Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Section 10A incorporates GDPR Standard Contractual Clauses (Module One, controller-to-controller) for transfers of Meta Ireland-controlled personal data outside the EEA to territories without a European Commission adequacy decision, designating the Irish Data Protection Commission as the competent supervisory authority and requiring developers to implement Meta's specified Technical and Organisational Measures.
This analysis describes what Meta's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision operationalizes GDPR Article 46 transfer safeguards by incorporating SCCs into the developer agreement by reference, establishing Ireland as the governing Member State and the Irish DPC as competent authority, and requiring developers to maintain Meta's specified technical and organizational measures as an Annex II obligation.
Under this clause, developers processing Meta Ireland-controlled personal data and transferring it outside the EEA are subject to Standard Contractual Clause obligations, including data security requirements and the data categories enumerated in Section 10A, which include profile information, location data, health data, biometric data, and political or religious beliefs.
Cross-platform context
See how other platforms handle EEA Data Transfer Standard Contractual Clauses and similar clauses.
Compare across platforms →Monitoring
Meta has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"This section shall apply to the extent that your Processing of Platform Data includes personal data controlled by Meta Platforms Ireland Limited ("Meta Ireland Data") and the transfer of such Meta Ireland Data to a territory outside of the European Economic Area that, at the time of such transfer, does not have a positive adequacy decision from the European Commission under Article 45 of Regulation (EU) 2016/679 (each an "EEA Data Transfer"). Whenever there is an EEA Data Transfer, your use of Meta Ireland Data is subject to your compliance with the Clauses in so far as they relate to controller to controller transfers (Module One). In each case, you agree that for the purposes of Section IV, Clauses 17 and 18 in the Clauses, Option 1 and Option (b) shall apply respectively and the Member State shall be Ireland.Excerpt from Meta's Platform Policy
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Article 46 (transfers subject to appropriate safeguards) and the European Commission's Standard Contractual Clauses for controller-to-controller transfers. The Irish Data Protection Commission is named as the competent supervisory authority, consistent with Meta Platforms Ireland Limited's EU establishment. Developers must ensure their own processing and transfer practices are consistent with both the SCCs and applicable GDPR obligations in their home jurisdictions. (2) GOVERNANCE EXPOSURE: High for developers transferring personal data outside the EEA. The data categories enumerated in Section 10A.b.ii include sensitive data categories under GDPR Article 9, specifically health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, and sexual orientation, which carry heightened processing and transfer obligations. (3) JURISDICTION FLAGS: EEA-based developers have direct DPC supervisory exposure. Non-EEA developers receiving Meta Ireland Data must ensure their jurisdiction's legal framework is compatible with SCC obligations. The post-Schrems II landscape requires developers to conduct transfer impact assessments for transfers to jurisdictions without adequate legal protection. (4) CONTRACT AND VENDOR IMPLICATIONS: The SCC incorporation means developers are bound by controller-to-controller obligations as data importers, including obligations to respond to data subject requests and cooperate with supervisory authority investigations. Developers should ensure their Sub-processor agreements are consistent with these SCC obligations. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that Technical and Organisational Measures referenced in Section 10A.d are documented, implemented, and auditable, and that data retention schedules align with the deletion obligations in Section 3.d. Transfer impact assessments should be maintained for all jurisdictions receiving Meta Ireland Data.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision operationalizes GDPR Article 46 transfer safeguards by incorporating SCCs into the developer agreement by reference, establishing Ireland as the governing Member State and the Irish DPC as competent authority, and requiring developers to maintain Meta's specified technical and organizational measures as an Annex II obligation.
Under this clause, developers processing Meta Ireland-controlled personal data and transferring it outside the EEA are subject to Standard Contractual Clause obligations, including data security requirements and the data categories enumerated in Section 10A, which include profile information, location data, health data, biometric data, and political or religious beliefs.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Meta.