Medium · Medium Privacy Policy · View original document ↗

Cross-Border Data Transfer

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Medium changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Medium recorded 11 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Medium Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that personal information may be transferred to and stored in jurisdictions outside the user's home country, including via Amazon Web Services data centers globally, and states that Medium will take steps to ensure adequate protection without specifying the legal transfer mechanisms used.

This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that international data transfers occur to jurisdictions that may not provide equivalent data protection to the user's home jurisdiction. The policy does not name the specific legal mechanisms used to safeguard these transfers, such as Standard Contractual Clauses, which is a detail that GDPR Chapter V compliance reviews typically require.

Interpretive note: The policy does not specify which legal transfer mechanisms are used, so the degree of compliance with GDPR Chapter V and equivalent frameworks cannot be confirmed from the document alone.

Recent Activity

This document changed recently

Medium Jun 19, 2026

The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, personal information submitted by users in the EEA, UK, Switzerland, or other jurisdictions may be stored or processed in the United States or other countries with potentially different data protection standards. The document states that steps will be taken to ensure adequate protection but does not specify what those steps are.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    To limit further processing, log into Medium, navigate to Settings, select Account, and delete your account. The policy states account data will be deleted within 14 days.

Cross-platform context

See how other platforms handle Cross-Border Data Transfer and similar clauses.

Compare across platforms →

Monitoring

Medium has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Medium is headquartered in the United States, and we have operations and service providers in the United States and other countries. Therefore, we and our service providers may transfer your personal information to, or store or access it in, jurisdictions that may not provide levels of data protection that are equivalent to those of your home jurisdiction. For example, we transfer personal data to Amazon Web Services, one of our service providers that processes personal information for us in various data center locations across the globe, including those listed here. We will take steps to ensure that your personal information receives an adequate level of protection in the jurisdictions in which we process it.

Excerpt from Medium's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V (transfers of personal data to third countries) for EEA users, the UK data protection framework's equivalent international transfer requirements, and the Swiss Federal Act on Data Protection. The relevant enforcement authorities are the applicable national Data Protection Authorities, the UK ICO, and the Swiss FDPIC. The policy's general assurance of 'adequate protection' without naming specific transfer mechanisms may not satisfy the specificity requirements applicable under these frameworks. 2) GOVERNANCE EXPOSURE: Medium. The absence of named transfer mechanisms (such as Standard Contractual Clauses or adequacy decisions) in the policy text creates potential exposure under GDPR Chapter V and equivalent UK and Swiss frameworks. Following the Schrems II decision by the Court of Justice of the European Union, reliance on transfer mechanisms requires supplementary assessment where data is transferred to the United States, and the policy does not address this. 3) JURISDICTION FLAGS: EEA and UK users face the highest exposure given GDPR and UK GDPR requirements for documented, specific transfer mechanisms. Swiss users are also affected under the revised Swiss Federal Act on Data Protection. California users are less directly affected by this provision as CCPA does not impose equivalent cross-border transfer requirements. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations subject to GDPR that use Medium's platform and submit personal data through it should assess whether Medium's transfer mechanisms are adequately documented and whether their own data processing agreements with Medium address GDPR Chapter V requirements. A vendor assessment may be warranted to confirm whether Standard Contractual Clauses or equivalent instruments are in place. 5) COMPLIANCE CONSIDERATIONS: Legal teams should request supplementary documentation from Medium regarding the specific transfer mechanisms in place for transfers to the United States and other non-adequate jurisdictions. Data mapping updates should reflect the international transfer of user data via AWS. Organizations subject to GDPR should evaluate whether their own Records of Processing Activities accurately capture the onward transfer of data through Medium's services.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over representations about data protection practices that may be evaluated under its consumer protection authority, including adequacy of disclosures about international data transfers.
    File a complaint →

Provision details

Document information
Document
Medium Privacy Policy
Entity
Medium
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014898
Document ID
CA-D-00246
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e130408799d47ec7cc19cd4b7dfb170a92948a0979f65deae988281c66c5510b
Analysis generated
July 9, 2026 06:40 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Medium
Document: Medium Privacy Policy
Record ID: CA-P-014898
Captured: 2026-07-09 06:40:42 UTC
SHA-256: e130408799d47ec7…
URL: https://conductatlas.com/platform/medium/medium-privacy-policy/provision/CA-P-014898/cross-border-data-transfer/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Medium's Cross-Border Data Transfer clause do?

This provision establishes that international data transfers occur to jurisdictions that may not provide equivalent data protection to the user's home jurisdiction. The policy does not name the specific legal mechanisms used to safeguard these transfers, such as Standard Contractual Clauses, which is a detail that GDPR Chapter V compliance reviews typically require.

How does this clause affect you?

Under this clause, personal information submitted by users in the EEA, UK, Switzerland, or other jurisdictions may be stored or processed in the United States or other countries with potentially different data protection standards. The document states that steps will be taken to ensure adequate protection but does not specify what those steps are.

Is ConductAtlas affiliated with Medium?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.