Provision record
StockX · StockX Privacy Policy · View original document ↗

GDPR Rights for EU and UK Users

Medium severity Medium confidence Inferred from context Common · 290 of 352 platforms
Stay ahead of the changes
Track StockX and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Users in the EU and UK have strong legal rights under GDPR to see, correct, delete, or move their personal data, and to object to how StockX uses it.

ⓘ

This analysis describes what StockX's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

GDPR rights are among the strongest data protection entitlements in the world and EU/UK users who exercise them can obtain meaningful visibility into and control over their personal data held by StockX.

⚠

Interpretive note: The complete verbatim GDPR rights language and lawful basis disclosures were not fully visible in the rendered document; the provision is grounded in what would be required under GDPR for a platform of StockX's scale serving EU and UK users, as well as partial policy text visible in the document.

Recent Activity

This document changed recently

Medium Jul 9, 2026

The updated policy authorizes StockX to share and sell personal information to a broader range of recipients than previously disclosed. Specifically, the policy now explicitly permits sharing or selling personal data, including identifiers, transaction data, and browsing behavior, to Live Sellers on the Live Shopping Platform, Sellers on the Listings Marketplace, and third-party data brokers. The prior version limited disclosures to 'sharing' with 'StockX Verified Sellers' without explicit reference to data sales or data brokers. Under the revised terms, data sale and sharing is now standard practice for analytics, advertising, and marketplace partners. The policy does not describe a consumer opt-out mechanism for this data sharing or selling.

View change record →

Consumer impact (what this means for users)

EU and UK users can request access to all personal data StockX holds about them, ask for it to be corrected or deleted, and object to uses such as behavioral advertising, potentially limiting how their data is used across the platform and with advertising partners.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Visit stockx.com/privacy and submit a data subject rights request specifying whether you want to access, correct, delete, or restrict processing of your personal data as an EU or UK user.

How other platforms handle this

Square Medium

You may contact our privacy team with any requests of disclosure, correction, or deletion of your personal information. You may also request suspension of use or suspension of sharing of your personal information with certain third parties.

Google Cloud Medium

Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.

Instacart Medium

By providing your mobile phone number, you consent to receive automated text (SMS) messages from Instacart...To opt out, reply STOP. For help, reply HELP or contact us directly...

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Union or United Kingdom, you have certain rights under applicable data protection law, including the right to access, correct, delete, or restrict processing of your personal data, and the right to data portability. You may also have the right to object to certain processing of your personal data.

Excerpt from StockX's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR (EU Regulation 2016/679) and the UK GDPR as retained post-Brexit.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
StockX Privacy Policy
Entity
StockX
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-009215
Document ID
CA-D-00734
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
1c4ce189cbfb0cf7f1a5d44fbf328c75909fbc4a8da491e50fc4d3f3433a52a3
Analysis generated
May 10, 2026 15:58 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: StockX
Document: StockX Privacy Policy
Record ID: CA-P-009215
Captured: 2026-05-10 15:58:27 UTC
SHA-256: 1c4ce189cbfb0cf7…
URL: https://conductatlas.com/platform/stockx/stockx-privacy-policy/provision/CA-P-009215/gdpr-rights-for-eu-and-uk-users/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does StockX's GDPR Rights for EU and UK Users clause do?

GDPR rights are among the strongest data protection entitlements in the world and EU/UK users who exercise them can obtain meaningful visibility into and control over their personal data held by StockX.

How does this clause affect you?

EU and UK users can request access to all personal data StockX holds about them, ask for it to be corrected or deleted, and object to uses such as behavioral advertising, potentially limiting how their data is used across the platform and with advertising partners.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with StockX?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by StockX.