Glean · Glean Privacy Policy · View original document ↗

EU-U.S. Data Privacy Framework Certification and Onward Transfer Liability

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Glean changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Glean Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Glean holds active DPF certification covering EU, UK, and Swiss data transfers and states that DPF Principles supersede conflicting provisions in this Privacy Statement. For onward transfers to third parties, Glean's liability is conditioned on its ability to demonstrate it was not party to events causing damages.

This analysis describes what Glean's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The onward transfer liability clause conditions Glean's DPF liability on a demonstration defense, which under DPF Annex I and applicable Principles may shift the burden of proof to Glean but has operational implications for how damages claims arising from third-party processor conduct are handled.

Interpretive note: The enforceability and long-term adequacy status of the EU-U.S. Data Privacy Framework is subject to ongoing review by EU institutions; the practical scope of onward transfer liability may depend on DPF Annex I interpretation and applicable enforcement context.

Consumer impact (what this means for users)

Under this clause, EEA, UK, and Swiss residents whose data is transferred to the U.S. are covered by DPF Principles, which supersede conflicting Privacy Statement terms; individuals may invoke binding arbitration for unresolved DPF complaints through the mechanism described in DPF Annex I.

Cross-platform context

See how other platforms handle EU-U.S. Data Privacy Framework Certification and Onward Transfer Liability and similar clauses.

Compare across platforms →

Monitoring

Glean has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Glean has certified to the Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework (DPF) Principles, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework, and is committed to all relevant framework Principles. To the extent any conflict exists between this Privacy Statement and the applicable Data Privacy Framework Principles, the relevant Principles shall govern. Glean uses standard contractual clauses for onward transfers to third parties unless we can demonstrate we were not a party to the events giving rise to any damages.

Excerpt from Glean's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly implicates the EU-U.S. Data Privacy Framework administered by the U.S. Department of Commerce and enforced by the FTC, as well as the UK Extension and Swiss-U.S. DPF. Glean's certification establishes obligations under DPF Principles including notice, choice, accountability for onward transfer, security, data integrity, access, and recourse. The statement's conflict resolution clause, which states DPF Principles govern over this Privacy Statement, provides a hierarchy that compliance teams should document. 2) GOVERNANCE EXPOSURE: Medium. The onward transfer liability condition, limiting liability to cases where Glean cannot demonstrate it was not party to the relevant events, aligns with standard DPF Annex I language but should be assessed against the full scope of Glean's third-party processor relationships. 3) JURISDICTION FLAGS: EEA, UK, and Swiss data subjects have access to DPF-specific recourse mechanisms including EU DPA cooperation, the Swiss Federal Data Protection and Information Commissioner, and binding arbitration under Annex I. The DPF's legal adequacy determination is subject to ongoing review by EU institutions, and compliance teams should monitor the framework's status. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations transferring employee or customer data to Glean under DPF should confirm Glean's active certification status at www.dataprivacyframework.gov and assess whether Standard Contractual Clauses are in place as a supplementary transfer mechanism given uncertainty about DPF's long-term adequacy status. 5) COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether Glean's DPF certification covers all data categories relevant to their use case, review the onward transfer provisions in Glean's vendor contracts, and assess whether binding arbitration under DPF Annex I is adequately disclosed to affected data subjects.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC holds investigatory and enforcement authority over Glean's DPF compliance, as expressly acknowledged in the Privacy Statement
    File a complaint →

Provision details

Document information
Document
Glean Privacy Policy
Entity
Glean
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015532
Document ID
CA-D-00505
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6f01b253c1c086bf482db0c0a7d69e0fb0af8ac9a18cb796aaa230928d7e99c5
Analysis generated
July 9, 2026 08:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Glean
Document: Glean Privacy Policy
Record ID: CA-P-015532
Captured: 2026-07-09 08:12:17 UTC
SHA-256: 6f01b253c1c086bf…
URL: https://conductatlas.com/platform/glean/glean-privacy-policy/provision/CA-P-015532/eu-us-data-privacy-framework-certification-and-onward-transfer-liability/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Glean's EU-U.S. Data Privacy Framework Certification and Onward Transfer Liability clause do?

The onward transfer liability clause conditions Glean's DPF liability on a demonstration defense, which under DPF Annex I and applicable Principles may shift the burden of proof to Glean but has operational implications for how damages claims arising from third-party processor conduct are handled.

How does this clause affect you?

Under this clause, EEA, UK, and Swiss residents whose data is transferred to the U.S. are covered by DPF Principles, which supersede conflicting Privacy Statement terms; individuals may invoke binding arbitration for unresolved DPF complaints through the mechanism described in DPF Annex I.

Is ConductAtlas affiliated with Glean?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Glean.