The policy discloses that personal information may be transferred to and stored in jurisdictions outside the user's home country, including via Amazon Web Services data centers globally, and states that Medium will take steps to ensure adequate protection without specifying the legal transfer mechanisms used.
This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that international data transfers occur to jurisdictions that may not provide equivalent data protection to the user's home jurisdiction. The policy does not name the specific legal mechanisms used to safeguard these transfers, such as Standard Contractual Clauses, which is a detail that GDPR Chapter V compliance reviews typically require.
Interpretive note: The policy does not specify which legal transfer mechanisms are used, so the degree of compliance with GDPR Chapter V and equivalent frameworks cannot be confirmed from the document alone.
The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.
View change record →Updated provision now specifies Medium's US headquarters, names Amazon Web Services as a specific data processor, and uses 'equivalent' instead of 'as protective' language, providing more concrete transparency about cross-border transfers.
View full change record →Under this clause, personal information submitted by users in the EEA, UK, Switzerland, or other jurisdictions may be stored or processed in the United States or other countries with potentially different data protection standards. The document states that steps will be taken to ensure adequate protection but does not specify what those steps are.
Cross-platform context
See how other platforms handle Cross-Border Data Transfer and similar clauses.
Compare across platforms →"Medium is headquartered in the United States, and we have operations and service providers in the United States and other countries. Therefore, we and our service providers may transfer your personal information to, or store or access it in, jurisdictions that may not provide levels of data protection that are equivalent to those of your home jurisdiction. For example, we transfer personal data to Amazon Web Services, one of our service providers that processes personal information for us in various data center locations across the globe, including those listed here. We will take steps to ensure that your personal information receives an adequate level of protection in the jurisdictions in which we process it.Excerpt from Medium's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V (transfers of personal data to third countries) for EEA users, the UK data protection framework's equivalent international transfer requirements, and the Swiss Federal Act on Data …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that international data transfers occur to jurisdictions that may not provide equivalent data protection to the user's home jurisdiction. The policy does not name the specific legal mechanisms used to safeguard these transfers, such as Standard Contractual Clauses, which is a detail that GDPR Chapter V compliance reviews typically require.
Under this clause, personal information submitted by users in the EEA, UK, Switzerland, or other jurisdictions may be stored or processed in the United States or other countries with potentially different data protection standards. The document states that steps will be taken to ensure adequate protection but does not specify what those steps are.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.