DPA Checker

Are your tech vendor data processing agreements compliant?

It's tempting to assume that you don't need to do much due diligence on popular vendors (if everyone's using them, they must be fine, right?) However, if you are sharing, uploading or inputting personal data to a SaaS, PaaS, IaaS platform it's likely that they will be a "data processor" under the GDPR/UK GDPR. And using these platforms doesn't relieve you from any of your legal obligations… in fact, it gives you additional obligations to verify their suitability for the task and ensure that a compliant data processing agreement is in place.

Many of the most commonly used tech vendors publish their data processing agreements and other GDPR compliance information online. The team at ClearCube has built an AI tool to check these documents and verify whether they meet the relevant rules — primarily whether the DPAs include all the provisions required by Article 28(3) of the GDPR, alongside a few other questions to help assess their suitability as a vendor. The results are below.

This tool isn't (currently!) interactive, however, if a vendor you'd like to check isn't on the list just let us know. For a limited time only, we'll be taking requests to add vendors to this list free of charge!

If you'd like us to perform a check on any vendor you use that doesn't make its GDPR documents publicly available, please contact us. We won't include them in this DPA Checker, but we'll be able to run an individual check, just for you.

29 organisations reviewed.

8x8

GDPR Addressed

8x8's DPA addresses the key GDPR requirements for EU, UK and Swiss data processing, with SCCs, flowdown obligations and processor-only restrictions in place. The main practical limitation is that audit rights are structured: customers receive summary audit reports rather than conducting open on-site inspections.

DPA: 07 Feb 2025 · Reviewed: 01 Jun 2026 Read more →

Abacum

Data Use Review

Abacum's DPA explicitly designates Abacum as an independent controller for account and usage data, permitting it to use that data to optimise the platform for its own purposes beyond the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

DPA: N/A · Reviewed: 17 Jun 2026 Read more →

Adobe

GDPR Addressed

Adobe's DPA is comprehensive, covering processor obligations, SCCs for EU/UK/Swiss transfers, sub-processor flowdown, breach notification, structured audit rights and DPIA assistance. Adobe explicitly restricts itself to acting as a processor only, with no independent use of personal data permitted.

DPA: 01 Jun 2024 · Reviewed: 01 Jun 2026 Read more →

Airtable

GDPR Addressed

Airtable's DPA covers the key GDPR requirements, including EU/UK/Swiss SCCs, 72-hour breach notification, and sub-processor flow-down obligations. The main practical point to note is that the DPA only becomes binding once separately executed via Airtable's online form, and is limited to Enterprise plans.

DPA: 05 Dec 2025 · Reviewed: 27 Jul 2026 Read more →

Amazon

GDPR Addressed

AWS's DPA addresses the key GDPR requirements, covering EU, UK, Swiss and US requirements with SCCs and processor-only restrictions in place. Audit rights are structured: customers access certifications and SOC reports rather than direct on-site inspections, but all material provisions are satisfied.

DPA: 27 Jul 2023 · Reviewed: 01 Jun 2026 Read more →

Anthropic

GDPR Addressed

Anthropic's DPA addresses the key GDPR requirements, including SCCs and UK/Swiss addenda for international transfers, 48-hour breach notification, and a clear restriction against using Customer Personal Data for purposes such as model training. The main reason for confidence is this strong sole-processor commitment.

DPA: 24 Feb 2025 · Reviewed: 27 Jul 2026 Read more →

Apple

Data Use Review

Apple's DPA covers the required processor obligations in respect of customer provided personal data. Apple reserves the right to collect diagnostic and usage data from users for its own internal purposes and to disclose personal data to protect its operations — it is not acting solely as a processor. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

DPA: 09 Sept 2025 · Reviewed: 03 Jun 2026 Read more →

Atlassian

Data Use Review

Atlassian's DPA covers the required processor obligations in respect of customer provided personal data. Atlassian's DPA explicitly permits Atlassian to "de-identify" and aggregate customer data to improve its own products — Atlassian is not acting solely as a processor. We recommend this contract is manually reviewed to ensure the data use terms are acceptable. NOTE: Currently published DPA takes effect on 17th August 2026. Prior to that date an archived version at https://www.atlassian.com/legal/archives/data-processing-addendum/data-processing-addendum-20260416#scope-and-term will still apply. This does not include the provisions around de-identified data.

DPA: 17 Aug 2026 · Reviewed: 03 Jun 2026 Read more →

Breathe HR

Data Use Review

Breathe's EULA reserves the right to anonymise and aggregate Client Data for its own product development, marketing, and benchmarking purposes, beyond processing on the Client's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

DPA: 01 Sept 2024 · Reviewed: 27 Jul 2026 Read more →

BrowserStack Software

Gaps Identified

BrowserStack's DPA contains core GDPR processor obligations and incorporates SCCs, but does not include explicit audit rights for customers or any provision for DPIA assistance. BrowserStack's main terms (clause 4.3.2) expressly prohibit the inclusion of personal data within the "Customer Content". We recommend this contract is manually reviewed to ensure the terms are acceptable to you.

DPA: 13 Feb 2026 · Reviewed: 03 Jun 2026 Read more →

BuiltWith

GDPR Addressed

BuiltWith's DPA addresses EU GDPR and Australian Privacy Act requirements, with SCCs, processor-only processing and strong flowdown obligations in place. The notable limitation is that on-site audits are explicitly excluded — adherence is demonstrated through documentation and information requests only.

DPA: 01 Jan 2025 · Reviewed: 03 Jun 2026 Read more →

Calendly

Data Use Review

Calendly's DPA addresses most GDPR requirements, but it is unclear whether Calendly's product-development and improvement processing extends to Processor/Customer data (e.g. meeting participant details) rather than being limited to Calendly's own account data. We recommend this contract is manually reviewed to ensure the terms are acceptable to you.

DPA: 01 Jun 2026 · Reviewed: 27 Jul 2026 Read more →

Canva

GDPR Addressed

Canva's DPA comprehensively covers GDPR processor requirements: instruction-only processing, explicit prohibition on selling or sharing customer data, SCCs (Module 2) under Irish law for restricted transfers, full sub-processor flowdown liability, and ISO 27001-backed structured audit rights. On termination, data is destroyed only — no return option. All key provisions are addressed.

DPA: 30 Oct 2025 · Reviewed: 02 Jun 2026 Read more →

Clio

GDPR Addressed

Clio's DPA addresses the key GDPR requirements, including SCCs for international transfers, a 72-hour breach notification commitment, and subprocessor flow-down obligations. The main practical point to note is that technical security measures are described only in general terms rather than an itemised list.

DPA: 18 Aug 2022 · Reviewed: 27 Jul 2026 Read more →

Confluence

Data Use Review

Confluence's (Atlassian) DPA covers the required processor obligations in respect of customer provided personal data. Confluence's (Atlassian) DPA explicitly permits Atlassian to "de-identify" and aggregate customer data to improve its own products — Atlassian is not acting solely as a processor. Contract should be manually reviewed to ensure the data use terms are acceptable. NOTE: Currently published DPA takes effect on 17th August 2026. Prior to that date an archived version at https://www.atlassian.com/legal/archives/data-processing-addendum/data-processing-addendum-20260416#scope-and-term will still apply. This does not include the provisions around de-identified data.

DPA: 17 Aug 2026 · Reviewed: 03 Jun 2026 Read more →

DocuSign

GDPR Addressed

DocuSign's DPA robustly restricts processing to customer instructions only, with BCRs as the primary transfer mechanism supplemented by EU SCCs and UK IDTA. The DPA explicitly prohibits selling, sharing, or independently using personal data and imposes full flowdown liability on sub-processors. All core GDPR provisions are addressed.

DPA: 04 Sept 2024 · Reviewed: 01 Jun 2026 Read more →

Dropbox

GDPR Addressed

Dropbox's DPA covers GDPR processor requirements, including restricting Customer Data processing to service provision on instructions; SOC 2 Type II security and liability for sub-processors. SCCs and Data Privacy Framework certification are in place for overseas transfers. One point to note is that security measures vary depending on the product and plan purchased, so users should check that these are suitable for their specific requirements.

DPA: 23 Aug 2024 · Reviewed: 04 Jun 2026 Read more →

Figma

GDPR Addressed

Figma's DPA addresses key GDPR, UK GDPR, Swiss FADP, Brazilian LGPD, and US data protection requirements, with SCCs in place for EEA, UK, Swiss, and Brazilian transfers plus US Data Privacy Framework certification. Processor-only restrictions and clear flowdown obligations apply throughout. Audit rights are structured: annual third-party reports are provided, with direct audit available once yearly on 45 days' notice.

DPA: 30 Mar 2026 · Reviewed: 04 Jun 2026 Read more →

Finn AI powered by Intercom

GDPR Addressed

Intercom's DPA addresses the key GDPR requirements, including Data Privacy Framework certification with SCCs as fallback, detailed security measures, and a clear restriction against using Customer Personal Data (e.g. conversation data) for Intercom's own purposes. The main practical point to note is that data is stored in the US by default unless a regional hosting add-on is purchased.

DPA: 09 Apr 2025 · Reviewed: 27 Jul 2026 Read more →

GitHub

Data Use Review

GitHub's DPA reserves rights to process Customer Personal Data as an independent controller for purposes including aggregated statistical analysis for revenue planning and product strategy. These uses extend beyond processing on Customer instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

DPA: 01 Oct 2025 · Reviewed: 04 Jun 2026 Read more →

Google

GDPR Addressed

Google's Cloud DPA (updated October 2025) addresses key GDPR requirements across EU, UK, Swiss, US, Brazilian, Israeli and Turkish law, with SCCs incorporated and processor-only restrictions in place. Audit rights are structured: customers access SOC reports and security documentation, with direct inspection available on agreed terms.

DPA: 23 Oct 2025 · Reviewed: 01 Jun 2026 Read more →

Granola

Data Use Review

Granola's DPA covers the required processor obligations in respect of customer provided personal data. Granola's DPA explicitly reserves the right to act as an independent controller over Business Contact Data and Usage Data for account management, fraud detection, compliance and other business purposes. Granola also retains aggregated data for AI model training after account termination. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

DPA: 02 Jul 2025 · Reviewed: 03 Jun 2026 Read more →

HubSpot

Data Use Review

HubSpot's DPA covers the required processor obligations in respect of customer provided personal data. HubSpot explicitly claims independent controller status over website tracking data and professional enrichment data, using it to build and improve its own commercial dataset — not solely to deliver the contracted service. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

DPA: 14 Apr 2026 · Reviewed: 03 Jun 2026 Read more →

Kaseya

GDPR Addressed

Kaseya's DPA addresses GDPR, UK, Swiss and US requirements with EU SCCs, UK IDTA and Data Privacy Frameworks in place for international transfers. TOMs are detailed and contractually binding. Audit rights are structured: capped at once per year, with third-party audit reports substituted for direct inspection.

DPA: 04 Feb 2026 · Reviewed: 17 Jun 2026 Read more →

Lead Forensics

GDPR Addressed

Lead Forensics' DPA addresses EU and UK GDPR requirements, with SCCs, processor-only restrictions and strong sub-processor flowdown in place. A notable positive is the 48-hour data breach notification commitment — stricter than the standard 72-hour GDPR requirement.

DPA: 01 Oct 2024 · Reviewed: 17 Jun 2026 Read more →

Legl

GDPR Addressed

Legl's Services Agreement addresses the key GDPR requirements for its UK-based operations, including breach notification, subprocessor flow-down obligations, and audit rights. The main practical point to note is that international transfer safeguards (e.g. SCCs) are committed to only on a conditional, as-needed basis rather than pre-emptively incorporated.

DPA: 26 Jun 2023 · Reviewed: 27 Jul 2026 Read more →

Linear

Data Use Review

Linear explicitly claims independent controller status over account and usage data and uses it to optimise and develop its own platform — going beyond processing on the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

DPA: 31 May 2025 · Reviewed: 17 Jun 2026 Read more →

Microsoft Azure

Data Use Review

The "Processing for Business Operations Incident to Providing the Products and Services to Customer" section of Microsoft's DPA explicitly obtains the Customer's authorisation for Microsoft to act as an independent data controller of certain personal data that it would otherwise be processing as a data processor, in connection with "business operations processing". We recommend this contract (and in particular, the "Processing for Business Operations Incident to Providing the Products and Services to Customer" section) is manually reviewed to ensure the data use terms are acceptable to you.

DPA: 22 May 2026 · Reviewed: 22 Jun 2026 Read more →

Salesforce

GDPR Addressed

Salesforce's DPA addresses the key GDPR requirements, covering EU, UK, Swiss, US and Asia-Pacific requirements, with SCCs and Binding Corporate Rules in place. Audit rights are structured: third-party certifications are provided first, with on-site audits available once per year on three weeks' notice.

DPA: 10 Apr 2026 · Reviewed: 17 Jun 2026 Read more →