Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal information may be shared or transferred in connection with a merger, asset sale, financing, or acquisition of Medium, including during the negotiation phase of such transactions, with user notification described as prominent notice or direct communication.
This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that personal data may be disclosed to prospective acquirers or transaction counterparties prior to deal completion, which creates data exposure outside Medium's direct operational relationships and may engage GDPR requirements for lawful transfer basis during pre-transaction due diligence.
The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.
View change record →Removal of explicit merger and acquisition data transfer language means the current policy no longer clearly discloses how user data will be handled in business sale or acquisition scenarios, potentially weakening transparency around this significant use case.
View full change record →Removed specific scenarios (financing due diligence, reorganization, bankruptcy, receivership, transition of service) and affiliate entity references, now covers only mergers, asset sales, and acquisition scenarios.
View full change record →The agreement authorizes transfer of personal information to third parties involved in corporate transactions, including during negotiation phases, which may result in personal data being processed by entities not yet bound by Medium's privacy commitments.
How other platforms handle this
In certain circumstances, the right to data portability, which means that you can request that we provide certain Personal Data we hold about you in a machine-readable format
If you want to see what information we have collected about you, you can request a copy of your data in the Data & Privacy section of your User Settings. You should receive your data packet within 30 days.
For data portability requests, We will select a format to provide Your personal information that is readily useable and should allow You to transmit the information from one entity to another entity without hindrance.
Monitoring
Medium has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company.Excerpt from Medium's Privacy Policy
1. REGULATORY LANDSCAPE: GDPR Article 6 requires a lawful basis for data transfers in M&A contexts; legitimate interests may be asserted but must satisfy a balancing test. CCPA requires that successor entities honor existing privacy commitments or provide notice and choice. The FTC has issued guidance on data transfers in business transactions. 2. GOVERNANCE EXPOSURE: Medium. The inclusion of 'negotiations' as a trigger for data sharing means personal data may be disclosed to prospective acquirers who are not yet contractually bound to Medium's privacy standards, creating a window of reduced oversight. 3. JURISDICTION FLAGS: EU users have heightened exposure because GDPR's lawful basis requirements apply to M&A due diligence data disclosures, and supervisory authorities have scrutinized such transfers. California users retain CCPA rights that must be honored by any successor entity. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations with contractual data protection obligations toward their own users or customers should assess whether Medium's M&A transfer clause is compatible with their own downstream data protection commitments if Medium is a processing vendor. 5. COMPLIANCE CONSIDERATIONS: Legal teams should monitor for any announced corporate transactions involving Medium and evaluate whether updated privacy notices or consent mechanisms are required. EU data protection officers should assess whether the M&A transfer basis is documented in the ROPA.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that personal data may be disclosed to prospective acquirers or transaction counterparties prior to deal completion, which creates data exposure outside Medium's direct operational relationships and may engage GDPR requirements for lawful transfer basis during pre-transaction due diligence.
The agreement authorizes transfer of personal information to third parties involved in corporate transactions, including during negotiation phases, which may result in personal data being processed by entities not yet bound by Medium's privacy commitments.
ConductAtlas has identified this type of provision across 294 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.