Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Personal Data of individuals located in the EEA, UK, Canada, and other non-U.S. jurisdictions will be processed and stored in the United States or in countries where Calendly's service providers operate, and that those jurisdictions may not offer equivalent privacy protections.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that Personal Data from EEA, UK, and Canadian individuals is transferred to and stored in the United States, a jurisdiction that has historically been subject to adequacy assessments by European and UK data protection authorities. The policy states that transfer mechanisms including the DPF, Standard Contractual Clauses, and UK Addendum are relied upon to legitimize these transfers.
Under this clause, Personal Data submitted by EEA, UK, and Canadian users is stated to be transferred to and processed in the United States or in countries where Calendly's service providers are located. The policy acknowledges that these jurisdictions may not provide the same level of privacy protection as the user's home country.
Cross-platform context
See how other platforms handle International Data Transfer and U.S. Storage Disclosure and similar clauses.
Compare across platforms →Monitoring
Calendly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you are an individual located in the European Economic Area, the United Kingdom, Canada or another jurisdiction outside of the United States with laws and regulations governing Personal Data collection, use, and disclosure that differ from United States laws, please be aware that information we collect (including through the use of methods such as Cookies and other web technologies) will be processed and stored in the United States or in other countries where we or our Service Providers have operations. By submitting your Personal Data to Calendly and using Calendly, please be aware that your Personal Data may be transferred to, processed, and stored in the United States or another jurisdiction which may not offer the same level of privacy protection as those in the country where you reside.Excerpt from Calendly's Privacy Notice
1. REGULATORY LANDSCAPE: Cross-border data transfers from the EEA are governed by GDPR Chapter V, which requires a lawful transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or binding corporate rules. The EU-U.S. DPF constitutes an adequacy decision for DPF-certified organizations. UK transfers are governed by UK GDPR and the UK International Data Transfer Agreement. Canadian transfers are governed by PIPEDA and provincial equivalents. 2. GOVERNANCE EXPOSURE: Medium. The policy's reliance on the DPF adequacy decision is subject to ongoing legal and political risk; organizations should maintain Standard Contractual Clauses as a supplementary mechanism in the event of DPF invalidation, consistent with the policy's statement that SCCs are also relied upon. The reference to service provider locations without specific enumeration creates some opacity for data mapping purposes, though a sub-processor list is referenced. 3. JURISDICTION FLAGS: EEA and UK individuals face the most structured regulatory framework governing their data transfers, with enforcement by national data protection authorities and the European Data Protection Board. Canadian users are subject to PIPEDA, which requires comparable protection for offshore transfers. The policy does not address transfers to or from other specific non-U.S. jurisdictions in detail. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations in the EEA and UK procuring Calendly should confirm that Standard Contractual Clauses are executed in addition to reliance on the DPF, given the historical pattern of DPF predecessor frameworks being invalidated. The sub-processor list referenced in the policy should be reviewed to identify the jurisdictions in which sub-processors operate and assess the adequacy of transfer mechanisms for each. 5. COMPLIANCE CONSIDERATIONS: Data protection officers in EEA and UK organizations should conduct transfer impact assessments for Calendly data flows, particularly for meeting recordings and transcripts that may contain sensitive personal data. The policy's reliance on SCCs and the UK Addendum should be confirmed against executed data processing agreements. Canadian compliance teams should assess whether Calendly's transfer arrangements satisfy PIPEDA accountability principles for offshore processing.
This provision discloses that Personal Data from EEA, UK, and Canadian individuals is transferred to and stored in the United States, a jurisdiction that has historically been subject to adequacy assessments by European and UK data protection authorities. The policy states that transfer mechanisms including the DPF, Standard Contractual Clauses, and UK Addendum are relied upon to legitimize these transfers.
Under this clause, Personal Data submitted by EEA, UK, and Canadian users is stated to be transferred to and processed in the United States or in countries where Calendly's service providers are located. The policy acknowledges that these jurisdictions may not provide the same level of privacy protection as the user's home country.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.