GDPR
Sending personal data to the US from Ireland, in 2026
Yes, and with conditions. The Framework holds, the checks are specific, and the part people skip is whether the particular company is actually on the list for the particular data.
By Oscar CobbeCurrent as at 11 minute read7 sources
The question, in the shape it actually arrives
Almost nobody asks this in the abstract. It arrives as: we want to use this American tool, is that allowed. The tool is a CRM, a helpdesk, an email platform, a model provider or a hosting company, and the person asking has already been told by somebody that Schrems II made it illegal.
The short answer is that transfers to the United States are lawful under an adequacy decision, that the adequacy decision survived its first annulment action in September 2025, and that the work is in three checks rather than in a legal argument.
How Chapter V works, in three steps
Chapter V of the GDPR governs transfers of personal data to countries outside the EEA, and it offers a ladder.
Article 45 is adequacy. Where the Commission has decided that a country ensures an adequate level of protection, no further authorisation is needed. The United States is on the adequacy list for organisations participating in the EU-US Data Privacy Framework.
Article 46 is appropriate safeguards, of which the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 are the ordinary route. These remain the answer for any US recipient not covered by the Framework, and they come with a transfer impact assessment attached.
Article 49 is derogations for specific situations: explicit consent, necessity for a contract, important reasons of public interest, legal claims, vital interests. The European Data Protection Board's guidelines are unambiguous that these must be interpreted restrictively so that the exception does not become the rule. They are not a route for a recurring business transfer.
Where the Framework stands
The adequacy decision is Commission Implementing Decision (EU) 2023/1795 of 10 July 2023. It is in force and has not been annulled, suspended or repealed.
It was challenged. In Case T-553/23, Latombe v Commission, the General Court dismissed the action on 3 September 2025. An appeal was lodged and appeals of this kind do not suspend the decision.
The nuance that matters commercially, and that gets lost in the headlines: the General Court assessed adequacy as at the date the decision was adopted. It is authority that the Framework was validly adopted. It is not a ruling that the arrangements are sound today.
The Commission's first periodic review reported in October 2024 that the US authorities had put in place the necessary structures and procedures. The Commission moved to a three-year review cycle, so the next scheduled review is not due until around October 2027.
The live question, stated at its actual strength
On 31 July 2026 the Chair of the European Data Protection Board wrote to the Commission asking it to assess closely whether the US Supreme Court's decision in Trump v. Slaughter, which removed for-cause removal protection from Federal Trade Commission Commissioners, affects the functioning of the adequacy decision. That is a request for assessment. It is not a call for suspension and it is not a finding of invalidity. Anybody telling you the Framework has been cast into doubt is overreading a letter.
The three checks, which is the actual work
Relying on adequacy is not a matter of believing that America is fine. It is a matter of establishing that this recipient is covered for this data.
- 1Check the specific legal entity is on the Data Privacy Framework list and that the certification is active. Certifications are annual and they lapse. A parent company's certification does not automatically carry a subsidiary: subsidiaries appear under the entry's other covered entities.
- 2Check the certification covers the type of data you are sending. Certifications are scoped, and not all of them cover HR data.
- 3Check the recipient is even eligible. Only organisations under the jurisdiction of the Federal Trade Commission or the Department of Transportation can certify, which excludes most banks, insurers, telecoms in their common-carrier activities, and non-profits. If your supplier is one of those, the Framework is not available and you are on standard contractual clauses.
The HR data rule, which is more generous than usually reported
Sending employee data to a US supplier, a payroll platform or a group parent is the case where this most often goes wrong, and the common summary of the rule is too strict.
The European Data Protection Board's guidance for businesses sets it out as a two-limb test. The US organisation must either hold an active certification that covers the data as HR data, or hold an active certification covering it as another type of personal data and have committed in its privacy policy to cooperate with EU data protection authorities.
There is also a duty on you rather than on them. The exporter has to tell the US organisation that the transfer includes HR data.
What adequacy does not do
This is the part that turns a transfer question into a compliance gap, and it is short.
Adequacy answers Chapter V. It does not supply a lawful basis under Article 6, it does not satisfy the transparency duties in Articles 13 and 14, and it does not remove the need for a written processor agreement under Article 28. A certified US processor still needs a data processing agreement with the required clauses in it.
That last one is not theoretical in Ireland. The Data Protection Commission's decision against a small credit union found infringements of both Article 28(1) and Article 28(3) alongside the security failures, and the processor paperwork was the part nobody had looked at.
Your privacy notice also has to say this out loud. Article 13(1)(f) requires you to state the intended third country transfers, whether there is an adequacy decision, and the safeguards relied on where there is not. Most Irish notices do not.
What to do where the supplier is not certified
Standard contractual clauses under Article 46, plus a transfer impact assessment, which is the document that asks whether the law of the destination country undermines the clauses in practice and what supplementary measures you have applied.
One gap worth knowing about before anybody promises a client otherwise: the Commission has still not adopted the additional set of clauses for importers that are themselves directly subject to the GDPR under Article 3(2). Its own page continues to describe them as in development. Commentary that quoted a 2025 target for them was reporting an intention rather than an instrument.
The practical order for an Irish SME is: use the Framework where the supplier is genuinely on the list, fall back to clauses where it is not, and treat Article 49 derogations as what they are, which is a route for the one-off rather than for the pipeline.
The AI supplier case, which is the one people ask about now
The same ladder applies to a model provider, and the questions do not change: is the legal entity certified, does the certification cover this data, is there a processor agreement, and does the privacy notice say so.
What does change is the volume and the sensitivity of what goes across, because the input to a model is whatever an employee typed. That is the argument for the rule about confidential and personal data in an AI literacy note, which is the cheapest control available and the one most often skipped.
Sources
- 1.Adequacy decisions, including the EU-US Data Privacy Framework · European Commission
- 2.Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 · EUR-Lex, Publications Office of the European Union
- 3.Data Privacy Framework list of participating organisations · US Department of Commerce, International Trade Administration
- 4.Standard contractual clauses for international transfers · European Commission
- 5.Commission Implementing Decision (EU) 2021/914 on standard contractual clauses · EUR-Lex, Publications Office of the European Union
- 6.EDPB letter to the European Commission on the US Supreme Court judgment · European Data Protection Board
- 7.Regulation (EU) 2016/679, Chapter V · EUR-Lex, Publications Office of the European Union
Free, and the answers stay in your browser
Check whether the processing needs an assessment first
Moving customer records into a new supplier's system is frequently a new purpose for data collected for something else, which is item 1 on the Irish list. The free check says whether an assessment is mandatory.
Run the free checkThe supplier list, and what each one actually holds
The compliance audit produces the register behind all of this: every processor, where it sits, whether it is certified, whether there is an agreement, and the gaps. The gaps are the deliverable as much as the document is.
GDPR and AI compliance auditWho wrote this
Oscar Cobbe · Founder, FourWinds Digital
Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.
More about how we work →Read next
GDPR
Do you need a DPIA? Ireland has its own list, and it is specific
Most guidance answers this with European criteria. Ireland has a published list of its own, and it is the one that decides the question here.
GDPR
Does a small Irish business website need a privacy notice?
We fetched 82 Irish business websites in one week. Thirty-four had no privacy notice at any of the usual addresses, and three had one that nothing on the site linked to.
Measurement
What you are allowed to measure before anybody clicks accept
Most of the measurement conversation is about recovering data that consent removed. A smaller and more useful conversation is about what never needed consent.
Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.