Whatnot · Whatnot Privacy Policy · View original document ↗

Cross-Border Data Transfers

Medium severity Medium confidence Explicitdocumentlanguage Common · 78 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Whatnot recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Whatnot Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Whatnot transfers your personal data to the United States for processing, and US privacy laws may offer fewer protections than those in your home country.

This analysis describes what Whatnot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

For users in the EU, UK, and other jurisdictions with strong data protection laws, this transfer must be covered by a lawful mechanism such as Standard Contractual Clauses, and the policy does not specify which transfer mechanism is used.

Interpretive note: The policy does not specify the legal transfer mechanism used for EU and UK data flows, creating uncertainty about whether all required GDPR safeguards are in place.

Consumer impact (what this means for users)

EU and UK users' personal data is transferred to the US, where it may be subject to US government access rights and different privacy standards, and the specific safeguards in place for this transfer are not detailed in the policy.

How other platforms handle this

PlanetScale Medium

You will provide personal information directly to our website in the United States. We may also transfer personal information to our partners and service providers in the United States and other jurisdictions. Please note that such jurisdictions may not provide the same protections as the data prote...

Notion Medium

Notion is based in the United States and the information we collect is governed by U.S. law. If you are accessing our Services from outside of the United States, please be aware that information collected through the Services may be transferred to, processed, stored, and used in the United States an...

Cohere Medium

Your personal information may be transferred to and processed in countries other than your country of residence, including Canada and the United States, where our servers are located and our central database is operated. These countries may have data protection laws that are different from those in ...

See all platforms with this clause type →

Monitoring

Whatnot has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Your information may be transferred to, and maintained on, computers located outside of your state, province, country or other governmental jurisdiction where the privacy laws may not be as protective as those in your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Information, to the United States and process it there.

— Excerpt from Whatnot's Whatnot Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Chapter V, which requires that personal data transferred outside the EU/EEA be covered by an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or another approved mechanism. Following Schrems II, transfers to the US require additional technical and contractual safeguards. UK GDPR imposes analogous requirements for transfers from the UK. The relevant enforcement authorities are EU supervisory authorities (coordinated through EDPB) and the UK ICO. GOVERNANCE EXPOSURE: High for EU and UK user populations. The policy discloses the transfer but does not identify the specific transfer mechanism in use, which may be insufficient for GDPR transparency requirements and could create exposure in the event of a supervisory authority inquiry or complaint. JURISDICTION FLAGS: EU and UK users face the highest exposure. EU member state supervisory authorities have taken enforcement action against companies that failed to document or implement adequate transfer mechanisms. Switzerland, Brazil, and other jurisdictions with GDPR-equivalent laws may impose similar obligations. CONTRACT AND VENDOR IMPLICATIONS: DPAs and SCCs with US-based processors and sub-processors must be current and include the supplementary measures required post-Schrems II. Procurement teams should confirm that transfer impact assessments have been conducted for US data flows. COMPLIANCE CONSIDERATIONS: Legal teams should identify and document the specific transfer mechanism used for EU and UK data flows, update the privacy notice to reflect this, and conduct or update a transfer impact assessment. If the EU-US Data Privacy Framework is relied upon, confirm Whatnot's certification status.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    EU supervisory authorities and the UK ICO (analogous to state-level regulators in this context) have enforcement authority over cross-border data transfers from EU and UK jurisdictions
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union

Provision details

Document information
Document
Whatnot Privacy Policy
Entity
Whatnot
Document last updated
May 5, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 11, 2026
Record ID
CA-P-007068
Document ID
CA-D-00732
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b004999cb5790fcea852f2c7a74f97dc701c834bd53dc7719ae5d0ff36889183
Analysis generated
May 11, 2026 06:35 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Whatnot
Document: Whatnot Privacy Policy
Record ID: CA-P-007068
Captured: 2026-05-11 06:35:36 UTC
SHA-256: b004999cb5790fce…
URL: https://conductatlas.com/platform/whatnot/whatnot-privacy-policy/cross-border-data-transfers/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Whatnot's Cross-Border Data Transfers clause do?

For users in the EU, UK, and other jurisdictions with strong data protection laws, this transfer must be covered by a lawful mechanism such as Standard Contractual Clauses, and the policy does not specify which transfer mechanism is used.

How does this clause affect you?

EU and UK users' personal data is transferred to the US, where it may be subject to US government access rights and different privacy standards, and the specific safeguards in place for this transfer are not detailed in the policy.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 78 platforms. See the full comparison.

Is ConductAtlas affiliated with Whatnot?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Whatnot.