Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that Twilio may derive aggregated, anonymized, or de-identified data from personal data and use it for any purpose, subject to a stated commitment not to attempt re-identification and to share only with parties bound to maintain de-identification.
This analysis describes what Segment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes unrestricted use of data derived from personal data once it has been classified as de-identified or anonymized. The scope of this authorization depends on whether de-identification standards applied by Twilio satisfy the thresholds required under applicable law, which varies by jurisdiction.
Interpretive note: The notice does not specify the technical standard or methodology applied to achieve de-identification, and whether Twilio's practices satisfy the anonymization thresholds required under GDPR, CCPA, or other applicable frameworks cannot be confirmed from the document alone.
The updated policy establishes a new opt-out mechanism allowing users to decline having their data disclosed to third parties (other than service providers) or used for purposes materially different from the original collection purpose. The policy also explicitly discloses that Twilio Inc. is subject to FTC investigatory and enforcement powers, providing users with notice of the regulatory authority overseeing the company's privacy practices. You can exercise this opt-out right by contacting Segment through the mechanism specified in their privacy policy.
View change record →The updated terms establish clearer disclosure of how Segment transfers personal data internationally. Segment now explicitly certifies its compliance with the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. Data Privacy Framework, and states that these DPF Principles take precedence if they conflict with other policy terms. The updated policy also adds specific rights allowing you to opt out of: (i) disclosure of your personal data to third parties other than service providers acting under Segment's instructions, or (ii) use of your personal data for purposes materially different from the original purpose or your subsequent authorization. You can exercise these rights by contacting privacy@twilio.com.
View change record →The agreement establishes that data derived from personal information and classified as de-identified may be used for any purpose without restriction. Under these terms, the practical protection afforded by this commitment depends on the robustness of de-identification standards applied and on the legal and technical obligations imposed on third-party recipients.
Cross-platform context
See how other platforms handle Aggregated and De-Identified Data Unrestricted Use and similar clauses.
Compare across platforms →Monitoring
Segment has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may derive aggregated, anonymized, or de-identified data from your personal data. Because this data does not identify you, it is not considered personal data under the law. We may use this data for any purpose. We commit to never attempting to re-identify this information, and we will only share it with third parties who are legally or technically bound to keep it de-identified.Excerpt from Segment's Privacy Policy
1) REGULATORY LANDSCAPE: GDPR does not apply to truly anonymous data but requires that anonymization be irreversible; the standard for anonymization under GDPR has been interpreted rigorously by data protection authorities. CCPA and CPRA define deidentified data and impose specific technical and organizational safeguards and contractual obligations on recipients. The FTC has issued guidance on de-identification standards. Whether Twilio's de-identification practices satisfy these varying standards is not specified in the notice. 2) GOVERNANCE EXPOSURE: Medium. The notice asserts that de-identified data is not personal data and may be used for any purpose, which is a common industry position but is subject to regulatory scrutiny regarding the adequacy of de-identification methodology. The commitment to bind third-party recipients contractually or technically provides a stated safeguard but does not specify the standard applied. 3) JURISDICTION FLAGS: EU and UK regulators have applied rigorous standards to anonymization claims and have found that data described as anonymous may remain subject to GDPR where re-identification risk is non-trivial. California's CPRA imposes specific deidentification requirements and business process obligations. Organizations in jurisdictions with strict anonymization standards should assess whether Twilio's practices meet the applicable threshold. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should evaluate whether their DPAs address the scope of permissible use for de-identified data derived from their customers' communications content. The unrestricted use claim for de-identified data may not align with enterprise customers' own contractual obligations to end users or with sectoral regulations in healthcare or financial services contexts. 5) COMPLIANCE CONSIDERATIONS: Legal teams should review the specific de-identification methodologies Twilio applies and assess whether they satisfy applicable standards under GDPR, CCPA, and any relevant sectoral regulations. Contract review should confirm whether enterprise DPAs impose additional limits on Twilio's use of de-identified data derived from customer content.
This provision authorizes unrestricted use of data derived from personal data once it has been classified as de-identified or anonymized. The scope of this authorization depends on whether de-identification standards applied by Twilio satisfy the thresholds required under applicable law, which varies by jurisdiction.
The agreement establishes that data derived from personal information and classified as de-identified may be used for any purpose without restriction. Under these terms, the practical protection afforded by this commitment depends on the robustness of de-identification standards applied and on the legal and technical obligations imposed on third-party recipients.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Segment.