By using X, you agree that your personal information can be transferred to and stored in the United States, Ireland, and other countries, which may have different privacy laws than your home country.
This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause operationalizes international data transfers as a component of the service's data handling framework, placing the legal basis for cross-border data movement within the scope of service use consent rather than requiring separate consent mechanisms.
Users in the EU, UK, and other jurisdictions with strong data protection laws may find their data subject to less protective legal regimes once transferred internationally. This is particularly significant for EU users given GDPR cross-border transfer restrictions.
How other platforms handle this
Whenever we transfer personal data internationally, we use tools and transfer agreements to: make sure the data transfer complies with applicable law; and help to give your data the same level of protection as it has in the EU...
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
Each payment processor uses and processes your complete payment information in accordance with its applicable privacy policy (Stripe and PayPal).
"You understand that through your use of the Services you consent to the collection and use (as set forth in the Privacy Policy) of this information, including the transfer of this information to the United States, Ireland, and/or other countries for storage, processing and use by us and our affiliates.Excerpt from X's Terms of Service
Consent-based international data transfers under Article 49 GDPR are a high-risk mechanism that may not satisfy adequacy requirements; compliance teams should assess whether X relies on Standard Contractual Clauses or other transfer mechanisms as primary …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause operationalizes international data transfers as a component of the service's data handling framework, placing the legal basis for cross-border data movement within the scope of service use consent rather than requiring separate consent mechanisms.
Users in the EU, UK, and other jurisdictions with strong data protection laws may find their data subject to less protective legal regimes once transferred internationally. This is particularly significant for EU users given GDPR cross-border transfer restrictions.
ConductAtlas has identified this type of provision across 288 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.