Calm · Calm Privacy Policy · View original document ↗

International Data Transfer Mechanisms

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Calm Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Calm transfers personal data outside of the EU and other jurisdictions and uses legal mechanisms such as Standard Contractual Clauses to make those transfers lawful; you can request a copy of these agreements by emailing Calm.

This analysis describes what Calm's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

For EU, UK, and Swiss users, the lawfulness of data transfers to the US depends on these mechanisms being properly implemented and maintained.

Interpretive note: The policy does not specify which transfer mechanism applies in which context or confirm the existence of transfer impact assessments, creating some uncertainty about the completeness of compliance with post-Schrems II requirements.

Consumer impact (what this means for users)

Your personal data may be transferred to and processed in the United States, which may have different data protection standards than your home country; Calm states it uses legal transfer mechanisms including Standard Contractual Clauses to protect these transfers.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Email support@calm.com to request a copy of the Standard Contractual Clauses or other transfer safeguards applicable to your personal data as an EU, UK, or Swiss user.

How other platforms handle this

Mistral AI Medium

Customer authorized Mistral AI to transfer Personal Data to any country deemed to have an adequate level of data protection by the European Commission. Customer also authorizes Mistral AI to perform International Data Transfers to (a) on the basis of adequate safeguards in accordance with Applicable...

Unity Medium

Personal data collected by Unity may be transferred to and processed in countries outside of the European Economic Area, including the United States, where data protection laws may differ from those in your country. Where we transfer personal data from the EEA or the UK, we rely on appropriate safeg...

Upwork Medium

When we transfer personal data outside the European Economic Area, United Kingdom, or Switzerland, we use appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, to ensure your data is protected.

See all platforms with this clause type →

Monitoring

Calm has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Where required by law, we provide adequate protection for the transfer of personal data in accordance with applicable law, such as by obtaining your consent, relying on the European Commission's adequacy decisions, or executing Standard Contractual Clauses. Where relevant, you may request a copy of these Standard Contractual Clauses by emailing us at support@calm.com.

— Excerpt from Calm's Calm Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: International data transfers from the EEA and UK to the US are regulated under GDPR Chapter V and the UK GDPR. The policy references European Commission adequacy decisions and Standard Contractual Clauses as transfer mechanisms. Following Schrems II, SCCs must be accompanied by a transfer impact assessment where the destination country's laws may not provide equivalent protection. The EU-US Data Privacy Framework may also be relevant if Calm has certified under it, though the policy does not reference this framework explicitly. (2) GOVERNANCE EXPOSURE: Medium. The policy asserts use of SCCs and adequacy decisions but does not specify which applies in which context, and does not reference transfer impact assessments. For organizations conducting due diligence on Calm as a data processor or sub-processor, the absence of specificity may require additional inquiry. (3) JURISDICTION FLAGS: EEA, UK, and Swiss users face the most direct exposure. The policy names separate representatives for EEA (The DPO Centre Europe Ltd, Dublin) and UK (The DPO Centre, London), which is consistent with post-Brexit requirements. Swiss users should be aware that Swiss data protection law has its own transfer requirements that may differ from the GDPR framework. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations using Calm as a vendor or employee benefit provider should request and review the applicable SCCs and any transfer impact assessments. The policy's offer to provide SCC copies upon request at support@calm.com is a positive disclosure commitment that should be tested in vendor assessments. (5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm whether Calm has certified under the EU-US Data Privacy Framework and whether UK adequacy or transfer mechanisms are separately documented. Periodic review of transfer documentation should be incorporated into vendor management cycles given the evolving landscape of international transfer regulations.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    EU/EEA supervisory authorities (listed at edpb.europa.eu) and the UK ICO are the relevant enforcement bodies for international data transfer compliance; US State AG offices may have parallel jurisdiction for US-resident concerns.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Calm Privacy Policy
Entity
Calm
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-009941
Document ID
CA-D-00218
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6b81368a982bdbc72c1c75ee7ed70374d68d979bedcaaa382c4440f59aef9243
Analysis generated
May 8, 2026 12:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Calm
Document: Calm Privacy Policy
Record ID: CA-P-009941
Captured: 2026-05-08 12:04:34 UTC
SHA-256: 6b81368a982bdbc7…
URL: https://conductatlas.com/platform/calm/calm-privacy-policy/international-data-transfer-mechanisms/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Calm's International Data Transfer Mechanisms clause do?

For EU, UK, and Swiss users, the lawfulness of data transfers to the US depends on these mechanisms being properly implemented and maintained.

How does this clause affect you?

Your personal data may be transferred to and processed in the United States, which may have different data protection standards than your home country; Calm states it uses legal transfer mechanisms including Standard Contractual Clauses to protect these transfers.

Is ConductAtlas affiliated with Calm?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calm.