Synthesia · Synthesia Privacy Policy · View original document ↗

Data Sharing in Business Transfer Events

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Synthesia changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Synthesia recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Synthesia Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that personal data including contact information, financial data, usage data, technical data, and potentially biometric data may be transferred to third parties in the event of a merger, acquisition, asset sale, bankruptcy, or insolvency, including during pre-transaction due diligence.

This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision reserves the right to transfer personal data including biometric data to acquiring entities or parties involved in due diligence prior to any transaction closing, which may occur before users are notified of the transfer. The inclusion of biometric data in potentially transferable assets creates heightened compliance considerations under BIPA and GDPR Article 9.

Interpretive note: Whether biometric data is included in transferable assets is not explicitly confirmed but is inferable from the broad 'some or all of our assets' language; applicability of BIPA to business transfers lacks definitive judicial resolution in all contexts.

Consumer impact (what this means for users)

Under this clause, the agreement states that personal data may be shared with third parties during due diligence or transferred to a new entity in connection with a merger, acquisition, or similar transaction. The policy does not specify a user notification mechanism before or after such transfers occur.

Cross-platform context

See how other platforms handle Data Sharing in Business Transfer Events and similar clauses.

Compare across platforms →

Monitoring

Synthesia has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Other entities as part of a business transfer - if Synthesia undertakes or is involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer, or share some or all of our assets, including your personal data, in connection with such transaction or in contemplation of such transaction, such as due diligence.

Excerpt from Synthesia's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Article 6 lawful basis requirements for data transfers and Article 9 for biometric data specifically. The FTC has previously scrutinized business transfer data sharing provisions for consistency with original consent purposes. UK GDPR contains equivalent requirements. BIPA does not include a carve-out for business transfers, meaning biometric data transferred in a corporate transaction may require renewed consent from data subjects in Illinois. 2. GOVERNANCE EXPOSURE: Medium. The inclusion of personal data including potentially biometric data as transferable assets in business transactions is a standard provision but creates specific compliance exposure for biometric data under BIPA, which does not recognize business transfer exceptions to its consent and prohibition-on-profit requirements. Enterprise customers should assess whether their DPAs address change-of-control scenarios. 3. JURISDICTION FLAGS: Illinois creates the highest exposure given BIPA's treatment of biometric data in commercial transactions. EU and UK users may have rights to be informed of controller changes under GDPR. California users may have rights regarding transfers of personal information under CCPA. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should assess whether their agreements with Synthesia include change-of-control provisions that protect Customer Data in acquisition scenarios. DPAs should address the treatment of Customer Data and biometric data in business transfer events, including whether customer instructions must be honored by a successor entity. 5. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the business transfer provision is consistent with the original consent purposes under which biometric data was collected. BIPA compliance teams should evaluate whether a corporate transaction involving Synthesia would trigger re-consent obligations for Illinois users. GDPR teams should assess whether data subjects would need to be notified of a controller change under Article 13 or 14.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has oversight authority over data transfers in business transactions and has previously examined whether such transfers are consistent with original consumer consent.
    File a complaint →
  • State AG
    State attorneys general in Illinois and other biometric-law states may have enforcement authority over biometric data transfers in corporate transactions under applicable state law.
    File a complaint →

Provision details

Document information
Document
Synthesia Privacy Policy
Entity
Synthesia
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015748
Document ID
CA-D-00470
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c48a575e2d96eda30f9d795d55b7e461edba6b3a934c98d2b8aa22e3fc6ec27f
Analysis generated
July 9, 2026 08:42 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Synthesia
Document: Synthesia Privacy Policy
Record ID: CA-P-015748
Captured: 2026-07-09 08:42:29 UTC
SHA-256: c48a575e2d96eda3…
URL: https://conductatlas.com/platform/synthesia/synthesia-privacy-policy/provision/CA-P-015748/data-sharing-in-business-transfer-events/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Synthesia's Data Sharing in Business Transfer Events clause do?

This provision reserves the right to transfer personal data including biometric data to acquiring entities or parties involved in due diligence prior to any transaction closing, which may occur before users are notified of the transfer. The inclusion of biometric data in potentially transferable assets creates heightened compliance considerations under BIPA and GDPR Article 9.

How does this clause affect you?

Under this clause, the agreement states that personal data may be shared with third parties during due diligence or transferred to a new entity in connection with a merger, acquisition, or similar transaction. The policy does not specify a user notification mechanism before or after such transfers occur.

Is ConductAtlas affiliated with Synthesia?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.