Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Samsung shares identifiers and online activity data with advertising services via automated technologies and server-to-server connections, and acknowledges this may constitute a sale of personal information or use for targeted advertising under applicable state privacy laws. Users who have consented may have their personal information shared for personalized ad delivery.
This analysis describes what Samsung's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Samsung's ad data sharing practices may trigger sale or targeted advertising definitions under state privacy laws such as the CCPA and CPRA, requiring Samsung to honor opt-out requests submitted through the designated mechanisms. The use of server-to-server connections alongside automated technologies broadens the scope of third-party data access beyond cookie-based collection.
The updated policy expands Samsung's data collection authority to include device registration, verification for repairs, and configuration of device settings. The terms now explicitly state that Samsung may collect card and transaction information if you apply for a Samsung-branded payment card. Samsung clarified that it will only send personalized marketing when you have provided consent, where required by law. The policy removed its previous statement that defective devices are wiped of personal information before analysis; the updated terms now state Samsung will analyze returned defective devices without that explicit pre-analysis data deletion commitment. For US residents, the policy now discloses rights to opt out of sale of personal information, sharing for cross-context behavioral advertising, targeted advertising processing, sensitive data collection or processing, and to request lists of third parties receiving your information.
View change record →Under this provision, Samsung shares identifiers and online activity data with advertising services through automated technologies and server-to-server connections, and the document acknowledges this sharing may qualify as a sale under applicable state law. Users in applicable states may opt out of this data sharing by submitting a request through the Samsung privacy portal or by enabling a browser opt-out preference signal.
Cross-platform context
See how other platforms handle Ad Data Sharing as Potential Sale or Targeted Advertising and similar clauses.
Compare across platforms →Monitoring
Samsung has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"To serve personalized ads, we may share your personal information (such as identifiers and online activity) by allowing certain third parties (such as online advertising services) to collect your personal information via automated technologies and server-to-server connections on the Services. This kind of sharing may be considered a "sale" of personal information or the use of personal information to serve "targeted advertising" under certain privacy laws. Where you have consented, we may share your personal information to deliver personalized ads.Excerpt from Samsung's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly implicates the California Consumer Privacy Act and California Privacy Rights Act definitions of sale and sharing for cross-context behavioral advertising, as well as analogous definitions in Virginia, Colorado, Connecticut, Texas, and other state comprehensive privacy laws. The FTC has jurisdiction over unfair or deceptive practices in ad data sharing. The provision's reference to server-to-server connections may engage additional regulatory scrutiny where such connections are not captured by standard browser-based opt-out signals. 2. GOVERNANCE EXPOSURE: High. The acknowledgment that sharing may constitute a sale or targeted advertising use under certain laws is a material disclosure that requires operational opt-out mechanisms meeting applicable state law standards. The document states Samsung uses an automated solution to process opt-out signals but notes it does not respond to signals that do not meet applicable state law requirements, which may create gaps for users employing older or non-compliant opt-out technologies. 3. JURISDICTION FLAGS: California creates the highest exposure given the CCPA and CPRA frameworks, particularly for the right to opt out of sale and sharing. Virginia, Colorado, Connecticut, Texas, Montana, and other states with enacted comprehensive privacy laws impose comparable opt-out requirements. The document's statement that it does not respond to browser signals not meeting applicable state law requirements may warrant evaluation in jurisdictions where specific signal standards are mandated. 4. CONTRACT AND VENDOR IMPLICATIONS: The use of server-to-server connections with advertising services may require data processing agreements with each advertising partner. Enterprise customers using Samsung devices should assess whether Samsung's ad data collection on Smart TVs and mobile devices via advertising IDs intersects with internal data governance obligations. The document discloses that Samsung participates in advertising networks that track users across websites and apps, which may implicate vendor assessment obligations for organizations subject to GDPR or applicable state law. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether opt-out mechanisms described in the policy (web form, phone, browser opt-out signal) are technically and operationally compliant with each applicable state law's requirements. Data mapping should reflect server-to-server ad data flows as a distinct category from cookie-based collection. Consent records for personalized ad sharing should be maintained and auditable given the policy's acknowledgment of consent as a basis for some sharing.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that Samsung's ad data sharing practices may trigger sale or targeted advertising definitions under state privacy laws such as the CCPA and CPRA, requiring Samsung to honor opt-out requests submitted through the designated mechanisms. The use of server-to-server connections alongside automated technologies broadens the scope of third-party data access beyond cookie-based collection.
Under this provision, Samsung shares identifiers and online activity data with advertising services through automated technologies and server-to-server connections, and the document acknowledges this sharing may qualify as a sale under applicable state law. Users in applicable states may opt out of this data sharing by submitting a request through the Samsung privacy portal or by enabling a browser opt-out …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Samsung.