9 Total
3 High severity
5 Medium severity
1 Low severity
Summary

This is Thomson Reuters' privacy policy, covering how the company collects and uses your personal information across its legal, tax, news, and risk products, as well as its website. The most significant aspect for most people is that Thomson Reuters may collect a wide range of sensitive personal data, including financial records, government ID numbers, and professional history, and may use that data to build information products sold to third parties, since Thomson Reuters operates as a data broker in addition to being a software and media company. If you are a U.S. resident, you should check whether your state grants you the right to opt out of the sale or sharing of your personal information, and submit a request through Thomson Reuters' privacy rights portal if applicable.

Technical / Legal Breakdown

This document is Thomson Reuters' global Privacy Statement, governing how Thomson Reuters and its worldwide affiliated companies and subsidiaries collect, use, disclose, and retain personal information across their products, services, and websites, with stated legal bases including consent, legitimate interests, contract performance, and legal obligation. The statement asserts that Thomson Reuters collects a broad range of personal data including contact details, financial information, government-issued identifiers, professional and employment data, location data, device and usage data, and sensitive categories such as health, biometric, and political information, and states that this data may be shared with affiliated entities, business partners, third-party service providers, government authorities, and purchasers in corporate transactions. Notably, the statement covers Thomson Reuters' role both as a data controller and as a data processor on behalf of business customers, and explicitly addresses the use of personal data in AI and machine learning model training, which creates distinct exposure in jurisdictions with emerging AI-specific regulation; the statement also discloses that Thomson Reuters operates as a data broker in certain contexts, compiling and selling information products derived from publicly available and licensed data sources. The statement engages GDPR and UK GDPR for EU and UK residents, CCPA and CPRA for California residents, PIPEDA and provincial equivalents for Canadian users, and a range of additional national frameworks; the document includes region-specific supplemental notices and describes cross-border data transfer mechanisms including Standard Contractual Clauses and adequacy decisions. Material compliance considerations include the adequacy of consent mechanisms for sensitive data processing, the lawfulness of AI training data use under GDPR, and the sufficiency of Thomson Reuters' data broker disclosures under state-level U.S. law.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 3 provisions
Medium — 5 provisions
Low — 1 provision

Monitoring

Thomson Reuters has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle AI and Automated Processing Disclosures and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:40 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000720
Version ID CA-V-001349
SHA-256 24cac4e8e78d0e0012d9406c93d767f72f569061cc422ffeee1d2867625b0f37
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans