Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Chegg collects government identification including social security numbers and driver's licenses for identity verification, hiring, and security purposes, and authorizes disclosure to affiliated companies, technology service providers, security vendors, government agencies, and parties in connection with business transitions or legal proceedings.
This analysis describes what Chegg's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Chegg collects social security numbers and other government-issued identifiers, and authorizes disclosure of this data to affiliated companies and cloud computing and technology service providers, which requires review of data security and vendor management controls given the elevated identity theft risk associated with this category.
The updated policy expands disclosure of how personal data is collected, used, and shared across Chegg's services and regional contexts. Users in the EEA, UK, Switzerland, and the US now have access to region-specific privacy disclosures that detail additional legal rights applicable in their jurisdictions. The policy explicitly states that when users access services through an educational institution or employer, Chegg will share personal data and service usage information with that institution or employer to allow monitoring of service use. The policy also discloses that user-provided content, including audio, video, and written materials, may be used to train or fine-tune Chegg and third-party AI models. Users can review their region-specific disclosures and Busuu's supplemental privacy policy to understand additional rights and practices.
View change record →Under these terms, government identification data including social security numbers may be disclosed to affiliated companies, technology infrastructure providers, and security vendors as described, though the policy states this category is not sold or shared for targeted advertising.
Cross-platform context
See how other platforms handle Government Identification Collection and Disclosure and similar clauses.
Compare across platforms →Monitoring
Chegg has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"B. Government Identification (such as social security number, driver's license, and other government-issued identification) a. Purposes for Collection: (1) Administrative (to verify your identity); (2) Hiring Related Purposes (to facilitate your job search; process your employment application; prepare related governmental and internal statistics reports); (3) Security (to investigate, prevent, detect, and protect against misuse of our systems, fraud or other crime, or activities that violate our policies) ... b. Categories of Third Parties the Data May Be Disclosed To: (1) Affiliated Companies; (2) Technology Systems Service Providers (including webhosts, database hosts, software-as-a-service or other cloud computing providers, and technology maintenance and repair vendors) ... c. Third Parties to Whom the Data May Be Sold/Shared for Targeted Advertising: This category of data is not sold or shared for targeted advertising.Excerpt from Chegg's Privacy Policy
REGULATORY LANDSCAPE: Collection and storage of social security numbers and government-issued identifiers is subject to state data security and breach notification statutes in all U.S. states, with heightened requirements in states including California, New York (SHIELD Act), and others. The FTC Act's prohibition on unfair or deceptive practices applies to inadequate security measures for sensitive identifiers. State-specific social security number protection statutes may restrict permissible uses and required safeguards beyond what the policy describes. GOVERNANCE EXPOSURE: High. Social security numbers are a primary target category for identity theft and are subject to heightened security and breach notification obligations under virtually all U.S. state breach notification statutes. The policy's disclosure that this category may be shared with technology service providers including cloud computing vendors requires confirmation of adequate data processing agreements and security controls. JURISDICTION FLAGS: New York's SHIELD Act, California's data breach notification statute, and equivalent statutes in all U.S. states impose specific breach notification and reasonable security obligations for social security numbers. Several states additionally restrict permissible uses of social security numbers beyond those stated in the policy. EU/EEA national identification numbers are regulated as personal data under GDPR with potential special category treatment depending on member state law. CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with technology service providers, cloud computing vendors, and affiliated companies receiving government identification data should specify encryption standards, access controls, retention limits, and breach notification procedures. The policy's authorization to share this data with affiliated companies and technology vendors in connection with business transitions requires review of transition planning and data handling protocols. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that social security number collection is limited to contexts where legally required or operationally necessary, review data processing agreements with all technology service provider recipients of this category, assess encryption and access control standards applied to government identification data at rest and in transit, and ensure breach notification procedures are operationally implemented for this high-risk data category.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that Chegg collects social security numbers and other government-issued identifiers, and authorizes disclosure of this data to affiliated companies and cloud computing and technology service providers, which requires review of data security and vendor management controls given the elevated identity theft risk associated with this category.
Under these terms, government identification data including social security numbers may be disclosed to affiliated companies, technology infrastructure providers, and security vendors as described, though the policy states this category is not sold or shared for targeted advertising.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Chegg.