Medium · Medium Privacy Policy · View original document ↗

Address Book Contact Processing

Low severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Medium changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Medium recorded 10 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Medium Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that users who opt into the address book feature have their contact names and email addresses converted to encrypted non-reversible identifiers, matched against Medium's member database, with non-member identifiers deleted immediately and all identifiers deleted within 30 days.

This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision describes a contact matching process that processes personal data of individuals who are not Medium users, relying on legitimate interests as the stated lawful basis. The policy states that non-member identifiers are deleted immediately after matching, and all identifiers within 30 days, which are concrete operational data minimization commitments.

Interpretive note: The adequacy of the legitimate interests basis for processing non-member contact data and the GDPR Article 14 obligations toward those individuals are not addressed in the policy, creating interpretive uncertainty.

Recent Activity

This document changed recently

Medium Jun 19, 2026

The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, users who opt into the address book feature authorize Medium to process their device contacts using one-way encryption for the purpose of identifying known Medium members, with deletion of third-party contact identifiers occurring immediately for non-members and within 30 days for all.

Cross-platform context

See how other platforms handle Address Book Contact Processing and similar clauses.

Compare across platforms →

Monitoring

Medium has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
When you use our address book feature, we process contact information from your device to help you discover people you know who are on Medium. Why we do this: We rely on legitimate interests to offer this feature — specifically, our interest in helping you connect with people you know, and our mission to deepen collective understanding through writing, which supports your fundamental right to freedom of expression and information. How it works: When you opt in, we convert contact names and email addresses into encrypted, non-reversible identifiers and match them against our member database. We don't store names or emails in plain text. For contacts who aren't Medium members, we delete their encrypted identifiers immediately after checking. We delete all encrypted identifiers within 30 days.

Excerpt from Medium's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 6 (lawful basis for processing third-party contact data) and potentially GDPR Article 14 (information to be provided where personal data has not been obtained from the data subject) for EEA and UK users, as contacts being processed have not directly provided their data to Medium. The relevant enforcement authorities are national Data Protection Authorities. The reliance on legitimate interests for processing third-party contact data may be subject to scrutiny given that the contacts themselves have not consented to or been notified of this processing. 2) GOVERNANCE EXPOSURE: Medium. The processing of contact data belonging to individuals who are not Medium users raises GDPR Article 14 transparency obligations toward those third parties, which may be difficult to satisfy operationally given the nature of the feature. The policy's stated reliance on legitimate interests for this processing may require a documented Legitimate Interests Assessment. 3) JURISDICTION FLAGS: EEA and UK users face heightened exposure given GDPR obligations regarding processing of third-party personal data. The feature is opt-in, which partially mitigates exposure, but the GDPR transparency obligations toward non-member contacts are not addressed in the policy. Illinois BIPA may be relevant if the encryption process constitutes biometric processing, though this is not established by the document. 4) CONTRACT AND VENDOR IMPLICATIONS: The address book feature processes device contact data, which may include data belonging to individuals not party to Medium's terms. Organizations deploying Medium to employees should assess whether use of this feature is compatible with their own data protection policies regarding third-party contact data. 5) COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether Medium's legitimate interests basis for processing third-party contact data is adequately documented and whether any notification obligations toward non-member contacts arise under applicable law. The 30-day deletion commitment should be verified against Medium's data retention practices.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over consumer data practices including the processing of third-party contact information by consumer platforms.
    File a complaint →

Provision details

Document information
Document
Medium Privacy Policy
Entity
Medium
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014903
Document ID
CA-D-00246
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e130408799d47ec7cc19cd4b7dfb170a92948a0979f65deae988281c66c5510b
Analysis generated
July 9, 2026 06:40 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Medium
Document: Medium Privacy Policy
Record ID: CA-P-014903
Captured: 2026-07-09 06:40:42 UTC
SHA-256: e130408799d47ec7…
URL: https://conductatlas.com/platform/medium/medium-privacy-policy/provision/CA-P-014903/address-book-contact-processing/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Medium's Address Book Contact Processing clause do?

This provision describes a contact matching process that processes personal data of individuals who are not Medium users, relying on legitimate interests as the stated lawful basis. The policy states that non-member identifiers are deleted immediately after matching, and all identifiers within 30 days, which are concrete operational data minimization commitments.

How does this clause affect you?

Under this clause, users who opt into the address book feature authorize Medium to process their device contacts using one-way encryption for the purpose of identifying known Medium members, with deletion of third-party contact identifiers occurring immediately for non-members and within 30 days for all.

Is ConductAtlas affiliated with Medium?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.