Mercury · Mercury Privacy Policy · View original document ↗

International Data Transfers and Standard Contractual Clauses

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Mercury changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mercury recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Mercury Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Personal Information may be stored and processed in any country where Mercury or its affiliates and service providers operate, and that EEA and UK transfers are protected by Standard Contractual Clauses and additional technical safeguards.

This analysis describes what Mercury's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.

Interpretive note: The policy references SCCs and 'additional technical and organizational safeguards' without specifying the nature of supplementary measures or confirming transfer impact assessments, which are required under post-Schrems II regulatory guidance; actual compliance depends on operational implementation not described in the document.

Consumer impact (what this means for users)

Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.

Cross-platform context

See how other platforms handle International Data Transfers and Standard Contractual Clauses and similar clauses.

Compare across platforms →

Monitoring

Mercury has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Mercury is headquartered in the United States, and we may store and process Personal Information in the United States or any other country in which we or our affiliates, business partners, or service providers operate. Our Services are primarily intended for individuals and businesses operating in the United States. If you are located outside the United States, your Personal Information may be transferred to and processed in jurisdictions that may not provide the same level of data protection as your home country. When we transfer Personal Information across borders, we implement safeguards required under applicable law. For example, for transfers from the European Economic Area or United Kingdom, we rely on approved contractual protections (such as Standard Contractual Clauses) and additional technical and organizational safeguards designed to ensure your information remains protected.

Excerpt from Mercury's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (Articles 44-49) governing international data transfers from the EEA, and the UK GDPR's equivalent transfer restriction provisions. Standard Contractual Clauses are an approved transfer mechanism under both frameworks. The European Data Protection Board and UK Information Commissioner's Office have issued guidance requiring supplementary measures and transfer impact assessments where SCCs are used for transfers to third countries, including the United States. Canadian transfers are subject to PIPEDA's accountability principle. 2) GOVERNANCE EXPOSURE: Medium. The policy references SCCs without specifying whether transfer impact assessments have been conducted or what supplementary technical measures are in place. Post-Schrems II, regulators expect documented TIAs for US-bound transfers; the absence of this detail in the policy does not confirm or deny their existence but creates a due diligence review area. 3) JURISDICTION FLAGS: EEA and UK users have the highest exposure as GDPR and UK GDPR impose strict transfer restrictions. Canadian users are subject to PIPEDA accountability requirements for cross-border transfers. Users in other jurisdictions outside the US may be subject to local data transfer laws not explicitly addressed in this policy. 4) CONTRACT AND VENDOR IMPLICATIONS: Mercury's disclosure that service providers and business partners may process data in multiple countries requires that data processing agreements with those parties include appropriate transfer mechanisms. Procurement teams should verify that SCC execution extends to all third-country data importers identified in the cookie table and the data disclosure chart. 5) COMPLIANCE CONSIDERATIONS: Legal teams should maintain executed SCC documentation for all EEA and UK data transfer relationships and document transfer impact assessments. DPA-template updates and the EU Commission's 2021 SCC revision should be confirmed as implemented across Mercury's processor agreements. UK GDPR's International Data Transfer Agreement (IDTA) requirements should be confirmed as distinct from EU SCCs for UK-bound flows.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • State AG
    EEA and UK data protection authorities (equivalent to State_AG oversight) handle complaints about international data transfer compliance under GDPR and UK GDPR
    File a complaint →

Provision details

Document information
Document
Mercury Privacy Policy
Entity
Mercury
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015755
Document ID
CA-D-00530
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f8b49beb208e6c3f2b9fb8ddafa22b88d22bbef9e6d3e086c87840d1d5a282f8
Analysis generated
July 9, 2026 08:43 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mercury
Document: Mercury Privacy Policy
Record ID: CA-P-015755
Captured: 2026-07-09 08:43:59 UTC
SHA-256: f8b49beb208e6c3f…
URL: https://conductatlas.com/platform/mercury/mercury-privacy-policy/provision/CA-P-015755/international-data-transfers-and-standard-contractual-clauses/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Mercury's International Data Transfers and Standard Contractual Clauses clause do?

This provision establishes Mercury's cross-border data transfer mechanism for EEA and UK users as Standard Contractual Clauses, which are the primary approved transfer tool under GDPR Chapter V; compliance teams should confirm that SCCs are executed with all relevant data importers and that the required transfer impact assessments are conducted.

How does this clause affect you?

Under this provision, EEA and UK users' Personal Information may be transferred to and processed in the United States and other jurisdictions, with Standard Contractual Clauses stated as the primary legal transfer mechanism; users may lodge complaints with their local data protection authority if they believe transfers do not comply with applicable law.

Is ConductAtlas affiliated with Mercury?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mercury.