Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Uniswap Labs collects and logs blockchain wallet addresses upon connection and screens them using third-party blockchain analytics providers to detect prior illicit activity.
This analysis describes what Uniswap's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes an automated screening process applied to all connecting wallet addresses using third-party intelligence services, with no opt-out mechanism described in the policy. Compliance teams should assess the contractual and data-sharing terms governing these analytics providers, including data retention, onward transfer, and whether the screening constitutes automated decision-making with significant effects under GDPR.
Under this clause, every wallet address connected to the Services is logged and submitted to third-party blockchain analytics providers for illicit activity screening. The policy does not describe an opt-out mechanism for this screening process.
Cross-platform context
See how other platforms handle Wallet Address Screening via Blockchain Analytics and similar clauses.
Compare across platforms →Monitoring
Uniswap has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"When you connect your non-custodial blockchain wallet to the Services, we collect and log your publicly-available blockchain address to learn more about your use of the Services and to screen your wallet for any prior illicit activity. We screen your wallet using intelligence provided by leading blockchain analytics providers.Excerpt from Uniswap's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR (lawful basis for processing, and potentially automated decision-making obligations), CCPA (disclosure of data sharing with service providers), and applicable financial crime and anti-money laundering frameworks. The FTC has jurisdiction over data sharing practices with third parties in the U.S. context. The use of third-party analytics providers for screening may require evaluation under GDPR data processor requirements and applicable supervisory authority guidance on automated processing. 2) GOVERNANCE EXPOSURE: Medium. The provision discloses wallet screening by named and unnamed third-party analytics providers without specifying provider names beyond referencing Infura and Cloudflare for infrastructure (analytics providers are not named). The absence of an opt-out mechanism and the automated nature of the screening may create exposure under GDPR's provisions on automated decision-making, depending on how screening outcomes affect user access to the Services. 3) JURISDICTION FLAGS: EU/EEA users face the highest exposure given GDPR requirements around automated processing, data processor agreements, and the need for an adequately documented lawful basis. California users have CCPA-based rights to request information about data shared with service providers. Users in jurisdictions with strict data localization requirements may face additional considerations. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should review data processing agreements with the blockchain analytics providers used for screening, including provisions on data retention, secondary use, and cross-border transfers. The policy does not name the specific analytics providers used for screening (distinct from infrastructure providers), which may complicate vendor assessment. 5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the wallet screening process meets the threshold for automated decision-making with legal or significant effects under GDPR Article 22, and whether appropriate safeguards or disclosures are in place. Data mapping exercises should capture the wallet address data flow to analytics providers, including transfer mechanisms for non-U.S. users.
This provision establishes an automated screening process applied to all connecting wallet addresses using third-party intelligence services, with no opt-out mechanism described in the policy. Compliance teams should assess the contractual and data-sharing terms governing these analytics providers, including data retention, onward transfer, and whether the screening constitutes automated decision-making with significant effects under GDPR.
Under this clause, every wallet address connected to the Services is logged and submitted to third-party blockchain analytics providers for illicit activity screening. The policy does not describe an opt-out mechanism for this screening process.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Uniswap.