Compliance with the GDPR by US companies doing business in the EU has become a sore point between the parties, the most recent salvo being invalidation of the Privacy Shield framework by the European Court of Justice. In March 2022, the European Commission and the US reached an agreement in principle for a Trans-Atlantic Data Privacy Framework. On July 10, 2023 of this year, the European Commission adopted its adequacy decision for the Framework.
The Framework introduces new binding safeguards to address the concerns raised by the European Court of Justice with Privacy Shield, including limiting access to data by US intelligence services to what is necessary and proportionate. The Framework also established a Data Protection Review Court (DPRC). In the event the DPRC finds that data was collected in violation of the Framework it will be able to order deletion of the data. US companies will be able to join the Framework by committing to comply with a detailed set of privacy obligations.
More about decision can be found here: https://ec.europa.eu/commission/presscorner/detail/en/ip_23_3721.