The policy states that personal data, including that of EEA, Swiss, and UK users, is processed and stored on servers in the United States, with transfers covered by Standard Contractual Clauses, EU-US Data Privacy Framework certification, or adequacy decisions as applicable.
This analysis describes what AI21 Labs's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that EEA, Swiss, and UK personal data is transferred to and processed in the United States, and identifies the transfer mechanisms relied upon. Compliance teams at EEA organizations should verify that applicable SCCs are current and correctly implemented, and that DPF certification covers the relevant processing activities.
Interpretive note: The policy does not specify which transfer mechanism applies to which category of data or recipient, and the ongoing legal status of the EU-US Data Privacy Framework creates some uncertainty about the durability of DPF-based transfers.
The policy states that personal data of EEA, Swiss, and UK users is transferred to and processed on servers in the United States. AI21 states it relies on Standard Contractual Clauses, EU-US Data Privacy Framework certification, or adequacy decisions as transfer mechanisms.
Cross-platform context
See how other platforms handle International Data Transfers to the United States and similar clauses.
Compare across platforms →"We process Personal Data on servers located outside of the EEA, Switzerland and the UK for the purposes described in this Privacy Policy. This includes processing and storing your Personal Data in our facilities and servers in the United States. While data protection law varies by country and some countries may not offer the same level of data protection as your country, we apply the below-mentioned protections to your Personal Data. We will obtain contractual commitments from them to protect your Personal Data. We will comply with the transfers rules under the GDPR, including, by implementing a transfer mechanism, for example, transferring Personal Data to a country declared adequate by the European Commission, executing Standard Contractual Clauses with the data recipient and/or relying on their Data Privacy Framework certification.Excerpt from AI21 Labs's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V requirements governing transfers of personal data to third countries.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision discloses that EEA, Swiss, and UK personal data is transferred to and processed in the United States, and identifies the transfer mechanisms relied upon. Compliance teams at EEA organizations should verify that applicable SCCs are current and correctly implemented, and that DPF certification covers the relevant processing activities.
The policy states that personal data of EEA, Swiss, and UK users is transferred to and processed on servers in the United States. AI21 states it relies on Standard Contractual Clauses, EU-US Data Privacy Framework certification, or adequacy decisions as transfer mechanisms.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AI21 Labs.