The policy authorizes sharing of personal information with third-party vendors and service providers for purposes including payment processing, data analysis, email delivery, hosting, customer service, and marketing, without specifying a complete list of named providers or requiring user notification prior to each sharing event.
This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the contractual basis under which Medium transfers personal data to external parties for operational purposes, which implicates GDPR Article 28 data processor agreement requirements and CCPA business-purpose sharing disclosure obligations.
The updated policy states that Medium and its vendors may scan, analyze, and review your content, messages, AI interactions, and associated metadata. Data sharing now explicitly includes information you submitted or posted through the service, extending beyond infrastructure support to machine learning model training and improvement. The policy does not indicate an opt-out mechanism or granular user control over this specific use of content.
View change record →Provision now explicitly mentions use of personal information for ML model training and includes reference to 'information you submitted or posted,' significantly expanding the scope of data sharing purposes.
View full change record →Language simplified and narrowed to remove explicit mention of fraud prevention and business partners, consolidating focus on service providers only.
View full change record →Under this clause, personal information including identifiers and behavioral data may be transferred to third-party vendors for analytics, marketing, and infrastructure purposes, with disclosure limited to categorical description rather than named recipients.
How other platforms handle this
We will also provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected.
You and your organization's administrator can access several types of Service Data directly from Google Cloud, including your account information, billing contact information, payment and transaction information, as well as product and communication settings and configurations.
to request that your data be transferred to a third party (data portability)
"We may share your personal information with third party vendors and service providers that perform services for us or on our behalf, such as payment processing, data analysis, email delivery, hosting services, customer service, and marketing assistance.Excerpt from Medium's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the contractual basis under which Medium transfers personal data to external parties for operational purposes, which implicates GDPR Article 28 data processor agreement requirements and CCPA business-purpose sharing disclosure obligations.
Under this clause, personal information including identifiers and behavioral data may be transferred to third-party vendors for analytics, marketing, and infrastructure purposes, with disclosure limited to categorical description rather than named recipients.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.