Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Calendly has certified to the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. DPF, and that in any conflict between the privacy notice and DPF Principles, the Principles govern; it also establishes that Calendly bears liability for onward transfers to third-party agents who process data inconsistently with the DPF Principles unless Calendly proves it is not responsible.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes DPF certification as the primary legal mechanism for EU, UK, and Swiss data transfers to the United States, with DPF Principles taking precedence over the privacy notice in cases of conflict. The onward transfer liability provision is a materially significant commitment: Calendly accepts liability for its agents' DPF-inconsistent processing unless it can demonstrate it is not responsible.
Under this clause, EU, UK, and Swiss individuals whose Personal Data is transferred to Calendly in the United States are covered by DPF Principles, which in conflicts with the privacy notice take precedence. Unresolved complaints about DPF compliance can be escalated to JAMS dispute resolution at no charge, and binding arbitration is available under DPF Annex I as a further mechanism.
Cross-platform context
See how other platforms handle EU-U.S. Data Privacy Framework Certification and Binding Arbitration and similar clauses.
Compare across platforms →Monitoring
Calendly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Calendly, LLC complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Calendly has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this privacy notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. In compliance with the DPF principles, when we transfer Personal Data to a third party acting as our agent, we will be liable under the Principles if our agent processes such Personal Data in a manner inconsistent with the Principles unless we prove we are not responsible for the event giving rise to the damage.Excerpt from Calendly's Privacy Notice
1. REGULATORY LANDSCAPE: The EU-U.S. Data Privacy Framework is administered by the U.S. Department of Commerce and overseen by the FTC for commercial organizations. The DPF was adopted by the European Commission under an adequacy decision; its continued adequacy is subject to ongoing review by European data protection authorities and the Court of Justice of the European Union. Standard Contractual Clauses and the UK Addendum are also stated as supplementary transfer mechanisms. The FTC is identified as the enforcement authority for DPF compliance. 2. GOVERNANCE EXPOSURE: Medium. DPF certification creates enforceable obligations regarding data handling, onward transfer, access, and redress for EU, UK, and Swiss individuals. The onward transfer liability provision means Calendly bears compliance risk for how its sub-processors handle data received from European individuals. Organizations in the EEA relying on Calendly's DPF certification for transfer legitimacy should monitor the status of the DPF adequacy decision. 3. JURISDICTION FLAGS: EEA, UK, and Swiss individuals have the highest exposure and the most formal redress rights under this provision, including the right to contact JAMS and, ultimately, to invoke binding arbitration under DPF Annex I. U.S. organizations with EEA, UK, or Swiss employees or customers using Calendly as a scheduling tool should assess whether their data processing agreements with Calendly adequately address DPF transfer requirements. 4. CONTRACT AND VENDOR IMPLICATIONS: The DPF certification can be verified at https://www.dataprivacyframework.gov/. Organizations relying on this certification for GDPR Article 46 transfer compliance should confirm current certification status and scope, including whether all relevant data processing activities are covered. The liability commitment for onward transfers means Calendly's sub-processor management practices are directly relevant to DPF compliance posture. 5. COMPLIANCE CONSIDERATIONS: Legal teams should verify Calendly's current DPF certification status and scope at the DPF program registry. EEA data protection officers should assess whether the Standard Contractual Clauses and UK Addendum in place provide adequate supplementary protection given the current regulatory environment for U.S. transfers. The availability of JAMS as a free dispute resolution mechanism and binding arbitration under DPF Annex I should be documented in privacy compliance records for EU, UK, and Swiss individuals.
This provision establishes DPF certification as the primary legal mechanism for EU, UK, and Swiss data transfers to the United States, with DPF Principles taking precedence over the privacy notice in cases of conflict. The onward transfer liability provision is a materially significant commitment: Calendly accepts liability for its agents' DPF-inconsistent processing unless it can demonstrate it is not responsible.
Under this clause, EU, UK, and Swiss individuals whose Personal Data is transferred to Calendly in the United States are covered by DPF Principles, which in conflicts with the privacy notice take precedence. Unresolved complaints about DPF compliance can be escalated to JAMS dispute resolution at no charge, and binding arbitration is available under DPF Annex I as a further …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.