Provision Registry

7353 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Medium × Clear all
medium Cross border
Discord · Discord Privacy Policy
The provision sets the operational framework for Discord's data handling infrastructure by anchoring jurisdiction to U.S. law and establishing that data residency extends beyond the user's home country. This allocation of legal governance determines which regulatory standards and enforcement mechanisms apply to user information.
CA-P-005858 First tracked May 8, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Cloudflare · Cloudflare Privacy Policy
If you are in the EU, UK, or Switzerland, your data is transferred to the U.S. under Standard Contractual Clauses, a mechanism whose adequacy has been subject to ongoing legal scrutiny, and you may have fewer legal protections in the destination country.
CA-P-003012 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
medium Cross border
Cohere · Cohere Privacy Policy
The provision establishes the operational framework for Cohere's global data infrastructure and specifies the legal basis for international transfers. For EEA/UK/Switzerland users, the Standard Contractual Clauses serve as the contractual mechanism enabling lawful cross-border data flows where adequacy decisions do not exist.
CA-P-005260 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Cross border
Egnyte · Egnyte Privacy Policy
The provision establishes the operational framework for cross-border data processing and specifies the contractual mechanism—Standard Contractual Clauses—that the company relies upon to maintain legal compliance when personal information flows to jurisdictions with varying regulatory requirements.
CA-P-006399 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Dropbox · Dropbox Privacy Policy
EU, UK, and Swiss users have strong data protection rights, and the legal mechanisms Dropbox relies on to transfer data to the US have been subject to legal challenge; if those mechanisms were invalidated, data transfer practices would need to change.
CA-P-008461 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Copy.ai · Copy.ai Privacy Policy
For EU users in particular, relying on use of the service as consent to international data transfer may not satisfy GDPR's requirements for a valid transfer mechanism, as consent alone is generally not considered an adequate legal basis for routine international transfers under GDPR guidance.
CA-P-004322 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Whatnot · Whatnot Privacy Policy
This provision addresses cross-border data transfers, which for EU and UK users require specific transfer mechanisms under GDPR and UK GDPR; the policy's reference to 'appropriate safeguards' without specifying the mechanism (such as standard contractual clauses or adequacy decisions) leaves the specific legal basis for transfers unspecified in the publicly available policy text.
CA-P-012496 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data sharing
Hugging Face · Hugging Face Privacy Policy
International data transfer provisions are operationally significant because they define how personal data moves across regulatory boundaries and what protections apply during transit and storage. The provision establishes compliance mechanisms for jurisdictions like the EU, which restrict transfers to countries without adequate data protection safeguards.
CA-P-001647 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Data sharing
23andMe · 23andMe Privacy Statement
International data transfers are operationally significant because genetic and health data is subject to varying regulatory requirements across jurisdictions. The provision defines how 23andMe complies with data localization rules, adequacy determinations, and standard contractual clauses that govern cross-border data movement.
CA-P-000904 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →
medium Cross border
GOAT · GOAT Privacy Policy
International data transfer provisions are operationally significant because they establish compliance mechanisms for cross-border data flows, which are subject to varying regulatory requirements across jurisdictions, particularly in the EU and other regions with restrictive data transfer laws. The provision determines what legal instruments GOAT relies on to legitimize such transfers.
CA-P-005266 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data sharing
Grindr · Grindr Privacy Policy
The provision discloses the jurisdictional scope of data transfers and establishes notice that the legal and regulatory framework governing data protection in receiving jurisdictions may not be equivalent to the user's home jurisdiction. This is operationally significant because it identifies where personal information is processed and alerts users to potential variation in statutory privacy standards.
CA-P-001414 First tracked Apr 3, 2026 Last seen Apr 17, 2026 Compare across platforms →
medium Data sharing
Stability AI · Stability AI Privacy Policy
The provision establishes that data processing occurs across multiple jurisdictions, which affects the applicable regulatory framework governing that data. Users' personal data may be subject to the privacy and security laws of the destination country rather than the laws of their country of residence.
CA-P-001624 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Duolingo · Duolingo Privacy Policy
The policy states that by using the service, users consent to data transfer to the US, which for EU and UK users intersects with GDPR requirements for lawful international data transfer mechanisms that go beyond consent alone.
CA-P-011282 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Pinterest · Pinterest Privacy Policy
The policy states that personal data of non-US users is processed in the United States, which does not have a general federal privacy law equivalent to GDPR, and that transfers are protected through standard contractual clauses and other approved mechanisms, though the adequacy of those mechanisms is subject to ongoing regulatory and legal developments.
CA-P-000688 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Ledger · Ledger Privacy Policy
Data transferred outside the EEA may be subject to less protective legal regimes, and compliance with post-Schrems II transfer requirements depends on whether Ledger has implemented the 2021 updated SCCs and conducted transfer impact assessments.
CA-P-001471 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Eventbrite · Eventbrite Privacy Policy
EU and UK users' data is processed under US law once transferred, and the adequacy of Standard Contractual Clauses as a transfer mechanism is subject to ongoing regulatory and legal scrutiny.
CA-P-008241 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Vercel AI · Vercel AI SDK Privacy
For EU and UK users, transferring data to the US requires specific legal safeguards under GDPR and UK GDPR, and asserting broad consent as the transfer mechanism may not meet the required legal standard in all cases.
CA-P-008980 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Fiverr · Fiverr Privacy Policy
For EU and UK users, international data transfers carry legal significance because your data may leave a jurisdiction with strong privacy protections and be processed under different legal regimes, with Fiverr relying on Standard Contractual Clauses as the primary safeguard.
CA-P-007432 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Medium · Medium Privacy Policy
The policy's disclosure of cross-border data transfers without specifying the legal mechanism used for EEA transfers, such as Standard Contractual Clauses or an adequacy decision, creates a compliance documentation gap relevant to GDPR Chapter V requirements enforced by EU supervisory authorities.
CA-P-012729 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Writer · Writer Privacy Policy
This provision discloses cross-border data transfers to the United States but does not specify which transfer mechanism (such as standard contractual clauses or the EU-U.S. Data Privacy Framework) applies, which may require evaluation under current GDPR transfer adequacy requirements.
CA-P-009059 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data sharing
Anthropic · Anthropic Privacy Policy
The clause establishes the jurisdictional framework for data processing and identifies the legal regime (U.S. law) that governs personal data handling, which has operational significance for users accessing the service from outside the United States.
CA-P-008342 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Tabnine · Tabnine Privacy Policy
The policy states that data may be transferred internationally and that standard contractual clauses or equivalent mechanisms are used, but does not specify which mechanisms apply to which transfer routes, which is relevant for EU and UK users assessing GDPR transfer compliance.
CA-P-011750 First tracked May 12, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Twitch · Twitch Privacy Notice
International data transfers can mean your personal information is processed in countries with different levels of legal privacy protection than your home country, which is particularly significant for EU and UK users.
CA-P-009603 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
PlanetScale · PlanetScale Privacy Policy
EU, UK, and Swiss users have their data transferred to the US, a jurisdiction that historically has not met the EU's adequacy standard without specific frameworks; the policy's reference to both DPF and contractual protections suggests a layered approach, but the adequacy of those protections depends on which mechanism is applied and whether it remains legally valid.
CA-P-005431 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
Salesforce · Salesforce Privacy Statement
For EU, UK, and Swiss users, your data crossing borders to the US triggers specific legal protections. Salesforce's use of the DPF and SCCs is meant to provide those protections, but the legal landscape for transatlantic data transfers has been subject to ongoing legal challenges.
CA-P-004507 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
EA · EA Privacy and Cookie Policy
EU, UK, and Swiss users' data is processed in the US under the DPF framework, which provides specific rights including access to a free dispute resolution mechanism and, as a last resort, binding arbitration.
CA-P-009049 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Egnyte · Egnyte Privacy Policy
The legal mechanism used for international data transfers affects whether your data is protected under EU standards when it is processed in the United States, and the DPF's long-term legal stability has been subject to ongoing political and legal scrutiny.
CA-P-009683 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Mistral AI · Mistral AI Data Processing Addendum
The incorporation of SCC Module 4 by reference upon DPA acceptance provides a recognized GDPR transfer mechanism, but fixes French law as the governing law and French courts as the dispute forum, which affects where and under what legal framework customers in non-adequate third countries (such as the US, absent an adequacy decision) must pursue remedies.
CA-P-010505 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Okta · Okta Privacy Policy
The provision operationalizes the company's global data handling framework by specifying the legal mechanisms used to authorize cross-border transfers and establish baseline protection standards in jurisdictions outside the user's country of residence.
CA-P-005531 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
Zoom · Zoom Privacy Statement
The provision describes Zoom's compliance framework for international data transfers under EU data protection regulations. Standard Contractual Clauses and adequacy decisions are the contractual and regulatory mechanisms that permit cross-border data flows when the destination country is not deemed to have equivalent data protection.
CA-P-009833 First tracked May 10, 2026 Last seen May 11, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial