CA-C-002165
Medium — Medium Privacy Policy
Entity
Date detected
May 18, 2026
Effective date
May 18, 2026
Severity
Low
Direction
Positive
Affected users
all users users who use address book feature
Taxonomy
Transparency removal
Changes
+7 sentences added · −1 sentence removed · 2 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch Medium Get alerts when this policy changes.
Watch — Free

Event Summary

Medium updated its Privacy Policy on May 18, 2026 to add detailed disclosure about its address book contact feature. The new language explains that when users opt in to this feature, Medium converts contact names and email addresses into encrypted, non-reversible identifiers to match against its member database. Medium does not store names or emails in plain text, deletes identifiers for non-members immediately, and deletes all encrypted identifiers within 30 days. The policy also reorganized its personal information collection disclosure, though the categories themselves (identifiers, commercial information, internet activity, inferences) remain unchanged.

LOW

Consumer Impact

The updated policy adds transparency about Medium's address book feature by explaining the technical process: contact names and emails are converted into encrypted identifiers, matched against Medium's member database, and then deleted. For contacts who are not Medium members, these encrypted identifiers are deleted immediately; all encrypted identifiers are deleted within 30 days regardless. The policy states Medium relies on legitimate interests to offer this feature, specifically its interest in helping users connect with people they know. You can review the specific disclosure in the 'Helping You Connect With People You Know' section of the updated policy.

Governance Analysis

The updated terms establish explicit disclosure of a previously undescribed contact matching feature. This disclosure documents the technical safeguards (encryption, deletion timelines, plain-text non-storage) and the lawful basis (legitimate interests) Medium asserts for the processing. For users, this clarifies how contact data is handled when they opt into address book features. For regulators and data protection authorities, this disclosure creates a documented record of processing practices and safeguards.

Key Clauses Affected

Address Book Contact Matching Disclosure

Added new section explaining that contact names and emails are converted to encrypted identifiers, matched against Medium's database, and deleted within 30 days (immediately for non-members).

Lawful Basis Statement

Stated that Medium relies on legitimate interests under Article 6(1)(f) to offer this feature, citing the interest in helping users connect and supporting freedom of expression.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Medium — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
344b4b3cfd9dbacaed219b488b7c41d5a4f6226b22f3fb0ba7fd7224f1946573
April 26, 2026 06:19 UTC
✓ Verified
Current Version
311b83ba6da0980f518b95cc57466bfc704e527da40a9471e2fde7c772eae6ef
May 18, 2026 00:26 UTC
✓ Verified
Change Detected
May 18, 2026 00:26 UTC
Analysis Methodology
Citation Record
Entity: Medium
Document: Medium Privacy Policy
Record ID: CA-C-002165
Captured: 2026-05-18 00:26:27 UTC
URL: https://conductatlas.com/change/2026-05-18-medium-medium-privacy-policy-2165/
Accessed: May 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Medium added explicit disclosure of its address book contact matching feature and the technical safeguards it employs. The change operationalizes consent and technical documentation that may be relevant to GDPR Article 6(1)(f) (legitimate interests), Article 35 (DPIA trigger), and CCPA/CPRA collection and deletion obligations. The disclosure identifies the feature as opt-in and describes encryption, non-storage of plain-text data, and deletion timelines. No material change to Medium's stated processing practices appears to have occurred; the change is primarily disclosure and documentation. Organizations using Medium for user acquisition or account linking should verify whether this feature engages their own data controller or processor obligations.

Regulatory Exposure

GDPR (lawful basis for processing under Article 6(1)(f), international data transfers if applicable), CCPA/CPRA (collection and deletion requirements), LGPD (Brazil), and ePrivacy Directive (electronic communications data).

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002165.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Medium Privacy Policy
Entity
Medium
Captured
May 18, 2026
Source URL
https://policy.medium.com/medium-privacy-policy-f03bf92035c9
Other changes to Medium Privacy Policy
Previous change Apr 26, 2026
Medium's privacy policy was updated on April 26, 2026, but the changes appear to be primarily formatting and structural rather …
Low Neutral
View full version history →
More from Medium
May 1, 2026 Low
Medium Terms of Service

Medium's Terms of Service page now displays a '46K' metric next to the Listen and Share buttons, which appears to …

Apr 26, 2026 Low
Medium Privacy Policy

Medium's privacy policy was updated on April 26, 2026, but the changes appear to be primarily formatting and structural rather …

Apr 26, 2026 Low
Medium Terms of Service

Medium's Terms of Service were updated on April 26, 2026, but the detected changes appear to be primarily formatting and …

Track Medium policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.