Data transfer impact assessment

V2.0 | Effective: September 29, 2026

GDPR DTIA overview

This document provides information to help Telnyx customers conduct their own transfer impact assessments in connection with their use of Telnyx services, in light of the recommendations from the European Data Protection Board.

In particular, this document describes the legal regimes applicable to Telnyx in the US, the safeguards Telnyx puts in place in connection with transfers of customer personal data from the European Economic Area, United Kingdom or Switzerland ("Europe"), and how Telnyx approaches its obligations as "data importer" under the Standard Contractual Clauses ("SCCs").

For more details about Telnyx's privacy practices, please visit the Telnyx Privacy Policy available at https://telnyx.com/privacy-policy.

STEP 1

Know your transfer

Where Telnyx processes personal data governed by European data protection laws as a processor (on behalf of our customers), Telnyx complies with its obligations under its Data Processing Addendum available at telnyx.com/legal/data-processing-addendum ("DPA"). The DPA incorporates the SCCs and provides the following information:

  • Description of Telnyx's processing of customer personal data; and
  • Description of Telnyx's security measures.

Please refer to the DPA for information on the nature of Telnyx's processing activities in connection with the provision of the Services, the types of customer personal data we process and transfer, and the categories of data subjects. Telnyx also acts as an independent controller for certain data, as described in Section 2 of the DPA, and the SCC modules apply accordingly.

Telnyx's Sub-processors are listed at telnyx.com/legal/subprocessors, and changes are notified as described in the DPA.

We may transfer customer personal data wherever we or our Sub-processors operate for the purpose of providing the Services. Where a customer selects a processing or storage region, data is processed as described in Section 5.5 of the DPA. Customer communications may also transit third-party telecommunications networks and messaging platforms, and customer-selected AI providers may process customer inputs, as described in Sections 4.6 and 4.8 of the DPA.

STEP 2

Identify the transfer tool relied upon

Where personal data originating from Europe is transferred to Telnyx, Telnyx relies upon the EU-U.S. Data Privacy Framework ("DPF") (including the UK Extension and the Swiss-U.S. DPF) and the SCCs, as set out in Sections 5.1 and 5.6 of the DPA. If Telnyx's DPF certification ceases to apply, the SCCs continue to apply. To review these terms, please see the DPA.

Where customer personal data originating from Europe is transferred between Telnyx group companies or by Telnyx to Sub-processors, Telnyx engages them on written terms and puts transfer mechanisms in place as required by Sections 4.1 and 5.4 of the DPA.

STEP 3

Assess whether the transfer tool relied upon is effective in light of the circumstances of the transfer

U.S. Surveillance Laws

FISA 702, Executive Order 12333 and Executive Order 14086

The following US laws were identified by the Court of Justice of the European Union in Schrems II as potential obstacles to ensuring essentially equivalent protection for personal data in the US, together with the executive order adopted in response to that judgment:

  • FISA Section 702 ("FISA 702"): allows US government authorities to compel providers to assist in acquiring the communications of non-US persons reasonably believed to be located outside the US for the purpose of acquiring foreign intelligence information. The Foreign Intelligence Surveillance Court approves annual certifications rather than individual targets. In-scope providers are electronic communication service providers ("ECSP") within the meaning of 50 U.S.C. § 1881(b)(4). Section 702 sunset on June 12, 2026. Directives issued before that date remain in effect until they expire, and Congress may reauthorize the authority.
  • Executive Order 12333 ("EO 12333"): authorizes intelligence agencies (like the US National Security Agency) to conduct surveillance outside of the US. In particular, it provides authority for US intelligence agencies to collect foreign "signals intelligence" information, being information collected from communications and other data passed or accessible by radio, wire and other electromagnetic means. This may include accessing undersea cables carrying internet data in transit to the US. EO 12333 does not itself authorize the compelled assistance of service providers.
  • Executive Order 14086 ("EO 14086"), adopted in 2022 in response to Schrems II, requires US signals intelligence activities to be necessary and proportionate and provides a redress mechanism for individuals in designated qualifying states, including the EU/EEA, the UK and Switzerland. It applies regardless of the transfer tool relied upon and may be amended or revoked.

The European Commission's adequacy decision for the DPF was upheld by the EU General Court in September 2025, and an appeal is pending. Telnyx maintains the SCCs alongside the DPF.

CLOUD Act

For more information on the CLOUD Act, review the U.S. Department of Justice's CLOUD Act white paper and frequently asked questions, available at https://www.justice.gov/criminal/cloud-act-resources.

  • The CLOUD Act requires providers subject to US jurisdiction to comply with valid US legal process for data in their possession, custody or control, regardless of where it is stored. The required legal process depends on the data sought.
  • The CLOUD Act concerns criminal law enforcement process and does not itself authorize foreign intelligence surveillance, and it does not authorize bulk surveillance.

Is Telnyx subject to FISA 702 or EO 12333?

Telnyx provides electronic communication services and falls within the FISA 702 definition of an electronic communication service provider. Telnyx does not represent that it is unlikely to receive a FISA 702 directive.

EO 12333 does not authorize the US government to compel Telnyx to disclose personal data, although data in transit over networks outside Telnyx's control could be collected under it without Telnyx's involvement.

To Telnyx's knowledge, as of September 29, 2026, Telnyx has not received a US national security request (including under FISA 702 or EO 12333) for customer personal data.

STEP 4

Identify the technical, contractual, and organizational measures applied to protect the transferred data

Telnyx uses the following technical measures to help protect customer data:

  • Encryption: Telnyx uses encryption as described in its Technical and Organizational Security Practices. Where Telnyx must process data in the clear to provide the Services (for example, to route calls and messages), encryption does not by itself prevent access to that data.
  • Security and certifications: Additional information about Telnyx's security practices and certifications is available at telnyx.com/legal/technical-organizational-security-practices and in the Telnyx Trust Center.

Telnyx's contractual measures are set out in the DPA, which incorporates the SCCs. In particular, we are subject to the following requirements:

  • Technical measures: Telnyx is contractually obligated to have in place appropriate technical and organizational measures to safeguard personal data under the DPA and the SCCs.
  • Transparency: Telnyx is obligated under the SCCs to notify the relevant customer if it receives a legally binding request from a public authority for disclosure of customer personal data transferred under the SCCs. Where Telnyx is legally prohibited from making such a disclosure, Telnyx will seek a waiver of the prohibition as required by the SCCs.
  • Actions to challenge access: Under the SCCs, Telnyx is obligated to review the legality of a request for disclosure and challenge it where, after careful assessment, Telnyx concludes there are reasonable grounds to consider it unlawful, and to disclose only the minimum information permissible.

Telnyx's organizational measures to secure customer data include:

  • Policy for government access: Telnyx responds to government requests for data in accordance with applicable law and the DPA. Telnyx generally requires law enforcement officials to provide legal process appropriate for the type of information sought, such as a subpoena, court order, or warrant, except where applicable law permits disclosure without legal process.
  • Onward transfers: Whenever we share customer personal data with Sub-processors, we remain responsible for them as set out in the DPA. We carry out a risk-based security assessment of vendors before engaging them and review them periodically, as described in our Technical and Organizational Security Practices.
  • Employee training: All Telnyx employees complete security and privacy training at least annually.

STEP 5

Procedural steps necessary to implement effective supplementary measures

In light of the information provided in this document, including Telnyx's practical experience with government requests and the technical, contractual, and organizational measures Telnyx has implemented to protect customer personal data, Telnyx has not identified laws or practices that, in its view, prevent it from fulfilling its obligations as data importer under the SCCs. This is not a guarantee that personal data will not be accessed by public authorities. Each customer, as data exporter, remains responsible for its own assessment, including whether supplementary measures are appropriate for its transfers.

STEP 6

Re-evaluate at appropriate intervals

Telnyx will review this assessment when there are material developments and will update the risks involved and the measures it has implemented as appropriate. Telnyx will notify customers as required by Clause 14(e) of the SCCs.


Legal Notice: Customers are responsible for making their own independent assessment of the information in this document. This document: (a) is for informational purposes only and is not legal advice, (b) represents current Telnyx product offerings and practices, which are subject to change without notice, and (c) does not create any commitments or assurances from Telnyx and its affiliates, suppliers or licensors. The responsibilities and liabilities of Telnyx to its customers are controlled by Telnyx agreements, and this document is not part of, nor does it modify, any agreement between Telnyx and its customers.