Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal information will be transferred to and processed in the Republic of Korea, and acknowledges that data protection laws in recipient countries may not be as comprehensive as those in the user's country of residence. For EEA, UK, and Swiss residents, the policy states it relies on standard contractual clauses and adequacy determinations for transfers to the Republic of Korea.
This analysis describes what Samsung's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The explicit identification of the Republic of Korea as a primary destination for personal information transfers is a specific and material disclosure for users in jurisdictions with transfer restrictions, including EEA and UK residents subject to GDPR and UK GDPR. The policy's reliance on adequacy determinations for the Republic of Korea reflects the EU-Korea adequacy decision but may require ongoing monitoring given the evolving regulatory landscape for international transfers.
The updated policy expands Samsung's data collection authority to include device registration, verification for repairs, and configuration of device settings. The terms now explicitly state that Samsung may collect card and transaction information if you apply for a Samsung-branded payment card. Samsung clarified that it will only send personalized marketing when you have provided consent, where required by law. The policy removed its previous statement that defective devices are wiped of personal information before analysis; the updated terms now state Samsung will analyze returned defective devices without that explicit pre-analysis data deletion commitment. For US residents, the policy now discloses rights to opt out of sale of personal information, sharing for cross-context behavioral advertising, targeted advertising processing, sensitive data collection or processing, and to request lists of third parties receiving your information.
View change record →The agreement establishes that personal information collected through Samsung services will be transferred to and processed in the Republic of Korea, with the policy acknowledging that local data protection laws may differ from those in the user's home country. EEA, UK, and Swiss residents are told that standard contractual clauses and adequacy determinations apply to protect their data in transit.
Cross-platform context
See how other platforms handle International Data Transfer to Republic of Korea and similar clauses.
Compare across platforms →Monitoring
Samsung has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Your use of our Services will involve the transfer, storage, and processing of your personal information within and outside of your country of residence where necessary. In particular, your personal information will be transferred to the Republic of Korea. Please note that the data protection laws and other laws of countries to which your information may be transferred might not be as comprehensive as those in your country. We take appropriate measures, in compliance with applicable law, to ensure that your personal information remains protected. For European Economic Area (EEA), UK and Swiss residents only We will comply with applicable European data protection law when transferring your personal information outside of Europe. We may transfer your personal information to countries which have been found to provide adequate protection of personal information by the relevant data protection authority, including the Republic of Korea.Excerpt from Samsung's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Chapter V restrictions on international personal data transfers and requires a valid transfer mechanism such as an adequacy decision or standard contractual clauses. The European Commission has adopted an adequacy decision regarding the Republic of Korea's commercial data protection framework, which the policy references. UK GDPR imposes comparable transfer requirements following Brexit. For US residents, federal and state privacy laws do not impose comparable international transfer restrictions, but the disclosure is operationally relevant for risk assessment. 2. GOVERNANCE EXPOSURE: Medium. The reliance on adequacy decisions for transfers to the Republic of Korea provides a recognized legal basis under GDPR, but adequacy decisions are subject to periodic review and potential suspension. The policy's statement that it also relies on standard contractual clauses as a fallback provides an additional transfer mechanism, but the contractual clauses themselves must comply with current supervisory authority requirements, including transfer impact assessments where required. 3. JURISDICTION FLAGS: EEA member states and the UK create the highest exposure for international transfer compliance. Switzerland has its own transfer framework under the Federal Act on Data Protection. US residents are not subject to international transfer restrictions under federal law, but enterprise customers in regulated industries (financial services, healthcare) may have contractual or regulatory obligations regarding offshore data processing. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers subject to GDPR or UK GDPR who use Samsung services should evaluate whether Samsung's transfer mechanisms satisfy their own data processing agreement requirements and whether transfer impact assessments are required. The policy's offer to provide copies of standard contractual clauses upon request (via the Contact Us section) facilitates due diligence for B2B customers. 5. COMPLIANCE CONSIDERATIONS: Compliance teams in EEA and UK jurisdictions should monitor the status of the EU adequacy decision for the Republic of Korea and assess whether Samsung's standard contractual clauses have been updated to reflect current supervisory authority requirements. Data mapping should reflect the Republic of Korea as a processing destination. Organizations subject to GDPR Article 28 should review their data processing agreements with Samsung to confirm alignment with transfer mechanism disclosures in the policy.
The explicit identification of the Republic of Korea as a primary destination for personal information transfers is a specific and material disclosure for users in jurisdictions with transfer restrictions, including EEA and UK residents subject to GDPR and UK GDPR. The policy's reliance on adequacy determinations for the Republic of Korea reflects the EU-Korea adequacy decision but may require ongoing …
The agreement establishes that personal information collected through Samsung services will be transferred to and processed in the Republic of Korea, with the policy acknowledging that local data protection laws may differ from those in the user's home country. EEA, UK, and Swiss residents are told that standard contractual clauses and adequacy determinations apply to protect their data in transit.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Samsung.