110 Total
47 High severity
54 Medium severity
9 Low severity

Key Facts

What risk does Thomson Reuters require users to acknowledge?
Thomson Reuters requires users to acknowledge the risk that their personal information may be transferred to countries that provide less privacy protection than their home country.
What does Thomson Reuters use personal information to do?
Thomson Reuters uses personal information to annotate, tag, and add metadata to its content, including naming or tagging individuals in its news content.
What does Thomson Reuters do with biometric data it maintains?
Thomson Reuters takes steps to permanently destroy biometric data it maintains within the timeframe specified by applicable law or when it is no longer necessary for the purpose for which it was collected.
When does Thomson Reuters permanently destroy biometric data it maintains?
Thomson Reuters takes steps to permanently destroy biometric data it maintains within the timeframe specified by applicable law or when it is no longer necessary for the purpose for which it was collected.
What does Thomson Reuters deem Chinese residents to have consented to?
Thomson Reuters deems Chinese residents to have consented to the collection and processing of their sensitive personal information by interacting with Thomson Reuters.
How does Thomson Reuters deem Chinese residents to have consented to the collection and processing of their sensitive personal information?
Thomson Reuters deems Chinese residents to have consented to the collection and processing of their sensitive personal information by interacting with Thomson Reuters.
From whom may Thomson Reuters receive personal information about users?
Thomson Reuters may receive personal information about users from third parties, including data brokers and advertising partners.
What biometric data does Thomson Reuters collect?
Thomson Reuters collects biometric data, including fingerprints, scans of face geometry, and other data generated by automatic measurements of an individual's physiological, biological, or behavioral characteristics.
What personal information does Thomson Reuters collect?
Thomson Reuters collects personal information contained in content and communications uploaded, sent, shared, or inputted through its Services, including the content of artificial intelligence prompts.
What does Thomson Reuters require users to authorize?
Thomson Reuters requires users to authorize the transfer of their personal information outside their home country by interacting with Thomson Reuters.
Stay ahead of the changes
Track Thomson Reuters and get the diff the day its terms change.
Summary

This document explains how Thomson Reuters collects, uses, and shares your personal information. It collects a wide range of data — including biometrics and the content of your AI prompts — and may use it to send you personalized advertising or share it with third parties in ways that some laws treat as a sale of your data. By simply using Thomson Reuters services, you are treated as having authorized international data transfers and, if you are a Chinese resident, as having consented to the processing of your sensitive personal information.

Analysis

This document establishes Thomson Reuters's collection, use, sharing, and retention practices for personal information across its services. Thomson Reuters collects a broad range of personal data — including biometric data, AI prompt content, and third-party-sourced data from data brokers and advertising partners — and uses it for purposes including content annotation, interest-based advertising, and service provision to third parties that may constitute a sale under applicable privacy laws. Cross-border transfers and deemed consent for sensitive data collection are structured through interaction-based authorization rather than separate affirmative consent. Thomson Reuters retains the right to update its Privacy Statement at any time for any reason, and commits to JAMS arbitration for unresolved complaints arising under the EU-U.S. Data Privacy Framework.

What this means for you

Using Thomson Reuters services means your personal information — including biometric data, AI prompt content, and data obtained about you from data brokers — is collected and may be used to tag published news content, target you with interest-based advertising, and shared with third parties in ways that may qualify as a sale of your personal information under some local privacy laws. Cross-border transfers and, for Chinese residents, processing of sensitive personal information are authorized through the act of interaction itself rather than through a separate consent step. Users in jurisdictions where third-party sharing qualifies as a sale may have a right to opt out of that sale under applicable local law.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

8 important changes detected

14 versions captured · Last updated: July 2026

What changed Thomson Reuters modified two sentences in its privacy policy header detected on July 21, 2026. The opening tagline changed from 'Our technology powers the professionals who are shaping the world' to 'Trusted AI built on 175 years of Thomson Reuters knowledge,' and a section heading changed from 'Meet the changemakers' to 'Meet The CoCo.' These are editorial and branding updates to the document's introductory language with no material changes to data governance, privacy rights, or operational obligations.
Why this matters This change modifies only the introductory messaging and branding language in the privacy policy header. The updated terms do not alter data collection practices, privacy rights, retention policies, or data sharing obligations. The policy continues to apply as previously written, with only the marketing and section naming language updated.
View full change record →
What changed Thomson Reuters modified marketing and promotional language in their privacy policy, replacing sections about expert human intelligence and professional insights with messaging about changemakers and empowerment. Two sentences were added describing customer success stories and upcoming events. These are editorial and marketing text updates with no material change to Thomson Reuters' data collection, processing, or privacy practices.
Why this matters The updated privacy policy includes revised marketing and promotional language describing Thomson Reuters products and services. These changes are editorial in nature and do not modify Thomson Reuters' data collection, retention, processing, or sharing practices. No action is required from users.
View full change record →

July 14, 2026 low

Thomson Reuters reorganized the structure and labeling of its insights content hub in an update detected on July 14, 2026. Previously, the policy described separate 'Legal insights' and 'Tax insights' …

View change record →
June 26, 2026 low

Thomson Reuters updated a section of their privacy policy on June 26, 2026 that was previously directed at tax, audit, and accounting firms. The revised language now specifically references 'CoCounsel …

View change record →
June 13, 2026 low

Thomson Reuters updated its privacy policy on June 13, 2026 by adding two practice areas to its navigation menu (Labor & employment and Mergers & acquisitions law) and correcting a …

View change record →
June 10, 2026 low

Thomson Reuters removed a single sentence from its privacy policy navigation or marketing section on June 10, 2026. The deleted text referenced 'Labor & employment law' within a navigation menu …

View change record →
June 5, 2026 low

Thomson Reuters made three minor navigation and content organization updates to their privacy policy website on June 5, 2026. The changes reorganized product category listings and added 'Labor & employment …

View change record →
May 29, 2026 low

Thomson Reuters updated its privacy policy landing page on May 29, 2026, making three editorial and organizational changes: adding a new marketing tagline ('Our technology powers the professionals who are …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

110 provisions
12 featured
14 clause types
47 high severity
Data Collection 26 14 high
Show all 26 data collection provisions
Privacy Rights 24 4 high
Show all 24 privacy rights provisions
AI / Automated Decision-Making 1 1 high
Stay ahead of the changes

Monitoring

Thomson Reuters has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Acknowledgment of risk from transfers to less-protective countries and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 11, 2026 01:22 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000720
Version ID CA-V-005697
SHA-256 fefe2326eda6411ef6628e51126b840f090cc6df10ad441e1d563f330449ff23
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans