Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that Mixpanel relies on the EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework for cross-border personal data transfers from EU, UK, and Switzerland, and accepts ongoing liability for onward transfers to third-party agents that process data inconsistently with the Frameworks.
This analysis describes what Mixpanel's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes Mixpanel's cross-border data transfer legal basis and accepts liability for downstream agent non-compliance with Data Privacy Framework Principles, which is a material contractual and regulatory commitment. The provision also states that Framework Principles govern over conflicting Privacy Statement terms, creating a hierarchy of applicable standards.
Under this clause, EU, UK, and Swiss personal data transferred to Mixpanel in the United States is processed under Data Privacy Framework Principles, and EU, UK, and Swiss residents may seek binding arbitration against Mixpanel for unresolved Framework violations. The agreement also states that users may contact compliance@mixpanel.com with privacy complaints before engaging supervisory authorities.
Cross-platform context
See how other platforms handle EU-US Data Privacy Framework and SCC Reliance and similar clauses.
Compare across platforms →Monitoring
Mixpanel has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Mixpanel participates in the U.S. Department of Commerce self-certification process and adheres to the Data Privacy Framework Principles ("Principles") with regard to the processing of personal data received from the European Union, United Kingdom and Switzerland, in reliance on these Data Privacy Frameworks. If there is any conflict between the terms in this Privacy Statement and the Data Privacy Frameworks or the Principles, the Data Privacy Frameworks and Principles shall govern. Mixpanel is responsible for the processing of the personal data it receives under each Data Privacy Framework, and subsequent transfers to any third party acting as an agent on its behalf. If third-party agents process personal data on our behalf in a manner inconsistent with the principles of any of the Data Privacy Frameworks, we remain liable unless we prove we are not responsible for the event giving rise to the damage.Excerpt from Mixpanel's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision implicates the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US Data Privacy Framework, all administered by the U.S. Department of Commerce with FTC enforcement authority. GDPR Chapter V governs adequacy and appropriate safeguards for international transfers. Standard Contractual Clauses as adopted by the European Commission provide the parallel contractual transfer mechanism. Relevant enforcement authorities include the FTC, EU DPAs, the UK ICO, and the Swiss FDPIC. (2) GOVERNANCE EXPOSURE: Medium. Self-certification under the Data Privacy Framework is an ongoing obligation requiring annual recertification and maintenance of compliant data practices. The provision's acceptance of agent liability for downstream processing creates a material compliance dependency on Mixpanel's sub-processor management. The document also discloses that SCC are used for intra-group and sub-processor transfers, providing a secondary transfer mechanism. (3) JURISDICTION FLAGS: EU, UK, and Swiss users have the highest exposure. EU users retain the right to lodge complaints with their national supervisory authority regardless of Mixpanel's Framework participation. The Framework's legal status has been subject to prior legal challenges in the EU, and compliance teams should monitor for developments affecting Framework adequacy, although as of this policy's publication date the EU-US DPF has been in effect. (4) CONTRACT AND VENDOR IMPLICATIONS: B2B customers in the EU, UK, or Switzerland should confirm whether they have executed Standard Contractual Clauses with Mixpanel as required under their own GDPR transfer obligations. The DPF self-certification reduces but does not eliminate the need for customers to conduct transfer impact assessments depending on their internal compliance standards. Procurement teams should request evidence of current DPF certification. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify Mixpanel's current DPF certification status on the Department of Commerce certification database; confirm that SCC addenda are in place in the executed DPA; assess whether Mixpanel's sub-processor list is current and whether sub-processors are themselves covered by Framework or SCC arrangements; and document the legal basis for transfers in internal records of processing activities.
This provision establishes Mixpanel's cross-border data transfer legal basis and accepts liability for downstream agent non-compliance with Data Privacy Framework Principles, which is a material contractual and regulatory commitment. The provision also states that Framework Principles govern over conflicting Privacy Statement terms, creating a hierarchy of applicable standards.
Under this clause, EU, UK, and Swiss personal data transferred to Mixpanel in the United States is processed under Data Privacy Framework Principles, and EU, UK, and Swiss residents may seek binding arbitration against Mixpanel for unresolved Framework violations. The agreement also states that users may contact compliance@mixpanel.com with privacy complaints before engaging supervisory authorities.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mixpanel.