Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that personal data including contact information, financial data, usage data, technical data, and potentially biometric data may be transferred to third parties in the event of a merger, acquisition, asset sale, bankruptcy, or insolvency, including during pre-transaction due diligence.
This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision reserves the right to transfer personal data including biometric data to acquiring entities or parties involved in due diligence prior to any transaction closing, which may occur before users are notified of the transfer. The inclusion of biometric data in potentially transferable assets creates heightened compliance considerations under BIPA and GDPR Article 9.
Interpretive note: Whether biometric data is included in transferable assets is not explicitly confirmed but is inferable from the broad 'some or all of our assets' language; applicability of BIPA to business transfers lacks definitive judicial resolution in all contexts.
Under this clause, the agreement states that personal data may be shared with third parties during due diligence or transferred to a new entity in connection with a merger, acquisition, or similar transaction. The policy does not specify a user notification mechanism before or after such transfers occur.
Cross-platform context
See how other platforms handle Data Sharing in Business Transfer Events and similar clauses.
Compare across platforms →Monitoring
Synthesia has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Other entities as part of a business transfer - if Synthesia undertakes or is involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer, or share some or all of our assets, including your personal data, in connection with such transaction or in contemplation of such transaction, such as due diligence.Excerpt from Synthesia's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR Article 6 lawful basis requirements for data transfers and Article 9 for biometric data specifically. The FTC has previously scrutinized business transfer data sharing provisions for consistency with original consent purposes. UK GDPR contains equivalent requirements. BIPA does not include a carve-out for business transfers, meaning biometric data transferred in a corporate transaction may require renewed consent from data subjects in Illinois. 2. GOVERNANCE EXPOSURE: Medium. The inclusion of personal data including potentially biometric data as transferable assets in business transactions is a standard provision but creates specific compliance exposure for biometric data under BIPA, which does not recognize business transfer exceptions to its consent and prohibition-on-profit requirements. Enterprise customers should assess whether their DPAs address change-of-control scenarios. 3. JURISDICTION FLAGS: Illinois creates the highest exposure given BIPA's treatment of biometric data in commercial transactions. EU and UK users may have rights to be informed of controller changes under GDPR. California users may have rights regarding transfers of personal information under CCPA. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should assess whether their agreements with Synthesia include change-of-control provisions that protect Customer Data in acquisition scenarios. DPAs should address the treatment of Customer Data and biometric data in business transfer events, including whether customer instructions must be honored by a successor entity. 5. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the business transfer provision is consistent with the original consent purposes under which biometric data was collected. BIPA compliance teams should evaluate whether a corporate transaction involving Synthesia would trigger re-consent obligations for Illinois users. GDPR teams should assess whether data subjects would need to be notified of a controller change under Article 13 or 14.
This provision reserves the right to transfer personal data including biometric data to acquiring entities or parties involved in due diligence prior to any transaction closing, which may occur before users are notified of the transfer. The inclusion of biometric data in potentially transferable assets creates heightened compliance considerations under BIPA and GDPR Article 9.
Under this clause, the agreement states that personal data may be shared with third parties during due diligence or transferred to a new entity in connection with a merger, acquisition, or similar transaction. The policy does not specify a user notification mechanism before or after such transfers occur.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.