Airtable

Last Reviewed: 27 Jul 2026

GDPR Addressed

At a Glance

Airtable's DPA covers the key GDPR requirements, including EU/UK/Swiss SCCs, 72-hour breach notification, and sub-processor flow-down obligations. The main practical point to note is that the DPA only becomes binding once separately executed via Airtable's online form, and is limited to Enterprise plans.

Company & Product Details

HQ

United States

Products

App-Building & Database Platform

Product description

No-code platform for building custom databases, apps, and workflow automations.

What data is being processed?

Customer Personal Data (Customer Data as defined in the Agreement) and Business Contact Data (business contact information and account log-in data of Customer's employees and authorized users)

Document Details

Date of DPA

05 Dec 2025

Additional date information

Document states "Last Updated: December 5, 2025" at the top (Preamble).

What jurisdictions are covered?

Applicable Law is defined to include US, UK, and EU privacy/data protection law, including the CCPA/CPRA, UK Data Protection Act 2018, GDPR, and UK GDPR. The EEA (EU member states, Norway, Iceland, Liechtenstein) plus Switzerland are addressed for international transfers; governing law/jurisdiction for the EU SCCs is Ireland (clauses 1.2, 1.7, 9.2–9.4).

Is the DPA incorporated into service or customer agreements?

Unclear
The Preamble states the DPA "is incorporated by reference into the agreement... that governs Customer's use of the Services," suggesting automatic incorporation. However, it also states the DPA "will not become binding and enforceable unless and until it has been validly executed by the Parties" via a separate process at airtable.com/dpaform, and is reported to be available only on Enterprise plans. It is unclear whether the DPA terms apply automatically or only once a separate execution step is completed (Preamble, Section 13).

Location & Transfers

Where is data held or processed?

Not Explicitly Stated The DPA does not state where Customer Personal Data is stored or hosted; it addresses only the mechanisms governing international transfers of the data (Section 9).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU SCCs apply to transfers from the EEA (Module 2 where Customer is Controller, Module 3 where Customer is Processor); the UK Addendum (ICO International Data Transfer Addendum) applies to UK transfers; and the EU SCCs, adapted for the Swiss FADP, apply to transfers from Switzerland. The parties are deemed to sign the SCCs by entering into the DPA (clauses 1.8, 1.13, 9.2–9.4).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Technical and organisational measures are set out at a separate published URL (information-security-standards page), referenced and incorporated by the DPA; Airtable may make future updates provided they do not materially lower the level of protection (clause 6.1).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Clause 3.1 (Purpose Limitation) restricts Airtable from processing Customer Personal Data for any purpose beyond that set out in the Agreement, from combining it with data from other sources, and from re-identifying any deidentified data disclosed by Customer. Airtable and Customer are independent controllers only with respect to Business Contact Data (employee contact/login information), which is User/Account Data and does not affect this assessment (clauses 2.1, 3.1).

Subprocessing

General authorization

General
Airtable may use Affiliates and third parties as sub-processors under a general written authorization (SCC Clause 9, Option 2). The current sub-processor list is published online. Airtable must give at least 10 days' written notice of new sub-processors; Customer may object within 10 business days on reasonable data-protection grounds, triggering a process to find an alternative or, failing that, termination of the affected services (clauses 5.1–5.3, 9.2(4)).

Do all the DPA terms flow down to sub-processors?

Yes
Airtable imposes obligations on sub-processors substantially the same as those in this DPA and remains liable for their performance to the same extent as for its own performance (clause 5.1).

Is data only processed on the instruction of the controller?

Yes
The Agreement and this DPA constitute Customer's complete and final processing instructions; Airtable must inform Customer without undue delay if an instruction appears to infringe Applicable Law (clause 3.2).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Airtable will notify Customer without undue delay of any Data Subject Request it receives and, upon request, take commercially reasonable efforts to assist Customer in responding where Customer cannot address the request itself (clause 7).

Does the contract include staff confidentiality clauses?

Yes
Airtable requires all employees, contractors and agents who process Customer Personal Data to protect its confidentiality, and ensures authorized personnel are bound by written confidentiality agreements or an equivalent statutory duty (clauses 4, 6.1).

Are there audit rights for the data?

Structured
Customer may request Airtable's most recent SOC 2 Type II and ISO 27001 reports once annually as its Audit; a third-party auditor may be used at Customer's expense, subject to confidentiality. Airtable requires 90 business days' prior notice, audits are capped at 2 business days, and Customer cannot access other customers' data or unrelated confidential information (clause 10).

Is there assistance with DPIA requests?

Yes
Upon Customer's written request, Airtable will provide reasonable cooperation and assistance for data protection impact assessments and consultation with a Supervisory Authority, to the extent required under Applicable Law (clause 8).

How much notice is provided for data breaches?

Airtable will inform Customer of a substantiated Personal Data Breach without undue delay and, in any event, no later than 72 hours after substantiation, including the breach's nature, likely consequences, and mitigation measures, with periodic updates as more information becomes available (clause 6.2).

What happens to the data on termination?

On termination and written request from Customer, Airtable will delete or anonymize Customer Personal Data, unless prohibited by law. Data retained in security, backup, or business-continuity files may be kept until Airtable's normal retention processes conclude, but remains protected under the DPA (clause 12).