Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision states that customers using Regional Twilio may select Ireland or Australia for data storage and processing, but that this regional restriction is subject to an exception permitting US processing when Twilio investigates fraud or abuse. Non-content account and usage data continues to be processed in the United States regardless of regional selection.
This analysis describes what Segment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that the regional data residency guarantee is conditional, with an explicit carve-out for fraud and abuse investigations that routes data to US processing without specifying procedural safeguards, notification requirements, or limits on scope. Customers with strict data residency obligations under sector-specific regulations or contractual commitments should assess whether this exception is compatible with those requirements.
Interpretive note: The document does not specify which transfer mechanism applies during US processing under the fraud exception, leaving the GDPR Chapter V compliance basis for those transfers unclear.
Under this clause, customers who select regional processing in Ireland or Australia may have their Customer Content processed in the United States if Twilio determines that a fraud or abuse investigation requires it. Additionally, the document states that account and usage data (outside of Customer Content) is processed in the United States regardless of the regional setting selected.
Cross-platform context
See how other platforms handle Regional Processing Exception for Fraud and Abuse Investigations and similar clauses.
Compare across platforms →Monitoring
Segment has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"* If using Regional Twilio for supported products, Customer Content is stored and processed in the region selected (Ireland or Australia). Exceptions will occur as necessary to investigate issues of fraud and abuse. At this time, all other data relating to your account and use of the Twilio Services will continue to be processed in the United States to allow Twilio to continue to provide and improve our Services to you.Excerpt from Segment's Sub-Processors
1) REGULATORY LANDSCAPE: This provision may require evaluation under GDPR Chapter V, as processing EU personal data in the United States requires an adequate transfer mechanism; the fraud exception does not specify which transfer mechanism applies in those circumstances. Sector-specific data localization requirements (e.g. financial services regulations in certain EU member states, or healthcare data requirements) may create additional constraints. The Irish DPC is the lead supervisory authority for Twilio Ireland Ltd. 2) GOVERNANCE EXPOSURE: High. The exception is broadly defined as necessary to investigate issues of fraud and abuse without specifying procedural safeguards, customer notification obligations, scope limitations, or the transfer mechanisms applied during such investigations. This ambiguity creates compliance exposure for customers with binding data residency or transfer restrictions. 3) JURISDICTION FLAGS: EU and EEA customers face the highest exposure due to GDPR Chapter V requirements for third-country transfers. UK customers face equivalent risks under UK GDPR. Financial services customers in the EU subject to EBA or ECB data localization guidance and healthcare customers subject to sector-specific residency requirements should conduct heightened review. Australian customers selecting the Australia region should also assess whether the fraud exception is compatible with Australian Privacy Act obligations. 4) CONTRACT AND VENDOR IMPLICATIONS: Customers whose DPAs or master service agreements with Twilio include data residency commitments should determine whether the fraud and abuse exception is incorporated into those agreements and whether it overrides contractual residency guarantees. Legal teams should assess whether this exception requires a separate transfer mechanism disclosure or addendum. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should document this exception in their records of processing activities and assess whether it requires disclosure in their own privacy notices or data processing records. Where organizational policy or regulatory obligation prohibits US processing of specific data categories, teams should evaluate whether Regional Twilio with this exception provides sufficient assurance, and consider requesting contractual clarification from Twilio on the scope and procedural controls governing the exception.
This provision establishes that the regional data residency guarantee is conditional, with an explicit carve-out for fraud and abuse investigations that routes data to US processing without specifying procedural safeguards, notification requirements, or limits on scope. Customers with strict data residency obligations under sector-specific regulations or contractual commitments should assess whether this exception is compatible with those requirements.
Under this clause, customers who select regional processing in Ireland or Australia may have their Customer Content processed in the United States if Twilio determines that a fraud or abuse investigation requires it. Additionally, the document states that account and usage data (outside of Customer Content) is processed in the United States regardless of the regional setting selected.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Segment.