Provision Registry

12505 classified provisions across 299 platforms — browse, filter, and compare.

Every clause classified by type, severity, and platform. Updated as policies change.

Start Compliance free trial Track specific clauses across platforms with provision-level alerts.
medium Privacy rights
Adyen · Adyen Privacy Policy
Cross-border transfers expose your data to legal systems with potentially lower privacy protections than the EU or UK, and the adequacy of Standard Contractual Clauses as a safeguard depends on ongoing regulatory and judicial developments.
CA-P-008769 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
NVIDIA NIM · NVIDIA Privacy Policy
The policy discloses that personal data may be transferred internationally and that NVIDIA relies on Standard Contractual Clauses or equivalent mechanisms; the adequacy of these mechanisms and NVIDIA's implementation of supplementary safeguards is relevant for EU/EEA and UK users.
CA-P-011885 First tracked May 12, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data sharing
Pinterest · Pinterest Privacy Policy
The clause establishes the geographic scope of data processing operations and creates a jurisdictional framework for where user information may be stored and accessed. For users in regulated regions, it conditions cross-border transfers on the existence of adequate legal safeguards, reflecting compliance with regional data protection requirements.
CA-P-010366 First tracked May 11, 2026 Last seen May 11, 2026 Compare across platforms →
medium Data sharing
Whatnot · Whatnot Privacy Policy
For users in the EU, UK, and other jurisdictions with strong data protection laws, this transfer must be covered by a lawful mechanism such as Standard Contractual Clauses, and the policy does not specify which transfer mechanism is used.
CA-P-007068 First tracked May 8, 2026 Last seen May 20, 2026 Compare across platforms →
medium Cross border
Square · Square Privacy Notice
The clause establishes the operational framework for Square's global data handling infrastructure, permitting the company to move personal information across jurisdictions with different regulatory environments. This authorization enables Square to centralize data processing, storage, and systems management across its international operations.
CA-P-007029 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Cross border
Figma · Figma Privacy Policy
The provision operationalizes Figma's data handling framework by establishing U.S. law as the governing framework and authorizing international data transfers. This determines the legal regime applicable to data management and defines the jurisdictional scope within which data protection obligations operate.
CA-P-006775 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
Webull · Webull Privacy Policy
For users outside the United States, particularly in the EU and UK, this means your personal and financial data may be subject to U.S. legal process and privacy standards that may differ from those that apply in your jurisdiction.
CA-P-000495 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Coinbase · Coinbase Privacy Policy
For EU and UK users, data transferred to the US is subject to US surveillance laws and the adequacy of Standard Contractual Clauses as a safeguard depends on Coinbase conducting and maintaining transfer impact assessments documenting risks and mitigations.
CA-P-001870 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Peloton · Peloton Privacy Policy
EU and UK users are entitled to have their data protected to GDPR standards even when transferred abroad, and this clause creates an obligation on Peloton to implement legally adequate transfer mechanisms such as Standard Contractual Clauses.
CA-P-003564 First tracked Apr 27, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Grindr · Grindr Privacy Policy
For EU and UK users, transferring sensitive personal data to the US without adequate transfer mechanisms can violate GDPR and create legal exposure for Grindr and reduced rights protections for users.
CA-P-009389 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Shopify · Shopify Privacy Policy
The policy states that personal data may be transferred across borders to jurisdictions with different data protection standards, and identifies Standard Contractual Clauses as the primary transfer mechanism for EEA, UK, and Swiss data, which requires ongoing legal validity assessments following the Schrems II ruling.
CA-P-000805 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Adobe · Adobe Privacy Policy
Users outside the U.S., particularly in the EU, have legal protections governing international data transfers, and the adequacy of those protections depends on the legal mechanisms Adobe uses, such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.
CA-P-001075 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Klarna · Klarna Privacy Policy
When your data is transferred outside the EU or UK, it may be subject to government access or privacy standards that are different from those in your home country, even if contractual protections are in place.
CA-P-000924 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Notion · Notion Privacy Policy
The policy asserts consent to international data transfer based on use of the service, but under GDPR this type of implied consent is generally insufficient as a transfer mechanism; the policy separately references Standard Contractual Clauses for EEA transfers, which is the operationally relevant mechanism for EU users.
CA-P-002962 First tracked Apr 18, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Uber · Uber Privacy Notice
Cross-border data transfers of EU/EEA driver data to the US and other third countries require valid transfer mechanisms under GDPR Chapter V, and the adequacy and supplementary safeguards supporting SCCs must be documented and available for supervisory authority review, particularly given the volume and sensitivity of the data categories involved.
CA-P-000767 First tracked Apr 3, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
HubSpot · HubSpot Privacy Policy
This provision establishes Standard Contractual Clauses as the primary mechanism for cross-border data transfers out of the EEA, which requires that a transfer impact assessment be conducted and documented for organizations subject to GDPR requirements.
CA-P-012542 First tracked May 20, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Stripe · Stripe Privacy Policy
International data transfers are subject to legal requirements in the EU, UK, and other jurisdictions, and the adequacy of Stripe's transfer mechanisms directly affects whether EU and UK user data is protected to required standards when processed outside those regions.
CA-P-002343 First tracked Apr 9, 2026 Last seen May 20, 2026 Compare across platforms →
medium Privacy rights
Activision · Activision Privacy Policy
For EU and UK users, the legal adequacy of data transfers to the US is an ongoing regulatory concern following the Schrems II decision, and the effectiveness of Standard Contractual Clauses depends on accompanying transfer impact assessments.
CA-P-007618 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data sharing
GitHub · GitHub Privacy Statement
The provision establishes the operational framework under which GitHub processes personal data across jurisdictions with varying legal protections. The use of Standard Contractual Clauses represents the contractual mechanism GitHub employs to comply with EU data transfer requirements and provide a defined safeguard structure for international data flows.
CA-P-001344 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
RapidAPI · RapidAPI Privacy Policy
Transferring personal data from the EU to the US requires specific legal mechanisms under GDPR, and users should understand their data may be processed under US law rather than their home country's privacy framework.
CA-P-007339 First tracked May 9, 2026 Last seen May 22, 2026 Compare across platforms →
medium Privacy rights
Auth0 · Auth0 Privacy Policy
Cross-border data transfers from the EU and UK to the US remain a significant regulatory concern following the Schrems II ruling, and the adequacy and current status of Okta's SCCs and any supplementary measures are important for both individual data subjects and enterprise customers.
CA-P-009759 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Data sharing
Twilio · Twilio Privacy Notice
The provision establishes the operational framework for cross-border data processing and specifies the contractual mechanisms Twilio uses to address jurisdictional differences in data protection requirements. This directly affects how personal information flows through Twilio's infrastructure and which legal standards apply to different segments of data processing.
CA-P-001328 First tracked Apr 3, 2026 Last seen May 11, 2026 Compare across platforms →
medium Cross border
Duolingo · Duolingo Privacy Policy
The clause establishes the geographic scope of data processing operations and notifies users that their information will be subject to the legal and regulatory frameworks of the jurisdiction where servers are located, rather than remaining under their home jurisdiction's data protection regime.
CA-P-005773 First tracked May 8, 2026 Last seen May 11, 2026 Compare across platforms →
medium Privacy rights
Thomson Reuters · Thomson Reuters Privacy
International data transfers are a key compliance area under GDPR; the sufficiency of transfer mechanisms depends on whether Thomson Reuters has conducted Transfer Impact Assessments, particularly for transfers to the United States.
CA-P-009351 First tracked May 10, 2026 Last seen May 22, 2026 Compare across platforms →
medium Cross border
Miro · Miro Privacy Policy
The clause establishes the operational framework for Miro's cross-border data processing infrastructure. It documents the company's use of a specific legal mechanism (Standard Contractual Clauses) to address the jurisdictional differences that arise when personal data moves between countries with varying regulatory requirements.
CA-P-004982 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Cross border
BeReal · BeReal Privacy Policy
The clause establishes the operational framework under which BeReal may process user data across multiple jurisdictions, creating a requirement that international transfers comply with EU-approved contractual mechanisms rather than relying solely on equivalence determinations.
CA-P-006341 First tracked May 8, 2026 Last seen May 8, 2026 Compare across platforms →
medium Privacy rights
ElevenLabs · ElevenLabs Privacy Policy
Cross-border data transfers from the EU/EEA to the United States require an approved transfer mechanism under GDPR Chapter V. The policy does not specify in detail which transfer mechanisms are relied upon, which warrants verification by compliance teams evaluating EU data flows.
CA-P-012817 First tracked May 21, 2026 Last seen May 22, 2026 Compare across platforms →
medium Cross border
Airbnb · Airbnb Privacy Policy
This provision establishes the operational framework under which Airbnb processes personal data across multiple jurisdictions. The clause addresses a core compliance requirement for international data transfers, particularly for EU/EEA users, by identifying the legal mechanisms (standard contractual clauses) used to authorize cross-border data movement.
CA-P-006871 First tracked May 8, 2026 Last seen May 12, 2026 Compare across platforms →
medium Cross border
Riot Games · Riot Games Privacy Notice
The provision establishes the operational framework under which Riot Games processes personal information across jurisdictions with varying regulatory requirements. Standard Contractual Clauses create a contractual basis for lawful international transfer where adequacy decisions do not exist, addressing the legal requirements imposed by EEA, UK, and Swiss data protection regimes.
CA-P-005353 First tracked May 7, 2026 Last seen May 7, 2026 Compare across platforms →
medium Data sharing
Lyft · Lyft Privacy Policy
Cross-border data transfer provisions establish the operational scope of data flows and define which legal frameworks govern data protection once information leaves the user's home jurisdiction. This affects the regulatory oversight and security standards applicable to personal information during transit and storage.
CA-P-000850 First tracked Apr 3, 2026 Last seen Apr 10, 2026 Compare across platforms →

Compliance Governance Intelligence

Monitor specific governance provisions across platforms.

Compliance includes provision-level monitoring, regulatory mapping, and audit-ready analysis.

Start free Start Compliance free trial