Oracle AI Services procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | medium | “The audit shall be conducted no more than once during a twelve-month period, during regular business hours, subject to Oracle’s on-site policies and regulations, and may not unreasonably interfere with business activities. If You would like to use a third party to conduct the audit, the third party auditor shall be mutually agreed to by the parties and the third-party auditor must execute a written confidentiality agreement acceptable to Oracle. Upon completion of the audit, You will provide Oracle with a copy of the audit report, which is classified as confidential information under the terms of Your agreement with Oracle.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “Oracle will contribute to such audits by providing You with the information and assistance reasonably necessary to conduct the audit, including any relevant records of processing activities applicable to the Services. If the requested audit scope is addressed in a SOC 1 or SOC 2, ISO, NIST, PCI DSS, HIPAA or similar audit report issued by a qualified third party auditor within the prior twelve months and Oracle provides such report to You confirming there are no known material changes in the controls audited, You agree to accept the findings presented in the third party audit report in lieu of requesting an audit of the same controls covered by the report. Additional audit terms may be included in Your order for Services.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “For personal information collected INSIDE the EU/EEA, You may contact Oracle’s external EU Data Protection Officer by filling out the [inquiry form](https://www.oracle.com/legal/data-privacy-inquiry-form/) and selecting “Other Privacy Inquiry - Contact our DPO” in our drop down box or by written inquiry to.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “See [additional details](https://www.oracle.com/contracts/) regarding the specific security measures that apply to the Services are set out in the security practices for these Services, including regarding data retention and deletion, available for review.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “You control access to Your Services Personal Information by Your end users, and Your end users should direct any requests related to their Services Personal Information to You. To the extent such access is not available to You, Oracle will provide reasonable assistance with requests from individuals to access, delete or erase, restrict, rectify, receive and transmit, block access to or object to processing of Services Personal Information on Oracle systems. If Oracle directly receives any requests or inquiries from Your end users that have identified You as the controller, we will promptly pass on such requests to You without responding to the end user.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Please see the [Data Privacy Framework website](https://www.dataprivacyframework.gov/) or refer to [this list of U.S. entities](https://www.oracle.com/legal/privacy/data-protection-authority/#dpf) covered under Oracle’s DPF self-certification. With respect to Services Personal Information received or transferred pursuant to the DPF, the Federal Trade Commission has jurisdiction over Oracle’s compliance with the DPF.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Oracle is a global corporation with operations in over 80 countries and Services Personal Information may be processed globally as necessary in accordance with this policy and other relevant privacy terms specified applicable to Your Services. If Services Personal Information is transferred to an Oracle recipient in a country that does not provide an adequate level of protection for personal information, Oracle will take adequate measures designed to protect the Services Personal Information, such as ensuring that such transfers are subject to the terms of the EU Standard Contractual Clauses or other adequate transfer mechanism as required under relevant data protection laws.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ For personal information collected INSIDE the EU/EEA, You may contact Oracle’s external EU Data Protection Officer by filling out the inquiry form and selecting “Other Privacy Inquiry - Contact our DPO” in our drop down box or by written inquiry to.” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In the event the Services agreement between You and Oracle references the Oracle Data Processing Agreement for Oracle Services (“DPA”), further details on the relevant data transfer mechanism that applies to Your order for Oracle services are available in the DPA. In particular, for Services Personal Information transferred from the European Economic Area (EEA) or Switzerland, such transfers are subject to Oracle’s Binding Corporate Rules for Processors (BCR-P) or the terms of the EU Standard Contractual Clauses. For Services Personal Information transferred from the United Kingdom (UK), such transfers are subject to the UK Addendum or other appropriate transfer mechanism.” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “3.3 Oracle will maintain means to track , inventory, and monitor AI Systems that have undergone an AI System review and have been deployed as required by applicable law. 3.4 Oracle periodically reviews and updates the Oracle AI System Development Practices, including to account for changes in applicable regulations and industry standards. The Oracle AI System Development Practices apply to AI Systems developed after April 1, 2025.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “If personal information contained in Systems Operations Data is transferred to an Oracle recipient in a country that does not provide an adequate level of protection for personal information, Oracle will take measures designed to adequately protect information about Users, such as ensuring that such transfers are subject to the terms of the EU Standard Contractual Clauses or other adequate transfer mechanism as required under relevant data protection laws.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “You are the controller of the Services Personal Information processed by Oracle to perform the Services. Oracle will process your Services Personal Information as specified in Your Services order and Your documented additional written instructions to the extent necessary for Oracle to (i) comply with its processor obligations under applicable data protection law or (ii) assist You to comply with Your controller obligations under applicable data protection law relevant to Your use of the Services. Oracle will promptly inform You if, in our reasonable opinion, Your instruction infringes applicable data protection law. You acknowledge and agree that Oracle is not responsible for performing legal research and/or for providing legal advice to You. Additional fees may apply.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Oracle also complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) (collectively, the “DPF”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of Services Personal Information when You and Oracle have agreed by contract that transfers of such information from the EEA, United Kingdom (and Gibraltar), or Switzerland will be transferred and processed pursuant to the applicable DPF for the relevant Services. Oracle will then be responsible for ensuring that third parties acting as a subprocessor on our behalf do the same. Oracle shall remain liable under the DPF Principles if its subprocessor processes Services Personal Information in a manner inconsistent with the DPF Principles, unless Oracle proves that it is not responsible for the event giving rise to the damage.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “To the extent provided in your order for Services, You may at Your sole expense audit Oracle’s compliance with the terms of this Services Privacy Policy by sending Oracle a written request, including a detailed audit plan, at least two weeks in advance of the proposed audit date. You and Oracle will work cooperatively to agree on a final audit plan.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Oracle has certified to the U.S. Department of Commerce that it adheres to the DPF Principles with regard to Services Personal Information (as described above) that is transferred from the European Union, the United Kingdom (and Gibraltar), and/or Switzerland to the United States when specified in a relevant contract. If there is any conflict between the terms in this Services Privacy Policy and the DPF Principles, the DPF Principles shall govern. To learn more about the DPF program, and to view Oracle’s certification, please visit the Data Privacy Framework website .” | Captured 2026-08-12Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “In the event the Services agreement between You and Oracle references the [Oracle Data Processing Agreement for Oracle Services](https://www.oracle.com/contracts/cloud-services/) (“DPA”), further details on the relevant data transfer mechanism that applies to Your order for Oracle services are available in the DPA. In particular, for Services Personal Information transferred from the European Economic Area (EEA) or Switzerland, such transfers are subject to Oracle’s Binding Corporate Rules for Processors (BCR-P) or the terms of the EU Standard Contractual Clauses. For Services Personal Information transferred from the United Kingdom (UK), such transfers are subject to the UK Addendum or other appropriate transfer mechanism.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Oracle has certified to the U.S. Department of Commerce that it adheres to the DPF Principles with regard to Services Personal Information (as described above) that is transferred from the European Union, the United Kingdom (and Gibraltar), and/or Switzerland to the United States when specified in a relevant contract. If there is any conflict between the terms in this Services Privacy Policy and the DPF Principles, the DPF Principles shall govern. To learn more about the DPF program, and to view Oracle’s certification, please visit the [Data Privacy Framework website](https://www.dataprivacyframework.gov/).” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ See additional details regarding the specific security measures that apply to the Services are set out in the security practices for these Services, including regarding data retention and deletion, available for review.” | Captured 2026-08-12Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “- c) to administer our back-up disaster recovery plans and policies;” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “Except as otherwise specified in an order for services or required by law, upon termination of services, Oracle will return or delete any remaining copies of Your production customer data, including any Services Personal Information, located on Oracle systems or Services environments. Additional information on data deletion functionality is provided in the applicable Services descriptions.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ 2. deletes personal information we collected about You or corrects inaccurate personal information about You, unless retained solely for legal and compliance purposes and as otherwise set out in the CCPA” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ as required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to government requests, including public and government authorities outside your country of residence, for national security and/or law enforcement purposes.” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ third-party service providers (for example IT service providers, lawyers and auditors) in order for those service providers to perform business functions on behalf of Oracle;” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “- the categories of third parties to whom we sold or otherwise disclosed personal information, if applicable.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- as required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to government requests, including public and government authorities outside your country of residence, for national security and/or law enforcement purposes.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “Oracle maintains lists of Oracle affiliates and subprocessors that may process Services Personal Information. Additional information is available to You via My Oracle Support ( [https://support.oracle.com](https://support.oracle.com/)) Document ID 2121811.1, or other applicable primary support tool provided for the Services.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “We may also share such personal information with the following third parties:” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Oracle may be required to provide access to Services Personal Information and to personal information contained in Systems Operations Data as required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect Your or a User’s safety or the safety of others, investigate fraud, or respond to government requests, including public and government authorities outside Your or a User’s country of residence, for national security and/or law enforcement purposes.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- relevant third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings);” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- f) to comply with applicable laws and regulations and to operate our business, including to comply with legally mandated reporting, disclosure or other legal process requests, for mergers and acquisitions, finance and accounting, archiving and insurance purposes, legal and business consulting and in the context of dispute resolution.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Oracle Corporation and its affiliated entities are responsible for processing personal information that may be incidentally contained in Systems Operations Data in accordance with Sections II and III of this Policy. See the list of [Oracle entities](https://www.oracle.com/corporate/contact/global.html). Please select a region and country to view the registered address and contact details of the Oracle entity or entities located in each country.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ relevant third parties in the event of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings);” | Captured 2026-08-12Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “When third parties are given access to personal information contained in Systems Operations Data, we will take the appropriate contractual, technical and organizational measures to ensure, for example, that personal information is only processed to the extent that such processing is necessary, consistent with this Privacy Policy and in accordance with applicable law. Oracle does not share or sell Systems Operations Data subject to this Privacy Policy with third parties for any commercial purposes.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- third-party service providers (for example IT service providers, lawyers and auditors) in order for those service providers to perform business functions on behalf of Oracle;” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Oracle will promptly inform You of requests to provide access to Services Personal Information, unless otherwise required by law.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “To the extent Oracle engages Oracle affiliates and third-party subprocessors to have access to Services Personal Information for the purpose of assisting in the provision of Services, such subprocessors shall be subject to the same level of data protection and security as Oracle under the terms of Your order for Services. Oracle is responsible for its subprocessors’ compliance with the terms of Your order for Services.” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.