Post-withdrawal, Annual Affirmation Questionnaire

Self-Certifications under the Data Privacy Framework Program

instr_DPF post-withdrawal aff qnr_06-01-23_clean

OMB: 0625-0280

Document [pdf]
Download: pdf | pdf
A Federal agency may not conduct or sponsor an information collection subject to the requirements of the Paperwork Reduction Act of 1995
unless the information collection has a currently valid OMB Control Number. The approved OMB Control Number for this information
collection is 06XX-XXXX (expires MM/DD/YYYY). Without this approval, we could not conduct this information collection. Public reporting for
this information collection is estimated to be approximately 25 minutes per response, including the time for reviewing instructions,
searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the information collection. All
responses to this information collection are voluntary. Send comments regarding this burden estimate or any other aspect of this
information collection, including suggestions for reducing this burden to ITA Paperwork Reduction Act Officer at [email protected].

You are receiving this questionnaire because your organization withdrew from the the EU-U.S. Data Privacy Framework (EUU.S. DPF) and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. Data Privacy Framework (Swiss-U.S.
DPF) and verified at the time of its withdrawal from the relevant part(s) of the DPF program that it would retain personal data
received in reliance on said part(s) of the DPF program, continue to apply the DPF Principles to such data, and affirm to the
U.S. Department of Commerce's International Trade Administration (ITA) on an annual basis its commitment to apply the DPF
Principles to such data.
Your organization must continue to apply the DPF Principles to the personal data that it received under the relevant part(s) of
the DPF program and affirm to the ITA on an annual basis its commitment to do so, for as long as it stores, uses or discloses
such data; otherwise, your organization must return or delete the data or provide “adequate” protection for the data by
another authorized means and notify the ITA of such action.
Your organization must verify in this questionnaire what it has done and, as applicable, will do with the personal data that it
received in reliance on its participation in the relevant part(s) of the DPF program and who within the organization will serve
as an ongoing point of contact for DPF-related questions. If your organization has returned or deleted all such data or
provides “adequate” protection for the data by another authorized means and notifies the ITA of such action by completing
and submitting this questionnaire, it will no longer be required to complete and submit this annual questionnaire.
Failure to respond to this request within 30 days may be subject to enforcement action by the Federal Trade Commission, 
the U.S. Department of Transportation, or other enforcement authorities. 

Post-withdrawal, Annual Affirmation Questionnaire
1) Please confirm that: (i) you are authorized to make representations on behalf of your organization
and its covered U.S. entities and U.S. subsidiaries regarding its adherence to the DPF Principles for
purposes of withdrawal from the relevant part(s) of the DPF program; (ii) the information submitted
to the U.S. Department of Commerce for purposes of such withdrawal, including with regard to
personal data received in reliance on its participation in the relevant part(s) of the DPF program, is
accurate and correct; (iii) you understand that misrepresentations in any information provided to
the Department may be actionable under the False Statements Act, 18 U.S.C. § 1001; and (iv) you
understand that failure to adhere to the DPF Principles with regard to such personal data may lead
to enforcement actions by the relevant enforcement authority.

2) Please provide the following information concerning the organization that self‐certified its
adherence to the DPF Principles:
a. Organization Name;

b. Organization Contact (the individual and/or office within your organization handling
complaints, access requests, and any other issues concerning your organization’s compliance
with the EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the
Swiss-U.S. DPF);

i. Name;
ii. Job title;
iii. Phone number; and
iv. E‐mail address
c. Organization Corporate Officer (the individual certifying your organization’s compliance with
the EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the SwissU.S. DPF);
i.

Name;

ii.

Job title;

iii.

Phone number; and

iv.

E‐mail address

d. Mailing Address

Select the relevant part(s) of the DPF program from which your organization withdrew:
EU-U.S. DPF

3) With regard to personal data received in reliance on the relevant part(s) of the DPF program, which
your organization indicated at the time of its withdrawal would be retained by your organization,
please verify that it was:
a. Retained and subjected to the DPF Principles;
b. Retained and “adequate” protection for such data was provided by another authorized
means; or
c. Returned or deleted.  If so, specify the date by which all such data was returned or deleted.

4) With regard to personal data received in reliance on the relevant part(s) of the DPF program, which
is retained by your organization, please verify that your organization will:
a. Retain such data, continue to apply the DPF Principles to such data, and affirm to the ITA on
an annual basis its commitment to apply the DPF Principles to such data; or
b. Retain such data and provide “adequate” protection for such data by another authorized
means.


File Typeapplication/pdf
File TitleMicrosoft Word - PS questionnaire_Withdrawal_04-2017
AuthorDavid Ritchie
File Modified2023-05-11
File Created2017-04-17

© 2024 OMB.report | Privacy Policy