Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data may be transferred to and processed in jurisdictions outside the user's country, and that consent to this policy combined with submission of information constitutes agreement to such transfers.
This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision asserts that consent to the privacy policy itself, combined with data submission, serves as the legal mechanism authorizing international data transfers. For EEA and UK users, the policy separately references standard contractual clauses as the transfer mechanism, which is the operative legal basis under GDPR; reliance on policy consent alone as a transfer mechanism may warrant evaluation against applicable transfer adequacy requirements.
Interpretive note: The policy's reliance on consent to the privacy policy as the legal basis for international transfers may not satisfy GDPR's transfer mechanism requirements; the EEA supplemental section references standard contractual clauses as the operative mechanism, creating potential ambiguity about which basis applies to which users.
Under these terms, personal data may be transferred to and processed in jurisdictions with different data protection laws. For EEA and UK users, the policy separately states that standard contractual clauses are used to safeguard such transfers, providing an additional legal mechanism beyond general policy consent.
Cross-platform context
See how other platforms handle International Data Transfer via Policy Consent and similar clauses.
Compare across platforms →Monitoring
Midjourney has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ from those in Your jurisdiction. Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.Excerpt from Midjourney's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V requirements on international data transfers, enforced by EU supervisory authorities, and UK GDPR transfer requirements enforced by the UK Information Commissioner's Office. The assertion that consent to the privacy policy constitutes agreement to international transfers may not satisfy GDPR's requirements for explicit, freely given, specific, and informed consent for data transfers as a lawful basis under applicable supervisory authority guidance. 2. GOVERNANCE EXPOSURE: Medium. For EEA and UK users, the policy separately references standard contractual clauses as the operative transfer mechanism, which provides a recognized legal basis under GDPR. However, the general consent-via-policy-acceptance framing in the main transfer clause may create ambiguity about which mechanism governs for non-EEA users. 3. JURISDICTION FLAGS: EEA, Switzerland, and UK users have the highest exposure given GDPR and UK GDPR transfer restrictions. Organizations in Switzerland should note the Swiss Federal Act on Data Protection's separate transfer requirements. Non-EEA jurisdictions with data localization requirements may also be implicated depending on user location. 4. CONTRACT AND VENDOR IMPLICATIONS: Business users should request documentation of the standard contractual clauses referenced in the EEA supplemental section and assess whether additional safeguards described in the policy are implemented. Vendor due diligence should include a review of Midjourney's data transfer impact assessments where applicable under GDPR. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm which transfer mechanism applies for each user geography and whether standard contractual clauses have been executed with all relevant sub-processors. For GDPR-governed deployments, a transfer impact assessment may be warranted. Data processing agreements should specify the applicable transfer mechanism and the jurisdictions to which data may be transferred.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision asserts that consent to the privacy policy itself, combined with data submission, serves as the legal mechanism authorizing international data transfers. For EEA and UK users, the policy separately references standard contractual clauses as the transfer mechanism, which is the operative legal basis under GDPR; reliance on policy consent alone as a transfer mechanism may warrant evaluation against …
Under these terms, personal data may be transferred to and processed in jurisdictions with different data protection laws. For EEA and UK users, the policy separately states that standard contractual clauses are used to safeguard such transfers, providing an additional legal mechanism beyond general policy consent.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.