Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that contact book data shared with Snapchat is retained until the user explicitly removes it through in-app settings, and that updating device-level permissions alone does not delete previously shared contacts. The policy also states that contact data uploaded by other Snapchatters that includes a user's information may be combined with other data Snap holds about that user.
This analysis describes what Snapchat's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that contact data has a distinct retention mechanism that is decoupled from device-level permission changes, meaning users who revoke contact book permissions at the OS level may not achieve deletion of previously shared contact data without an additional in-app action. The secondary combination of third-party-uploaded contact data with existing user profiles is also authorized, which may affect non-Snapchat users whose information is included in uploaded contact lists.
Under this clause, contact book data previously shared with Snapchat persists until explicitly removed through Snapchat's in-app settings, not through device permission revocation alone. Additionally, contact information uploaded by other users that includes a person's data may be combined with Snap's existing profile data for that individual, including for non-Snapchat users.
Cross-platform context
See how other platforms handle Contact Book Data Collection and Retention and similar clauses.
Compare across platforms →Monitoring
Snapchat has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"if another Snapchatter uploads their contact list which includes your information, we may combine that with other information we have about you to better understand who you may want to communicate with. ... we keep your shared list of contacts until you ask us to remove them in our app settings (note: updating your device permissions may not remove the contacts you've previously shared with Snapchat).Excerpt from Snapchat's Privacy Policy
1) REGULATORY LANDSCAPE: The collection and processing of contact data from non-users whose information is uploaded by third-party Snapchatters implicates GDPR requirements regarding processing of personal data without a direct relationship with the data subject, including transparency obligations. CCPA provisions regarding data collected from third parties and its combination with existing consumer profiles are also relevant. The FTC has examined contact data aggregation practices under unfair or deceptive acts standards. Enforcement authorities include EU data protection authorities, the CPPA, and the FTC. 2) GOVERNANCE EXPOSURE: Medium. The decoupling of device permission revocation from actual data deletion creates a disclosure and user expectation gap that may be assessed under data minimization and purpose limitation standards. The aggregation of third-party-uploaded contact data with existing profiles for people who have no direct relationship with Snap raises transparency questions under GDPR and equivalent frameworks. 3) JURISDICTION FLAGS: EU and EEA users are protected by GDPR rights of access, erasure, and objection, which may apply to contact data held about non-users. California residents may have CCPA rights to know about and delete personal information collected from third parties. The policy's note that device permission updates do not remove previously shared contacts is particularly relevant for users who believe they have withdrawn consent through OS-level settings changes. 4) CONTRACT AND VENDOR IMPLICATIONS: The policy does not specify whether contact data is shared with service providers or partners for purposes beyond friend-finding functionality. Procurement and compliance teams should assess whether contact data retention practices align with data processing agreement obligations where Snapchat is used in organizational contexts. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the in-app disclosure about the decoupling of device permissions from data deletion is sufficiently prominent to satisfy informed consent standards in applicable jurisdictions. A data mapping review should confirm the full processing lifecycle for contact data, including how third-party-uploaded contact data is combined, stored, and eventually deleted. Organizations with employees using Snapchat should consider whether organizational contact information may be uploaded and aggregated through this mechanism.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that contact data has a distinct retention mechanism that is decoupled from device-level permission changes, meaning users who revoke contact book permissions at the OS level may not achieve deletion of previously shared contact data without an additional in-app action. The secondary combination of third-party-uploaded contact data with existing user profiles is also authorized, which may affect …
Under this clause, contact book data previously shared with Snapchat persists until explicitly removed through Snapchat's in-app settings, not through device permission revocation alone. Additionally, contact information uploaded by other users that includes a person's data may be combined with Snap's existing profile data for that individual, including for non-Snapchat users.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Snapchat.