Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that monday.com Inc. is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions, and relies primarily on this certification for EEA, UK, and Switzerland to US data transfers, with Standard Contractual Clauses used for transfers to other non-adequate countries. DPF Principles govern in case of conflict with policy terms.
This analysis describes what Monday.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability to Service Providers under that framework. The DPF is subject to ongoing legal and political scrutiny, and its continued validity as a transfer mechanism depends on factors external to monday.com's own policy.
Under these terms, personal data transferred from the EEA, UK, and Switzerland to the US is processed under the EU-US Data Privacy Framework certification, with DPF Principles governing in case of conflict with the privacy policy. EEA, UK, and Swiss individuals may submit DPF-related complaints to monday.com at privacy@monday.com or to VeraSafe as a free dispute resolution service.
Cross-platform context
See how other platforms handle Cross-Border Data Transfers and DPF Certification and similar clauses.
Compare across platforms →Monitoring
Monday.com has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"monday.com Inc., our US subsidiary, complies with the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework as set forth by the US Department of Commerce, and where appropriate – primarily relies on such certification for accepting transfers of data from the EEA, UK and Switzerland to the US (as applicable). monday.com Inc., will remain liable for onward transfers of your personal data to third parties (including our Service Providers) in accordance with applicable data transfer mechanisms. If there is any conflict between the terms in this privacy policy and the EU-US DPF Principles and/or the Swiss-US DPF, the Principles shall govern with respect to personal data transferred under the DPF.Excerpt from Monday.com's Privacy Policy
1. REGULATORY LANDSCAPE: The EU-US Data Privacy Framework was established following the Schrems II ruling by the Court of Justice of the EU. The framework is subject to periodic review and potential legal challenge. The policy also references Standard Contractual Clauses as approved by the European Commission, the UK ICO, and the Swiss FDPIC for transfers to non-adequate third countries. monday.com Inc. is subject to FTC investigatory and enforcement powers under the DPF. 2. GOVERNANCE EXPOSURE: Medium. DPF certification provides a recognized transfer mechanism but is contingent on US adherence to the framework's conditions. Organizations relying on monday.com's DPF certification for their own GDPR transfer compliance should monitor the framework's status and maintain awareness of Standard Contractual Clauses as a fallback mechanism. 3. JURISDICTION FLAGS: EEA, UK, and Swiss organizations are the primary affected parties. The policy discloses data storage locations including Guatemala and the Philippines, which are not identified as adequate jurisdictions by the European Commission, requiring SCC coverage for those transfers. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers in the EEA, UK, or Switzerland should confirm that their Data Processing Addendum with monday.com includes current SCC annexes for all transfer destinations, including sub-processor locations such as Guatemala and the Philippines. The onward transfer liability assertion by monday.com Inc. for Service Provider transfers under the DPF should be documented. 5. COMPLIANCE CONSIDERATIONS: Legal teams should monitor the status of the EU-US DPF and ensure that fallback transfer mechanisms (SCCs) are in place and documented in the DPA. Complaints regarding DPF compliance may be submitted to privacy@monday.com or to VeraSafe at https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability to Service Providers under that framework. The DPF is subject to ongoing legal and political scrutiny, and its continued validity as a transfer mechanism depends on factors external to monday.com's own policy.
Under these terms, personal data transferred from the EEA, UK, and Switzerland to the US is processed under the EU-US Data Privacy Framework certification, with DPF Principles governing in case of conflict with the privacy policy. EEA, UK, and Swiss individuals may submit DPF-related complaints to monday.com at privacy@monday.com or to VeraSafe as a free dispute resolution service.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Monday.com.