Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Personal Information may be transferred in connection with a merger, acquisition, bankruptcy, or similar transaction, and that users may opt out of such transfer if the successor entity has not committed to maintaining equivalent privacy protections.
This analysis describes what Rumble's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a conditional opt-out right for users whose Personal Information is transferred in a business transaction, conditioned on whether the successor entity has committed to equivalent privacy protections. The policy does not specify the mechanism or timeline for exercising this opt-out right.
Interpretive note: The policy does not specify the mechanism, timeline, or notice procedure for exercising the opt-out right in a business transaction, creating ambiguity about how this right would operate in practice.
The updated policy modifies the language governing notification of Personal Information disclosure. The prior version stated that Rumble 'will attempt to notify you before we disclose your Personal Information,' whereas the revised language states the company 'may attempt to notify you.' This shifts the provision from an asserted commitment to attempt notification toward a discretionary authorization to do so when permitted by law. Under the revised terms, notification attempts are now framed as optional rather than intended.
View change record →Under this clause, Rumble's Personal Information holdings may be transferred to successor entities in a merger, acquisition, or bankruptcy proceeding. The agreement states that users may opt out of this transfer if the successor entity has not committed to privacy protections materially equivalent to this policy, though no specific opt-out mechanism or deadline is described.
Cross-platform context
See how other platforms handle Business Transaction Data Transfer and similar clauses.
Compare across platforms →Monitoring
Rumble has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In the event that Rumble goes through a business transition, such as a corporate divestiture, merger, acquisition, joint venture, bankruptcy, dissolution, reorganization, or any other similar transaction or proceeding, your Personal Information may be sold, divested, assigned, shared, or otherwise transferred in connection with the proposed transaction. You may opt out of the transfer of your Personal Information to the successor entity, if that entity has not committed to comply with this Privacy Policy or a privacy policy that is in all material respects as protective of your Personal Information as this Privacy Policy.Excerpt from Rumble's Privacy Policy
(1) REGULATORY LANDSCAPE: The FTC has historically reviewed data asset transfers in M&A contexts involving consumer data, particularly where privacy commitments made to consumers may be altered post-transaction. CCPA and applicable state privacy laws may impose requirements on how Personal Information is handled in business transitions. GDPR requires that any transfer of personal data to a new data controller be accompanied by appropriate legal basis and notice to data subjects. (2) GOVERNANCE EXPOSURE: Medium. The conditional opt-out right is limited to circumstances where the successor entity has not committed to equivalent privacy protections, meaning users may not have an opt-out right if the successor makes a qualifying commitment. The absence of a specified opt-out mechanism or timeline creates ambiguity about the operationalization of this right. (3) JURISDICTION FLAGS: EU and UK users are subject to GDPR requirements for lawful data controller transfers, which may require notification and potentially a new legal basis depending on the nature of the transaction. California residents may have additional rights under the CCPA with respect to Personal Information transferred in business transactions. (4) CONTRACT AND VENDOR IMPLICATIONS: In M&A due diligence contexts, acquirers should assess whether the successor entity privacy commitment standard described in this policy is satisfied by the acquirer's existing privacy policy. Data asset schedules in transaction documents should reflect the categories of Personal Information subject to this provision. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should establish a process for notifying users and providing an opt-out mechanism in the event of a qualifying business transition. The policy's lack of specificity regarding the opt-out mechanism and timeline means that pre-transaction planning should include defining these operational parameters. GDPR-compliant data transfer mechanisms should be assessed for any cross-border transaction involving EEA/UK user data.
This provision establishes a conditional opt-out right for users whose Personal Information is transferred in a business transaction, conditioned on whether the successor entity has committed to equivalent privacy protections. The policy does not specify the mechanism or timeline for exercising this opt-out right.
Under this clause, Rumble's Personal Information holdings may be transferred to successor entities in a merger, acquisition, or bankruptcy proceeding. The agreement states that users may opt out of this transfer if the successor entity has not committed to privacy protections materially equivalent to this policy, though no specific opt-out mechanism or deadline is described.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Rumble.