Adobe

Last Reviewed: 01 Jun 2026

GDPR Addressed

At a Glance

Adobe's DPA is comprehensive, covering processor obligations, SCCs for EU/UK/Swiss transfers, sub-processor flowdown, breach notification, structured audit rights and DPIA assistance. Adobe explicitly restricts itself to acting as a processor only, with no independent use of personal data permitted.

Company & Product Details

HQ

United States

Products

Adobe Cloud Services

Product description

Cloud-based creative, document and related enterprise services.

What data is being processed?

Customer account data, user profile/contact data, files/documents and any personal data included in customer content processed through Adobe cloud services.

Document Details

Date of DPA

01 Jun 2024

Additional date information

Adobe DPA, June 2024

What jurisdictions are covered?

The DPA covers EU GDPR, UK Data Protection Law (UK GDPR), the Swiss Federal Act on Data Protection, and U.S. state privacy laws including CCPA. Adobe is the Data Processor; Customer is the Data Controller. European Area transfers route through Adobe Systems Software Ireland Limited with appropriate transfer mechanisms. (clauses 1.7, 1.9, 1.10, 3.1, 7.1, 7.2)

Is the DPA incorporated into service or customer agreements?

Yes
The DPA supplements the General Terms, Sales Order, or other written or electronic terms agreement between Adobe and Customer. In the event of conflict, the DPA prevails over the Agreement for processing of personal data. Liability provisions in the underlying Agreement also apply to the DPA and transfer mechanisms. (clauses 2, 10.1, 10.2)

Location & Transfers

Where is data held or processed?

Not explicitly stated Adobe publishes processing locations and sub-processors at https://www.adobe.com/go/processing. European Area data is initially processed by Adobe Systems Software Ireland Limited before transfer to sub-processors. Specific locations are governed by Adobe's published sub-processor list and the Agreement. (clauses 7.2, Exhibit 1 §5)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The DPA defines and incorporates EU SCCs (European Commission SCCs of 4 June 2021), UK SCCs (UK international data transfer addendum), and Swiss DPA transfer clauses. European Area transfers route through Adobe Ireland as the initial data recipient. Upon written request, Adobe Ireland will provide evidence of SCCs with sub-processors and transfer risk assessments. Adobe remains liable for sub-processor compliance with transfer mechanisms. (clauses 1.14, 7.1, 7.2)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Adobe has implemented Technical and Organisational Measures (TOMs) published at https://www.adobe.com/go/CloudSvcsTOSM. The measures account for the state of the art, implementation costs, nature, scope, context and purposes of processing. Adobe may update measures provided updates do not materially diminish overall security. Third-party certifications and audits are listed at Adobe's Trust Center (https://www.adobe.com/trust/compliance/compliance-list.html). (clauses 5.1, 5.2)

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA explicitly prohibits Adobe from combining personal data received from Customer with other personal data, or processing personal data outside the direct business relationship with Customer (except as needed to provide the Cloud Services). Adobe will not independently "sell" or "share" personal data under CCPA or other U.S. data protection laws. No independent controller rights are claimed. (clauses 3.1, 3.5)

Subprocessing

General authorization

General
General authorisation for Adobe Affiliates and other sub-processors listed at https://www.adobe.com/go/processing. Adobe gives at least 14 days' advance notice of new sub-processors via a subscription mechanism. Customers may object in writing within the notice period on reasonable grounds; if unresolved and the sub-processor cannot be replaced, Customer may terminate the relevant Sales Order for affected services only. (clauses 4.1, 4.3)

Do all the DPA terms flow down to sub-processors?

Yes
Adobe enters into a written agreement with each sub-processor imposing data protection obligations and security measures materially no less protective than Adobe's own obligations under the DPA, to the extent applicable to the services provided by the sub-processor. Adobe remains fully liable for each sub-processor's compliance with the DPA obligations. (clause 4.2)

Is data only processed on the instruction of the controller?

Yes
The Agreement (including the DPA) constitutes the complete instructions to Adobe for all processing of personal data. Adobe processes personal data only on behalf of Customer and for the limited and specific business purposes set out in Exhibit 1. Adobe will notify Customer without undue delay if it can no longer meet its Data Protection Law obligations. (clauses 3.2, 3.4)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Adobe promptly notifies Customer of Data Subject Requests and provides controls within the Cloud Services to assist Customer in responding. Where Customer cannot access the relevant personal data within the Cloud Services, Adobe will provide commercially reasonable cooperation upon written request. Additional assistance beyond purchased functionality may be charged where not commercially reasonable to provide without charge. (clauses 9.1, 9.2)

Does the contract include staff confidentiality clauses?

Yes
Any person authorised by Adobe to process personal data, including its staff, agents and subcontractors, must be under an appropriate obligation of confidentiality — whether contractual or statutory in nature. (clause 5.3)

Are there audit rights for the data?

Structured
Adobe provides certifications and audit reports from its Trust Center as the first step. If Customer reasonably determines this is insufficient, a full audit is permitted no more than once annually on 60 days' written notice, at a mutually agreed date, time and format. The scope requires Adobe's pre-approval; physical access to Adobe or sub-processor environments is excluded. Audit costs are borne by each party. (clauses 6.1, 6.2)

Is there assistance with DPIA requests?

Yes
Adobe provides reasonably requested information about the Cloud Services to enable Customer to conduct DPIAs and prior consultations with data protection authorities, where Customer does not already have access to the relevant information. Additional assistance beyond purchased Cloud Services functionality may be charged where it is not commercially reasonable to provide without charge. (clauses 9.2, 9.3)

How much notice is provided for data breaches?

Adobe will notify Customer without undue delay after becoming aware of a Personal Data Breach, per the notice provisions in the Agreement. Adobe will promptly take reasonable steps to contain, investigate and mitigate the breach, and provide timely information including the nature and consequences of the breach, measures taken, investigation status, and categories and approximate number of affected data records. (clauses 8.1, 8.2)

What happens to the data on termination?

At Customer's choice, Adobe will delete or return all Personal Data after the end of the applicable Cloud Services term, as further specified under the Agreement. Processing continues until deletion pursuant to the Agreement; specific timelines and retention criteria are determined by Customer via configuration of the Cloud Services. (clause 9.4, Exhibit 1 §6)