Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that Mixpanel may purchase personal data about users from third-party sources including social networks, location service providers, co-brand partners, and public databases, and combines this data with information collected directly.
This analysis describes what Mixpanel's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes external data enrichment through purchase of personal data from social networks and other third-party data sources, which may engage GDPR Article 14 transparency obligations regarding data obtained from sources other than the data subject and CCPA source disclosure requirements.
Under this clause, personal data about a user may be purchased from social networks, location providers, and public databases and incorporated into Mixpanel's records about that user, beyond what the user directly provides. The agreement requires Mixpanel to apply its Privacy Statement protections to this purchased data.
Cross-platform context
See how other platforms handle Third-Party Data Purchase Authorization and similar clauses.
Compare across platforms →Monitoring
Mixpanel has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"When we collect information in connection with our business relationship with you, we may also purchase data about you from third parties. We protect information obtained from third parties according to the practices described in this Privacy Statement, plus any additional restrictions imposed by the third party providing the data. These third-party sources include, for example: Applications and services, such as social networks that make users' information available to others; Service providers that help us determine your device's location based on its IP Address to customize certain products to your physical location; Partners with which we offer co-branded services or engage in joint marketing activities; and Publicly available sources, such as open government databases or other information in the public domain.Excerpt from Mixpanel's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 14, which requires that controllers provide transparency notices to data subjects when personal data is obtained from sources other than the data subject, including the categories of data and the source. Under CCPA, the categories of sources must be disclosed, which this policy partially fulfills by naming source types. The FTC Act applies to deceptive practices around data sourcing. Relevant enforcement authorities include EU DPAs, the UK ICO, and the FTC. (2) GOVERNANCE EXPOSURE: Medium. The provision discloses that data purchases occur and identifies category-level sources, satisfying baseline CCPA source disclosure. However, GDPR Article 14 may require more granular notice to EU data subjects at the time of purchase or first use, including identification of specific data categories obtained. The provision does not describe the categories of data purchased or the frequency of such purchases. (3) JURISDICTION FLAGS: EU and UK users have the most direct exposure given GDPR Article 14 notice requirements. California residents are entitled to know the categories of sources from which Personal Information is collected under CCPA, which the policy partially addresses. Businesses in Illinois, New York, and other states with data broker registration requirements should assess whether Mixpanel's data sourcing practices engage those obligations. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm whether Mixpanel's Data Processing Agreement specifies the categories of third-party data sources and establishes contractual limits on enrichment practices. The provision's reference to 'additional restrictions imposed by the third party providing the data' introduces variable data handling standards that may be difficult to audit. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether Mixpanel's Article 14 GDPR notices are implemented for EU users when third-party data is first used; whether data purchased from social networks meets applicable consent standards in the source jurisdiction; and whether internal data mapping records reflect Mixpanel as a third-party data source.
This provision authorizes external data enrichment through purchase of personal data from social networks and other third-party data sources, which may engage GDPR Article 14 transparency obligations regarding data obtained from sources other than the data subject and CCPA source disclosure requirements.
Under this clause, personal data about a user may be purchased from social networks, location providers, and public databases and incorporated into Mixpanel's records about that user, beyond what the user directly provides. The agreement requires Mixpanel to apply its Privacy Statement protections to this purchased data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mixpanel.