The policy authorizes any subsidiary or affiliated entity within the Walt Disney Family of Companies to access a user's personal information both to perform services for the primary data controller and independently for that subsidiary's own purposes, subject to applicable law.
This analysis describes what Disney+'s agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a dual-role access structure across a portfolio of more than 40 named brands, under which each subsidiary entity may use personal information for its own independent data controller purposes, not solely in a service capacity. This arrangement may require evaluation under GDPR purpose limitation and data minimization principles, as well as CCPA obligations governing intra-group data flows.
Interpretive note: The breadth of permissible independent use by subsidiary entities as data controllers depends on applicable law in each jurisdiction and may be more limited in practice under GDPR and state privacy frameworks than the policy's broad assertion suggests.
Under this clause, personal information collected through any Disney-branded property may be accessed and used independently by other members of the Walt Disney Family of Companies, including ESPN, Hulu, Marvel, National Geographic, and others, for purposes each entity determines as a data controller. The agreement does not require a separate consent event for each subsidiary's independent use, subject to applicable law.
Cross-platform context
See how other platforms handle Intra-Family Cross-Brand Data Sharing and similar clauses.
Compare across platforms →"Other members of The Walt Disney Family of Companies may access your information where they perform services on behalf of the data controllers (as data processors) and, unless prohibited under applicable law, for use on their own behalf (as data controllers) for the purposes described in this policy.Excerpt from Disney+'s Walt Disney Company Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 4(7), 26, and 5 (purpose limitation, data minimization) for EU and UK users, and CCPA's definitions of business purpose and service provider for California residents.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a dual-role access structure across a portfolio of more than 40 named brands, under which each subsidiary entity may use personal information for its own independent data controller purposes, not solely in a service capacity. This arrangement may require evaluation under GDPR purpose limitation and data minimization principles, as well as CCPA obligations governing intra-group data flows.
Under this clause, personal information collected through any Disney-branded property may be accessed and used independently by other members of the Walt Disney Family of Companies, including ESPN, Hulu, Marvel, National Geographic, and others, for purposes each entity determines as a data controller. The agreement does not require a separate consent event for each subsidiary's independent use, subject to applicable …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Disney+.