The policy states that personal data may be transferred to countries outside Australia and the EEA, and that the company states it uses mechanisms such as Standard Contractual Clauses for EEA transfers.
This analysis describes what Leonardo AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes international transfers of user personal data and asserts that transfer safeguards such as Standard Contractual Clauses are in place, but does not identify specific recipient countries or named third-party recipients for these transfers.
Interpretive note: The policy asserts SCC use but does not identify specific recipient countries or document transfer impact assessment procedures, leaving the completeness of the transfer framework uncertain.
Under this clause, personal data including identifiers, usage activity, and payment information may be transferred to and processed in countries outside Australia and the EEA. The policy states that safeguards such as SCCs are applied for EEA transfers, but does not specify recipient jurisdictions.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"We may transfer your personal information to countries outside of Australia and the European Economic Area. When we transfer personal information outside of the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.Excerpt from Leonardo AI's Privacy Policy
REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V (restrictions on transfers to third countries), which requires an adequacy decision, SCCs, or other approved transfer mechanism for transfers from the EEA.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision authorizes international transfers of user personal data and asserts that transfer safeguards such as Standard Contractual Clauses are in place, but does not identify specific recipient countries or named third-party recipients for these transfers.
Under this clause, personal data including identifiers, usage activity, and payment information may be transferred to and processed in countries outside Australia and the EEA. The policy states that safeguards such as SCCs are applied for EEA transfers, but does not specify recipient jurisdictions.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Leonardo AI.