8x8

Last Reviewed: 01 Jun 2026

GDPR Addressed

At a Glance

8x8's DPA addresses the key GDPR requirements for EU, UK and Swiss data processing, with SCCs, flowdown obligations and processor-only restrictions in place. The main practical limitation is that audit rights are structured: customers receive summary audit reports rather than conducting open on-site inspections.

Company & Product Details

HQ

United States

Products

8x8 UCaaS / CCaaS / CPaaS

Product description

Integrated cloud contact centre, unified communications and communications platform as a service products.

What data is being processed?

Communications content and related metadata, including voice calls, video meetings, voicemails, messages, call recordings, contact profiles, support / ticket notes and related usage data.

Document Details

Date of DPA

07 Feb 2025

What jurisdictions are covered?

Applicable Data Protection Law generally, including GDPR / UK GDPR / Swiss FADP transfer terms and CCPA/CPRA restrictions in the DPA.

Is the DPA incorporated into service or customer agreements?

Yes
The Global DPA applies to the customer's contract with 8x8 for 8x8 SaaS Services.

Location & Transfers

Where is data held or processed?

Not explicitly stated Not exhaustively limited in the public DPA. Processing can occur through 8x8 systems and approved sub-processors, with international transfers subject to the DPA transfer safeguards.

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
Adequacy decisions, binding corporate rules where applicable, EU SCCs, UK Addendum and Swiss-specific modifications. The DPA includes EEA Module 2 / 3 SCC mechanics and UK Addendum language.

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

DPA includes written security program, NIST 800-53 r5 (or equivalent), independent audits against SOC 2 / ISO 27001 / ISO 9001 / ISO 140001 / Cyber Trust Mark / Cyber Essentials Plus, encryption at rest and in transit, access controls, BC/DR and user training.

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA designates 8x8 as a processor only (clause DPA-3: "8x8 is a processor of Customer Personal Data. The Parties do not act as joint controllers for any processing of Customer Personal Data."). The Permitted Purposes in clause DPA-4(a) include "providing, supporting, enhancing, and quality-controlling the 8x8 SaaS Services", which is broad but remains framed as processing on behalf of the Customer. Clause DPA-7 (California Consumer Data) explicitly prohibits 8x8 from retaining, using, or disclosing Customer Personal Data for any purpose outside the direct business relationship, or combining it with data from other customers. No independent controller rights or rights to use Customer Data for 8x8's own unrelated purposes were found (clauses DPA-3, DPA-4(a), DPA-7).

Subprocessing

General authorization

General
8x8 maintains a public sub-processor list and updates it at least 10 days before a change; customers can object on reasonable data protection grounds.

Do all the DPA terms flow down to sub-processors?

Yes
8x8 must impose no less onerous data protection terms on sub-processors and remains liable for relevant breaches.

Is data only processed on the instruction of the controller?

Yes
8x8 processes customer personal data for the permitted purposes and in accordance with customer instructions / agreement terms.

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
8x8 will reasonably and timely help with data subject rights requests and related correspondence.

Does the contract include staff confidentiality clauses?

Yes
8x8 says authorised personnel are subject to appropriate confidentiality obligations.

Are there audit rights for the data?

Structured
The DPA provides for summary copies of audit reports on request; it does not grant a broad open-ended inspection right in the published DPA text.

Is there assistance with DPIA requests?

Yes
8x8 will reasonably cooperate with a DPIA where the processing is likely to result in high risk and the law requires it.

How much notice is provided for data breaches?

Without undue delay after confirmation of a Security Incident.

What happens to the data on termination?

8x8 will destroy customer personal data within 60 days after the customer deletes it from or closes the relevant account, subject to legal retention and protected backup copies.