Cohere · Cohere Privacy Policy · View original document ↗

Cross-Border Data Transfers

Medium severity Medium confidence Inferredfromcontext Common · 83 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Cohere recorded 5 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Cohere Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Cohere states that your data may be stored and processed in Canada and the United States, which may have different privacy protections than your home country.

This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision is particularly significant for EU and UK users because transfers of personal data from the EEA and UK to the United States require a lawful transfer mechanism under GDPR and UK GDPR, and the adequacy or sufficiency of those mechanisms is subject to ongoing regulatory scrutiny.

Interpretive note: The specific transfer mechanisms relied upon by Cohere for EU-to-US transfers are not detailed in the available document text; the description reflects the standard framework applicable to companies of this profile.

Recent Activity

This document changed recently

Medium Apr 29, 2026

The updated policy removes explicit language describing data retention timelines and deletion request procedures that were previously available. The prior policy stated that Enterprise Users' inputs and outputs were retained for 30 days, that Trial Users and Researchers were not intended to process personal information, and that deletion requests would normally be responded to within one month (up to three months for complex requests). The updated policy now contains only a general reference to 'retention practices' without specifying these timelines, response windows, or user-type distinctions. Users cannot determine from the updated policy what retention periods apply to their account category or what timeline to expect for deletion requests.

View change record →

Consumer impact (what this means for users)

If you are based in the EU, UK, or another jurisdiction with cross-border transfer restrictions, your personal data may be transferred to Canada and the United States under the transfer mechanisms Cohere relies upon, which may include Standard Contractual Clauses or adequacy decisions depending on the destination.

How other platforms handle this

Grindr Medium

Your personal information may be transferred to, stored, and processed in the United States or other countries outside of your country of residence, which may have data protection laws that are different from those in your country.

Peloton Medium

Your personal information may be transferred to, stored, and processed in the United States or other countries where our service providers and partners operate. By using our Services, you acknowledge that your personal information may be transferred to countries outside your country of residence, in...

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

See all platforms with this clause type →

Monitoring

Cohere has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Your personal information may be transferred to and processed in countries other than your country of residence, including Canada and the United States, where our servers are located and our central database is operated. These countries may have data protection laws that are different from those in your country.

— Excerpt from Cohere's Cohere Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V (Articles 44-49) governing cross-border data transfers, and the equivalent provisions of UK GDPR. For transfers to Canada, the European Commission's adequacy decision for Canada under PIPEDA covers certain commercial transfers, though the scope of adequacy is limited. For transfers to the United States, the EU-US Data Privacy Framework may apply if Cohere is certified, or Standard Contractual Clauses may be relied upon. The relevant enforcement authorities are EU supervisory authorities for EEA users and the ICO for UK users. (2) GOVERNANCE EXPOSURE: High for EU and UK enterprise customers. The lawfulness of US transfers remains subject to challenge and the specific transfer mechanism Cohere relies upon is not detailed in the available policy text, creating a due diligence gap for organizations required to document transfer impact assessments under GDPR. (3) JURISDICTION FLAGS: EU and EEA users face the highest regulatory exposure under GDPR Chapter V. UK users face equivalent requirements under UK GDPR International Data Transfer Agreements. Canadian users are the intended recipients of an adequacy-covered transfer from the EU in many scenarios, though the reverse transfer from Canada to the US may require additional assessment. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers subject to GDPR should request Cohere's Standard Contractual Clauses or Data Privacy Framework certification status and conduct a transfer impact assessment for US-bound transfers. Procurement teams should ensure that data processing agreements include explicit transfer mechanism provisions and that those mechanisms remain current given the evolving regulatory environment. (5) COMPLIANCE CONSIDERATIONS: Data protection officers should document the transfer mechanisms Cohere relies upon in their records of processing activities and assess whether transfer impact assessments are required. Organizations with data localization requirements, including those in the financial services or public sector, should evaluate whether Cohere's cross-border transfer model is consistent with their specific obligations.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC co-administers the EU-US Data Privacy Framework and has enforcement authority over US-based companies' cross-border data transfer commitments.
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Cohere Privacy Policy
Entity
Cohere
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 12, 2026
Record ID
CA-P-004376
Document ID
CA-D-00440
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
48f574f6141f754b1e207ebd31ad81a85645609ea91087c0f35d0f4211dd49a2
Analysis generated
May 10, 2026 04:19 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cohere
Document: Cohere Privacy Policy
Record ID: CA-P-004376
Captured: 2026-05-10 04:19:09 UTC
SHA-256: 48f574f6141f754b…
URL: https://conductatlas.com/platform/cohere/cohere-privacy-policy/cross-border-data-transfers/
Accessed: June 17, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Cohere's Cross-Border Data Transfers clause do?

This provision is particularly significant for EU and UK users because transfers of personal data from the EEA and UK to the United States require a lawful transfer mechanism under GDPR and UK GDPR, and the adequacy or sufficiency of those mechanisms is subject to ongoing regulatory scrutiny.

How does this clause affect you?

If you are based in the EU, UK, or another jurisdiction with cross-border transfer restrictions, your personal data may be transferred to Canada and the United States under the transfer mechanisms Cohere relies upon, which may include Standard Contractual Clauses or adequacy decisions depending on the destination.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 83 platforms. See the full comparison.

Is ConductAtlas affiliated with Cohere?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.