Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Snowflake publishes a Data Processing Addendum, a Transfer Mechanism document, and a DPIA Fact Sheet as part of its legal framework, indicating that cross-border personal data transfers and GDPR-compliant processing obligations are addressed through separate operative documents.
This analysis describes what Snowflake's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Snowflake's GDPR-related data processing obligations, including the legal basis for cross-border data transfers, are governed by a separate Data Processing Addendum and Transfer Mechanism document. EU and UK customers must obtain and review these documents to confirm that their use of Snowflake satisfies GDPR Chapter V transfer requirements.
Interpretive note: The operative terms of the DPA and Transfer Mechanism are not disclosed on this index page; assessment requires review of the full linked documents.
The updated Privacy Notice no longer includes explicit language stating that users 'may unsubscribe through unsubscribe links at any time.' This removal means the document no longer contains that specific commitment to unsubscribe availability. The updated terms still reference a Privacy Notice governing data processing and retain cookie-related disclosures, but the removal of the unsubscribe guarantee eliminates a documented mechanism users may have relied on. You can review the full Privacy Notice to understand current communication and preference management options.
View change record →EU and UK customers processing personal data through Snowflake are subject to the terms of the Data Processing Addendum and Transfer Mechanism in addition to the base Terms of Service. The DPIA Fact Sheet is available to assist customers in conducting their own data protection impact assessments as required under GDPR Article 35.
Cross-platform context
See how other platforms handle Data Processing Addendum and GDPR Transfer Mechanism and similar clauses.
Compare across platforms →Monitoring
Snowflake has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Data Processing Addendum ... Transfer Mechanism ... Data Protection Impact Assessment (DPIA) Fact SheetExcerpt from Snowflake's Privacy Notice
1. REGULATORY LANDSCAPE: The Data Processing Addendum and Transfer Mechanism directly engage GDPR, including Articles 28 (processor obligations), 32 (security of processing), and Chapter V (cross-border transfer restrictions). The DPIA Fact Sheet engages GDPR Article 35. Enforcement authorities include EU member state data protection authorities and the UK Information Commissioner's Office. The existence of a Snowflake Data Privacy Framework Notice also indicates engagement with the EU-U.S. Data Privacy Framework as a transfer mechanism. 2. GOVERNANCE EXPOSURE: High for EU and UK customers. The operative content of the DPA and Transfer Mechanism is not disclosed on this index page, requiring customers to obtain and review the full documents. The DPA must satisfy GDPR Article 28 requirements to constitute a valid processor agreement. If the DPA or Transfer Mechanism is deficient, EU and UK customers may face regulatory exposure for unlawful data transfers or inadequate processor agreements. 3. JURISDICTION FLAGS: EU member states and the UK create the highest exposure under this provision. Organizations subject to Swiss data protection law should also confirm the applicability of the Transfer Mechanism to Swiss-origin data. The Data Privacy Framework Notice indicates that Snowflake may rely on the EU-U.S. Data Privacy Framework for some transfers, which has a distinct legal basis from Standard Contractual Clauses. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should obtain the full DPA and Transfer Mechanism documents and confirm they satisfy the requirements of applicable data protection law. The DPA should specify the subject matter, duration, nature, and purpose of processing; the type of personal data; and the categories of data subjects, as required under GDPR Article 28(3). Organizations should also review the Sub-Processors list in conjunction with the DPA to assess sub-processor management obligations. 5. COMPLIANCE CONSIDERATIONS: EU and UK organizations should confirm that a fully executed DPA is in place with Snowflake covering all applicable processing activities. The DPIA Fact Sheet should be obtained and reviewed as part of any internal DPIA process for high-risk processing activities. Organizations using the EU-U.S. Data Privacy Framework as a transfer mechanism should monitor any changes to that framework's adequacy status.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that Snowflake's GDPR-related data processing obligations, including the legal basis for cross-border data transfers, are governed by a separate Data Processing Addendum and Transfer Mechanism document. EU and UK customers must obtain and review these documents to confirm that their use of Snowflake satisfies GDPR Chapter V transfer requirements.
EU and UK customers processing personal data through Snowflake are subject to the terms of the Data Processing Addendum and Transfer Mechanism in addition to the base Terms of Service. The DPIA Fact Sheet is available to assist customers in conducting their own data protection impact assessments as required under GDPR Article 35.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Snowflake.