Uniswap · Uniswap Privacy Policy · View original document ↗

GDPR Processing Bases and Data Subject Rights

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Uniswap changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Uniswap recorded 21 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Uniswap Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states four GDPR lawful bases for processing EU user data: consent, contract performance, legal obligation, and legitimate interests. It also enumerates GDPR rights including access, rectification, erasure, objection, restriction, and portability, exercisable by contacting privacy@uniswap.org.

This analysis describes what Uniswap's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the GDPR compliance framework for EU data subjects and invokes legitimate interests as one of four processing bases without specifying the particular processing activities to which each basis applies, which may require evaluation under applicable supervisory authority guidance on documentation of legitimate interests assessments.

Interpretive note: The policy does not map specific processing activities to specific GDPR lawful bases, and the adequacy of the legitimate interests reliance without a published balancing test is subject to supervisory authority interpretation.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

EU data subjects may exercise GDPR rights including data access, rectification, erasure, restriction, objection, and portability by contacting privacy@uniswap.org, though the policy notes that on-chain data cannot be deleted or modified and that Uniswap Labs may retain data for legitimate interests including legal compliance and fraud prevention.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    EU data subjects can email privacy@uniswap.org to request access to, a copy of, rectification of, erasure of, or portability of their personal data held by Uniswap Labs. Additional identifying information may be required to process the request.

Cross-platform context

See how other platforms handle GDPR Processing Bases and Data Subject Rights and similar clauses.

Compare across platforms →

Monitoring

Uniswap has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Our bases for processing your data include: (i) you have given consent to the process to us or our service provides for one or more specific purposes; (ii) processing is necessary for the performance of a contract with you; (iii) processing is necessary for compliance with a legal obligation; and/or (iv) processing is necessary for the purposes of the legitimate interested pursued by us or a third party, and your interests and fundamental rights and freedoms do not override those interests. Your rights under the General Data Protection Regulations ("GDPR") include the right to (i) request access and obtain a copy of your personal data, (ii) request rectification or erasure of your personal data, (iii) object to or restrict the processing of your personal data; and (iv) request portability of your personal data.

Excerpt from Uniswap's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly engages GDPR, including lawful basis requirements, data subject rights obligations, and legitimate interests balancing test requirements. Relevant enforcement authorities include national data protection authorities (DPAs) in EU member states. The adequacy of the legitimate interests basis as applied to specific processing activities including wallet screening and device data collection should be evaluated against applicable DPA guidance. 2) GOVERNANCE EXPOSURE: Medium. The policy does not map specific processing activities to specific lawful bases, which may create documentation gaps under GDPR's accountability principle. The invocation of legitimate interests without a published balancing test may require evaluation under applicable DPA guidance, particularly for processing activities that may affect users' fundamental rights. 3) JURISDICTION FLAGS: EU/EEA users and users in countries with GDPR-equivalent frameworks face the highest exposure. The lead supervisory authority for Universal Navigation Inc. as a U.S.-based entity processing EU personal data would depend on whether the company has an EU establishment, which the document does not address. 4) CONTRACT AND VENDOR IMPLICATIONS: Data processing agreements with service providers including blockchain analytics providers, Infura, Cloudflare, and Google should be assessed for GDPR Article 28 compliance, including provisions on sub-processing, data transfer mechanisms, and audit rights. 5) COMPLIANCE CONSIDERATIONS: Legal teams should document legitimate interests assessments for each processing activity relying on that basis, confirm that data subject request response procedures meet GDPR timelines, assess transfer mechanisms for personal data flows to U.S.-based processors, and evaluate whether the on-chain data limitation is adequately disclosed to EU users in a manner consistent with GDPR transparency requirements.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over U.S.-based entities' data practices affecting consumers, including representations made in privacy policies regarding international data protection compliance.
    File a complaint →

Provision details

Document information
Document
Uniswap Privacy Policy
Entity
Uniswap
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015281
Document ID
CA-D-00304
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
10f414c03a376dbc286269f429c8cca230b16853b8d35e84a545d677043a41db
Analysis generated
July 9, 2026 07:37 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Uniswap
Document: Uniswap Privacy Policy
Record ID: CA-P-015281
Captured: 2026-07-09 07:37:18 UTC
SHA-256: 10f414c03a376dbc…
URL: https://conductatlas.com/platform/uniswap/uniswap-privacy-policy/provision/CA-P-015281/gdpr-processing-bases-and-data-subject-rights/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Uniswap's GDPR Processing Bases and Data Subject Rights clause do?

This provision establishes the GDPR compliance framework for EU data subjects and invokes legitimate interests as one of four processing bases without specifying the particular processing activities to which each basis applies, which may require evaluation under applicable supervisory authority guidance on documentation of legitimate interests assessments.

How does this clause affect you?

EU data subjects may exercise GDPR rights including data access, rectification, erasure, restriction, objection, and portability by contacting privacy@uniswap.org, though the policy notes that on-chain data cannot be deleted or modified and that Uniswap Labs may retain data for legitimate interests including legal compliance and fraud prevention.

Is ConductAtlas affiliated with Uniswap?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Uniswap.