Provision record
Adyen · Adyen Privacy Policy · View original document ↗

Cross-Border Data Transfer via Standard Contractual Clauses

Medium severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Adyen and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Adyen transfers personal data to group companies and service providers outside the EEA using Standard Contractual Clauses embedded in an intragroup agreement and in third-party service provider contracts, with a separate disclosure for Quebec residents regarding intra-group transfers.

This analysis describes what Adyen's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes SCCs as the primary mechanism for EEA data exports, which requires Adyen to have conducted transfer impact assessments for all destination countries following the CJEU's Schrems II decision, and compliance teams should verify whether those assessments are current and documented for all disclosed transfer destinations.

Interpretive note: The adequacy of Adyen's SCC-based transfer framework depends on whether transfer impact assessments have been conducted for all destination countries, which the document does not confirm.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this provision, personal data submitted to Adyen may be transferred to Adyen group companies and service providers in countries outside the EEA, with SCCs serving as the stated safeguard. The policy references a list of countries where Adyen has operations but does not enumerate them within the privacy statement itself.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact Adyen's Data Protection Officer at dpo@adyen.com to request further information about the safeguards applied to cross-border transfers or to exercise data subject rights in connection with transferred data.

Cross-platform context

See how other platforms handle Cross-Border Data Transfer via Standard Contractual Clauses and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Some of the information you send us may be disclosed to other Adyen group companies outside of the European Economic Area ("EEA"). These countries encompass the countries in which we have operations (you can find a full list here). If you are a resident in Quebec, some of the information you send us may be disclosed to Adyen group companies outside of Quebec. To protect your data when it is transferred to countries outside of the EEA, we have implemented appropriate safeguards. When we transfer data to our Adyen group companies, the transfers are protected by an intragroup agreement containing Standard Contractual Clauses. For transfers to our services providers located outside of the EEA, we rely on Standard Contractual Clauses.

Excerpt from Adyen's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
Adyen Privacy Policy
Entity
Adyen
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
July 9, 2026
Record ID
CA-P-016122
Document ID
CA-D-00665
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9602a235ae55da92a34e62451772c2da8be4a10613dd511a8cca10f9447bd5b2
Analysis generated
May 7, 2026 23:14 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Adyen
Document: Adyen Privacy Policy
Record ID: CA-P-016122
Captured: 2026-05-07 23:14:02 UTC
SHA-256: 9602a235ae55da92…
URL: https://conductatlas.com/platform/adyen/adyen-privacy-policy/provision/CA-P-016122/cross-border-data-transfer-via-standard-contractual-clauses/
Accessed: Aug. 11, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Adyen's Cross-Border Data Transfer via Standard Contractual Clauses clause do?

This provision establishes SCCs as the primary mechanism for EEA data exports, which requires Adyen to have conducted transfer impact assessments for all destination countries following the CJEU's Schrems II decision, and compliance teams should verify whether those assessments are current and documented for all disclosed transfer destinations.

How does this clause affect you?

Under this provision, personal data submitted to Adyen may be transferred to Adyen group companies and service providers in countries outside the EEA, with SCCs serving as the stated safeguard. The policy references a list of countries where Adyen has operations but does not enumerate them within the privacy statement itself.

Is ConductAtlas affiliated with Adyen?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Adyen.