Provision record
Mercury · Mercury Privacy Policy · View original document ↗

International Data Transfers and Standard Contractual Clauses

Medium severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Mercury and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy states that Personal Information may be stored and processed in any country where Mercury or its affiliates and service providers operate, and that EEA and UK transfers are protected by Standard Contractual Clauses and additional technical safeguards.

ⓘ

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.

⚠

Interpretive note: The policy references SCCs and 'additional technical and organizational safeguards' without specifying the nature of supplementary measures or confirming transfer impact assessments, which are required under post-Schrems II regulatory guidance; actual compliance depends on operational implementation not described in the document.

Recent Activity

This document changed recently

Medium Aug 28, 2026

The updated policy states that Mercury may now collect personal information directly from employees, contractors, payment beneficiaries, and dependents at a business's direction, without requiring those individuals' direct consent to Mercury. This expands the pool of individuals whose data Mercury processes beyond those who directly use the service. Additionally, the revised SMS terms separate transactional messages (receipts, confirmations) from marketing messages, requiring separate consent for marketing SMS. You can manage marketing SMS consent independently from transactional message receipt.

View change record →
Medium Jul 24, 2026

The updated privacy policy now discloses that cookies from Facebook Ads, Bing Ads, Braze, Google Ads, and LinkedIn Ads serve an additional purpose: 'SaleOfInfo'. This means data collected through these cookies may be sold or shared with third-party commercial partners, beyond their existing use for advertising and analytics. Under the revised policy, Mercury treats data from these cookies as subject to potential sale or commercial sharing. You can review Mercury's full privacy policy to understand your data rights and any available opt-out mechanisms.

View change record →

Consumer impact (what this means for users)

Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.

Cross-platform context

See how other platforms handle International Data Transfers and Standard Contractual Clauses and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Mercury is headquartered in the United States, and we may store and process Personal Information in the United States or any other country in which we or our affiliates, business partners, or service providers operate. Our Services are primarily intended for individuals and businesses operating in the United States. If you are located outside the United States, your Personal Information may be transferred to and processed in jurisdictions that may not provide the same level of data protection as your home country. When we transfer Personal Information across borders, we implement safeguards required under applicable law. For example, for transfers from the European Economic Area or United Kingdom, we rely on approved contractual protections (such as Standard Contractual Clauses) and additional technical and organizational safeguards designed to ensure your information remains protected.

Excerpt from Mercury's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (Articles 44-49) governing international data transfers from the EEA, and the UK GDPR's equivalent transfer restriction provisions.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
Mercury Privacy Policy
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015755
Document ID
CA-D-00530
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f8b49beb208e6c3f2b9fb8ddafa22b88d22bbef9e6d3e086c87840d1d5a282f8
Analysis generated
July 9, 2026 08:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Privacy Policy
Record ID: CA-P-015755
Captured: 2026-07-09 08:43:59 UTC
SHA-256: f8b49beb208e6c3f…
URL: https://conductatlas.com/platform/mercury/mercury-privacy-policy/provision/CA-P-015755/international-data-transfers-and-standard-contractual-clauses/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Mercury's International Data Transfers and Standard Contractual Clauses clause do?

This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.

How does this clause affect you?

Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.