Home / Blog

Can you go to the cloud with Uncle Sam?

September 25, 2026 · International transfers

Can you go to the cloud with Uncle Sam?

A frequently asked question is whether a Dutch organisation is allowed to use American cloud services.

The EU and the United States have concluded an agreement that sets out when personal data may be transferred to American companies: the EU–US Data Privacy Framework (DPF).

American companies that meet the rules and conditions set out in the EU–US Data Privacy Framework (DPF) can, after certification, register in the DPF register and may then receive personal data from the EU without additional safeguards.

How do you quickly establish whether a company is DPF-certified?

The easiest way is to use the official DPF register. This register is managed by the US Department of Commerce (DoC) and shows for each company:

  • whether it is DPF-certified,
  • which entity or entities and services this applies to,
  • and what its current status is.

You can find the register here: https://www.dataprivacyframework.gov/list

Use the search function, enter the company name and check whether the status is Active. This is much faster and more reliable than searching through long privacy statements on company websites, where the information is often scattered and hard to find.

Why is it better to use the register?

On the websites of American suppliers, information about DPF certification is often hidden in long legal texts. It is vaguely worded, sometimes spread across several documents, and rarely prominent. In the register you can see at once whether the company is certified and which services the certification covers.

Please note: certification only applies to the services included in its scope.

  • Example: Microsoft Corporation is certified for Microsoft 365 and Azure, but that does not mean every other Microsoft product automatically falls under the DPF.
  • LinkedIn, a Microsoft subsidiary, has its own certification. An organisation that uses LinkedIn therefore has to check whether this specific entity is in the register as well.

What if a company is not in the DPF register?

If a company does not appear in the register, that does not automatically mean using it is unlawful.

  • The company may be certified under a different legal entity.
  • Some sectors, such as banks, insurers and telecom providers, cannot register under the DPF at all, because they do not fall under the jurisdiction of the FTC or the DoT.
  • In such cases data can only be transferred with alternative safeguards, such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), often combined with technical measures such as encryption.

What are the risks for the user?

  • If the company is DPF-certified and the service provided to you falls within the scope, you can rely on the EU–US Data Privacy Framework (DPF).
  • If the company is not DPF-certified, or the service provided to you falls outside the scope, and there are no other safeguards, the data transfer is in breach of the GDPR. If something then goes wrong, the company or organisation can be held liable.

How do you check a company in the DPF register?

  1. Go to https://www.dataprivacyframework.gov/list.
  2. Use the search field and enter the name of the company (for example “Microsoft”).
  3. Check whether the result appears and whether the status is Active.
  4. Click through to the details to see which services the certification covers.
  5. Save the information (for example as a screenshot) for your own compliance documentation.

Legal uncertainty around the DPF

Although the DPF is currently valid, there is legal uncertainty about how long it will hold. Privacy organisations such as NOYB have already announced that they will challenge the DPF again before the European Court of Justice. This means companies and organisations may simply use it, but should stay alert to changes.

Finally

Working with American cloud services is possible, but only under the right conditions. Always check the DPF register first and do not rely on vague claims in privacy statements. Check regularly (for example once a year) whether the company is still in the register. Keep in mind that certification does not automatically apply to all services. If the company is not in the register, or the service you use falls outside the scope, you need to establish whether other safeguards are in place. And remember: the legal durability of the DPF is under pressure, so keep following developments. In the end, you as the user are responsible if something goes wrong.

← All articles

From reading to fixing.

RealCob checks every GDPR and NIS2 obligation and makes it demonstrable. Try it free for 30 days or book a 20-minute demo.

No credit card required · Prefer to see where you stand first? Take the free GDPR check

Try free for 30 days