Provision record
Greenhouse · Greenhouse Privacy Policy · View original document ↗

International Data Transfers and Transfer Mechanisms

Low severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Greenhouse changes these terms. Follow Greenhouse →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Greenhouse Monitor emails you the same day this changes. The archive stays free.
Follow Greenhouse →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that Personal Information may be transferred to and processed in countries with different or less protective data protection laws, and states that Greenhouse will use lawful transfer mechanisms and contractual restrictions to maintain protections.

This analysis describes what Greenhouse's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes Greenhouse's general commitment to lawful transfer mechanisms for international data flows, which in practice is supplemented by the DPF certification described elsewhere in the policy; the provision does not enumerate specific transfer mechanisms beyond the DPF program, leaving the operational implementation to be confirmed through the Data Processing Addendum.

Interpretive note: The provision does not enumerate specific transfer mechanisms beyond DPF certification, and the availability of standard contractual clauses or other mechanisms as alternatives is not stated in this policy.

Consumer impact (what this means for users)

Under this clause, Personal Information collected from users in any jurisdiction may be transferred to the United States or other countries for processing. Greenhouse states it applies lawful transfer mechanisms and contractual restrictions, with DPF certification serving as the primary stated mechanism for EU, UK, and Swiss data.

Cross-platform context

See how other platforms handle International Data Transfers and Transfer Mechanisms and similar clauses.

Compare across platforms →

Monitoring

Greenhouse has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Greenhouse → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Your Personal Information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective). In any case, Greenhouse will take sufficient measures to ensure protections are applied through the use of lawful transfer mechanisms and contractual restrictions.

Excerpt from Greenhouse's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V restrictions on international data transfers, UK GDPR equivalent provisions, and the Swiss Federal Act on Data Protection. The DPF certification described elsewhere in the policy serves as the primary stated transfer mechanism for EU, UK, and Swiss personal data. Standard contractual clauses may serve as a secondary mechanism but are not explicitly identified in this provision. 2. GOVERNANCE EXPOSURE: Medium. The provision's general reference to lawful transfer mechanisms without enumerating specific mechanisms beyond DPF may create uncertainty for enterprise customers conducting due diligence on Greenhouse as a processor. The DPF's political and legal durability as an adequacy mechanism warrants contingency planning. 3. JURISDICTION FLAGS: EEA, UK, and Swiss users have the highest exposure given their regulatory frameworks' restrictions on international transfers. The policy does not address transfer mechanisms for users in other jurisdictions with cross-border transfer restrictions, such as China or Brazil, which may be relevant depending on Greenhouse's customer base. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose candidate or employee data may be transferred internationally should confirm that the Data Processing Addendum incorporates specific lawful transfer mechanisms, including standard contractual clauses as a DPF backup, and that sub-processor transfer arrangements are documented. Procurement teams should request confirmation of current DPF certification status. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that Greenhouse's Transfer Impact Assessments or equivalent documentation are available for review under the Data Processing Addendum and that sub-processor agreements include equivalent transfer mechanism requirements. DPF certification status should be monitored given its dependence on the adequacy decision underlying the framework.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Provision details

Document information
Document
Greenhouse Privacy Policy
Entity
Greenhouse
Document last updated
July 5, 2026
Tracking information
First tracked
July 6, 2026
Last verified
July 9, 2026
Record ID
CA-P-015551
Document ID
CA-D-00918
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8eed11ab4b13cf36349d959508396725d190ee2515f43b08f6e7be1f429e377d
Analysis generated
July 6, 2026 15:44 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Greenhouse
Document: Greenhouse Privacy Policy
Record ID: CA-P-015551
Captured: 2026-07-06 15:44:37 UTC
SHA-256: 8eed11ab4b13cf36…
URL: https://conductatlas.com/platform/greenhouse/greenhouse-privacy-policy/provision/CA-P-015551/international-data-transfers-and-transfer-mechanisms/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Greenhouse's International Data Transfers and Transfer Mechanisms clause do?

This provision establishes Greenhouse's general commitment to lawful transfer mechanisms for international data flows, which in practice is supplemented by the DPF certification described elsewhere in the policy; the provision does not enumerate specific transfer mechanisms beyond the DPF program, leaving the operational implementation to be confirmed through the Data Processing Addendum.

How does this clause affect you?

Under this clause, Personal Information collected from users in any jurisdiction may be transferred to the United States or other countries for processing. Greenhouse states it applies lawful transfer mechanisms and contractual restrictions, with DPF certification serving as the primary stated mechanism for EU, UK, and Swiss data.

Is ConductAtlas affiliated with Greenhouse?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Greenhouse.