Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data is transferred to and stored in countries outside users' jurisdictions, including the United States, and that transfers from the EEA, UK, and Switzerland are conducted under adequacy decisions or standard contractual clauses adopted by the European Commission.
This analysis describes what Kick's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that personal data of EEA, UK, and Swiss users is processed in the United States and other third countries, relying on adequacy decisions or standard contractual clauses as the stated transfer mechanism. The UK's post-Brexit transfer framework and Switzerland's own adequacy assessment framework operate separately from EU GDPR and should be evaluated independently.
Under this clause, personal information of EEA, UK, and Swiss users may be transferred to and stored in countries outside those regions, including the United States. The agreement states that transfers will be conducted under adequacy recognition or standard contractual clauses, and users may inquire about specific safeguards by contacting Kick.
Cross-platform context
See how other platforms handle International Data Transfers Outside EEA, UK, and Switzerland and similar clauses.
Compare across platforms →Monitoring
Kick has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"The personal information we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third-party service providers have operations, including in the United States. If you are accessing our Services from the European Economic Area ('EEA'), UK or Switzerland, your personal information will be processed outside of the EEA, the UK and Switzerland. In the event of such a transfer, we will ensure that: (i) the personal information is transferred to countries recognised as offering an equivalent level of protection to that of the EEA; or (ii) the transfer is made pursuant to appropriate safeguards, such as standard contractual clauses adopted by the European Commission.Excerpt from Kick's Privacy Policy
1) REGULATORY LANDSCAPE: International data transfers from the EEA engage GDPR Chapter V, which requires an adequacy decision, standard contractual clauses, or another permissible transfer mechanism. UK data transfers are governed by the UK GDPR and the UK's International Data Transfer Agreement framework. Swiss transfers are governed by the Swiss Federal Act on Data Protection. The US adequacy framework (EU-US Data Privacy Framework) should be confirmed as applicable to Kick's specific processing activities and subprocessors. 2) GOVERNANCE EXPOSURE: Medium. The policy's reliance on adequacy recognition and standard contractual clauses is consistent with standard industry practice for GDPR compliance. However, the adequacy framework for US transfers remains subject to legal challenge history, and ongoing compliance requires monitoring of regulatory developments. The UK operates a separate transfer mechanism framework that requires independent documentation. 3) JURISDICTION FLAGS: EEA, UK, and Swiss users have heightened exposure. The specific adequacy status of all countries where Kick and its subprocessors store data should be confirmed, as adequacy decisions do not cover all countries. The UK's International Data Transfer Agreement is a distinct instrument from the EU's standard contractual clauses and requires separate implementation. 4) CONTRACT AND VENDOR IMPLICATIONS: All subprocessors and third-party service providers receiving EEA, UK, or Swiss personal data should have documented transfer mechanisms in place. Kick's DPO contact at dpo@kick.com should be able to provide details of the specific safeguards used for each transfer context. 5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm which specific transfer mechanism is in place for each major data recipient country and subprocessor, and maintain a transfer impact assessment where required. The DPO at dpo@kick.com should be engaged to provide transfer mechanism documentation upon request. Compliance with the UK IADTA and Swiss nFADP transfer requirements should be documented separately from EU GDPR compliance.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that personal data of EEA, UK, and Swiss users is processed in the United States and other third countries, relying on adequacy decisions or standard contractual clauses as the stated transfer mechanism. The UK's post-Brexit transfer framework and Switzerland's own adequacy assessment framework operate separately from EU GDPR and should be evaluated independently.
Under this clause, personal information of EEA, UK, and Swiss users may be transferred to and stored in countries outside those regions, including the United States. The agreement states that transfers will be conducted under adequacy recognition or standard contractual clauses, and users may inquire about specific safeguards by contacting Kick.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Kick.