Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that users who opt into the address book feature have their contact names and email addresses converted to encrypted non-reversible identifiers, matched against Medium's member database, with non-member identifiers deleted immediately and all identifiers deleted within 30 days.
This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision describes a contact matching process that processes personal data of individuals who are not Medium users, relying on legitimate interests as the stated lawful basis. The policy states that non-member identifiers are deleted immediately after matching, and all identifiers within 30 days, which are concrete operational data minimization commitments.
Interpretive note: The adequacy of the legitimate interests basis for processing non-member contact data and the GDPR Article 14 obligations toward those individuals are not addressed in the policy, creating interpretive uncertainty.
The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.
View change record →Under this clause, users who opt into the address book feature authorize Medium to process their device contacts using one-way encryption for the purpose of identifying known Medium members, with deletion of third-party contact identifiers occurring immediately for non-members and within 30 days for all.
Cross-platform context
See how other platforms handle Address Book Contact Processing and similar clauses.
Compare across platforms →Monitoring
Medium has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When you use our address book feature, we process contact information from your device to help you discover people you know who are on Medium. Why we do this: We rely on legitimate interests to offer this feature — specifically, our interest in helping you connect with people you know, and our mission to deepen collective understanding through writing, which supports your fundamental right to freedom of expression and information. How it works: When you opt in, we convert contact names and email addresses into encrypted, non-reversible identifiers and match them against our member database. We don't store names or emails in plain text. For contacts who aren't Medium members, we delete their encrypted identifiers immediately after checking. We delete all encrypted identifiers within 30 days.Excerpt from Medium's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 6 (lawful basis for processing third-party contact data) and potentially GDPR Article 14 (information to be provided where personal data has not been obtained from the data subject) for EEA and UK users, as contacts being processed have not directly provided their data to Medium. The relevant enforcement authorities are national Data Protection Authorities. The reliance on legitimate interests for processing third-party contact data may be subject to scrutiny given that the contacts themselves have not consented to or been notified of this processing. 2) GOVERNANCE EXPOSURE: Medium. The processing of contact data belonging to individuals who are not Medium users raises GDPR Article 14 transparency obligations toward those third parties, which may be difficult to satisfy operationally given the nature of the feature. The policy's stated reliance on legitimate interests for this processing may require a documented Legitimate Interests Assessment. 3) JURISDICTION FLAGS: EEA and UK users face heightened exposure given GDPR obligations regarding processing of third-party personal data. The feature is opt-in, which partially mitigates exposure, but the GDPR transparency obligations toward non-member contacts are not addressed in the policy. Illinois BIPA may be relevant if the encryption process constitutes biometric processing, though this is not established by the document. 4) CONTRACT AND VENDOR IMPLICATIONS: The address book feature processes device contact data, which may include data belonging to individuals not party to Medium's terms. Organizations deploying Medium to employees should assess whether use of this feature is compatible with their own data protection policies regarding third-party contact data. 5) COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether Medium's legitimate interests basis for processing third-party contact data is adequately documented and whether any notification obligations toward non-member contacts arise under applicable law. The 30-day deletion commitment should be verified against Medium's data retention practices.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision describes a contact matching process that processes personal data of individuals who are not Medium users, relying on legitimate interests as the stated lawful basis. The policy states that non-member identifiers are deleted immediately after matching, and all identifiers within 30 days, which are concrete operational data minimization commitments.
Under this clause, users who opt into the address book feature authorize Medium to process their device contacts using one-way encryption for the purpose of identifying known Medium members, with deletion of third-party contact identifiers occurring immediately for non-members and within 30 days for all.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.