Change record
CA-C-002187
Segment Privacy Policy
Entity
Date detected
May 19, 2026
Effective date
May 19, 2026
Severity
Direction
Positive
Affected users
all users EU users UK users Swiss users
Taxonomy
Cross border transfer change
Changes
+12 sentences added · 3 sentences modified
Get alerted the next time Segment changes these terms. Follow Segment →
Share 𝕏 Share in Share 🔒 PDF
Segment: get same-day alerts

We email you the diff and what it means, the day it happens.

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Event Summary

Segment updated its privacy policy on May 19, 2026 to provide more detailed disclosure of its Data Privacy Framework (DPF) compliance certifications and mechanisms. The policy now explicitly states that Twilio Inc. and subsidiary Stytch Inc. have certified compliance with the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF frameworks, and clarifies that if these frameworks conflict with other policy terms, the DPF Principles govern. The policy also added specific opt-out rights for third-party disclosure and non-originally-authorized uses of personal data, and replaced a reference to a dispute resolution provider with the named provider JAMS.

MEDIUM

Consumer Impact

The updated terms establish clearer disclosure of how Segment transfers personal data internationally. Segment now explicitly certifies its compliance with the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. Data Privacy Framework, and states that these DPF Principles take precedence if they conflict with other policy terms. The updated policy also adds specific rights allowing you to opt out of: (i) disclosure of your personal data to third parties other than service providers acting under Segment's instructions, or (ii) use of your personal data for purposes materially different from the original purpose or your subsequent authorization. You can exercise these rights by contacting privacy@twilio.com.

Governance Analysis

The updated terms establish explicit legal compliance commitments and international transfer mechanisms for personal data from regulated jurisdictions. By certifying DPF compliance and stating that DPF Principles take precedence, Segment provides clearer legal grounding for cross-border data transfers from the EU, UK, and Switzerland to the U.S. The addition of specific opt-out rights for third-party disclosure and non-authorized uses strengthens transparency and user control mechanisms for affected data subjects. Organizations relying on Segment must ensure their own compliance documentation and vendor management accurately reflect these mechanisms.

Available Actions

Review the Data Privacy Framework program information at https://www.dataprivacyframework.gov/ to understand your protections

Contact privacy@twilio.com if you wish to opt out of third-party disclosure of your personal data or use of your data for non-originally-authorized purposes

If No Action Is Taken

Your personal data will be transferred across borders under the Data Privacy Framework mechanisms as stated, unless you affirmatively opt out.

If Segment processes your data in a way that violates DPF Principles, Twilio remains liable unless it proves it was not responsible for the violation.

Key Clauses Affected

Data Privacy Framework Certification and Precedence

Segment explicitly certifies compliance with EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF, and states DPF Principles take precedence over conflicting policy terms.

DPF Opt-Out Rights

Added explicit opt-out mechanism for third-party disclosure and non-originally-authorized uses of personal data, exercisable by contacting privacy@twilio.com.

Third-Party Liability Under DPF

Policy establishes that Twilio remains liable for DPF violations by third parties processing data on Twilio's behalf unless Twilio proves non-responsibility.

Full clause-by-clause analysis available with Insight.
Get alerted on what happens next

These clauses may change again. Monitor gets you a same-day alert with the diff.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
8aa34d875deca43dc028e30e5b310acd78aaa2c08ec1ee04ae93e035e3836716
May 5, 2026 06:38 UTC
✓ Verified
Current Version
a4a3739040fcfcfee702f9dde1f1911f4986a957578b5fbc26065971ffb592c4
May 19, 2026 01:14 UTC
✓ Verified
Change Detected
May 19, 2026 01:14 UTC
Analysis Methodology
✓ Verified
Source Document
https://segment.com/legal/privacy/
Citation Record
Entity: Segment
Document: Segment Privacy Policy
Record ID: CA-C-002187
Captured: 2026-05-19 01:14:48 UTC
URL: https://conductatlas.com/change/2026-05-19-segment-segment-privacy-policy-2187/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

2
New obligations
1
Expanded
Data controllers using Segment Added

If you use Segment to process EU, UK, or Swiss personal data, Segment now commits to DPF compliance and you should disclose this in your own privacy notices.

Data subjects (consumers) Added

You can now opt out of Segment sharing your data with third parties and using your data for new purposes not originally disclosed, by contacting privacy@twilio.com.

Data controllers using Segment Expanded

When EU, UK, or Swiss data is involved, DPF requirements override other policy terms if there is conflict.

For legal and compliance teams

Institutional Analysis

Assessment

Segment updated its privacy policy to provide more granular disclosure of Data Privacy Framework compliance and certification status, and to establish explicit opt-out mechanisms for third-party disclosure and non-originally-authorized uses of personal data. The policy now states that DPF Principles take precedence over conflicting policy terms. For organizations using Segment, this change affects how they represent Segment's international data transfer safeguards to their own customers and regulators, particularly for EU, UK, and Swiss data subjects. Organizations should verify whether their Data Processing Agreements, Standard Contractual Clauses, and privacy notices accurately reflect these updated mechanisms and whether downstream disclosure to their own customers requires updating.

Full institutional analysis

Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002187.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
Segment Privacy Policy
Entity
Segment
Captured
May 19, 2026
Source URL
https://segment.com/legal/privacy/
Other changes to Segment Privacy Policy
Next change May 22, 2026
Segment updated its privacy policy on May 22, 2026 to add two new provisions and clarify one existing process. The …
Medium Positive
View full version history →
More from Segment
Jul 17, 2026 Low
Segment Terms of Service

Segment updated its Terms of Service to expand the geographic scope of jurisdictional provisions, adding Albania and Nigeria to the …

Jul 3, 2026 Low
Segment Privacy Policy

Segment's privacy policy navigation menu was updated on July 3, 2026 to remove the reference to 'GDPR Customer Data Protection …

Jul 3, 2026 Low
Segment Terms of Service

Segment's Terms of Service table of contents was updated on July 3, 2026, with a single sentence change. The update …

Related Analysis
Privacy · April 29, 2026
What 38 AI Companies Actually Say About Your Data (2026)

We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and lia…

Track Segment policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All Segment changes →