Bluesky · Bluesky Privacy Policy · View original document ↗

International Data Transfers with Standard Contractual Clauses

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Bluesky Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Bluesky may store and process your data anywhere in the world, and for users in the EU, UK, and Brazil it uses Standard Contractual Clauses or similar approved mechanisms to make those transfers legal.

This analysis describes what Bluesky's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

EU, UK, and Brazilian users should know their data may be transferred to the US or other countries with different privacy protections, though Bluesky states it uses legally recognized transfer mechanisms to protect that data.

Consumer impact (what this means for users)

Personal data of EU, UK, and Brazilian users may be transferred to and stored in countries with weaker data protection laws; Bluesky states it uses Standard Contractual Clauses or equivalent mechanisms to provide legal protection for those transfers.

How other platforms handle this

Unity Medium

Personal data collected by Unity may be transferred to and processed in countries outside of the European Economic Area, including the United States, where data protection laws may differ from those in your country. Where we transfer personal data from the EEA or the UK, we rely on appropriate safeg...

Upwork Medium

When we transfer personal data outside the European Economic Area, United Kingdom, or Switzerland, we use appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, to ensure your data is protected.

Figma Medium

When we transfer personal information from the European Economic Area, United Kingdom, or Switzerland to countries that have not been found to provide an adequate level of protection under applicable law, we take steps to provide appropriate safeguards, including through the use of Standard Contract...

See all platforms with this clause type →

Monitoring

Bluesky has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may transfer, process, and store all personal information we collect anywhere in the world. Different countries have different data protection laws. If we transfer personal information from the European Economic Area, Switzerland, Brazil and/or the United Kingdom to a country that does not provide an adequate level of protection under applicable data protection laws, we will do so (i) using appropriate safeguards; (ii) based on safeguards like the European Commission-approved, UK Government-approved, or Brazil's Data Protection Authority Standard Contractual Clauses or Addenda; or (iii) otherwise in accordance with applicable data protection laws.

— Excerpt from Bluesky's Bluesky Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V on international transfers, UK GDPR equivalent provisions, and Brazil's LGPD international transfer rules. Standard Contractual Clauses (SCCs) approved by the European Commission are the primary transfer mechanism referenced, and their validity depends on supplementary measures where the destination country's surveillance laws may undermine SCC protections (the Schrems II framework). The relevant supervisory authorities are EU national Data Protection Authorities, the UK ICO, and Brazil's ANPD. (2) GOVERNANCE EXPOSURE: Medium. Use of SCCs is standard practice and a recognized transfer mechanism, but post-Schrems II compliance requires documented Transfer Impact Assessments (TIAs) confirming that SCCs provide effective protection in the destination country. The policy does not specify whether TIAs have been conducted or what supplementary measures are in place. (3) JURISDICTION FLAGS: EU and UK users face the most significant exposure if SCCs are not accompanied by adequate supplementary measures. Switzerland has its own transfer adequacy framework. Brazilian LGPD international transfer rules are still developing and may require monitoring. US government surveillance capabilities remain a relevant factor in TIA assessments for transfers to the US. (4) CONTRACT AND VENDOR IMPLICATIONS: All processors receiving EU, UK, or Brazilian user data must have executed SCCs or equivalent instruments. Procurement and vendor management teams should maintain a register of international transfer mechanisms and conduct periodic TIA reviews, particularly for processors located in the United States. (5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that Transfer Impact Assessments are in place for all material international transfer pathways, particularly to the US. The policy should ideally specify which version of the EU SCCs is in use (the 2021 European Commission SCCs) and confirm that UK IDTA or addenda are in place for UK transfers. ANPD guidance on LGPD international transfers should be monitored for developing requirements.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
DMA
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Bluesky Privacy Policy
Entity
Bluesky
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 9, 2026
Record ID
CA-P-007840
Document ID
CA-D-00540
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d3fb9d2fd438c6da2bbc607b5416b4e0db38629057fd4171e71f8fb9f7bd1deb
Analysis generated
May 7, 2026 14:41 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Bluesky
Document: Bluesky Privacy Policy
Record ID: CA-P-007840
Captured: 2026-05-07 14:41:50 UTC
SHA-256: d3fb9d2fd438c6da…
URL: https://conductatlas.com/platform/bluesky/bluesky-privacy-policy/international-data-transfers-with-standard-contractual-clauses/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Bluesky's International Data Transfers with Standard Contractual Clauses clause do?

EU, UK, and Brazilian users should know their data may be transferred to the US or other countries with different privacy protections, though Bluesky states it uses legally recognized transfer mechanisms to protect that data.

How does this clause affect you?

Personal data of EU, UK, and Brazilian users may be transferred to and stored in countries with weaker data protection laws; Bluesky states it uses Standard Contractual Clauses or equivalent mechanisms to provide legal protection for those transfers.

Is ConductAtlas affiliated with Bluesky?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Bluesky.