Adyen transfers personal data to group companies and service providers outside the EEA using Standard Contractual Clauses embedded in an intragroup agreement and in third-party service provider contracts, with a separate disclosure for Quebec residents regarding intra-group transfers.
This analysis describes what Adyen's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes SCCs as the primary mechanism for EEA data exports, which requires Adyen to have conducted transfer impact assessments for all destination countries following the CJEU's Schrems II decision, and compliance teams should verify whether those assessments are current and documented for all disclosed transfer destinations.
Interpretive note: The adequacy of Adyen's SCC-based transfer framework depends on whether transfer impact assessments have been conducted for all destination countries, which the document does not confirm.
Under this provision, personal data submitted to Adyen may be transferred to Adyen group companies and service providers in countries outside the EEA, with SCCs serving as the stated safeguard. The policy references a list of countries where Adyen has operations but does not enumerate them within the privacy statement itself.
Cross-platform context
See how other platforms handle Cross-Border Data Transfer via Standard Contractual Clauses and similar clauses.
Compare across platforms →"Some of the information you send us may be disclosed to other Adyen group companies outside of the European Economic Area ("EEA"). These countries encompass the countries in which we have operations (you can find a full list here). If you are a resident in Quebec, some of the information you send us may be disclosed to Adyen group companies outside of Quebec. To protect your data when it is transferred to countries outside of the EEA, we have implemented appropriate safeguards. When we transfer data to our Adyen group companies, the transfers are protected by an intragroup agreement containing Standard Contractual Clauses. For transfers to our services providers located outside of the EEA, we rely on Standard Contractual Clauses.Excerpt from Adyen's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes SCCs as the primary mechanism for EEA data exports, which requires Adyen to have conducted transfer impact assessments for all destination countries following the CJEU's Schrems II decision, and compliance teams should verify whether those assessments are current and documented for all disclosed transfer destinations.
Under this provision, personal data submitted to Adyen may be transferred to Adyen group companies and service providers in countries outside the EEA, with SCCs serving as the stated safeguard. The policy references a list of countries where Adyen has operations but does not enumerate them within the privacy statement itself.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Adyen.