IBM watsonx procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ Contractual Clauses, such as those approved by the EU Commission and accepted in several other countries. Data Privacy Framework Certification. Where applicable, certain designated IBM services (for example, IBM Infrastructure-as-a-Service, Platform-as-a-Service, Software-as-a-Service, and select other hosted offerings) are certified to comply with the Data Privacy Framework. For more information, see IBM Data Privacy Framework Policy for Certified IBM Cloud Services . Binding Corporate Rules for Controllers (IBM BCR-C). We have BCR-C approved by the European Data Protection Authorities and the UK Information Commissioner’s Office. For more information, see IBM Controller Binding Corporate Rules . IBM’s privacy practices, described in this Privacy Statement, comply with the Global Cross-Border Privacy Rules (CBPR) Program Requirements. The Global Cross-Border Privacy Rules (CBPR) System provides protection of personal information and supports trusted and secure international data flows among participating jurisdictions as it pertains to online information collected through ibm.com . IBM’s privacy practices, described in this Privacy Statement, comply with the APEC Cross Border Privacy Rules Framework. The APEC Cross Border Privacy Rules (CBPR) system provides protection of personal information that is transferred among participating APEC economies as it pertains to online information collected through ibm.com.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ Your personal information may be transferred to or accessed by IBM subsidiaries and third parties globally. IBM complies with laws on the transfer of personal information between countries to keep your personal information protected, wherever it may be.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ The contact details of the main subsidiary of a country or region can be found here .” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ You can verify the status of requests that you have submitted by using the DR webform in the IBM Trust Center for 90 days after completion of the request. The data relevant to your DR request is retained for a minimum of three years from the date of your last DR-related communication with IBM, to address any request you may have in relation to it, and for IBM's compliance and recording purposes.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ audit and accounting purposes, statutory retention terms, the handling of disputes, and the establishment, exercise, or defense of legal claims in the countries where we do business. ” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ When an employee leaves IBM, we retain basic information from the former employee about their employment at IBM.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We only retain personal information as long as necessary to fulfill the purposes for which it is processed, or to comply with legal and regulatory retention requirements. Legal and regulatory retention requirements may include retaining information for:” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ When personal information is no longer needed, we have processes in place to securely delete it, for example by erasing electronic files and shredding physical records.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain any contractual relationship information for administrative purposes, legal and regulatory retention requirements, defending IBM rights, and to manage IBM's relationship with you. The information that is provided in a supplementary privacy notice may provide more detailed information on applicable retention terms.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Our internal access to personal information is restricted and granted only on a need-to-know basis. Sharing of this information is subject to the appropriate intracompany arrangements, our policies, and security standards. For more information, see Legal Basis .” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We may share your personal information internally and externally with suppliers, advisors, or Business Partners for IBM’s legitimate business purposes, and only on a need-to-know basis.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Received from third-party data providers, subject to controls confirming that the third party legally acquired the information and has the right to provide the information to IBM for use in our marketing communications” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ If we decide to sell, buy, merge, or otherwise reorganize businesses in some countries, such a transaction may involve disclosing some personal information to prospective or actual business purchasers, or the collection of personal information from those selling such businesses.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Our websites offer the possibility to use third-party social media options. If you elect to use these options, these third-party sites may log information about you, such as your IP address, access time, and referring website URLs. If you are logged in to those social media sites, they may also link collected information with your profile information. We accept no responsibility for the privacy practices of these third-party services and encourage you to review their privacy policies for more information.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Internally, personal information is shared for our business purposes: to improve efficiency, for cost savings, and internal collaboration between our subsidiaries (such as Red Hat). For example, we may share personal information such as managing our relationship with you and other external parties, compliance programs, or systems and networks security.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “In certain circumstances, personal information may be subject to disclosure to government agencies in accordance with judicial proceedings, court orders, or legal processes. We may also share personal information to protect the rights of IBM or others when IBM believes that such rights may be affected, for example to prevent fraud.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ protect or enforce our rights, including to detect fraud or other criminal activities (for example, by using information in payment systems) handle and resolve disputes answer complaints and defend IBM in legal proceedings and comply with legal obligations in the countries where we do business” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ When sharing personal information, we implement appropriate checks and controls to confirm that the information can be shared in accordance with the applicable law.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ If your IBMid is created through an Enterprise Federation Partner (Identity Provider), basic personal information is collected from the Identity Partner and shared with IBM.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We prepare reports on the use of our websites to derive insights into trending topics and general market knowledge. These reports may be provided to third parties with details on how users interacted with or showed interest in the third-party products or services that were presented on our websites.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may share your personal information internally and externally with suppliers, advisors, or Business Partners for IBM’s legitimate business purposes, and only on a need-to-know basis. This section describes how we share information and how we facilitate that sharing.” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.