Whatnot · Whatnot Legal Terms · View original document ↗

Cross-Border Data Transfers

Medium severity Medium confidence Explicitdocumentlanguage Common · 294 of 352 platforms
Get alerted the next time Whatnot changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Whatnot recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Whatnot Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that personal information may be transferred to and processed in the United States and other countries with potentially different data protection standards than the user's country of residence.

This analysis describes what Whatnot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Cross-border transfers of personal data from EU and UK residents to the United States require a lawful transfer mechanism under GDPR such as Standard Contractual Clauses or adequacy decisions; the policy's acknowledgment of differing data protection standards is a disclosure obligation but does not confirm that specific transfer mechanisms are in place.

Interpretive note: The adequacy of the policy's transfer disclosure depends on which specific transfer mechanisms Whatnot relies upon for each jurisdiction, which are not detailed in the publicly available policy text reviewed.

Recent Activity

This document changed recently

High Jun 24, 2026

The updated Influencer Engagement Agreement now requires all disputes between influencers and Whatnot to be resolved through binding arbitration under the Terms of Service Section 21, rather than through California state or federal courts. This replaces the previous language permitting influencers to pursue legal claims in Los Angeles courts and waives jury trial rights. The agreement also removes language that explicitly limited dispute resolution to claims arising solely from the Influencer Agreement, extending arbitration to disputes relating to Whatnot Platform use and the influencer-platform relationship.

View change record →
Medium Jun 18, 2026

The new Australian Creator Program Terms establish binding legal requirements for creators submitting video content and promotional codes. Creators grant Whatnot a non-exclusive, worldwide, irrevocable license to use submitted videos across platforms (organic and paid social media, television, in-app, websites, and more) for one year from submission. The terms require creators to comply with Australian Consumer Law, AANA ethical standards, and AiMCO guidelines, with explicit disclosure requirements when promoting Whatnot or affiliated products. Rewards for approved Shopping Hauls submissions are issued within 30 business days of receiving both ad codes and raw video. You can review the specific disclosure and content standards on the Program Page before submitting content.

View change record →
High Jun 16, 2026

Under the updated agreement, Australian sellers can no longer resolve disputes through court proceedings in Los Angeles. Instead, all disputes related to the Whatnot platform or the seller relationship must be resolved through mandatory individual arbitration under Whatnot's main Terms of Service. The updated terms eliminate the jury trial waiver provision and replace court access with binding arbitration, with limited exceptions only as expressly permitted in the main Terms of Service.

View change record →

Consumer impact (what this means for users)

Under this provision, personal information collected from users in the EU, UK, Australia, and Canada may be transferred to and processed in the United States or other jurisdictions. The policy acknowledges that these countries may have different data protection standards but does not specify in the body of the policy which transfer mechanisms apply to each data flow.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EU and UK residents who wish to inquire about the transfer mechanisms applicable to their data or submit a data rights request may do so through Whatnot's privacy rights mechanism described in the policy.

How other platforms handle this

Adobe Medium

we also transfer personal information to all other countries in which Adobe or its affiliates, providers, and partners operate. We carry out these transfers in compliance with applicable laws – for example, by putting data transfer agreements in place...

Squarespace Medium

Each payment processor uses and processes your complete payment information in accordance with its applicable privacy policy (Stripe and PayPal).

Lime Medium

if you are accessing and using Lime Services under a corporate account...you acknowledge and agree that Lime may share certain of your usage information with whomever provided you with access to the Lime Services

See all platforms with this clause type →

Monitoring

Whatnot has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Your personal information may be transferred to and processed in countries other than your country of residence, including the United States, where our servers are located and our central database is operated. These countries may have data protection laws that are different from those of your country of residence.

Excerpt from Whatnot's Legal Terms

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: GDPR Chapter V and UK GDPR govern international transfers of personal data, requiring either an adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or another approved mechanism. The EU-US Data Privacy Framework (DPF) provides an adequacy basis for transfers to certified US organizations. The Australian Privacy Act and PIPEDA also impose obligations on cross-border data transfers. The relevant enforcement authorities are EU member state supervisory authorities, the UK Information Commissioner's Office (ICO), the Office of the Privacy Commissioner of Canada (OPC), and the Office of the Australian Information Commissioner (OAIC). 2. GOVERNANCE EXPOSURE: Medium. The policy discloses cross-border transfers but does not detail in the public-facing document which specific transfer mechanisms are relied upon for each jurisdiction, creating potential documentation and accountability gaps under GDPR Article 5(2) and Article 13/14 disclosure requirements. 3. JURISDICTION FLAGS: EU and EEA (GDPR Chapter V and SCCs), UK (UK GDPR and UK SCCs or International Data Transfer Agreements), Australia (Privacy Act cross-border disclosure obligations under APP 8), and Canada (PIPEDA cross-border transfer requirements). Post-Schrems II scrutiny of transfers to the US remains relevant for EU and UK user data. 4. CONTRACT AND VENDOR IMPLICATIONS: All data processor agreements with US-based and non-EEA vendors should include SCCs or equivalent mechanisms. Transfer Impact Assessments may be required for EU and UK data flows to US processors that are subject to surveillance laws. B2B customers in the EU or UK may require representations about transfer mechanisms as part of their own vendor due diligence. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that the EU-US Data Privacy Framework certification is current if relied upon for US transfers, and that SCCs or UK ICTAs are in place for any US or third-country processors not covered by an adequacy decision. The privacy policy should be reviewed to confirm that transfer mechanism disclosures satisfy GDPR Articles 13 and 14 information requirements. A transfer mapping exercise should identify all cross-border data flows and their legal bases.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC enforces US-EU Data Privacy Framework obligations for certified US organizations and has authority over deceptive data transfer representations under Section 5 of the FTC Act.
    File a complaint →
  • State AG
    State attorneys general may have authority over cross-border data transfer disclosures where state privacy laws impose obligations on international data sharing practices.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Whatnot Legal Terms
Entity
Whatnot
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-007068
Document ID
CA-D-00732
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f9f4abe041f05f55b02d263028e84e0962ca631bce26c5da097dbb9e52b74f77
Analysis generated
July 9, 2026 09:50 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Whatnot
Document: Whatnot Legal Terms
Record ID: CA-P-007068
Captured: 2026-07-09 09:50:11 UTC
SHA-256: f9f4abe041f05f55…
URL: https://conductatlas.com/platform/whatnot/whatnot-legal-terms/provision/CA-P-007068/cross-border-data-transfers/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Whatnot's Cross-Border Data Transfers clause do?

Cross-border transfers of personal data from EU and UK residents to the United States require a lawful transfer mechanism under GDPR such as Standard Contractual Clauses or adequacy decisions; the policy's acknowledgment of differing data protection standards is a disclosure obligation but does not confirm that specific transfer mechanisms are in place.

How does this clause affect you?

Under this provision, personal information collected from users in the EU, UK, Australia, and Canada may be transferred to and processed in the United States or other jurisdictions. The policy acknowledges that these countries may have different data protection standards but does not specify in the body of the policy which transfer mechanisms apply to each data flow.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 294 platforms. See the full comparison.

Is ConductAtlas affiliated with Whatnot?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Whatnot.