Mixpanel · Mixpanel Privacy Statement · View original document ↗

EU-US Data Privacy Framework and SCC Reliance

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Mixpanel changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Mixpanel Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement states that Mixpanel relies on the EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework for cross-border personal data transfers from EU, UK, and Switzerland, and accepts ongoing liability for onward transfers to third-party agents that process data inconsistently with the Frameworks.

This analysis describes what Mixpanel's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes Mixpanel's cross-border data transfer legal basis and accepts liability for downstream agent non-compliance with Data Privacy Framework Principles, which is a material contractual and regulatory commitment. The provision also states that Framework Principles govern over conflicting Privacy Statement terms, creating a hierarchy of applicable standards.

Consumer impact (what this means for users)

Under this clause, EU, UK, and Swiss personal data transferred to Mixpanel in the United States is processed under Data Privacy Framework Principles, and EU, UK, and Swiss residents may seek binding arbitration against Mixpanel for unresolved Framework violations. The agreement also states that users may contact compliance@mixpanel.com with privacy complaints before engaging supervisory authorities.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EU, UK, and Swiss residents may submit access, correction, or deletion requests by emailing compliance@mixpanel.com. If a complaint remains unresolved, residents may escalate to their national supervisory authority or invoke binding arbitration under the Data Privacy Framework.

Cross-platform context

See how other platforms handle EU-US Data Privacy Framework and SCC Reliance and similar clauses.

Compare across platforms →

Monitoring

Mixpanel has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Mixpanel participates in the U.S. Department of Commerce self-certification process and adheres to the Data Privacy Framework Principles ("Principles") with regard to the processing of personal data received from the European Union, United Kingdom and Switzerland, in reliance on these Data Privacy Frameworks. If there is any conflict between the terms in this Privacy Statement and the Data Privacy Frameworks or the Principles, the Data Privacy Frameworks and Principles shall govern. Mixpanel is responsible for the processing of the personal data it receives under each Data Privacy Framework, and subsequent transfers to any third party acting as an agent on its behalf. If third-party agents process personal data on our behalf in a manner inconsistent with the principles of any of the Data Privacy Frameworks, we remain liable unless we prove we are not responsible for the event giving rise to the damage.

Excerpt from Mixpanel's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision implicates the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US Data Privacy Framework, all administered by the U.S. Department of Commerce with FTC enforcement authority. GDPR Chapter V governs adequacy and appropriate safeguards for international transfers. Standard Contractual Clauses as adopted by the European Commission provide the parallel contractual transfer mechanism. Relevant enforcement authorities include the FTC, EU DPAs, the UK ICO, and the Swiss FDPIC. (2) GOVERNANCE EXPOSURE: Medium. Self-certification under the Data Privacy Framework is an ongoing obligation requiring annual recertification and maintenance of compliant data practices. The provision's acceptance of agent liability for downstream processing creates a material compliance dependency on Mixpanel's sub-processor management. The document also discloses that SCC are used for intra-group and sub-processor transfers, providing a secondary transfer mechanism. (3) JURISDICTION FLAGS: EU, UK, and Swiss users have the highest exposure. EU users retain the right to lodge complaints with their national supervisory authority regardless of Mixpanel's Framework participation. The Framework's legal status has been subject to prior legal challenges in the EU, and compliance teams should monitor for developments affecting Framework adequacy, although as of this policy's publication date the EU-US DPF has been in effect. (4) CONTRACT AND VENDOR IMPLICATIONS: B2B customers in the EU, UK, or Switzerland should confirm whether they have executed Standard Contractual Clauses with Mixpanel as required under their own GDPR transfer obligations. The DPF self-certification reduces but does not eliminate the need for customers to conduct transfer impact assessments depending on their internal compliance standards. Procurement teams should request evidence of current DPF certification. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify Mixpanel's current DPF certification status on the Department of Commerce certification database; confirm that SCC addenda are in place in the executed DPA; assess whether Mixpanel's sub-processor list is current and whether sub-processors are themselves covered by Framework or SCC arrangements; and document the legal basis for transfers in internal records of processing activities.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC is the designated enforcement authority for Mixpanel's compliance with the EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework Principles.
    File a complaint →

Provision details

Document information
Document
Mixpanel Privacy Statement
Entity
Mixpanel
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016201
Document ID
CA-D-00704
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2bcb11dee9567aec1e9bcab8282833836bab779cdc687c86cbcbe7d1f0318fab
Analysis generated
July 9, 2026 09:49 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mixpanel
Document: Mixpanel Privacy Statement
Record ID: CA-P-016201
Captured: 2026-07-09 09:49:04 UTC
SHA-256: 2bcb11dee9567aec…
URL: https://conductatlas.com/platform/mixpanel/mixpanel-privacy-statement/provision/CA-P-016201/eu-us-data-privacy-framework-and-scc-reliance/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Mixpanel's EU-US Data Privacy Framework and SCC Reliance clause do?

This provision establishes Mixpanel's cross-border data transfer legal basis and accepts liability for downstream agent non-compliance with Data Privacy Framework Principles, which is a material contractual and regulatory commitment. The provision also states that Framework Principles govern over conflicting Privacy Statement terms, creating a hierarchy of applicable standards.

How does this clause affect you?

Under this clause, EU, UK, and Swiss personal data transferred to Mixpanel in the United States is processed under Data Privacy Framework Principles, and EU, UK, and Swiss residents may seek binding arbitration against Mixpanel for unresolved Framework violations. The agreement also states that users may contact compliance@mixpanel.com with privacy complaints before engaging supervisory authorities.

Is ConductAtlas affiliated with Mixpanel?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mixpanel.