Provision Registry

3351 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
Filtering: Privacy rights × Clear all
medium Privacy rights
Grindr · Grindr Privacy Policy
For EU and UK users, transferring sensitive personal data to the US without adequate transfer mechanisms can violate GDPR and create legal exposure for Grindr and reduced rights protections for users.
CA-P-009389 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Jasper AI · Jasper Privacy Policy
EU and UK users whose data is transferred to the United States or other countries must be protected by an appropriate transfer mechanism under GDPR; the policy does not specify which mechanisms Jasper relies upon in the available text.
CA-P-010662 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Intuit · Intuit Privacy Statement
For EU and UK users, international data transfers require specific legal safeguards, and the adequacy of those safeguards is subject to ongoing regulatory and judicial scrutiny.
CA-P-008513 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Adyen · Adyen Privacy Policy
Cross-border transfers expose your data to legal systems with potentially lower privacy protections than the EU or UK, and the adequacy of Standard Contractual Clauses as a safeguard depends on ongoing regulatory and judicial developments.
CA-P-008769 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Instacart · Instacart Privacy Policy
Canadian users' data may be subject to U.S. legal process and law enforcement access once transferred to the United States, and the protections available under Canadian law may not apply in full to data held in the U.S.
CA-P-002841 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Stability AI · Stability AI Privacy Policy
Cross-border data transfers from the EU or UK to countries without an adequacy decision require specific legal safeguards under GDPR and UK GDPR, and the policy's general disclosure does not specify which transfer mechanisms are used.
CA-P-003729 First tracked Apr 28, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Fly.io · Fly.io Privacy Policy
If you are in the EU, UK, or another jurisdiction with strong data protection laws, transfers to the US require specific legal safeguards that must be in place for the transfer to be lawful.
CA-P-005363 First tracked May 7, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Bumble · Bumble Privacy Policy
International data transfers mean your personal information may be processed under legal frameworks that provide different or potentially lower levels of protection than your home country's laws.
CA-P-005752 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Hinge · Hinge Privacy Policy
Cross-border transfers of personal data from the EEA to the United States require specific legal safeguards under GDPR, and users in the EEA should understand that their data is ultimately processed within a US-headquartered corporate group.
CA-P-006693 First tracked May 8, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Duo Security · Duo Privacy
Cross-border transfers of authentication data to the US are subject to EU privacy rules, and Standard Contractual Clauses are the primary safeguard Cisco uses, but the adequacy of those safeguards depends on implementation and cannot be assumed without verification.
CA-P-007439 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Anthropic · Anthropic Privacy Policy
Cross-border data transfers from the EU and UK to the U.S. are subject to specific legal requirements under GDPR, and users should be aware that their data leaves their home jurisdiction, even if transfer safeguards are in place.
CA-P-007410 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
NVIDIA NIM · NVIDIA Privacy Policy
The policy discloses that personal data may be transferred internationally and that NVIDIA relies on Standard Contractual Clauses or equivalent mechanisms; the adequacy of these mechanisms and NVIDIA's implementation of supplementary safeguards is relevant for EU/EEA and UK users.
CA-P-011885 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Synthesia · Synthesia Privacy Policy
International data transfers are a key area of GDPR enforcement and EU users should be aware that their data may be processed in countries with different privacy standards, though Synthesia asserts it uses approved transfer mechanisms.
CA-P-009279 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Lime · Lime Privacy Policy
For EU, UK, and other international users, this means their personal data including location history may be transferred to a jurisdiction with a different privacy legal framework, and the adequacy of the transfer mechanisms protecting that data is not detailed in the notice.
CA-P-008700 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Atlassian · Atlassian Privacy Policy
The policy states that personal data from EU and UK users may be transferred internationally and that Standard Contractual Clauses are the stated mechanism, which matters because the adequacy of these mechanisms for transfers to certain jurisdictions may require ongoing assessment under post-Schrems II guidance.
CA-P-011765 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Databricks · Databricks Privacy Notice
International data transfers from the EU require specific legal safeguards and the adequacy of Standard Contractual Clauses as a transfer mechanism has been the subject of ongoing legal scrutiny, meaning the practical protection afforded depends on Databricks' implementation.
CA-P-004413 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Grammarly · Grammarly Privacy Policy
For users in the EU, UK, or other jurisdictions with strong data protection laws, transferring data to the US requires specific legal safeguards, and the adequacy of those safeguards has been subject to ongoing legal scrutiny.
CA-P-004133 First tracked Apr 30, 2026 Last seen May 22, 2026 Compare across platforms →
Stripe · Stripe Privacy Policy
This provision establishes the legal mechanisms Stripe relies upon for cross-border data transfers, which are subject to ongoing regulatory review and potential challenge; organizations processing EU or UK personal data through Stripe must confirm these mechanisms remain current and adequate under applicable law.
CA-P-012529 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Okta · Okta Privacy Policy
EU, UK, and Swiss users' personal data is being transferred to the United States, and the legal validity of that transfer depends on Okta's correct implementation of the current SCCs, which were updated in 2021 and require accompanying transfer impact assessments.
CA-P-008605 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Canva · Canva Privacy Policy
Cross-border data transfers involving EU personal data require legally adequate safeguards under GDPR. Canva's reliance on Standard Contractual Clauses is a recognized mechanism but requires accompanying Transfer Impact Assessments under post-Schrems II obligations, and compliance with these requirements cannot be verified from policy text alone.
CA-P-010799 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Cursor · Cursor Privacy Policy
The policy references legally valid transfer mechanisms for EEA and UK data transfers but does not name the specific mechanism (such as Standard Contractual Clauses), which limits the ability of EEA or UK users to evaluate the adequacy of those protections without making a direct inquiry.
CA-P-011603 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Udemy · Udemy Privacy Policy
The legal mechanism used for cross-border data transfers determines what protections EU and UK users retain when their data is processed in the U.S.; the Data Privacy Framework has been adopted as an adequacy mechanism but remains subject to political and legal developments.
CA-P-010206 First tracked May 11, 2026 Last seen May 20, 2026 Compare across platforms →
ADP · ADP Privacy Statement
BCR are a recognized but operationally complex transfer mechanism. If regulators in any country determine that BCR do not provide adequate protection, data transfers relying on them could be suspended, potentially disrupting payroll and HR services.
CA-P-008498 First tracked May 10, 2026 Last seen May 20, 2026 Compare across platforms →
Google Cloud · Google Cloud Privacy
EU, UK, and Swiss users should know their data may be transferred to the United States, but Google states it uses legal transfer mechanisms to maintain applicable protections.
CA-P-008053 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
Fastly · Fastly Privacy Policy
Cross-border transfer mechanisms are a significant area of GDPR enforcement, and the adequacy of Standard Contractual Clauses depends on whether the destination country provides essentially equivalent protection. Organizations relying on SCCs may also need to conduct Transfer Impact Assessments.
CA-P-010404 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Figma · Figma Privacy Policy
EU and UK users' personal data is processed by Figma in the US, and the adequacy of the transfer mechanism used is subject to ongoing regulatory scrutiny, meaning users should understand that their data crosses borders and the legal protections that apply.
CA-P-010182 First tracked May 11, 2026 Last seen May 22, 2026 Compare across platforms →
Midjourney · Midjourney Privacy Policy
The policy asserts that consent to cross-border data transfer is established by a user's agreement to the policy itself; whether this mechanism satisfies GDPR Chapter V transfer requirements may require evaluation under applicable law, as the policy separately references use of standard contractual clauses for EEA, Switzerland, and UK users.
CA-P-010981 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
Dun & Bradstreet · D&B Terms of Use
For EU and UK users, international data transfers are subject to strict legal requirements under GDPR, and a general website consent embedded in terms of use may not constitute a sufficient legal basis for such transfers under applicable law.
CA-P-008408 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Leonardo AI · Leonardo AI Privacy Policy
This provision authorizes international transfers of user personal data and asserts that transfer safeguards such as Standard Contractual Clauses are in place, but does not identify specific recipient countries or named third-party recipients for these transfers.
CA-P-012583 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
DoorDash · DoorDash Privacy Policy
The policy states that personal information may be transferred and processed outside the user's home jurisdiction, including outside Australia, Canada (and Quebec specifically), New Zealand, and the United States, without specifying the legal mechanisms used to authorize those transfers.
CA-P-010988 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial