Provision Registry

696 classified provisions across 277 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Professional free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Data sharing × Medium × Clear all
medium Data sharing
Fitbit · Fitbit Privacy Policy
Health research data sharing involves your most sensitive biometric information being transferred to third parties outside Fitbit, and the consent terms at enrollment govern what protections apply—not this general privacy policy.
CA-P-005907 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
Wealthfront · Wealthfront Privacy Policy
Home lending clients are subject to a wider data sharing network than standard investment clients, and consent to this sharing is embedded in the agreement to begin a loan application, not a separate affirmative opt-in.
CA-P-008301 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
Midjourney · Midjourney Privacy Policy
Inferences can reveal sensitive personal traits without your explicit disclosure, and sharing them with third parties can result in profiling that affects the ads and content you see across the internet.
CA-P-000670 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
Spotify · Spotify Privacy Policy
Inferences derived from your behavior create a detailed personal profile that can be used for advertising targeting, and may not be obvious to users who think they are simply listening to music.
CA-P-002609 First tracked Apr 9, 2026 Last seen Apr 10, 2026 Compare across platforms →
T-Mobile · T-Mobile Privacy Policy
The inclusion of 'when we believe' disclosure is necessary to protect rights or safety, in addition to legally compelled disclosures, gives T-Mobile discretion to share data with government entities beyond situations of formal legal compulsion.
CA-P-010248 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
Nintendo · Nintendo Privacy Policy
The default opt-in structure means your data is shared with advertising partners unless you actively change your settings; this sharing may qualify as a 'sale' or 'sharing' of personal information under California law, giving California residents specific rights.
CA-P-007765 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Microsoft · Microsoft Privacy Statement (Legacy)
Even without sharing your name, the combination of search queries, location, device identifiers, and IP address shared with advertising partners can enable re-identification and detailed behavioural profiling by those third parties.
CA-P-002056 First tracked Apr 4, 2026 Last seen Apr 9, 2026 Compare across platforms →
PlanetScale · PlanetScale Privacy Policy
Your usage data, identifiers, and behavioral inferences from the PlanetScale platform may be used to target you with advertising on completely separate third-party platforms, which many users would not anticipate from a developer database service.
CA-P-005424 First tracked May 7, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data sharing
Runway · Runway Privacy Policy
For EU and UK users, international data transfers to the United States require a lawful transfer mechanism under GDPR Chapter V, such as Standard Contractual Clauses. The policy's reliance on user acknowledgment through service use as a consent mechanism for transfers may not satisfy GDPR transfer requirements.
CA-P-007580 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Craigslist · Craigslist Privacy Policy
Users outside the US, particularly in the EU and UK, have stronger data protection rights under local law, and transferring data to the US without a specific legal mechanism may not satisfy those legal requirements.
CA-P-008250 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
Supabase · Supabase Privacy Policy
For users in the EU, UK, and other jurisdictions with strong data protection laws, international transfers require specific legal safeguards; this provision acknowledges the transfer risk but does not specify which transfer mechanisms Supabase relies on.
CA-P-007515 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
Calm · Calm Privacy Policy
For EU, UK, and Swiss users, the lawfulness of data transfers to the US depends on these mechanisms being properly implemented and maintained.
CA-P-009941 First tracked May 11, 2026 Last seen May 12, 2026 Compare across platforms →
OpenAI · OpenAI Data Processing Addendum
This provision establishes the legal mechanism for transferring EU/EEA, UK, and Swiss personal data to OpenAI in the United States, which is a mandatory requirement under GDPR Chapter V. Operators relying on this mechanism should verify the SCCs are properly incorporated and that the associated transfer impact assessment is adequate.
CA-P-010995 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data sharing
Eventbrite · Eventbrite Privacy Policy
EU and UK users' data is processed under US law once transferred, and the adequacy of Standard Contractual Clauses as a transfer mechanism is subject to ongoing regulatory and legal scrutiny.
CA-P-008241 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data sharing
Amazon Marketplace · Amazon Privacy Notice
If you live in the EU, UK, or another jurisdiction with strong privacy protections, your data may be sent to countries with weaker legal protections, potentially reducing your rights and remedies.
CA-P-000243 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data sharing
Apple App Store · Apple Privacy Policy
Consent-based international data transfer clauses are legally contentious under GDPR, where consent alone is generally insufficient as a transfer mechanism — EU users should understand that their data is transferred to and processed in the US under Apple's Standard Contractual Clauses.
CA-P-000217 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Data sharing
23andMe · 23andMe Privacy Statement
For EU, UK, and other international users, transferring genetic data outside their jurisdiction may reduce the legal protections available to them under local law.
CA-P-000904 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Data sharing
Grindr · Grindr Privacy Policy
Transferring data internationally can expose it to different and potentially weaker legal protections than those available in the user's home country.
CA-P-001414 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data sharing
Hugging Face · Hugging Face Privacy Policy
If you are in the EU or UK, your data may be sent to countries without equivalent legal protections unless adequate safeguards are in place, which the policy does not detail.
CA-P-001647 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Data sharing
Netflix · Netflix Privacy Statement
International data transfers mean your personal information may be processed in countries with different levels of data protection, and understanding which Netflix entity controls your data determines which legal framework and rights apply to you.
CA-P-002624 First tracked Apr 9, 2026 Last seen Apr 18, 2026 Compare across platforms →
medium Data sharing
Tabnine · Tabnine Privacy Policy
The policy states that data may be transferred internationally and that standard contractual clauses or equivalent mechanisms are used, but does not specify which mechanisms apply to which transfer routes, which is relevant for EU and UK users assessing GDPR transfer compliance.
CA-P-011750 First tracked May 12, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data sharing
Coinbase · Coinbase Privacy Policy
Your data processed under EU or UK privacy law may be transferred to the US, where it could be subject to broader government surveillance access under US law — a key concern highlighted in the Schrems II ruling.
CA-P-000419 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data sharing
Peloton · Peloton Privacy Policy
Transferring your data internationally means it may be subject to different — and potentially weaker — legal protections, and may be accessible to foreign governments or other entities.
CA-P-001180 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data sharing
Salesforce · Salesforce Privacy Statement
International transfers mean your personal data may be subject to different legal protections depending on where it ends up, which is particularly significant for EU and UK residents with stronger home-country rights.
CA-P-001090 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data sharing
Fiverr · Fiverr Privacy Policy
For EU and UK users, international data transfers carry legal significance because your data may leave a jurisdiction with strong privacy protections and be processed under different legal regimes, with Fiverr relying on Standard Contractual Clauses as the primary safeguard.
CA-P-007432 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data sharing
Mixpanel · Mixpanel Privacy Statement
International data transfers from the EU to the US remain a compliance-sensitive area following the Schrems II ruling. The adequacy of Standard Contractual Clauses depends on supplementary measures and the nature of the data, and regulators continue to scrutinize these transfers.
CA-P-010319 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data sharing
MetaMask · MetaMask Privacy Policy
For EU and UK users, data transferred to the US must be protected by appropriate legal mechanisms; while SCCs are an accepted GDPR transfer tool, their adequacy in practice depends on the specific supplementary measures implemented alongside them.
CA-P-007289 First tracked May 9, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data sharing
Bumble · Bumble Privacy Policy
When your data is transferred internationally, it may be subject to foreign government access requests or weaker privacy laws, reducing your ability to enforce your rights.
CA-P-001197 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data sharing
AI21 Labs · AI21 Labs Privacy Policy
Data transferred outside the EU or UK may be subject to different legal protections, and the adequacy of Standard Contractual Clauses as a transfer mechanism depends on whether supplementary measures are in place given the privacy laws of the recipient country.
CA-P-008136 First tracked May 10, 2026 Last seen May 12, 2026 Compare across platforms →
medium Data sharing
Cursor · Cursor Privacy Policy
EEA and UK users have stronger data protection rights under GDPR and UK GDPR, and international transfers of their data require specific legal safeguards; this clause confirms transfers occur but does not name the specific transfer mechanisms used.
CA-P-008156 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →

Professional Governance Intelligence

Monitor specific governance provisions across platforms.

Professional includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Professional free trial