Provision record
Samsung · Samsung Privacy Policy · View original document ↗

Cross-Border Data Transfer

Medium severity Medium confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track Samsung and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy discloses that personal information may be transferred and processed in countries outside the user's country of residence and states that Samsung has implemented safeguards to maintain protection consistent with its privacy policy.

ⓘ

This analysis describes what Samsung's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision addresses cross-border data transfers, which engage GDPR adequacy and standard contractual clause requirements for EU/EEA users and analogous frameworks in other jurisdictions. The policy asserts that appropriate safeguards are in place but does not specify the legal transfer mechanisms used.

⚠

Interpretive note: The policy does not specify the legal transfer mechanisms used for cross-border transfers, creating uncertainty for institutional users seeking to verify GDPR or other jurisdictional compliance.

Recent Activity

This document changed recently

Medium Jul 22, 2026

The updated policy expands Samsung's data collection authority to include device registration, verification for repairs, and configuration of device settings. The terms now explicitly state that Samsung may collect card and transaction information if you apply for a Samsung-branded payment card. Samsung clarified that it will only send personalized marketing when you have provided consent, where required by law. The policy removed its previous statement that defective devices are wiped of personal information before analysis; the updated terms now state Samsung will analyze returned defective devices without that explicit pre-analysis data deletion commitment. For US residents, the policy now discloses rights to opt out of sale of personal information, sharing for cross-context behavioral advertising, targeted advertising processing, sensitive data collection or processing, and to request lists of third parties receiving your information.

View change record →

Consumer impact (what this means for users)

This provision establishes that Samsung may transfer personal data internationally and states that safeguards are in place to maintain protection. Users in the EU/EEA and other jurisdictions with cross-border transfer restrictions operate under these transfer mechanisms when using Samsung services.

How other platforms handle this

Square Medium

to request that your data be transferred to a third party (data portability)

Google Cloud Medium

Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.

Roblox Medium

Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
Your personal information may be transferred to, and processed in, countries other than the country in which you reside. These countries may have data protection laws that are different from the laws of your country. We have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Policy.

Excerpt from Samsung's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: GDPR Articles 44-49 govern cross-border data transfers from the EU/EEA, requiring adequacy decisions, standard contractual clauses (SCCs), or other approved mechanisms.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Samsung Privacy Policy
Entity
Samsung
Document last updated
May 5, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-013012
Document ID
CA-D-00571
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
725625358ee9042eab2ca26d512e59bc2e112bd4e4334d518abda2c6489e1b01
Analysis generated
May 21, 2026 03:56 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Samsung
Document: Samsung Privacy Policy
Record ID: CA-P-013012
Captured: 2026-05-21 03:56:36 UTC
SHA-256: 725625358ee9042e…
URL: https://conductatlas.com/platform/samsung/samsung-privacy-policy/provision/CA-P-013012/cross-border-data-transfer/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Samsung's Cross-Border Data Transfer clause do?

This provision addresses cross-border data transfers, which engage GDPR adequacy and standard contractual clause requirements for EU/EEA users and analogous frameworks in other jurisdictions. The policy asserts that appropriate safeguards are in place but does not specify the legal transfer mechanisms used.

How does this clause affect you?

This provision establishes that Samsung may transfer personal data internationally and states that safeguards are in place to maintain protection. Users in the EU/EEA and other jurisdictions with cross-border transfer restrictions operate under these transfer mechanisms when using Samsung services.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with Samsung?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Samsung.