Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states four GDPR lawful bases for processing EU user data: consent, contract performance, legal obligation, and legitimate interests. It also enumerates GDPR rights including access, rectification, erasure, objection, restriction, and portability, exercisable by contacting privacy@uniswap.org.
This analysis describes what Uniswap's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the GDPR compliance framework for EU data subjects and invokes legitimate interests as one of four processing bases without specifying the particular processing activities to which each basis applies, which may require evaluation under applicable supervisory authority guidance on documentation of legitimate interests assessments.
Interpretive note: The policy does not map specific processing activities to specific GDPR lawful bases, and the adequacy of the legitimate interests reliance without a published balancing test is subject to supervisory authority interpretation.
EU data subjects may exercise GDPR rights including data access, rectification, erasure, restriction, objection, and portability by contacting privacy@uniswap.org, though the policy notes that on-chain data cannot be deleted or modified and that Uniswap Labs may retain data for legitimate interests including legal compliance and fraud prevention.
Cross-platform context
See how other platforms handle GDPR Processing Bases and Data Subject Rights and similar clauses.
Compare across platforms →Monitoring
Uniswap has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Our bases for processing your data include: (i) you have given consent to the process to us or our service provides for one or more specific purposes; (ii) processing is necessary for the performance of a contract with you; (iii) processing is necessary for compliance with a legal obligation; and/or (iv) processing is necessary for the purposes of the legitimate interested pursued by us or a third party, and your interests and fundamental rights and freedoms do not override those interests. Your rights under the General Data Protection Regulations ("GDPR") include the right to (i) request access and obtain a copy of your personal data, (ii) request rectification or erasure of your personal data, (iii) object to or restrict the processing of your personal data; and (iv) request portability of your personal data.Excerpt from Uniswap's Privacy Policy
1) REGULATORY LANDSCAPE: This provision directly engages GDPR, including lawful basis requirements, data subject rights obligations, and legitimate interests balancing test requirements. Relevant enforcement authorities include national data protection authorities (DPAs) in EU member states. The adequacy of the legitimate interests basis as applied to specific processing activities including wallet screening and device data collection should be evaluated against applicable DPA guidance. 2) GOVERNANCE EXPOSURE: Medium. The policy does not map specific processing activities to specific lawful bases, which may create documentation gaps under GDPR's accountability principle. The invocation of legitimate interests without a published balancing test may require evaluation under applicable DPA guidance, particularly for processing activities that may affect users' fundamental rights. 3) JURISDICTION FLAGS: EU/EEA users and users in countries with GDPR-equivalent frameworks face the highest exposure. The lead supervisory authority for Universal Navigation Inc. as a U.S.-based entity processing EU personal data would depend on whether the company has an EU establishment, which the document does not address. 4) CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with service providers including blockchain analytics providers, Infura, Cloudflare, and Google should be assessed for GDPR Article 28 compliance, including provisions on sub-processing, data transfer mechanisms, and audit rights. 5) COMPLIANCE CONSIDERATIONS: Legal teams should document legitimate interests assessments for each processing activity relying on that basis, confirm that data subject request response procedures meet GDPR timelines, assess transfer mechanisms for personal data flows to U.S.-based processors, and evaluate whether the on-chain data limitation is adequately disclosed to EU users in a manner consistent with GDPR transparency requirements.
This provision establishes the GDPR compliance framework for EU data subjects and invokes legitimate interests as one of four processing bases without specifying the particular processing activities to which each basis applies, which may require evaluation under applicable supervisory authority guidance on documentation of legitimate interests assessments.
EU data subjects may exercise GDPR rights including data access, rectification, erasure, restriction, objection, and portability by contacting privacy@uniswap.org, though the policy notes that on-chain data cannot be deleted or modified and that Uniswap Labs may retain data for legitimate interests including legal compliance and fraud prevention.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Uniswap.