Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that when users interact with embedded third-party content on Medium pages, the hosting third party may collect data including IP address and interaction data directly, and that Medium's privacy policy does not govern this collection.
This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Medium's privacy protections and data rights mechanisms do not apply to data collected by third-party embed providers, and that Medium does not control or take responsibility for that collection. Users interacting with embedded video, audio, or other content are subject to the embed provider's own privacy terms.
The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.
View change record →Under this clause, interactions with embedded content on Medium pages, such as YouTube videos, may result in data including IP address and usage behavior being transmitted to the third-party host, and those interactions are governed by the third party's privacy policy rather than Medium's.
Cross-platform context
See how other platforms handle Third-Party Embed Data Collection and similar clauses.
Compare across platforms →Monitoring
Medium has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Medium does not host some of the content displayed on our Services. Users have the ability to post content that is actually hosted by a third party, but is embedded in our pages (an "Embed"). When you interact with an Embed, it can send information about your interaction to the hosting third party just as if you were visiting the third party's site directly. For example, when you load a Medium post page with a YouTube video Embed and watch the video, YouTube receives information about your activity, such as your IP address and how much of the video you watch. Medium does not control what information third parties collect through Embeds or what they do with the information. This Privacy Policy does not apply to information collected through Embeds.Excerpt from Medium's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR requirements regarding third-party data controllers, particularly where EEA users interact with embeds from non-EEA providers. The relevant enforcement authorities are the applicable national Data Protection Authorities. The provision may require evaluation under GDPR Article 26 (joint controllers) depending on whether Medium and embed providers share purposes for data processing, though Medium's policy disclaims control over embed data collection. 2) GOVERNANCE EXPOSURE: Low. The provision operates as a disclosure and limitation of Medium's responsibility for third-party data collection. However, the disclaimer may not fully extinguish Medium's obligations under GDPR if embed providers are determined to be joint controllers in certain processing contexts. 3) JURISDICTION FLAGS: EEA and UK users face heightened exposure given GDPR requirements around transparency and controller responsibility. The applicability of joint controller analysis depends on the specific embed provider and the nature of the data shared, which varies by jurisdiction and enforcement context. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations that publish content on Medium and embed third-party media should be aware that their readers' data may be collected by those embed providers without Medium's oversight. This may be relevant for organizations with strict data minimization policies or sector-specific regulatory requirements. 5) COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether the embeds present on Medium pages relevant to their use case trigger any additional disclosure obligations under applicable law. Users with heightened privacy concerns should review the privacy policies of third-party providers whose content is embedded on Medium pages before interacting with that content.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that Medium's privacy protections and data rights mechanisms do not apply to data collected by third-party embed providers, and that Medium does not control or take responsibility for that collection. Users interacting with embedded video, audio, or other content are subject to the embed provider's own privacy terms.
Under this clause, interactions with embedded content on Medium pages, such as YouTube videos, may result in data including IP address and usage behavior being transmitted to the third-party host, and those interactions are governed by the third party's privacy policy rather than Medium's.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.