Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The statement discloses that personal data transferred out of the EEA, UK, or Switzerland to non-adequate countries is protected using Standard Contractual Clauses approved by the European Commission, UK Secretary of State, or UK ICO.
This analysis describes what Palantir's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal mechanism Palantir relies upon for cross-border data transfers from the EEA, UK, and Switzerland to the United States and other third countries. Individuals may request additional information about applicable transfer safeguards by exercising their data access rights.
The updated Privacy Statement now authorizes Palantir to disclose personal data to promotional code partners who may then contact you if you sign up for a Palantir service using their code. This establishes a new third-party contact pathway not previously disclosed in the policy. The terms do not specify how frequently partners may contact you, what data is included in the disclosure, or whether you can opt out of partner contact after signing up.
View change record →Under this provision, personal data transferred from the EEA, UK, or Switzerland to the US or other countries is subject to Standard Contractual Clauses as the primary transfer safeguard. Individuals may request information about specific transfer mechanisms by contacting privacy@palantir.com.
Cross-platform context
See how other platforms handle Standard Contractual Clauses for International Data Transfers and similar clauses.
Compare across platforms →Monitoring
Palantir has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If your personal data is transferred out of the EEA, UK or Switzerland, your personal data may be transferred to the United States or other countries worldwide. If your personal data is transferred to a country or organization that is not subject to an adequacy decision by the European Commission or (where relevant) the UK Secretary of State, we will put in place suitable safeguards to ensure that any transfer is carried out in compliance with applicable data protection rules. To ensure an adequate level of protection for your personal data, we will use a data transfer agreement with the recipient based on Standard Contractual Clauses approved by the European Commission, the UK Secretary of State, or the UK Information Commissioner's Office (as applicable) under the UK GDPR and the EU GDPR (as applicable).Excerpt from Palantir's Privacy Statement
1. REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V requirements for international data transfers and the equivalent UK GDPR provisions. The use of Standard Contractual Clauses is a recognized transfer mechanism, but organizations must also conduct transfer impact assessments where required by the Schrems II framework. The UK ICO's International Data Transfer Agreement (IDTA) regime is separately referenced. Swiss data protection law requirements are also noted. 2. GOVERNANCE EXPOSURE: Medium. SCCs are a widely used transfer mechanism, but their adequacy depends on transfer impact assessments and supplementary measures where the destination country's legal framework may not provide equivalent protection to EU standards. The adequacy of transfers to the United States may be evaluated in the context of the EU-US Data Privacy Framework where applicable. 3. JURISDICTION FLAGS: EEA member states, the UK, and Switzerland create the primary exposure. Transfer impact assessment requirements apply to EEA and UK transfers where SCCs are relied upon. Swiss nFADP requirements apply to transfers from Switzerland. 4. CONTRACT AND VENDOR IMPLICATIONS: B2B customers contracting with Palantir entities in the EEA or UK should confirm whether data processing agreements incorporate appropriate SCCs or IDTA provisions and that transfer impact assessments have been conducted where required. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether transfer impact assessments are documented for transfers to the United States, whether supplementary measures are in place where required, and whether the applicable SCC version (2021 EU SCCs or UK IDTA) is correctly applied to each transfer relationship.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the legal mechanism Palantir relies upon for cross-border data transfers from the EEA, UK, and Switzerland to the United States and other third countries. Individuals may request additional information about applicable transfer safeguards by exercising their data access rights.
Under this provision, personal data transferred from the EEA, UK, or Switzerland to the US or other countries is subject to Standard Contractual Clauses as the primary transfer safeguard. Individuals may request information about specific transfer mechanisms by contacting privacy@palantir.com.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Palantir.