Compliance · Updated September 8, 2026

EU–US data transfers

International transfers depend on the recipient, the information transferred, and the applicable safeguards. A provider’s country alone does not answer every compliance question.

The Data Privacy Framework

The EU–US Data Privacy Framework provides an adequacy route for transfers to participating US organisations covered by the framework. Check the recipient’s participation and the scope of its certification; the framework does not remove other GDPR obligations. EDPB guidance for European businesses, updated January 2026.

Where Schrems II fits

The 2020 Schrems II judgment invalidated Privacy Shield. The newer Data Privacy Framework is a different mechanism. Other transfer routes, including standard contractual clauses where appropriate, require consideration of their own conditions and safeguards. European Commission overview.

Reviewing Fathom’s processing

Our data isolation overview describes Fathom’s approach to EU visitor traffic. Use it alongside the data journey, DPA, and subprocessor list when assessing the information processed and the providers involved.

Visitor analytics, account information, and support communications can involve different data flows. A claim about one flow should not be treated as a guarantee covering every transfer. Likewise, hashing does not by itself establish legal anonymity or eliminate transfer obligations.

Information to establish

For a transfer review, identify the data and recipients involved, the relevant contractual or adequacy mechanism, and any safeguards needed. If you need confirmation of regional routing, logging, or the processing boundary for your use case, contact us for the details needed by your privacy team.

These guides explain privacy requirements and how they relate to Fathom. They are general information, not legal advice. Your obligations depend on your website, its visitors, and how you use analytics. Contact us for information about your setup.