Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that personal information may be transferred to the United States and other countries with different data protection laws, and acknowledges that transferred data may be subject to foreign government, court, or law enforcement access under local law in the destination country.
This analysis describes what MyFitnessPal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that international data transfers may result in personal information becoming subject to foreign government access obligations, a disclosure that engages GDPR Chapter V transfer requirements and the adequacy determinations and supplementary measures framework established following the Schrems II ruling.
Interpretive note: The policy asserts 'appropriate steps' and 'applicable law' compliance for international transfers but does not specify the legal transfer mechanisms used, creating uncertainty as to whether GDPR Chapter V documentation requirements are fully satisfied.
The agreement informs users that their personal information, including health-adjacent diary data, may be transferred to countries with different privacy protections, and that local laws in those countries may permit government or law enforcement access to the transferred data.
Cross-platform context
See how other platforms handle International Data Transfers with Foreign Government Access Acknowledgment and similar clauses.
Compare across platforms →Monitoring
MyFitnessPal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"When we transfer your personal information outside of your country of residence, we do so in accordance with applicable law and take appropriate steps to ensure your information is protected. However, please note that while outside of the jurisdiction in which you reside, your personal information will be subject to applicable local laws, which might permit foreign governments, courts, law enforcement, or regulatory agencies to access your information in certain circumstances. By using the Services and/or sharing your personal information with MyFitnessPal, you are informed that your personal information may be transferred to countries outside of your country of residence.Excerpt from MyFitnessPal's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V governing transfers of personal data to third countries, the EU-US Data Privacy Framework (and equivalent UK and Swiss arrangements), and the CJEU's Schrems II decision, which requires assessment of destination country law as part of transfer impact analyses. Canada's PIPEDA, Brazil's LGPD, and South Korea's PIPA also impose international transfer obligations. The relevant enforcement authorities are EU supervisory authorities, the UK ICO, and equivalent bodies in Canada, Brazil, and South Korea. 2) GOVERNANCE EXPOSURE: Medium. The policy asserts compliance with applicable law and 'appropriate steps' for protection but does not specify the transfer mechanisms used (Standard Contractual Clauses, adequacy decisions, or other instruments). For EEA users, the absence of disclosed transfer mechanism specificity may require evaluation under GDPR Article 46 documentation requirements. 3) JURISDICTION FLAGS: EEA and UK users have the highest exposure given GDPR and UK GDPR Chapter V requirements and the active enforcement posture of EU supervisory authorities on US data transfers. Swiss users are separately addressed. South Korean and Brazilian users are subject to distinct transfer restriction regimes under PIPA and LGPD respectively. 4) CONTRACT AND VENDOR IMPLICATIONS: Service provider agreements with entities receiving personal information in third countries should incorporate appropriate transfer mechanisms. Data processing records should document the transfer basis for each recipient country. If Standard Contractual Clauses are the primary transfer mechanism, Transfer Impact Assessments should be maintained for high-risk destination countries. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate: (a) whether documented transfer mechanisms (SCCs, adequacy decisions, or binding corporate rules) are in place for all destination countries; (b) whether Transfer Impact Assessments are current following regulatory developments; (c) whether privacy notices for EEA and UK users sufficiently disclose the specific transfer mechanism as may be required by applicable supervisory authority guidance; and (d) whether the policy's acknowledgment of foreign government access is consistent with the supplementary measures analysis required under Schrems II.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that international data transfers may result in personal information becoming subject to foreign government access obligations, a disclosure that engages GDPR Chapter V transfer requirements and the adequacy determinations and supplementary measures framework established following the Schrems II ruling.
The agreement informs users that their personal information, including health-adjacent diary data, may be transferred to countries with different privacy protections, and that local laws in those countries may permit government or law enforcement access to the transferred data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by MyFitnessPal.