Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Modal Labs uses commercially acceptable means to protect personal information but does not guarantee absolute security against data breaches or unauthorized access.
This analysis describes what Modal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insufficient to satisfy GDPR's requirement for appropriate technical and organizational security measures.
Interpretive note: The standard of 'commercially acceptable means' is undefined in the document, making assessment of actual security measures indeterminate from this provision alone.
Under this clause, Modal Labs does not guarantee the security of personal information transmitted to or stored by the service, and the security standard applied is described only as 'commercially acceptable means' without further specification.
Cross-platform context
See how other platforms handle Security Limitation Disclaimer and similar clauses.
Compare across platforms →Monitoring
Modal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.Excerpt from Modal's Privacy Policy
(1) REGULATORY LANDSCAPE: GDPR requires that controllers implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The policy's reference to 'commercially acceptable means' does not describe specific measures and may not satisfy GDPR's documentation requirements. FTC enforcement actions have addressed inadequate data security practices at companies whose public representations did not match implemented security controls. (2) GOVERNANCE EXPOSURE: Medium. The absence of any description of specific security measures or frameworks creates ambiguity about Modal Labs' actual security posture, which is relevant for enterprise customers and developers transmitting sensitive data through the platform. (3) JURISDICTION FLAGS: EU and EEA users have heightened exposure under GDPR Article 32's requirement for appropriate security measures. California residents may have rights under CCPA and the California Consumer Privacy Act amendments regarding security practices. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers and developers should request documentation of Modal Labs' security practices, certifications, and incident response procedures before transmitting personal or sensitive data through the platform, given the absence of specific security disclosures in this policy. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether Modal Labs' security posture meets the requirements of any applicable data processing agreements, whether security certifications such as SOC 2 or ISO 27001 exist, and whether the security limitation disclaimer is consistent with representations made in vendor contracts.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The provision establishes a security standard of 'commercially acceptable means' without defining that standard or describing specific technical or organizational measures in place, which may be insufficient to satisfy GDPR's requirement for appropriate technical and organizational security measures.
Under this clause, Modal Labs does not guarantee the security of personal information transmitted to or stored by the service, and the security standard applied is described only as 'commercially acceptable means' without further specification.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Modal.