Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy reserves the right to update the Privacy Statement at any time for any reason, with notification provided solely by updating the 'last updated' date on the posted statement; email reminders may be sent periodically but are not guaranteed.
This analysis describes what Thomson Reuters's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that changes to data handling practices may take effect upon posting without individualized notice to users, placing the responsibility on users to monitor the statement for updates. Under GDPR, material changes to processing purposes or legal bases may require renewed consent or advance notice beyond a date-stamp update, a tension the provision does not address.
Interpretive note: Whether a date-stamp update satisfies GDPR and UK GDPR notification obligations for material processing changes is subject to supervisory authority interpretation and may vary by jurisdiction and the nature of the change.
Under this clause, Thomson Reuters may modify its data handling practices by updating the posted Privacy Statement, with the 'last updated' date as the primary notification mechanism and no guaranteed advance individual notice of material changes.
Cross-platform context
See how other platforms handle Privacy Statement Change Notification and similar clauses.
Compare across platforms →Monitoring
Thomson Reuters has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"This Privacy Statement is expected to change over time. We reserve the right to update it at any time for any reason. We will notify you of changes to our Privacy Statement by updating the 'last updated' date and posting the updated Privacy Statement on this page. We may email periodic reminders of our notices and terms and conditions, but you should check our Services frequently to see the current Privacy Statement and any changes made to it.Excerpt from Thomson Reuters's Privacy
1) REGULATORY LANDSCAPE: GDPR Article 13 and 14 require that individuals be informed of changes to processing purposes or legal bases, and the adequacy of a date-stamp update as the sole notification mechanism may require evaluation under applicable supervisory authority guidance. CCPA/CPRA does not impose specific notice mechanisms for policy changes but requires that the privacy policy accurately reflect current practices. The FTC Act's prohibition on deceptive practices applies if updated practices diverge from prior disclosures without adequate notice. 2) GOVERNANCE EXPOSURE: Low to Medium. The date-stamp change notification mechanism is common across the industry, but for processing changes that materially affect user rights or introduce new data uses, regulators in EU and UK jurisdictions have indicated that more specific notice may be required. 3) JURISDICTION FLAGS: EU and UK supervisory authorities have issued guidance suggesting that material changes to privacy notices require proactive individual notification rather than passive posting. California CPRA requires annual privacy notice review and accurate disclosure of current practices. 4) CONTRACT AND VENDOR IMPLICATIONS: B2B customers whose data processing agreements reference the Thomson Reuters Privacy Statement should include provisions specifying the notification obligations applicable to material policy changes, particularly where those changes affect the legal basis for processing or the categories of data shared with third parties. 5) COMPLIANCE CONSIDERATIONS: Legal teams should establish a monitoring process to track Thomson Reuters Privacy Statement updates, particularly for changes affecting sensitive data categories, cross-border transfer mechanisms, or data sharing arrangements. Where Thomson Reuters processes data as a controller affecting an organization's employees or end users, material policy changes may trigger the organization's own privacy notice update obligations.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that changes to data handling practices may take effect upon posting without individualized notice to users, placing the responsibility on users to monitor the statement for updates. Under GDPR, material changes to processing purposes or legal bases may require renewed consent or advance notice beyond a date-stamp update, a tension the provision does not address.
Under this clause, Thomson Reuters may modify its data handling practices by updating the posted Privacy Statement, with the 'last updated' date as the primary notification mechanism and no guaranteed advance individual notice of material changes.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Thomson Reuters.