Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision states that X may share user data with third-party collaborators who are then permitted to use that data for their own independent purposes, including training AI models, unless the user opts out via account settings.
This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes an opt-out default for data sharing with third parties for purposes outside X's own stated policy uses, including AI model training. The provision applies to all users globally and may require evaluation under GDPR's purpose limitation and lawful basis requirements, as well as CCPA's data sharing and opt-out disclosure obligations.
⚠ The terms permit X to share user data with third-party collaborators for AI model training as described, without further notice, if the user does not opt out via settings
Cross-platform context
See how other platforms handle Third-Party AI Training Data Sharing (Opt-Out) and similar clauses.
Compare across platforms →Monitoring
X has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Depending on your settings, or if you decide to share your data, we may share or disclose your information with third parties. If you do not opt out, in some instances the recipients of the information may use it for their own independent purposes in addition to those stated in X's Privacy Policy, including, for example, to train their artificial intelligence models, whether generative or otherwise.Excerpt from X's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR's purpose limitation principle and lawful basis requirements, CCPA's opt-out of sale or sharing obligations, and potentially the EU AI Act where AI training data sourcing is regulated. The Irish Data Protection Commission is the lead supervisory authority for EU and EEA users; the FTC has oversight authority for US users under its general consumer protection mandate and X's DPF commitments. 2) GOVERNANCE EXPOSURE: High. The opt-out default for AI training data sharing creates significant compliance exposure in EU and EEA jurisdictions where GDPR may require a documented lawful basis (such as legitimate interest with a balancing test, or explicit consent) for secondary data processing. In California, the provision may constitute data sharing under the CPRA, triggering opt-out disclosure and honoring obligations. The absence of named third-party recipients reduces transparency and may complicate data mapping requirements. 3) JURISDICTION FLAGS: EU and EEA users face heightened exposure given GDPR's purpose limitation and data subject rights framework. California residents have rights under CPRA to opt out of sharing and to know categories of third parties. Illinois users should note that if biometric data is included in shared data sets, BIPA may apply. Washington State users may have additional rights under the My Health My Data Act if health-adjacent behavioral data is included. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and vendor management teams should assess whether third-party collaborators receiving X data under this provision are subject to data processing agreements meeting GDPR Article 28 requirements. The provision states that X requires third parties to maintain equivalent data protections, but this assertion should be verified against actual DPA terms. B2B customers whose employee or customer data may flow through X (e.g., via embedded content or ad tracking) should evaluate whether this sharing is disclosed in their own privacy notices. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit current opt-out settings at an organizational level, verify that user-facing consent and opt-out mechanisms meet the requirements of applicable law in each jurisdiction where the platform is used, update internal data flow maps to reflect potential AI training sharing flows, and evaluate whether existing privacy notices to end users accurately describe this downstream sharing. For EU and EEA deployments, a legitimate interest assessment or consent mechanism review may be warranted.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause establishes an opt-out default for data sharing with third parties for purposes outside X's own stated policy uses, including AI model training. The provision applies to all users globally and may require evaluation under GDPR's purpose limitation and lawful basis requirements, as well as CCPA's data sharing and opt-out disclosure obligations.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.