The policy discloses that personal data may be transferred internationally, including to the United States, and states that HubSpot uses Standard Contractual Clauses as a transfer mechanism for EU data.
This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Standard Contractual Clauses as the primary mechanism for cross-border data transfers out of the EEA, which requires that a transfer impact assessment be conducted and documented for organizations subject to GDPR requirements.
Interpretive note: The policy does not specify whether transfer impact assessments have been conducted or whether the current EU SCCs (2021 version) are in use, which are material compliance details not determinable from the policy text alone.
Under this provision, personal data collected from EU, UK, or other non-US users may be transferred to the United States and other countries, with HubSpot relying on Standard Contractual Clauses as the stated legal transfer mechanism.
How other platforms handle this
Your personal information may be transferred to, stored, and processed in the United States or other countries outside of your country of residence, which may have data protection laws that are different from those in your country.
Your personal information may be transferred to, stored, and processed in the United States or other countries where our service providers and partners operate. By using our Services, you acknowledge that your personal information may be transferred to countries outside your country of residence, in...
At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.
Monitoring
HubSpot has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"HubSpot is a global company and we may transfer your personal information to countries other than the one in which you live, including to the United States. We take steps to ensure that personal information transferred internationally is subject to appropriate safeguards, including, where applicable, Standard Contractual Clauses approved by the European Commission.— Excerpt from HubSpot's HubSpot Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR Chapter V governing international transfers, the UK GDPR equivalent transfer provisions, and guidance from the European Data Protection Board on SCCs and transfer impact assessments. Following the Schrems II decision, SCC reliance requires a documented transfer impact assessment. The Irish DPC and UK ICO are the relevant supervisory authorities. 2. GOVERNANCE EXPOSURE: Medium. SCC-based transfers are a recognized mechanism but require accompanying transfer impact assessments, particularly for transfers to the United States, which may require evaluation under US surveillance law standards. 3. JURISDICTION FLAGS: EU and EEA organizations using HubSpot must ensure their data processing agreements with HubSpot incorporate current EU SCCs. UK organizations must confirm UK IDTA or addendum equivalents are in place. Brazil (LGPD) and Canada (PIPEDA) may also create transfer compliance obligations depending on user location. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should request HubSpot's current DPA and confirm it incorporates the 2021 European Commission standard contractual clauses. Transfer impact assessments should be documented for US-bound transfers as part of vendor due diligence records. 5. COMPLIANCE CONSIDERATIONS: Legal teams should verify that their HubSpot DPA is current and that transfer impact assessments have been conducted and documented. UK-based organizations should confirm whether the UK IDTA or addendum has been executed with HubSpot.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes Standard Contractual Clauses as the primary mechanism for cross-border data transfers out of the EEA, which requires that a transfer impact assessment be conducted and documented for organizations subject to GDPR requirements.
Under this provision, personal data collected from EU, UK, or other non-US users may be transferred to the United States and other countries, with HubSpot relying on Standard Contractual Clauses as the stated legal transfer mechanism.
ConductAtlas has identified this type of provision across 84 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.