Skip to main content
At Nebius, we aim for maximum clarity and transparency in the processing of personal data so that you can be sure that all the personal data you provide, is processed by us only to the extent necessary and only for the necessary purposes, in full compliance with the current legislation in force, in particular with the General Data Protection Regulation (GDPR), on the processing of personal data, as amended, as well as other related data protection and data privacy legislation. The purpose of this document is to inform you as data subject (Job Candidate and soon to be an Employee) about your rights in connection with the processing of personal data in the framework of Nebius’ conflict of interest processing activity and its scope.

Processing activity

Since Nebius is a company providing infrastructure services, we have to conduct mandatory due diligence activity pursuant to applicable laws (see more details in section Legal basis of this document). The Conflict of Interest (COI) process aims to identify potential situations that could compromise the company’s independence, objectivity, or ethical standards. It helps to assess whether any employees or their close relatives may have personal, financial, or professional ties — including connections to entities in Russia or Belarus, to Yandex, or to shareholdings exceeding 5% — that could present a potential conflict with Nebius’ business interests. The information provided is used solely for internal risk assessment and compliance, in accordance with applicable data protection laws.

Controller

Nebius Group N.V. acts as a joint-data controller together with the actual Nebius Employer and conducts data processing relating to the assessment of a conflict-of-interestemployee due diligence activity based upon a legal obligation and a legitimate interest. Data controller details: Nebius Group N.V., Schiphol Boulevard 165, 1118 BG, Schiphol, Netherlands.

Who are the data subjects?

The types of data subjects, whose data are processed for the processing activity conflict-of-interestemployee due diligence activity are Nebius’ Employees and Board of Directors members.

What types of personal data are processed?

The categories of personal data, whose data are processed for the Processing activities in order as listed above are as follows:
  • Employees and Board of Directors and Conflict of Interest Screening: First Name, Last Name, Contact details of the employer.
  • Questions contained in the COI questionnaire, that will be sent to you shortly after you receive the job offer.

Specific privacy requirements for U.S. residents

Certain U.S. privacy laws, like the CCPA (California Consumer Privacy Act), require specific disclosures for California residents. This notice is meant to support you in understanding how the Company processes your personal data: in the paragraphs above, we provided the following disclosures: I- the categories of personal data we collect and the sources of this information; II- how we use this personal data; III- when we disclose this personal data and how we store this data. The Company will never sell your personal data and does not “share’ this data under the definition of the CCPA. A few States laws also provide the right to request information on how we collect, utilize and disclose your personal data. In certain cases you also have the right to access and amend your personal data, request deletion and not to be subject to any discrimination for exercising these rights. If you have any question or concern related to how we process your personal data under CCPA or would like to exercise your rights, please contact: privacy@nebius.com. California residents have the right to designate an authorized agent to make a request on their behalf. If you would like an authorized agent to do so, you should either (a) directly confirm with us that you provided the authorized agent permission to submit the request, (b) or provide the authorized agent with your power of attorney in accordance with the law of the jurisdiction in which you are located, or (c) submit the request in accordance with applicable legislation.

How long do we keep your data?

Nebius retains your personal data only for the time necessary to fulfill the purpose of collection or further processing, namely for the period of the contractual relationship with Employees and Board of Directors and then for5 years from the closure of the assessment.

Who are the data recipients?

In principle, personal data is only shared with third parties (e.g. public authorities) if this is necessary for exercising Nebius’s property rights, protecting Nebius property or preventing and investigating adherence to legal obligations or as performing legal obligations (e.g. in the context of administrative proceedings). In addition, personal data are shared with the service providersrendering services related to systems where we conduct the processing activity. This might involve data transfers to countries outside the EEA, the United Kingdom and Switzerland. To ensure an adequate level of data protection, we agree on EU Standard Contractual Clauses with Swiss and United Kingdom Addendums with the data recipients if there is no EU adequacy decision for the respective country or if there are no other permissible transfer mechanisms. This processing activity is conducted in accordance with legal obligations which are as follows:
  • NASDAQ Listing Rule5610
  • Regulation S-K, Item 408/Securities Exchange Act of 1934
  • FCPA 15 U.S.C. §§ 78dd-1, 78dd-2, 78dd-3
  • Dutch Corporate Governance Code
The applicable laws listed above mandate that this activity is rendered with respect to the Board of Director members and members of management. This processing activity is conducted based on alegitimate interest with respect to Employees, who are not the Board of Director members and members of management.

What are my data protection rights and how are my data protected?

The data controller declares that it has taken all appropriate technical and organizational measures to secure personal data. In particular, the data controller has taken technical measures to secure database storage and storage of personal data in documentary form, in particular by implementing secure/encrypted access to systems and premises, encryption of passwords of authorized persons, regular updates of systems and regular backups. The controller declares that only persons authorized by it have access to personal data. You may obtain information about our processing of your personal data. Furthermore, you have a right to data portability. In addition, we will rectify incorrect data and delete data if it is no longer required to fulfill the purposes stated above. If necessary for further investigation of the crime or for the exercise or defense of legal rights, we may also retain the records for a longer period as long as it is needed. In addition, there is the right to restriction of personal data processing, the right to object to processing of personal data and the right to lodge a complaint with the supervisory authority. If you have any further questions or wish to claim your rights, please contact our privacy and data protection team at privacy@nebius.com.
Publication date: October 24, 2025
Effective date: October 24, 2025