HubSpot · HubSpot Privacy Policy · View original document ↗

Cross-Border Data Transfers (SCCs and EU-U.S. Data Privacy Framework)

Medium severity Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for HubSpot Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

When HubSpot moves your data from Europe or the UK to the United States or other countries, it relies on legal mechanisms like Standard Contractual Clauses or the EU-U.S. Data Privacy Framework to make that transfer lawful.

This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This clause operationalizes HubSpot's compliance framework for international data transfers under GDPR and UK data protection law. The provision documents the specific legal instruments the organization deploys to maintain adequate protection standards when personal data crosses EEA and UK borders.

Consumer impact (what this means for users)

Your personal data processed by HubSpot (a U.S.-headquartered company) is transferred to the United States, and the legal mechanism protecting that transfer could be challenged or invalidated, potentially leaving your data with reduced legal protections.

How other platforms handle this

Unreal Engine Medium

Epic Games, Inc. is headquartered in Cary, North Carolina. We and our subsidiaries have offices and operations located around the world that help create and deliver some of your favorite products and services, including games like Fortnite and developer tools like Unreal Engine.

Coinbase Medium

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, please note that we transfer your personal data to countries outside of these regions, including the United States, which may not provide the same level of data protection as your home country. We rely on app...

Canva Medium

Canva is headquartered in Australia, and the Service is operated from Australia. If you are located in the European Economic Area, the United Kingdom, or other regions with laws governing data collection and use, please note that your information may be transferred to and processed in countries that...

See all platforms with this clause type →

Monitoring

HubSpot has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
When we transfer your personal data outside the EEA or UK, we ensure an adequate level of protection is afforded to it by ensuring at least one of the following safeguards is implemented: transfers are to countries that have been deemed to provide an adequate level of protection for personal data; we use specific contracts approved by the European Commission, known as 'standard contractual clauses'; or the organization is registered under a Privacy Shield or Data Privacy Framework program.

— Excerpt from HubSpot's HubSpot Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY FRAMEWORK: GDPR Art. 44-49 governs cross-border transfers; the EU-U.S. Data Privacy Framework was adopted by European Commission Adequacy Decision of July 10, 2023, but remains subject to challenge (cf. Schrems II, Case C-311/18). Standard Contractual Clauses are governed by EC Implementing Decision 2021/914. UK transfers are governed by UK GDPR and the UK's International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs. The primary enforcement authority for transfer adequacy is the EDPB and national DPAs. (2)

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    EU/UK residents should contact their national Data Protection Authority; U.S. state AGs have jurisdiction over deceptive practices related to inadequate transfer safeguards.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union

Provision details

Document information
Document
HubSpot Privacy Policy
Entity
HubSpot
Document last updated
May 5, 2026
Tracking information
First tracked
April 18, 2026
Last verified
April 18, 2026
Record ID
CA-P-002977
Document ID
CA-D-00208
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9086069c646a8fb26903326cd813947f9a89ebc0ea991c257cd0694abc31cafb
Analysis generated
April 18, 2026 11:21 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: HubSpot
Document: HubSpot Privacy Policy
Record ID: CA-P-002977
Captured: 2026-04-18 11:21:28 UTC
SHA-256: 9086069c646a8fb2…
URL: https://conductatlas.com/platform/hubspot/hubspot-privacy-policy/cross-border-data-transfers-sccs-and-eu-us-data-privacy-framework/
Accessed: June 17, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does HubSpot's Cross-Border Data Transfers (SCCs and EU-U.S. Data Privacy Framework) clause do?

This clause operationalizes HubSpot's compliance framework for international data transfers under GDPR and UK data protection law. The provision documents the specific legal instruments the organization deploys to maintain adequate protection standards when personal data crosses EEA and UK borders.

How does this clause affect you?

Your personal data processed by HubSpot (a U.S.-headquartered company) is transferred to the United States, and the legal mechanism protecting that transfer could be challenged or invalidated, potentially leaving your data with reduced legal protections.

Is ConductAtlas affiliated with HubSpot?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.