Provision record
DoorDash · DoorDash Privacy Policy · View original document ↗

Cross-Border Transfer of Personal Information

Medium severity Medium confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track DoorDash and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

DoorDash may transfer your personal information to service providers located in other countries, which means your data may be processed under different privacy laws than those that apply where you live.

This analysis describes what DoorDash's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy states that personal information may be transferred and processed outside the user's home jurisdiction, including outside Australia, Canada (and Quebec specifically), New Zealand, and the United States, without specifying the legal mechanisms used to authorize those transfers.

Interpretive note: The policy does not specify which transfer mechanisms or safeguards are in place for cross-border transfers, making compliance assessment dependent on documentation outside the policy itself.

Clause Stability Stable

0
Changes
4
Months Monitored
May 12, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 5149 other provisions on other platforms.

Consumer impact (what this means for users)

Your personal information may be stored and processed by DoorDash's service providers in countries with different privacy standards than your home country. The policy does not specify what transfer safeguard mechanisms, such as standard contractual clauses, are in place for these cross-border transfers.

How other platforms handle this

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

ClickUp Medium

You can contact us in order to (1) update or correct your personally identifiable information, (2) change your preferences with respect to communications and other information you receive from us, or (3) delete the personally identifiable information maintained about you...

Notion Medium

Access information about you consistent with legal requirements. In addition, you may have the right in some cases to receive or have your electronic information transferred to another party.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
To Service Providers: To enable us to meet our business operations needs and to perform our Services, we may provide Personal Information to our service providers and vendors, including, but not limited to, providers of identification and verification services, cloud services, payment services, gift card program services, auditing services, security services, marketing and advertising services, promotions, sweepstakes and contest services, market research services, communication services, analytics services that help us understand usage of our Services, market enrichment services, location and mapping services, and customer support functions. These service providers may access, store and process your personal information outside of the jurisdiction in which you reside, including, without limitation, outside of Australia, Canada (and if you reside in the Province of Quebec, outside of Quebec), New Zealand and the United States.

Excerpt from DoorDash's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: Cross-border data transfers from the EU and EEA require appropriate transfer mechanisms under GDPR Chapter V, such as standard contractual clauses or adequacy decisions.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
TCPA
United States Federal
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
DoorDash Privacy Policy
Entity
DoorDash
Document last updated
May 5, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-010988
Document ID
CA-D-00134
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
36c24e9e80c20d02c0f6b7f63328244e08d914ed4a197c9cb9f052fe46da8132
Analysis generated
May 12, 2026 05:01 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: DoorDash
Document: DoorDash Privacy Policy
Record ID: CA-P-010988
Captured: 2026-05-12 05:01:26 UTC
SHA-256: 36c24e9e80c20d02…
URL: https://conductatlas.com/platform/doordash/doordash-privacy-policy/provision/CA-P-010988/cross-border-transfer-of-personal-information/
Accessed: Aug. 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does DoorDash's Cross-Border Transfer of Personal Information clause do?

The policy states that personal information may be transferred and processed outside the user's home jurisdiction, including outside Australia, Canada (and Quebec specifically), New Zealand, and the United States, without specifying the legal mechanisms used to authorize those transfers.

How does this clause affect you?

Your personal information may be stored and processed by DoorDash's service providers in countries with different privacy standards than your home country. The policy does not specify what transfer safeguard mechanisms, such as standard contractual clauses, are in place for these cross-border transfers.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with DoorDash?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by DoorDash.