Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement reserves Mixpanel's right to derive de-identified data from personal data and to use and disclose that de-identified data to third parties for any purpose, at Mixpanel's sole discretion, subject to applicable law.
This analysis describes what Mixpanel's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision asserts broad discretion over the secondary use and third-party disclosure of data derived from personal information, conditioned on de-identification rather than on user consent or specified purpose limitations. The practical scope of this reservation depends on the robustness of the de-identification standard applied and applicable law in relevant jurisdictions.
Interpretive note: The enforceability of the 'any purpose' reservation depends on whether Mixpanel's de-identification standard meets applicable legal thresholds under CCPA and GDPR, which the document does not specify.
Under this clause, data derived from a user's personal information may be shared with third parties for any purpose Mixpanel chooses, provided Mixpanel has applied a de-identification process. The policy separately states that Mixpanel may re-identify de-identified data to test de-identification processes, which is a condition that may interact with CCPA and GDPR standards for de-identified and pseudonymized data.
Cross-platform context
See how other platforms handle De-Identified Data Sole Discretion Reservation and similar clauses.
Compare across platforms →Monitoring
Mixpanel has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may create de-identified data records sourced or extracted from data connected to or associated with personal data by excluding information (such as your name) that makes the data personally identifiable to you. We use this de-identified data to analyze request and usage patterns so that we may enhance the content of our Services and improve our Services navigation. We reserve the right to use de-identified data for any purpose and disclose de-identified data to third parties in our sole discretion where permitted by applicable law.Excerpt from Mixpanel's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision implicates CCPA's definition of 'deidentified' data and associated obligations, including the requirement that businesses implementing de-identification maintain technical and administrative safeguards. GDPR's concept of pseudonymization differs from de-identification, and data that remains capable of re-identification may retain personal data status under GDPR. The FTC has published guidance on de-identification standards relevant to FTC Act enforcement. Relevant authorities include the FTC, EU DPAs, and the UK ICO. (2) GOVERNANCE EXPOSURE: Medium. The 'any purpose' and 'sole discretion' language asserts broad secondary use rights, but the enforceability of this reservation depends on the adequacy of the de-identification standard applied, which the document does not specify. If data does not meet applicable de-identification thresholds under CCPA or GDPR, the 'any purpose' reservation may not apply as asserted. (3) JURISDICTION FLAGS: California creates heightened exposure given CCPA's specific de-identification requirements and the CPPA's ongoing regulatory attention to de-identification practices. EU and UK users are protected by GDPR's broader definition of personal data, which may treat insufficiently de-identified data as personal data subject to full GDPR obligations. The document's admission that re-identification may occur for testing purposes may complicate GDPR de-identification claims. (4) CONTRACT AND VENDOR IMPLICATIONS: B2B customers whose data is processed through Mixpanel's platform should assess whether their contracts address the de-identification and secondary use of derived data, particularly where the derived data relates to their own end users. The 'sole discretion' language may not align with standard data processing agreement terms that require specified processing purposes. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether Mixpanel's de-identification methodology meets CCPA and GDPR standards; whether the Data Processing Agreement limits Mixpanel's secondary use rights over de-identified data derived from customer data; and whether re-identification testing practices are disclosed to data subjects and appropriately governed.
This provision asserts broad discretion over the secondary use and third-party disclosure of data derived from personal information, conditioned on de-identification rather than on user consent or specified purpose limitations. The practical scope of this reservation depends on the robustness of the de-identification standard applied and applicable law in relevant jurisdictions.
Under this clause, data derived from a user's personal information may be shared with third parties for any purpose Mixpanel chooses, provided Mixpanel has applied a de-identification process. The policy separately states that Mixpanel may re-identify de-identified data to test de-identification processes, which is a condition that may interact with CCPA and GDPR standards for de-identified and pseudonymized data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mixpanel.