Provision record
Waze · Waze Privacy Policy · View original document ↗

Cross-Border Data Transfers

Medium severity Medium confidence Explicit document language Common · 287 of 352 platforms
Stay ahead of the changes
Track Waze and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The policy discloses that user data may be processed on servers outside the user's country of residence, and states that Waze applies consistent protections regardless of processing location.

This analysis describes what Waze's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that cross-border data transfers occur, including to servers in the EU and U.S. as noted elsewhere in the policy, but does not specify the transfer mechanisms relied upon for compliance with GDPR Chapter V or equivalent frameworks.

Interpretive note: The specific legal transfer mechanisms relied upon for GDPR and LGPD compliance are not named in the document, creating interpretive uncertainty about the adequacy of the disclosed transfer framework.

Recent Activity

This document changed recently

Medium Jul 9, 2026

The updated policy now applies to users of any age by removing the prior 16+ requirement, but does not explicitly state whether parental consent is required for minors. The policy defines Personal Information more broadly to include location, route information, and data reasonably linked to you by Waze. The company removed documentation of the 'find friends' feature that previously collected phone numbers from device contacts, suggesting that feature is no longer active or has been redesigned. Privacy controls remain available through in-app settings where you can adjust which Personal Information Waze collects and how it is used.

View change record →

Clause Stability Mostly Stable

1
Change
5
Months Monitored
Apr 3, 2026
First Seen
Jul 9, 2026
Last Seen
This clause type exists across 4430 other provisions on other platforms.
This clause has changed once in 5 months of monitoring.

Change history

removed Jul 9, 2026

Elimination of dedicated cross-border data transfer provision suggests reduced transparency around mechanisms ensuring compliance with data localization and international transfer regulations like Standard Contractual Clauses.

View full change record →

Consumer impact (what this means for users)

Under this clause, personal data including location and route information may be processed on servers outside the user's home country. The policy states that consistent protections are applied regardless of processing location, but does not name the specific transfer mechanisms such as Standard Contractual Clauses used to authorize transfers under GDPR.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact Waze's data protection office at privacy@waze.com to submit questions or requests related to cross-border data processing, including requests to restrict processing or to obtain information about the transfer mechanisms applied to your data.

How other platforms handle this

Adobe Medium

we also transfer personal information to all other countries in which Adobe or its affiliates, providers, and partners operate. We carry out these transfers in compliance with applicable laws – for example, by putting data transfer agreements in place...

Tinder Medium

we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...

Skillshare Medium

Whenever we transfer personal data internationally, we use tools and transfer agreements to: make sure the data transfer complies with applicable law; and help to give your data the same level of protection as it has in the EU...

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
We store data on servers located around the world and your information may be processed on servers located outside of the country where you live. Data protection laws vary among countries, with some providing more protection than others. Regardless of where your information is processed, we apply the same protections described in this policy. When we receive formal written complaints, we respond by contacting the person who made the complaint. We work with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of your data that we cannot resolve with you directly.

Excerpt from Waze's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Cross-border data transfers from the EU, UK, and Brazil require documented legal mechanisms under GDPR Chapter V, UK GDPR, and LGPD respectively.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Waze Privacy Policy
Entity
Waze
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-001590
Document ID
CA-D-00323
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
937770f9c88757454718c0d4496325fb56387cdd9ad4d299ff06ed4533aed7e5
Analysis generated
July 9, 2026 07:05 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Waze
Document: Waze Privacy Policy
Record ID: CA-P-001590
Captured: 2026-07-09 07:05:51 UTC
SHA-256: 937770f9c8875745…
URL: https://conductatlas.com/platform/waze/waze-privacy-policy/provision/CA-P-001590/cross-border-data-transfers/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Waze's Cross-Border Data Transfers clause do?

This provision establishes that cross-border data transfers occur, including to servers in the EU and U.S. as noted elsewhere in the policy, but does not specify the transfer mechanisms relied upon for compliance with GDPR Chapter V or equivalent frameworks.

How does this clause affect you?

Under this clause, personal data including location and route information may be processed on servers outside the user's home country. The policy states that consistent protections are applied regardless of processing location, but does not name the specific transfer mechanisms such as Standard Contractual Clauses used to authorize transfers under GDPR.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 287 platforms. See the full comparison.

Is ConductAtlas affiliated with Waze?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Waze.