DPA Checker
Are your tech vendor data processing agreements compliant?
It's tempting to assume that you don't need to do much due diligence on popular vendors (if everyone's using them, they must be fine, right?) However, if you are sharing, uploading or inputting personal data to a SaaS, PaaS, IaaS platform it's likely that they will be a "data processor" under the GDPR/UK GDPR. And using these platforms doesn't relieve you from any of your legal obligations… in fact, it gives you additional obligations to verify their suitability for the task and ensure that a compliant data processing agreement is in place.
Many of the most commonly used tech vendors publish their data processing agreements and other GDPR compliance information online. The team at ClearCube has built an AI tool to check these documents and verify whether they meet the relevant rules — primarily whether the DPAs include all the provisions required by Article 28(3) of the GDPR, alongside a few other questions to help assess their suitability as a vendor. The results are below.
This tool isn't (currently!) interactive, however, if a vendor you'd like to check isn't on the list just let us know. For a limited time only, we'll be taking requests to add vendors to this list free of charge!
If you'd like us to perform a check on any vendor you use that doesn't make its GDPR documents publicly available, please contact us. We won't include them in this DPA Checker, but we'll be able to run an individual check, just for you.
29 organisations reviewed.
8x8
GDPR Addressed8x8's DPA addresses the key GDPR requirements for EU, UK and Swiss data processing, with SCCs, flowdown obligations and processor-only restrictions in place. The main practical limitation is that audit rights are structured: customers receive summary audit reports rather than conducting open on-site inspections.
Abacum
Data Use ReviewAbacum's DPA explicitly designates Abacum as an independent controller for account and usage data, permitting it to use that data to optimise the platform for its own purposes beyond the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Adobe
GDPR AddressedAdobe's DPA is comprehensive, covering processor obligations, SCCs for EU/UK/Swiss transfers, sub-processor flowdown, breach notification, structured audit rights and DPIA assistance. Adobe explicitly restricts itself to acting as a processor only, with no independent use of personal data permitted.
Airtable
GDPR AddressedAirtable's DPA covers the key GDPR requirements, including EU/UK/Swiss SCCs, 72-hour breach notification, and sub-processor flow-down obligations. The main practical point to note is that the DPA only becomes binding once separately executed via Airtable's online form, and is limited to Enterprise plans.
Amazon
GDPR AddressedAWS's DPA addresses the key GDPR requirements, covering EU, UK, Swiss and US requirements with SCCs and processor-only restrictions in place. Audit rights are structured: customers access certifications and SOC reports rather than direct on-site inspections, but all material provisions are satisfied.
Anthropic
GDPR AddressedAnthropic's DPA addresses the key GDPR requirements, including SCCs and UK/Swiss addenda for international transfers, 48-hour breach notification, and a clear restriction against using Customer Personal Data for purposes such as model training. The main reason for confidence is this strong sole-processor commitment.
Apple
Data Use ReviewApple's DPA covers the required processor obligations in respect of customer provided personal data. Apple reserves the right to collect diagnostic and usage data from users for its own internal purposes and to disclose personal data to protect its operations — it is not acting solely as a processor. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Atlassian
Data Use ReviewAtlassian's DPA covers the required processor obligations in respect of customer provided personal data. Atlassian's DPA explicitly permits Atlassian to "de-identify" and aggregate customer data to improve its own products — Atlassian is not acting solely as a processor. We recommend this contract is manually reviewed to ensure the data use terms are acceptable. NOTE: Currently published DPA takes effect on 17th August 2026. Prior to that date an archived version at https://www.atlassian.com/legal/archives/data-processing-addendum/data-processing-addendum-20260416#scope-and-term will still apply. This does not include the provisions around de-identified data.
Breathe HR
Data Use ReviewBreathe's EULA reserves the right to anonymise and aggregate Client Data for its own product development, marketing, and benchmarking purposes, beyond processing on the Client's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
BrowserStack Software
Gaps IdentifiedBrowserStack's DPA contains core GDPR processor obligations and incorporates SCCs, but does not include explicit audit rights for customers or any provision for DPIA assistance. BrowserStack's main terms (clause 4.3.2) expressly prohibit the inclusion of personal data within the "Customer Content". We recommend this contract is manually reviewed to ensure the terms are acceptable to you.
BuiltWith
GDPR AddressedBuiltWith's DPA addresses EU GDPR and Australian Privacy Act requirements, with SCCs, processor-only processing and strong flowdown obligations in place. The notable limitation is that on-site audits are explicitly excluded — adherence is demonstrated through documentation and information requests only.
Calendly
Data Use ReviewCalendly's DPA addresses most GDPR requirements, but it is unclear whether Calendly's product-development and improvement processing extends to Processor/Customer data (e.g. meeting participant details) rather than being limited to Calendly's own account data. We recommend this contract is manually reviewed to ensure the terms are acceptable to you.
Canva
GDPR AddressedCanva's DPA comprehensively covers GDPR processor requirements: instruction-only processing, explicit prohibition on selling or sharing customer data, SCCs (Module 2) under Irish law for restricted transfers, full sub-processor flowdown liability, and ISO 27001-backed structured audit rights. On termination, data is destroyed only — no return option. All key provisions are addressed.
Clio
GDPR AddressedClio's DPA addresses the key GDPR requirements, including SCCs for international transfers, a 72-hour breach notification commitment, and subprocessor flow-down obligations. The main practical point to note is that technical security measures are described only in general terms rather than an itemised list.
Confluence
Data Use ReviewConfluence's (Atlassian) DPA covers the required processor obligations in respect of customer provided personal data. Confluence's (Atlassian) DPA explicitly permits Atlassian to "de-identify" and aggregate customer data to improve its own products — Atlassian is not acting solely as a processor. Contract should be manually reviewed to ensure the data use terms are acceptable. NOTE: Currently published DPA takes effect on 17th August 2026. Prior to that date an archived version at https://www.atlassian.com/legal/archives/data-processing-addendum/data-processing-addendum-20260416#scope-and-term will still apply. This does not include the provisions around de-identified data.
DocuSign
GDPR AddressedDocuSign's DPA robustly restricts processing to customer instructions only, with BCRs as the primary transfer mechanism supplemented by EU SCCs and UK IDTA. The DPA explicitly prohibits selling, sharing, or independently using personal data and imposes full flowdown liability on sub-processors. All core GDPR provisions are addressed.
Dropbox
GDPR AddressedDropbox's DPA covers GDPR processor requirements, including restricting Customer Data processing to service provision on instructions; SOC 2 Type II security and liability for sub-processors. SCCs and Data Privacy Framework certification are in place for overseas transfers. One point to note is that security measures vary depending on the product and plan purchased, so users should check that these are suitable for their specific requirements.
Figma
GDPR AddressedFigma's DPA addresses key GDPR, UK GDPR, Swiss FADP, Brazilian LGPD, and US data protection requirements, with SCCs in place for EEA, UK, Swiss, and Brazilian transfers plus US Data Privacy Framework certification. Processor-only restrictions and clear flowdown obligations apply throughout. Audit rights are structured: annual third-party reports are provided, with direct audit available once yearly on 45 days' notice.
Finn AI powered by Intercom
GDPR AddressedIntercom's DPA addresses the key GDPR requirements, including Data Privacy Framework certification with SCCs as fallback, detailed security measures, and a clear restriction against using Customer Personal Data (e.g. conversation data) for Intercom's own purposes. The main practical point to note is that data is stored in the US by default unless a regional hosting add-on is purchased.
GitHub
Data Use ReviewGitHub's DPA reserves rights to process Customer Personal Data as an independent controller for purposes including aggregated statistical analysis for revenue planning and product strategy. These uses extend beyond processing on Customer instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Google's Cloud DPA (updated October 2025) addresses key GDPR requirements across EU, UK, Swiss, US, Brazilian, Israeli and Turkish law, with SCCs incorporated and processor-only restrictions in place. Audit rights are structured: customers access SOC reports and security documentation, with direct inspection available on agreed terms.
Granola
Data Use ReviewGranola's DPA covers the required processor obligations in respect of customer provided personal data. Granola's DPA explicitly reserves the right to act as an independent controller over Business Contact Data and Usage Data for account management, fraud detection, compliance and other business purposes. Granola also retains aggregated data for AI model training after account termination. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
HubSpot
Data Use ReviewHubSpot's DPA covers the required processor obligations in respect of customer provided personal data. HubSpot explicitly claims independent controller status over website tracking data and professional enrichment data, using it to build and improve its own commercial dataset — not solely to deliver the contracted service. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Kaseya
GDPR AddressedKaseya's DPA addresses GDPR, UK, Swiss and US requirements with EU SCCs, UK IDTA and Data Privacy Frameworks in place for international transfers. TOMs are detailed and contractually binding. Audit rights are structured: capped at once per year, with third-party audit reports substituted for direct inspection.
Lead Forensics
GDPR AddressedLead Forensics' DPA addresses EU and UK GDPR requirements, with SCCs, processor-only restrictions and strong sub-processor flowdown in place. A notable positive is the 48-hour data breach notification commitment — stricter than the standard 72-hour GDPR requirement.
Legl
GDPR AddressedLegl's Services Agreement addresses the key GDPR requirements for its UK-based operations, including breach notification, subprocessor flow-down obligations, and audit rights. The main practical point to note is that international transfer safeguards (e.g. SCCs) are committed to only on a conditional, as-needed basis rather than pre-emptively incorporated.
Linear
Data Use ReviewLinear explicitly claims independent controller status over account and usage data and uses it to optimise and develop its own platform — going beyond processing on the customer's instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Microsoft Azure
Data Use ReviewThe "Processing for Business Operations Incident to Providing the Products and Services to Customer" section of Microsoft's DPA explicitly obtains the Customer's authorisation for Microsoft to act as an independent data controller of certain personal data that it would otherwise be processing as a data processor, in connection with "business operations processing". We recommend this contract (and in particular, the "Processing for Business Operations Incident to Providing the Products and Services to Customer" section) is manually reviewed to ensure the data use terms are acceptable to you.
Salesforce
GDPR AddressedSalesforce's DPA addresses the key GDPR requirements, covering EU, UK, Swiss, US and Asia-Pacific requirements, with SCCs and Binding Corporate Rules in place. Audit rights are structured: third-party certifications are provided first, with on-site audits available once per year on three weeks' notice.
Sorry, we can't find that company
Please add your contact details and the name of the company and we will let you know when we've analysed their DPA.