Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that all personal information from users outside the United States is transferred to and processed on U.S.-based servers. Users accessing the service from outside the U.S. are stated to acknowledge this transfer by using the service.
This analysis describes what Khan Academy's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Khan Academy processes all user data in the United States and characterizes service use from outside the U.S. as user acknowledgment of this transfer. The provision does not disclose specific legal transfer mechanisms such as Standard Contractual Clauses or adequacy decisions, which creates a compliance gap for EU, EEA, and UK users under GDPR and equivalent frameworks.
Interpretive note: The policy does not disclose the specific legal transfer mechanism relied upon for cross-border data transfers, and the adequacy of characterizing service use as acknowledgment of transfer depends on applicable jurisdictional requirements.
Under this provision, personal information of users outside the United States, including personal information and user-generated content, is collected, transferred, stored, and processed in the United States. The agreement states that users accessing the service from outside the U.S. acknowledge this data transfer arrangement.
Cross-platform context
See how other platforms handle International Data Transfer to U.S. Servers and similar clauses.
Compare across platforms →Monitoring
Khan Academy has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Our Service is operated and managed on servers located within the United States. If you access our Service from outside the United States, you acknowledge that Khan Academy will collect, transfer, store, and process your information, including personal information and user-generated content, in the United States, where data protection laws may differ from those in your jurisdiction.Excerpt from Khan Academy's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly engages GDPR (Chapter V) governing international transfers of personal data from the EU and EEA to third countries, the UK GDPR for UK users, and equivalent frameworks in other jurisdictions. Valid transfer mechanisms under GDPR include Standard Contractual Clauses, adequacy decisions, or binding corporate rules. The provision does not disclose which mechanism Khan Academy relies upon. Relevant enforcement authorities include EU national data protection authorities, the UK Information Commissioner's Office, and equivalent bodies in other jurisdictions. 2. GOVERNANCE EXPOSURE: Medium. The absence of disclosed transfer mechanisms in the policy text creates a compliance documentation gap for EU, EEA, and UK institutional users. The policy's framing of service use as user acknowledgment of data transfer does not constitute a valid GDPR transfer mechanism under applicable regulatory guidance. 3. JURISDICTION FLAGS: EU and EEA users face the highest exposure given GDPR's strict transfer requirements. UK users are subject to UK GDPR transfer rules post-Brexit. Canadian users are subject to PIPEDA's accountability principle for cross-border transfers. Users in Brazil, South Korea, and other jurisdictions with data localization or transfer restrictions may also face applicable legal requirements. 4. CONTRACT AND VENDOR IMPLICATIONS: EU and EEA institutional users and schools should request documentation from Khan Academy confirming the legal transfer mechanism in use (e.g., Standard Contractual Clauses) and whether data processing agreements are in place consistent with GDPR Article 28 requirements. Procurement teams in regulated sectors should treat the absence of disclosed transfer mechanisms as a due diligence flag. 5. COMPLIANCE CONSIDERATIONS: Compliance teams for EU or EEA institutional users should seek written confirmation of the applicable GDPR transfer mechanism from Khan Academy prior to deployment. Data mapping exercises should account for the U.S. server location of all processed personal data. Legal counsel should evaluate whether reliance on user acknowledgment as a transfer basis is consistent with applicable regulatory guidance in relevant jurisdictions.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that Khan Academy processes all user data in the United States and characterizes service use from outside the U.S. as user acknowledgment of this transfer. The provision does not disclose specific legal transfer mechanisms such as Standard Contractual Clauses or adequacy decisions, which creates a compliance gap for EU, EEA, and UK users under GDPR and equivalent …
Under this provision, personal information of users outside the United States, including personal information and user-generated content, is collected, transferred, stored, and processed in the United States. The agreement states that users accessing the service from outside the U.S. acknowledge this data transfer arrangement.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Khan Academy.