Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that in the event of a sale, merger, asset transfer, or other corporate reorganization, Calendly may transfer Personal Data to the parties involved, and users are stated to acknowledge that such transfers are permitted.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes transfer of Personal Data to acquiring or successor entities in a corporate reorganization without requiring additional individual consent at the time of transfer. Under GDPR and CCPA, such transfers may require assessment of whether the successor entity's data practices are consistent with the purposes for which data was originally collected.
Under this clause, Personal Data held by Calendly may be transferred to third parties involved in a corporate sale, merger, or reorganization, and the policy frames this as acknowledged and permitted by users. The terms do not specify notice requirements to individuals prior to or at the time of such a transfer.
Cross-platform context
See how other platforms handle Reorganization Event Data Transfer and similar clauses.
Compare across platforms →Monitoring
Calendly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may, as a result of a sale, merger, consolidation, change in control, transfer of assets, reorganization, or liquidation of our company (a 'Reorganization Event'), transfer or assign your Personal Data to parties involved in the Reorganization Event. You acknowledge that such transfers may occur and are permitted by and subject to this Privacy Notice.Excerpt from Calendly's Privacy Notice
1. REGULATORY LANDSCAPE: GDPR requires that data subjects be informed of changes in data controller identity, and that any material change in processing purposes following a corporate transaction be assessed for compatibility with the original collection purpose. CCPA and CPRA do not prohibit such transfers but require that successor entities honor existing consumer rights requests and opt-outs. The FTC Act may apply if data use by a successor entity materially differs from what was disclosed at collection. 2. GOVERNANCE EXPOSURE: Low to Medium. Corporate reorganization data transfer clauses are standard in commercial privacy notices. The provision's framing that users 'acknowledge' such transfers are permitted may be assessed differently under GDPR's consent and transparency requirements if a reorganization results in materially changed data processing. The absence of a specific notice commitment to individuals in advance of a reorganization transfer is a reviewable gap. 3. JURISDICTION FLAGS: EEA and UK individuals have GDPR rights regarding changes in data controller identity, which may require notification and potentially a new lawful basis assessment if processing purposes change. California residents retain their CCPA rights against successor entities. The enforceability of the 'acknowledgment' framing as consent for future transfers may be limited under GDPR. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations with data processing agreements with Calendly should assess whether those agreements address continuity of obligations in the event of a corporate reorganization, including whether the DPA binds successor entities. Audit rights and data security requirements should be confirmed to survive a reorganization event. 5. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that any corporate reorganization involving Calendly would trigger a data protection impact assessment and notification obligations under applicable law. GDPR Article 14 transparency requirements for changes in controller identity should be assessed in advance of any planned reorganization. The policy should be reviewed to determine whether a notification commitment to users is appropriate to add in future updates.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision authorizes transfer of Personal Data to acquiring or successor entities in a corporate reorganization without requiring additional individual consent at the time of transfer. Under GDPR and CCPA, such transfers may require assessment of whether the successor entity's data practices are consistent with the purposes for which data was originally collected.
Under this clause, Personal Data held by Calendly may be transferred to third parties involved in a corporate sale, merger, or reorganization, and the policy frames this as acknowledged and permitted by users. The terms do not specify notice requirements to individuals prior to or at the time of such a transfer.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.