Duolingo · Duolingo Privacy Policy · View original document ↗

Cross-Border Data Transfers

Medium severity Medium confidence Explicitdocumentlanguage Common · 78 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Duolingo recorded 3 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Duolingo Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Duolingo transfers your personal data to the United States for processing, regardless of where you are located, meaning your data may be subject to US laws rather than the stronger protections of your home country.

This analysis describes what Duolingo's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Cross-border data transfers from the EU and UK to the US require specific legal mechanisms under GDPR to be lawful, and the policy's disclosure that data is transferred to and processed in the US is a material compliance consideration requiring documented transfer basis such as Standard Contractual Clauses or EU-US Data Privacy Framework certification.

Interpretive note: The policy does not specify which GDPR-approved transfer mechanism Duolingo relies upon for EU-US data flows, creating uncertainty about the legal basis and whether full GDPR Article 13 disclosure requirements are satisfied.

Recent Activity

This document changed recently

Medium Apr 21, 2026

The updated policy now discloses a new Math Tutor feature that processes audio through Apple for transcription; audio is deleted but text transcripts may be retained and shared with AI vendors. Duoli…

Consumer impact (what this means for users)

If you use Duolingo from outside the United States, your personal data including learning behavior and voice recordings will be transferred to and stored in the US, where data protection standards differ from those in your country. EU and UK users should be aware that US government access to data transferred under certain frameworks remains a contested legal area.

How other platforms handle this

PlanetScale Medium

You will provide personal information directly to our website in the United States. We may also transfer personal information to our partners and service providers in the United States and other jurisdictions. Please note that such jurisdictions may not provide the same protections as the data prote...

Notion Medium

Notion is based in the United States and the information we collect is governed by U.S. law. If you are accessing our Services from outside of the United States, please be aware that information collected through the Services may be transferred to, processed, stored, and used in the United States an...

Cohere Medium

Your personal information may be transferred to and processed in countries other than your country of residence, including Canada and the United States, where our servers are located and our central database is operated. These countries may have data protection laws that are different from those in ...

See all platforms with this clause type →

Monitoring

Duolingo has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Your personal information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we transfer the data to the United States and process it there.

— Excerpt from Duolingo's Duolingo Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: Cross-border data transfers from the EEA to the US are governed by GDPR Chapter V, requiring either an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or another approved mechanism. The EU-US Data Privacy Framework (DPF) adopted in 2023 provides a transfer mechanism for certified US entities. The policy does not specify which transfer mechanism Duolingo relies upon, which is a disclosure gap relative to GDPR transparency requirements. The UK ICO has adopted a separate International Data Transfer Agreement (IDTA) framework for UK-US transfers. (2) GOVERNANCE EXPOSURE: Medium. The failure to specify the transfer mechanism in the policy text creates transparency exposure under GDPR Article 13(1)(f), which requires disclosure of the transfer mechanism or basis. If Duolingo relies on SCCs, the Schrems II ruling requires a transfer impact assessment to evaluate the risk of US government access to transferred data. If relying on DPF certification, the certification must be current and verifiable. (3) JURISDICTION FLAGS: EU/EEA (GDPR Chapter V), UK (UK GDPR and IDTA framework), Switzerland (Swiss FDPA transfer requirements). Non-EEA countries with data localization requirements (e.g., Russia, China, India) may create additional compliance obligations for Duolingo's global user base. (4) CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with US-based vendors processing EEA or UK user data must include appropriate transfer mechanism documentation (SCCs or DPF reliance). Transfer impact assessments should be maintained for all transfers to the US where SCCs are the relied-upon mechanism. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that Duolingo's EU-US data transfer mechanism is documented, current, and disclosed in the privacy policy or supplementary documentation. If relying on DPF, certification status should be verified at https://www.dataprivacyframework.gov. Transfer impact assessments should be maintained and reviewed following any changes in US surveillance law or DPF legal status.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC enforces participation in the EU-US Data Privacy Framework and can act against companies that misrepresent their DPF participation or fail to comply with its requirements.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union
UK GDPR
United Kingdom

Provision details

Document information
Document
Duolingo Privacy Policy
Entity
Duolingo
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-005773
Document ID
CA-D-00084
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0e272c40f8dab9b0ecb7e9d9d71e56883e23c7aa9adb6049c8631ca5c9147456
Analysis generated
May 10, 2026 12:08 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Duolingo
Document: Duolingo Privacy Policy
Record ID: CA-P-005773
Captured: 2026-05-10 12:08:13 UTC
SHA-256: 0e272c40f8dab9b0…
URL: https://conductatlas.com/platform/duolingo/duolingo-privacy-policy/cross-border-data-transfers/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Duolingo's Cross-Border Data Transfers clause do?

Cross-border data transfers from the EU and UK to the US require specific legal mechanisms under GDPR to be lawful, and the policy's disclosure that data is transferred to and processed in the US is a material compliance consideration requiring documented transfer basis such as Standard Contractual Clauses or EU-US Data Privacy Framework certification.

How does this clause affect you?

If you use Duolingo from outside the United States, your personal data including learning behavior and voice recordings will be transferred to and stored in the US, where data protection standards differ from those in your country. EU and UK users should be aware that US government access to data transferred under certain frameworks remains a contested legal area.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 78 platforms. See the full comparison.

Is ConductAtlas affiliated with Duolingo?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Duolingo.