Last week, the Federal Trade Commission (FTC) reached settlements with five companies regarding allegations that they had falsely claimed to be compliant with the EU-U.S. Privacy Shield framework.

The framework allows companies to transfer data from the U.S. to the EU without running afoul of privacy laws like the General Data Protection Regulation (GDPR), but—and this is a big “but”—companies have to certify ahead of time with the Department of Commerce or potentially face the wrath of the FTC.