/EC adopted, with Article 25 introducing the adequacy test
  • 26 July 2000: First adequacy decisions adopted, for Switzerland and the US Safe Harbor scheme
  • 6 October 2015: Court of Justice invalidates Safe Harbor in Schrems I
  • 12 July 2016: Commission adopts the Privacy Shield decision
  • 25 May 2018: GDPR becomes applicable, with Article 45 replacing Article 25
  • January 2019: Japan's reciprocal adequacy arrangement takes effect
  • 16 July 2020: Court of Justice invalidates Privacy Shield in Schrems II
  • 4 June 2021: Commission adopts modernised standard contractual clauses
  • 28 June 2021: Commission adopts two adequacy decisions for the United Kingdom
  • December 2021: Republic of Korea receives an adequacy decision
  • 7 October 2022: United States issues Executive Order 14086
  • 10 July 2023: Commission adopts the EU-US Data Privacy Framework
  • 1 September 2023: Google begins relying on the framework for advertising transfers
  • 12 October 2023: UK Extension to the Data Privacy Framework takes effect
  • 15 January 2024: Commission confirms the eleven Directive-era decisions
  • 19 June 2025: Data (Use and Access) Act 2025 receives Royal Assent
  • July 2025: European Patent Organisation becomes the first international organisation with a finding
  • 3 September 2025: General Court dismisses the Latombe challenge
  • 31 October 2025: Latombe appeals to the Court of Justice as Case C-703/25 P
  • 4 November 2025: EDPB adopts Opinion 28/2025 on Brazil
  • 19 December 2025: Commission renews the UK decisions until 27 December 2031
  • 26 January 2026: Commission adopts the adequacy decision for Brazil
  • 15 April 2026: EDPB approves Europrivacy as a transfer certification tool
  • 29 June 2026: US Supreme Court decides Trump v. Slaughter
  • 30 June 2026: noyb asks the Commission to withdraw the US decision
  • 31 July 2026: EDPB asks the Commission to assess the ruling's effect on the framework

Summary

Who. The European Commission adopts findings after an EDPB opinion and a member state vote. Exporters across the EEA rely on them, including advertisers, publishers and ad tech vendors, while importers range from certified US companies to entire national systems such as Japan's and Brazil's. Courts, the Board and litigants such as noyb and Philippe Latombe test them.

What. A Commission implementing act declaring that a destination outside the EEA protects personal data to an essentially equivalent standard, so transfers there need no further safeguard.

When. Introduced by the 1995 Directive, first applied on 26 July 2000, carried into Article 45 GDPR in 2018, and most recently extended to Brazil in January 2026 and renewed for the UK until December 2031.

Where. At the point where personal data leaves the EEA: bid requests to non-European DSPs, analytics and conversion endpoints, cloud hosting and remote access.

Why. It replaces contract-by-contract risk assessment with a single legal status. For transatlantic advertising that status depends on the DPF, whose foundations are under review after the Supreme Court's June 2026 ruling on FTC independence.