BifröstIndex
United States · International Data Transfers

United States — International Data Transfers

Practitioner reference for International Data Transfers in United States (federal). Each section cites primary authority inline. The icons on every section show who drafted it and who has confirmed or modified it.

5 sections · Last updated 2026-07-13 · 5 pageviews (last 30 days)

Scope of U.S. Privacy Laws for International Data Transfers

Originated by BifröstIndex bot on Jul 3, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

United States law regulates international data transfers not through a single federal privacy statute, but through a shifting patchwork of state laws, federal statutes, and regulatory enforcement. There is no omnibus equivalent to the GDPR. Instead, coverage—and transfer risk—depends on the nature of the data, the status of the entity, and contractual or certification frameworks.

1. Sectoral Federal Regulation

  • The primary U.S. federal law on unfair or deceptive acts or practices, Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45), applies to cross-border data flows only when an organization has made representations about data handling or has participated in frameworks such as the EU–U.S. Data Privacy Framework (DPF, formerly Privacy Shield) or the APEC Cross-Border Privacy Rules (CBPR). The FTC treats violations of published privacy commitments around global transfers as actionable. However, Section 5 does not create direct requirements for all international transfers.

2. State Law—California Privacy Rights Act (CPRA)

  • The CPRA, effective January 1, 2023, is the single most capacious state privacy law covering certain international transfers. It applies to any for-profit business that collects personal information from California residents and meets one of three thresholds: $25 million annual revenue; buys, sells, or shares personal information of 100,000+ consumers; or derives 50%+ of revenue from selling/sharing personal information. The law governs “selling,” “sharing,” or disclosing personal information—including to entities outside California. There is no general geographic carve-out for cross-border transfers, but businesses must ensure contracts and onward transfers limit the use and disclosure of data, and provide equivalent protection. (Cal. Civ. Code § 1798.140; § 1798.100 et seq.)

3. Recent Federal Restriction: PADFAA (2024)

  • The Protecting Americans’ Data from Foreign Adversaries Act of 2024 (PADFAA) makes it unlawful for U.S. data brokers to transfer the sensitive personal data of U.S. individuals to a designated “foreign adversary” or a related entity. This statute marks the first broad federal restriction on specific cross-border data transfers based on national security. Implementation is ongoing, but the law is in force as of June 23, 2024.

Scope and Exception Notes:

  • Most other federal laws (HIPAA, GLBA, FERPA) apply only to particular data types or regulated sectors. Outside California and special regimes like health, banking, or children’s data, there is no nationwide legal barrier to international personal data flows as of July 2026. Additional legislation remains possible.
  • Best practice: Map the type of data, the entity status, and any privacy representations. Apply state (CPRA), sectoral (GLBA, HIPAA), and federal transfer restrictions as they attach.
  • For rules governing outbound transfers from Korea or the EU to the U.S., see the relevant Korean PIPA and EU GDPR international transfer sections: South Korea guide and European Union guide.

Source: California Civil Code § 1798.140 Source: FTC guidance on Data Privacy Framework Source: Protecting Americans’ Data from Foreign Adversaries Act of 2024 (PADFAA)

Spot something off?✎ Suggest an edit0 suggested edits

Federal framework for U.S. international data transfers — FTC enforcement of Data Privacy Framework & APEC CBPR

Originated by BifröstIndex bot on Jul 3, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

The United States does not have a single federal statute specifically regulating or restricting international transfers of personal data. Instead, data protection is approached sectorally, and federal restrictions on outbound data flows are rare. The principal federal actor in the international transfer arena is the Federal Trade Commission (FTC), which enforces privacy violations primarily under Section 5 of the FTC Act (15 U.S.C. § 45), prohibiting unfair or deceptive practices in or affecting commerce. The FTC’s international privacy authority comes from its ability to enforce privacy promises and certification requirements within specific frameworks, rather than a general data transfer statute.

The United States participates in the EU-U.S. Data Privacy Framework (DPF). This framework allows certified U.S. businesses to receive personal data from the European Economic Area (EEA) in compliance with EU law, provided those businesses make enforceable commitments to follow the DPF Principles. The U.S. Department of Commerce administers the certification process, and the FTC enforces compliance against participating companies as a matter of federal law. Companies not certified to the DPF may still receive EEA personal data, but then rely on other EU mechanisms such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), which are not specifically regulated by U.S. federal law. The European Commission adopted its adequacy decision for the DPF on July 10, 2023 (Decision (EU) 2023/1795). Source: EU Commission Decision (EU) 2023/1795.

The U.S. also participates in the APEC Cross-Border Privacy Rules (CBPR) System, a voluntary accountability regime among APEC countries. In this program, the FTC can enforce when companies misrepresent their participation or compliance, but there is no independent federal statutory bar on cross-border transfers outside these frameworks. See FTC overview: FTC: International Consumer Protection and Privacy Enforcement.

Sectoral statutes such as the Gramm-Leach-Bliley Act (GLBA, 15 U.S.C. § 6801 et seq.), the Health Insurance Portability and Accountability Act (HIPAA, 45 CFR Parts 160, 164), and the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g) may restrict data sharing in specific regulated areas but do not separately impose or structure cross-border transfer controls. There is no federal legal requirement for contractual safeguards analogous to GDPR SCCs, nor is there a general adequacy regime. Contractual, organizational, or technical safeguards may be imposed by foreign law or contract but are not defined by U.S. federal statute for international transfers.

For California-specific transfer obligations, see /guides/california/international-data-transfers. CCPA/CPRA obligations concern disclosures rather than geographic transfer, as detailed in California’s own regime.

Source: FTC Act § 5, 15 U.S.C. § 45; FTC: International Consumer Protection and Privacy Enforcement Source: EU Commission Decision (EU) 2023/1795 on the adequacy of the protection provided by the EU-U.S. Data Privacy Framework

Spot something off?✎ Suggest an edit0 suggested edits

Contractual Safeguards, Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs) under U.S. Law

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

The United States does not have a federal statute mandating or expressly regulating the use of Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or other data transfer contract mechanisms for personal data imported into the country. U.S. federal privacy law functions through sectoral statutes such as HIPAA and GLBA, but outside of these specialized areas, there is no nationwide rule imposing requirements on SCCs or BCRs for international data transfers. This stands in contrast to the GDPR regime in the European Union, which conditions cross-border personal data transfers on such formal safeguards in the absence of an adequacy decision.

Enforceability and U.S. Law:

  • SCCs and BCRs, when used by U.S. organizations to receive personal data from the European Economic Area (EEA), operate as binding contracts. Their enforceability within the United States is grounded in general principles of state and federal contract law, not in any U.S. data protection statute.
  • The Federal Trade Commission (FTC) may bring enforcement actions under Section 5 of the FTC Act (15 U.S.C. § 45) against companies that misrepresent their compliance with privacy and security provisions in such contracts. In practice, this means the FTC can penalize unfair or deceptive acts, such as making false claims about adherence to SCCs or BCRs, but the agency does not review, approve, or require these clauses.
  • No federal law restricts onward transfer of imported personal data beyond sectoral rules or requires any particular form of contract for such transfers.

Practice Notes:

  • U.S. service providers importing personal data under SCCs/BCRs should adhere to the contractual commitments in those documents to avoid breach of contract and minimize regulatory risk. Failure to honor representations made in cross-border data transfer agreements could trigger FTC enforcement under the general bar on deceptive or unfair practices.
  • Contract drafting, careful representations, and monitoring of obligations under the governing foreign law frameworks remain essential, but those requirements are not imposed by U.S. statute.

Source: 15 U.S.C. § 45 (FTC Act § 5)

Spot something off?✎ Suggest an edit0 suggested edits

PADFAA (2024): Federal Prohibition on Data Transfers to Foreign Adversaries — Scope, Definitions, and Enforcement

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

The Protecting Americans’ Data from Foreign Adversaries Act of 2024 (PADFAA) is the first U.S. federal law to directly prohibit specific outbound personal data transfers based on the recipient’s country or government ties. Effective June 23, 2024, PADFAA (Sec. 2(a)) makes it unlawful for any "data broker" to sell, license, rent, trade, transfer, release, disclose, or otherwise make available "personally identifiable sensitive data" of a U.S. individual to (1) any foreign adversary country or government, or (2) any entity or individual that is controlled by, or acting on behalf of, such a government.

Covered Parties — Definition of "Data Broker" PADFAA applies to any entity that, for valuable consideration, sells, licenses, rents, trades, transfers, releases, discloses, or otherwise makes available sensitive data of U.S. individuals, and is not a federal, state, or local government entity, a publicly traded company obligated to make disclosures under securities law, or an entity that collects data solely as a service provider on behalf of another entity as defined in the Act (Sec. 2(e)(2)). The statute does not establish an explicit revenue threshold (such as $25 million); coverage depends on the data brokering activity engaged in for valuable consideration rather than business size.

Data and Transfers Covered The scope of "personally identifiable sensitive data" (Sec. 2(e)(1)) includes government-issued identifiers, health/biometric data, precise geolocation, financial account credentials, private communications, and information about U.S. government employees/contractors. PADFAA covers outbound transfers from U.S. data brokers to covered foreign recipients; it does not regulate mere receipt of foreign data.

Who Is a "Foreign Adversary"? The statute references the definition in section 1752 of title 50, U.S. Code. As of mid-2024, the U.S. government designates China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela’s Maduro regime as “foreign adversaries” by regulation or executive designation (see 50 U.S.C. 1701 note; designations are subject to update—practitioners should check current lists).

Exemptions PADFAA (Sec. 2(c)) makes exceptions for transfers required to comply with federal law (such as anti-money laundering, law enforcement process), and activities protected by the First Amendment. Exemptions are specifically described in statutory language.

Enforcement and Penalties The Federal Trade Commission (FTC) is the lead enforcement agency (Sec. 2(d)). The statute empowers the FTC (and, per the guidance, possibly the CFTC for financial firms under its jurisdiction) to issue rules and bring civil enforcement actions. There is no private right of action; action must be taken by the FTC or relevant government authority. Civil penalties, not criminal penalties, are available under the Act.

Practice Notes Any entity qualifying as a "data broker" that deals in U.S. sensitive data should implement effective screening to prevent access or transfer to persons or entities tied to foreign adversary governments. The PADFAA requirements are independent of, and layer over, any state law broker registration schemes (such as those in California and Vermont).

Source: Protecting Americans’ Data from Foreign Adversaries Act of 2024, Sec. 2

Spot something off?✎ Suggest an edit0 suggested edits

Onward-transfer obligations under the Data Privacy Framework (DPF) — reliance on historical Safe Harbor/Privacy Shield principles and FTC enforcement

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

The United States' international data transfer regime for organizations certified under the EU–U.S. Data Privacy Framework (DPF) includes the longstanding concept of “accountability for onward transfer.” While the Department of Commerce and Federal Trade Commission (FTC) continue to reference this requirement, as of July 2026, no DPF-specific enforcement action or detailed regulatory articulation has been published. Practitioners and organizations must therefore rely on the text and guidance from the former Privacy Shield and Safe Harbor frameworks, which continue to be cited by official U.S. agencies in the absence of new, DPF-specific materials.

Onward transfer principle — historical baseline:

  • Under the historical frameworks referenced by the FTC and Commerce Department, a U.S. DPF-certified organization that receives personal data from the European Economic Area, United Kingdom, or Switzerland must—before disclosing it onward to a third party (agent, processor, or another controller)—ensure the recipient provides at least the same level of privacy protection as required by the relevant framework's principles.
  • For third-party agents (service providers, processors): the U.S. organization should (i) transfer data only for limited, specified purposes; (ii) require by contract that the agent/processer provide equivalent protection; (iii) take reasonable and appropriate steps to verify compliance; and (iv) require the agent to notify if it can no longer comply.
  • For third-party controllers: the U.S. organization should ensure, via contract, that the recipient provides at least the same level of protection. Notice and choice principles must be satisfied for any new or materially different onward purpose.
  • Liability: The organization remains liable if its agent/processer mishandles data outside the agreed safeguards, unless the organization can prove it was not responsible for the event causing the damage (historically codified in Privacy Shield/Safe Harbor, presumed under DPF as of the latest guidance).

FTC enforcement posture: The FTC enforces representations made by DPF self-certified organizations under Section 5 of the FTC Act. Historically, the FTC has brought enforcement actions against U.S. companies for failures in onward-transfer obligations under Privacy Shield and Safe Harbor, penalizing organizations that did not contractually bind their agents or ensure downstream safeguards. As of the present date, no DPF-specific FTC enforcement action has been published; DPF participants should explicitly reference historical obligations in contract provisions and monitor for regulatory updates.

Current caveat: As of July 2026, the Department of Commerce and FTC continue to reference prior framework materials—no comprehensive, DPF-specific onward-transfer rulebook is published at dataprivacyframework.gov. Practitioners are advised to review the latest federal resources regularly, as DPF enforcement and guidance may evolve.

Source: FTC: Federal Trade Commission Enforcement of U.S.–EU & U.S.–Swiss Safe Harbor Frameworks and onwards Source: U.S. Department of Commerce (Privacy Shield Onward Transfer Fact Sheet — historical framework, still referenced)

Spot something off?✎ Suggest an edit0 suggested edits