Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Personal Information may be stored and processed in any country where Mercury or its affiliates and service providers operate, and that EEA and UK transfers are protected by Standard Contractual Clauses and additional technical safeguards.
This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.
Interpretive note: The policy references SCCs and 'additional technical and organizational safeguards' without specifying the nature of supplementary measures or confirming transfer impact assessments, which are required under post-Schrems II regulatory guidance; actual compliance depends on operational implementation not described in the document.
Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.
Cross-platform context
See how other platforms handle International Data Transfers and Standard Contractual Clauses and similar clauses.
Compare across platforms →Monitoring
Mercury has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Mercury is headquartered in the United States, and we may store and process Personal Information in the United States or any other country in which we or our affiliates, business partners, or service providers operate. Our Services are primarily intended for individuals and businesses operating in the United States. If you are located outside the United States, your Personal Information may be transferred to and processed in jurisdictions that may not provide the same level of data protection as your home country. When we transfer Personal Information across borders, we implement safeguards required under applicable law. For example, for transfers from the European Economic Area or United Kingdom, we rely on approved contractual protections (such as Standard Contractual Clauses) and additional technical and organizational safeguards designed to ensure your information remains protected.Excerpt from Mercury's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (Articles 44-49) governing international data transfers from the EEA, and the UK GDPR's equivalent transfer restriction provisions. Standard Contractual Clauses are an approved transfer mechanism under both frameworks. The European Data Protection Board and UK Information Commissioner's Office have issued guidance requiring supplementary measures and transfer impact assessments where SCCs are used for transfers to third countries, including the United States. Canadian transfers are subject to PIPEDA's accountability principle. 2) GOVERNANCE EXPOSURE: Medium. The policy references SCCs without specifying whether transfer impact assessments have been conducted or what supplementary technical measures are in place. Post-Schrems II, regulators expect documented TIAs for US-bound transfers; the absence of this detail in the policy does not confirm or deny their existence but creates a due diligence review area. 3) JURISDICTION FLAGS: EEA and UK users have the highest exposure as GDPR and UK GDPR impose strict transfer restrictions. Canadian users are subject to PIPEDA accountability requirements for cross-border transfers. Users in other jurisdictions outside the US may be subject to local data transfer laws not explicitly addressed in this policy. 4) CONTRACT AND VENDOR IMPLICATIONS: Mercury's disclosure that service providers and business partners may process data in multiple countries requires that data processing agreements with those parties include appropriate transfer mechanisms. Procurement teams should verify that SCC execution extends to all third-country data importers identified in the cookie table and the data disclosure chart. 5) COMPLIANCE CONSIDERATIONS: Legal teams should maintain executed SCC documentation for all EEA and UK data transfer relationships and document transfer impact assessments. DPA-template updates and the EU Commission's 2021 SCC revision should be confirmed as implemented across Mercury's processor agreements. UK GDPR's International Data Transfer Agreement (IDTA) requirements should be confirmed as distinct from EU SCCs for UK-bound flows.
This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.
Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.