Airtable
Last Reviewed: 27 Jul 2026
At a Glance
Airtable's DPA covers the key GDPR requirements, including EU/UK/Swiss SCCs, 72-hour breach notification, and sub-processor flow-down obligations. The main practical point to note is that the DPA only becomes binding once separately executed via Airtable's online form, and is limited to Enterprise plans.
Company & Product Details
HQ
United States
Products
App-Building & Database Platform
Product description
No-code platform for building custom databases, apps, and workflow automations.
What data is being processed?
Customer Personal Data (Customer Data as defined in the Agreement) and Business Contact Data (business contact information and account log-in data of Customer's employees and authorized users)
Document Details
Date of DPA
05 Dec 2025
Additional date information
Document states "Last Updated: December 5, 2025" at the top (Preamble).
What jurisdictions are covered?
Applicable Law is defined to include US, UK, and EU privacy/data protection law, including the CCPA/CPRA, UK Data Protection Act 2018, GDPR, and UK GDPR. The EEA (EU member states, Norway, Iceland, Liechtenstein) plus Switzerland are addressed for international transfers; governing law/jurisdiction for the EU SCCs is Ireland (clauses 1.2, 1.7, 9.2–9.4).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not Explicitly Stated The DPA does not state where Customer Personal Data is stored or hosted; it addresses only the mechanisms governing international transfers of the data (Section 9).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Technical and organisational measures are set out at a separate published URL (information-security-standards page), referenced and incorporated by the DPA; Airtable may make future updates provided they do not materially lower the level of protection (clause 6.1).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Airtable will inform Customer of a substantiated Personal Data Breach without undue delay and, in any event, no later than 72 hours after substantiation, including the breach's nature, likely consequences, and mitigation measures, with periodic updates as more information becomes available (clause 6.2).
What happens to the data on termination?
On termination and written request from Customer, Airtable will delete or anonymize Customer Personal Data, unless prohibited by law. Data retained in security, backup, or business-continuity files may be kept until Airtable's normal retention processes conclude, but remains protected under the DPA (clause 12).