The same company, a different document.
GDPR gives EU and UK users leverage US users don't have, and companies that operate globally often respond by publishing a second privacy policy for European users instead of rewriting the global one. That second document is easy to miss. It's usually one small link at the top of the page you're already reading.
The difference usually isn't a second document
12 of the 19 findings below turn on the same mechanism. A company writes that it trains on your data because doing so is in its legitimate interest, Article 6(1)(f), and then, further down, grants a right to object to processing carried out on that basis. Those two sentences are rarely near each other, and together they mean a reader in the EEA has a route to stopping the training that a reader in the US is simply not offered. In most of these cases no separate European policy is involved at all: the asymmetry is inside the one document everybody is already reading. TikTok is the exception. There, the European text really is a different page.
Where a row says “not established”
This monitor archives and quotes exactly the source documents registered for each company. See methodology. When a company splits its policy by region, the non-US version isn't automatically in scope. Someone has to register it as its own source before we can quote it. And a policy that names the UK in passing without naming UK GDPR hasn't told us that UK readers get the same treatment as EEA ones. In both cases the honest answer is "not established", not "same". Asserting equivalence we haven't checked is exactly the kind of unsourced claim this site exists to avoid making about anyone else.
What we've checked so far
- same as uk — the supplement covers both, under the Irish and UK Airbnb entities it names
- The Outside the United States Privacy Supplement applies, and adds an objection right: where processing rests on legitimate interest, "including where we use your personal information to develop and improve AI", you may object with reasons specific to your circumstances. Airbnb undertakes to review the objection, not to grant it.
- A separate United States Privacy Supplement exists and is not archived here, so the objection route above should not be assumed to apply. The preference named in the verdict is in the global policy and is not marked as regional.
- Different — the policy grants a right to object to processing done under "legitimate interest" (commonly Article 21 GDPR, though the policy itself doesn't cite the article number), which is the stated legal basis for AI/ML model training here. The policy warns that exercising it "may mean no longer using the Services."
- same as eu
- same as global baseline — no equivalent objection right is stated in this policy
- The opt-out is stated in the Regional Privacy Disclosures, whose preamble covers the US, EEA and UK. It sits above both regional sections rather than inside either, so it reads as general — but the document is framed as additional information for those jurisdictions.
- Same document, same ambiguity. The U.S. State Privacy Notice below it describes an advertising and sale opt-out, not a training one.
- Cohere names AI models directly in its legal basis — legitimate interests in "operating, securing, and improving our business and AI technologies, including enhancing the performance, reliability, and safety of our AI models" — and grants the right to "Object to our processing of your personal information where we are relying on a legitimate interest as our legal basis". The two clauses meet: in the EEA the model-improvement basis is objectable.
- The same, as stated. This policy names UK law explicitly alongside the EEA provisions, so the objection right is offered to UK readers on the same footing.
- No objection right. The US portion of the policy is about California retention and disclosure, and the training question is answered by the Model Training Privacy Notice instead — which rests on permission having been given rather than on legitimate interest.
- Accounts in the EEA, the UK and Switzerland get a switch in account settings, "Use personal data for AI development and training", on by default; the page says it is intended for those regions. Everywhere else the objection right is exercised as a request through the eBay Privacy Center.
- Different — the policy lists "the right to object to the processing of your Personal Data, as allowed by applicable law" among rights tied to residence location, covering the legitimate-interest basis it cites for AI/ML development. No comparable objection right is stated for the US baseline.
- same as eu
- same as global baseline — no equivalent objection right is stated in this policy
- The cited capture is the European-served text: it states interactions-training and names Google Ireland Limited as the data controller responsible for processing information to train Google's AI models. The EU/UK objection right in the control search applies to exactly these readers.
- same as eu
- Different — the US-served text omits the interactions-training sentence entirely; its only training language covers publicly available information, and it adds that Google does not sell or "share" (as the CCPA defines it) personal information. It neither repeats nor denies the interactions claim.
- Grammarly states the AI basis about as plainly as it can be stated: "We have a legitimate interest in operating and improving our services and developing new products through the use of AI (Art. 6 (1)(f) GDPR/ UK GDPR)". It then grants a right to object to processing carried out on a legitimate-interest basis. In the EEA that is a route to stopping the AI processing, exercised as a request rather than a setting.
- The same. The clause cites UK GDPR in the same breath as GDPR, so the basis and the objection right are stated for UK readers too.
- Not offered. The legal-basis framing exists only for readers the GDPR and UK GDPR cover; a US reader is given no corresponding way to object to the AI processing described in that clause.
- Weaker than the others on this page, and included because the structure is the same: Loom lists "develop and improve our Services" among its legitimate interests, and offers the right "to object to our use of information". Note the hedge — those rights are offered "where applicable under local law", and the improvement purpose is not tied specifically to AI, so this is a route worth knowing about rather than a stated remedy against training.
- Not established separately. The policy mentions the UK but does not name UK GDPR or the Data Protection Act, so it does not say whether UK readers get the same treatment as EEA readers.
- Not offered. The rights list is conditioned on local law, and the policy describes no US mechanism for objecting to the development-and-improvement purpose.
- The graded tier. The UK-served text's legitimate-interests table names developing and improving artificial intelligence technology as a purpose and lists public content and interactions with AI at Meta as the information used for it. The objection form is on Meta's generative-AI page, which states legitimate interests for the UK and EU.
- Different — the US-served text (Internet Archive, 1 June 2026) lists interactions with AI at Meta among the information collected and names no AI-development purpose. Graded UNCLEAR as its own tier rather than inferred from the UK text.
- same as uk
- The page read is the UK Privacy Centre text. It states legitimate interests as the basis "in the European region and the United Kingdom" and offers the objection form.
- The same page says that for other jurisdictions Meta relies on "an adequate legal basis", and that the objection forms shown depend on your region.
- The German-account policy is the one read; N26's hub page links a separate PDF for each of Germany, Austria, Spain and France.
- The text quoted is the en-GB policy, saved by hand on 6 September 2026. The switch and the training statement are not region-specific.
- Slack's predictive models are the training exposure in this verdict, and its policy says it "primarily relies on its legitimate interests" for processing. It then adds that "where we rely on legitimate interests ... you can object to that processing", and that it will stop unless it has compelling grounds. For EEA readers that runs in parallel with the global-model opt-out — and unlike that opt-out, it is not restricted to workspace owners.
- The same, as stated. The policy names the UK Data Protection Act alongside the GDPR when describing when a legal basis is required.
- No objection right. A US reader's only stated route is the one in the verdict: an org or workspace owner emailing Customer Experience to exclude the workspace from Slack's global models. Also named alongside the GDPR is Brazil's LGPD.
- Unverified, and probably different. Spotify publishes regional privacy policies and this monitor archives only the US one. That matters more here than usual: the words "legitimate interest", "object" and "restrict" appear zero times in the US text, and a GDPR-facing version would be expected to state the objection right the US version does not. Do not read the F above as a finding about the European policy.
- unverified — see eu
- the policy quoted above — Spotify serves it at /us/legal/privacy-policy/, and it is the document this verdict grades
- The graded tier: the Meta Privacy Policy's UK-served text governs, and it names AI development as a purpose with public content as its input; the objection form is on Meta's generative-AI page.
- Different — the Meta Privacy Policy's US-served text names no AI-development purpose. Unresolved as its own tier rather than inferred from the UK text.
- This verdict is based on the EEA policy. It states a right to object to processing carried out on public-interest and legitimate-interest bases, which is where the training purpose sits — a remedy you must exercise, not a switch.
- Not established separately. The EEA page is the only TikTok policy this monitor can read; whether the UK text matches it has not been checked.
- Not established — see row.
- Not established. The rest-of-world policy page renders client-side, so there is no readable capture of it to compare against the EEA text quoted here.
- Unverified. Uber publishes this notice per country, and only the UK version is archived here. An EEA version would be expected to state the Article 21 objection right this one does not, so do not read the F above as a finding about it.
- the notice captured above — Uber serves a per-country document and this is the United Kingdom one
- unverified — see eu; the US notice is a separate document this monitor has not captured
- The encryption sentence is from the European Region policy, provided by WhatsApp Ireland; the AI tier rests on Meta's generative-AI page, which states legitimate interests for the UK and EU and offers the objection form.
- Served under the global text (WhatsApp LLC). Same encryption, stated as "encrypted to protect against us and third parties from reading them", and no AI section.
- same as uk