Monday.com · Monday.com Privacy Policy · View original document ↗

Cross-Border Data Transfers and DPF Certification

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Monday.com changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Monday.com Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that monday.com Inc. is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions, and relies primarily on this certification for EEA, UK, and Switzerland to US data transfers, with Standard Contractual Clauses used for transfers to other non-adequate countries. DPF Principles govern in case of conflict with policy terms.

This analysis describes what Monday.com's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability to Service Providers under that framework. The DPF is subject to ongoing legal and political scrutiny, and its continued validity as a transfer mechanism depends on factors external to monday.com's own policy.

Consumer impact (what this means for users)

Under these terms, personal data transferred from the EEA, UK, and Switzerland to the US is processed under the EU-US Data Privacy Framework certification, with DPF Principles governing in case of conflict with the privacy policy. EEA, UK, and Swiss individuals may submit DPF-related complaints to monday.com at privacy@monday.com or to VeraSafe as a free dispute resolution service.

Cross-platform context

See how other platforms handle Cross-Border Data Transfers and DPF Certification and similar clauses.

Compare across platforms →

Monitoring

Monday.com has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
monday.com Inc., our US subsidiary, complies with the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework as set forth by the US Department of Commerce, and where appropriate – primarily relies on such certification for accepting transfers of data from the EEA, UK and Switzerland to the US (as applicable). monday.com Inc., will remain liable for onward transfers of your personal data to third parties (including our Service Providers) in accordance with applicable data transfer mechanisms. If there is any conflict between the terms in this privacy policy and the EU-US DPF Principles and/or the Swiss-US DPF, the Principles shall govern with respect to personal data transferred under the DPF.

Excerpt from Monday.com's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: The EU-US Data Privacy Framework was established following the Schrems II ruling by the Court of Justice of the EU. The framework is subject to periodic review and potential legal challenge. The policy also references Standard Contractual Clauses as approved by the European Commission, the UK ICO, and the Swiss FDPIC for transfers to non-adequate third countries. monday.com Inc. is subject to FTC investigatory and enforcement powers under the DPF. 2. GOVERNANCE EXPOSURE: Medium. DPF certification provides a recognized transfer mechanism but is contingent on US adherence to the framework's conditions. Organizations relying on monday.com's DPF certification for their own GDPR transfer compliance should monitor the framework's status and maintain awareness of Standard Contractual Clauses as a fallback mechanism. 3. JURISDICTION FLAGS: EEA, UK, and Swiss organizations are the primary affected parties. The policy discloses data storage locations including Guatemala and the Philippines, which are not identified as adequate jurisdictions by the European Commission, requiring SCC coverage for those transfers. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers in the EEA, UK, or Switzerland should confirm that their Data Processing Addendum with monday.com includes current SCC annexes for all transfer destinations, including sub-processor locations such as Guatemala and the Philippines. The onward transfer liability assertion by monday.com Inc. for Service Provider transfers under the DPF should be documented. 5. COMPLIANCE CONSIDERATIONS: Legal teams should monitor the status of the EU-US DPF and ensure that fallback transfer mechanisms (SCCs) are in place and documented in the DPA. Complaints regarding DPF compliance may be submitted to privacy@monday.com or to VeraSafe at https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC holds investigatory and enforcement powers over monday.com Inc. under the EU-US Data Privacy Framework as explicitly stated in the policy.
    File a complaint →

Provision details

Document information
Document
Monday.com Privacy Policy
Entity
Monday.com
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015839
Document ID
CA-D-00554
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
122167c43bb41ce919a6faf3fed5c0707592bf8b6c3ef510b7c4a5652edd0d39
Analysis generated
July 9, 2026 08:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Monday.com
Document: Monday.com Privacy Policy
Record ID: CA-P-015839
Captured: 2026-07-09 08:54:35 UTC
SHA-256: 122167c43bb41ce9…
URL: https://conductatlas.com/platform/mondaycom/mondaycom-privacy-policy/provision/CA-P-015839/cross-border-data-transfers-and-dpf-certification/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Monday.com's Cross-Border Data Transfers and DPF Certification clause do?

This provision establishes the legal mechanism for transatlantic data transfers, with monday.com Inc. asserting DPF certification as the primary transfer basis and accepting onward transfer liability to Service Providers under that framework. The DPF is subject to ongoing legal and political scrutiny, and its continued validity as a transfer mechanism depends on factors external to monday.com's own policy.

How does this clause affect you?

Under these terms, personal data transferred from the EEA, UK, and Switzerland to the US is processed under the EU-US Data Privacy Framework certification, with DPF Principles governing in case of conflict with the privacy policy. EEA, UK, and Swiss individuals may submit DPF-related complaints to monday.com at privacy@monday.com or to VeraSafe as a free dispute resolution service.

Is ConductAtlas affiliated with Monday.com?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Monday.com.