Midjourney · Midjourney Data Retention & Privacy FAQ · View original document ↗

Third-Party Data Sharing

Medium severity Medium confidence Explicitdocumentlanguage Uncommon · 24 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Midjourney recorded 6 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Midjourney Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Midjourney shares your data with service providers, business partners, and payment processors, and may transfer it if the company is sold; it states it does not sell your data under California law.

This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy authorizes sharing personal information with service providers, business partners, and payment processors, and permits data transfer in the event of a business acquisition; the categories of business partners are not fully enumerated, which limits user visibility into who may receive their data.

Interpretive note: The policy does not enumerate all business partners or specify the data categories shared with each, limiting the ability to assess the full scope of third-party sharing.

Consumer impact (what this means for users)

Your personal information, including account identifiers and potentially behavioral and content data, may be shared with service providers and business partners whose identities are not fully specified in the policy; in the event of a company sale or merger, your data may transfer to a new entity.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@midjourney.com to request information about which third parties have received your personal data, or to request deletion of your personal data from Midjourney's systems.

Cross-platform context

See how other platforms handle Third-Party Data Sharing and similar clauses.

Compare across platforms →

Monitoring

Midjourney has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We may share your personal information with third parties in the following circumstances: with service providers who assist us in operating the Services; with business partners; with payment processors; in connection with a merger, acquisition, or sale of assets; when required by law or to protect our rights; and with your consent. We do not sell your personal information as that term is defined under the California Consumer Privacy Act.

— Excerpt from Midjourney's Midjourney Data Retention & Privacy FAQ

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Third-party data sharing engages GDPR data processing agreement requirements (Article 28) for service providers acting as processors, and GDPR Article 46 transfer mechanisms for international data flows. CCPA/CPRA distinguishes between service providers (restricted use) and third parties (unrestricted sharing); the policy's reference to business partners without enumerated restrictions may require evaluation as to whether sharing constitutes CPRA-regulated sharing for cross-context behavioral advertising. The FTC's data broker and sharing practices guidance is relevant. GOVERNANCE EXPOSURE: Medium. The non-enumeration of business partners creates auditability challenges. GDPR Article 28 requires written contracts with processors specifying permissible use; compliance teams should verify that all service providers and business partners operate under appropriate data processing agreements. The business transfer clause creates a risk of data flowing to an entity with different privacy practices following an acquisition. JURISDICTION FLAGS: EU/EEA jurisdictions require Standard Contractual Clauses or equivalent transfer mechanisms for international data transfers. California's CPRA requires opt-out rights for sharing of personal information with third parties for cross-context behavioral advertising. The business partner category should be assessed under both frameworks. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should request a list of sub-processors and business partners. Contracts with Midjourney should include provisions addressing data transfer obligations in the event of a merger or acquisition, and should specify data destruction or return obligations upon contract termination. COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether the business partner sharing described constitutes CPRA-regulated sharing requiring a disclosed opt-out right. GDPR transfer impact assessments may be required for international sharing. Data flow mapping should document all third-party recipients and applicable legal bases.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over data sharing practices and unfair or deceptive acts related to third-party data disclosure.
    File a complaint →
  • State AG
    California's Attorney General and the California Privacy Protection Agency have enforcement authority under CCPA/CPRA for third-party data sharing obligations.
    File a complaint →

Provision details

Document information
Document
Midjourney Data Retention & Privacy FAQ
Entity
Midjourney
Document last updated
May 12, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-011985
Document ID
CA-D-00828
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
dc64a31f31e3763fff77bbf3fcb645d925ef20a453b61c9779b90767e2a4b4bc
Analysis generated
May 12, 2026 16:49 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Midjourney
Document: Midjourney Data Retention & Privacy FAQ
Record ID: CA-P-011985
Captured: 2026-05-12 16:49:44 UTC
SHA-256: dc64a31f31e3763f…
URL: https://conductatlas.com/platform/midjourney/midjourney-data-retention-privacy-faq/third-party-data-sharing/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Midjourney's Third-Party Data Sharing clause do?

The policy authorizes sharing personal information with service providers, business partners, and payment processors, and permits data transfer in the event of a business acquisition; the categories of business partners are not fully enumerated, which limits user visibility into who may receive their data.

How does this clause affect you?

Your personal information, including account identifiers and potentially behavioral and content data, may be shared with service providers and business partners whose identities are not fully specified in the policy; in the event of a company sale or merger, your data may transfer to a new entity.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 24 platforms. See the full comparison.

Is ConductAtlas affiliated with Midjourney?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.