Grammarly · Grammarly Privacy Policy · View original document ↗

EEA and UK User Rights under GDPR

Medium severity High confidence Explicitdocumentlanguage Rare · 2 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Grammarly Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you're in the EU, UK, or Switzerland, you have strong legal rights over your data under GDPR, including the ability to access, correct, delete, or move your information, and to complain to your country's data regulator.

This analysis describes what Grammarly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

GDPR rights are among the strongest consumer data protections globally, and Grammarly's policy acknowledges them for EEA and UK users, meaning those users have enforceable legal recourse if their data is mishandled.

Consumer impact (what this means for users)

EEA and UK users can request access to, correction or deletion of, or restriction of processing of their personal data held by Grammarly, and can object to processing based on legitimate interests including AI model training; these rights can be exercised through Grammarly's privacy portal.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Visit privacy.grammarly.com and submit your GDPR data subject request (access, deletion, restriction, or objection). Grammarly must respond within one month under GDPR. You may also contact your national data protection authority if your request is not fulfilled.

How other platforms handle this

Smartsheet Medium

If you are located in the EEA or UK, you may have the following rights under applicable data protection law: the right to access your personal data; the right to rectify inaccurate personal data; the right to erasure of your personal data; the right to restrict processing of your personal data; the ...

TransUnion Medium

Depending on where you live, you may have certain rights with respect to your personal information. These rights may include: The right to know what personal information we have collected about you, including the categories of personal information, the categories of sources from which we collected i...

Waze Medium

If you are located in the European Economic Area or the United Kingdom, you have certain rights under applicable data protection laws, including the right to access, correct, or delete your personal data, the right to object to or restrict processing, and the right to data portability. You may also ...

See all platforms with this clause type →

Monitoring

Grammarly has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the EEA, UK, or Switzerland, you have certain rights with respect to your personal information, including the right to access your personal data, to correct or delete your personal data, to restrict processing of your personal data, to data portability, and to object to processing of your personal data. You also have the right to lodge a complaint with your local supervisory authority.

— Excerpt from Grammarly's Grammarly Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR (Regulation 2016/679), enforced by national data protection authorities including the Irish Data Protection Commission as Grammarly's likely EU lead supervisory authority given its EU operations. UK GDPR, enforced by the Information Commissioner's Office, applies to UK users. Cross-border data transfers from the EEA to the US must rely on adequacy decisions, standard contractual clauses, or other approved mechanisms, and the policy's adequacy for these transfer mechanisms should be verified. GOVERNANCE EXPOSURE: High for EEA/UK operations. The combination of broad data collection, AI training use of user content, and third-party sharing creates meaningful exposure under GDPR's purpose limitation, data minimization, and lawful basis requirements. The right to object to processing based on legitimate interests, if exercised by EEA users specifically in relation to AI training, would require Grammarly to demonstrate compelling legitimate grounds. JURISDICTION FLAGS: Ireland, Germany, France, and the Netherlands have active DPA enforcement postures. UK ICO has independent enforcement authority post-Brexit. Swiss users are subject to the revised Swiss Federal Act on Data Protection. Organizations with EEA-based users or employees should ensure their own GDPR-compliant data processing records reflect Grammarly's role as a processor or controller as applicable. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers with EEA users must confirm that a GDPR-compliant data processing agreement (DPA) is in place with Grammarly. The DPA should specify Grammarly's role (processor or controller), lawful bases for processing, sub-processor lists, and cross-border transfer mechanisms. The absence of an adequate DPA creates direct compliance exposure for enterprise customers. COMPLIANCE CONSIDERATIONS: Legal teams should verify that Grammarly's transfer impact assessments for US-bound data transfers are current and adequate given the evolving EU-US data transfer landscape. Data subject request response procedures should be tested for timeliness and completeness. Organizations should confirm that Grammarly's privacy portal is accessible to EEA users and that response timelines meet GDPR's one-month standard.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Grammarly Privacy Policy
Entity
Grammarly
Document last updated
May 5, 2026
Tracking information
First tracked
April 30, 2026
Last verified
May 9, 2026
Record ID
CA-P-007154
Document ID
CA-D-00456
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d08a9713ff1dfd27ddd4383c3d20e95b0e83f623b74496507b64d9362c696444
Analysis generated
April 30, 2026 06:25 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Grammarly
Document: Grammarly Privacy Policy
Record ID: CA-P-007154
Captured: 2026-04-30 06:25:07 UTC
SHA-256: d08a9713ff1dfd27…
URL: https://conductatlas.com/platform/grammarly/grammarly-privacy-policy/eea-and-uk-user-rights-under-gdpr/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Grammarly's EEA and UK User Rights under GDPR clause do?

GDPR rights are among the strongest consumer data protections globally, and Grammarly's policy acknowledges them for EEA and UK users, meaning those users have enforceable legal recourse if their data is mishandled.

How does this clause affect you?

EEA and UK users can request access to, correction or deletion of, or restriction of processing of their personal data held by Grammarly, and can object to processing based on legitimate interests including AI model training; these rights can be exercised through Grammarly's privacy portal.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 2 platforms. See the full comparison.

Is ConductAtlas affiliated with Grammarly?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grammarly.