Adobe
Last Reviewed: 01 Jun 2026
At a Glance
Adobe's DPA is comprehensive, covering processor obligations, SCCs for EU/UK/Swiss transfers, sub-processor flowdown, breach notification, structured audit rights and DPIA assistance. Adobe explicitly restricts itself to acting as a processor only, with no independent use of personal data permitted.
Company & Product Details
HQ
United States
Products
Adobe Cloud Services
Product description
Cloud-based creative, document and related enterprise services.
What data is being processed?
Customer account data, user profile/contact data, files/documents and any personal data included in customer content processed through Adobe cloud services.
Document Details
Date of DPA
01 Jun 2024
Additional date information
Adobe DPA, June 2024
What jurisdictions are covered?
The DPA covers EU GDPR, UK Data Protection Law (UK GDPR), the Swiss Federal Act on Data Protection, and U.S. state privacy laws including CCPA. Adobe is the Data Processor; Customer is the Data Controller. European Area transfers route through Adobe Systems Software Ireland Limited with appropriate transfer mechanisms. (clauses 1.7, 1.9, 1.10, 3.1, 7.1, 7.2)
Is the DPA incorporated into service or customer agreements?
Link
https://www.adobe.com/content/dam/cc/en/legal/terms/enterprise/pdfs/DPA-WW.pdf
Location & Transfers
Where is data held or processed?
Not explicitly stated Adobe publishes processing locations and sub-processors at https://www.adobe.com/go/processing. European Area data is initially processed by Adobe Systems Software Ireland Limited before transfer to sub-processors. Specific locations are governed by Adobe's published sub-processor list and the Agreement. (clauses 7.2, Exhibit 1 §5)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Adobe has implemented Technical and Organisational Measures (TOMs) published at https://www.adobe.com/go/CloudSvcsTOSM. The measures account for the state of the art, implementation costs, nature, scope, context and purposes of processing. Adobe may update measures provided updates do not materially diminish overall security. Third-party certifications and audits are listed at Adobe's Trust Center (https://www.adobe.com/trust/compliance/compliance-list.html). (clauses 5.1, 5.2)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Adobe will notify Customer without undue delay after becoming aware of a Personal Data Breach, per the notice provisions in the Agreement. Adobe will promptly take reasonable steps to contain, investigate and mitigate the breach, and provide timely information including the nature and consequences of the breach, measures taken, investigation status, and categories and approximate number of affected data records. (clauses 8.1, 8.2)
What happens to the data on termination?
At Customer's choice, Adobe will delete or return all Personal Data after the end of the applicable Cloud Services term, as further specified under the Agreement. Processing continues until deletion pursuant to the Agreement; specific timelines and retention criteria are determined by Customer via configuration of the Cloud Services. (clause 9.4, Exhibit 1 §6)