Apple

Last Reviewed: 03 Jun 2026

Data Use Review

At a Glance

Apple's DPA covers the required processor obligations in respect of customer provided personal data. Apple reserves the right to collect diagnostic and usage data from users for its own internal purposes and to disclose personal data to protect its operations — it is not acting solely as a processor. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United States, Ireland

Products

Apple Business Manager / Managed Apple Accounts

Product description

Enterprise device deployment, app/content management and managed Apple account administration service.

What data is being processed?

Administrator and managed account data, device-related account data and any personal data stored in business iCloud storage linked to Managed Apple Accounts.

Document Details

Date of DPA

09 Sept 2025

Additional date information

Date stated explicitly within the document as "9 September 2025" (in English and Spanish versions).

What jurisdictions are covered?

The DPA explicitly references the GDPR (Regulation (EU) 2016/679), the CCPA, and the APEC CBPR/PRP certification framework. Apple must ensure international transfers use adequate safeguards such as SCCs, adequacy decisions, or APEC CBPR/PRP. Institution is responsible for compliance with all applicable privacy and data protection laws when using the Service. UK/EU transfers are addressed through Apple's published Data Transfer Agreements. (clauses 2.1(e), 9.3, 9.4)

Is the DPA incorporated into service or customer agreements?

Yes
The data processing terms are set out within the Apple Business Manager Agreement itself (Section 9). Separate Data Transfer Agreements incorporating SCCs are published at https://www.apple.com/legal/enterprise/datatransfer/ and Institution is required to enter into these where required by its jurisdiction. The Agreement is the binding contract between Institution and Apple for use of the Service. (clauses 9.3, 9.4)

Location & Transfers

Where is data held or processed?

Not explicitly stated Apple states that encrypted personal data may be stored at Apple's geographic discretion as part of the Service. International transfers will use adequate safeguards where required by law, including standard contractual clauses or adequacy decisions under Articles 46–47 GDPR. No specific list of storage countries is provided in the DPA — location is at Apple's discretion. (clauses 9.3, 9.4)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
Apple uses Model Contract Clauses (standard contractual clauses) under Articles 46–47 GDPR for international transfers. Separate Data Transfer Agreements, including EU SCCs, are available at https://www.apple.com/legal/enterprise/datatransfer/ and Institution agrees to enter into these if required by its jurisdiction. Apple also holds APEC CBPR/PRP certification for Asia-Pacific transfers. No specific mention of a UK Addendum or Swiss Addendum in the main DPA text. (clause 9.4)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Apple uses industry-standard measures including encryption at rest and in transit, ongoing confidentiality, integrity, availability and resilience controls, timely restoration of data availability after incidents, and regular testing and evaluation of security measures. Apple holds ISO 27001 and ISO 27018 certifications, expressly stated as sufficient for GDPR Article 32 and audit purposes. Employees, contractors and sub-processors must comply with applicable security and confidentiality laws. (clause 9.3)

Non Processor Data Use

Does the company process data solely as a processor?

No
Section 11.2 of the Agreement explicitly grants Apple and its affiliates the right to "collect, maintain, process and use diagnostic, technical, usage and related information, including but not limited to... information about Your and Your Authorized Users' use of the Service... for internal purposes such as auditing, data analysis, and research to improve Apple's devices, services, and customer communications." This data is to be treated under Apple's Privacy Policy rather than the DPA, indicating Apple is acting as an independent controller for this data. Section 9.6 also permits Apple to disclose Personal Data where it "determines that disclosure is reasonably necessary to enforce Apple's terms and conditions or protect Apple's operations or users." These provisions grant Apple rights to use data about Authorized Users for its own purposes beyond processing on the customer's documented instructions (clauses 9.6, 11.2).

Subprocessing

General authorization

General
Apple has general authorisation to use sub-processors, including all Apple group entities listed in the "Apple" definition and any others bound by data protection obligations at least as protective as those in the Agreement. A public sub-processor list is available at https://www.apple.com/legal/enterprise/data-transfer-agreements/subprocessors_us.pdf. Apple remains liable for sub-processor performance to the extent required by applicable law. No specific objection process is described. (clause 9.1)

Do all the DPA terms flow down to sub-processors?

Yes
Sub-processors are contractually bound by data protection obligations at least as protective as those in the Agreement. Apple remains fully liable to Institution for sub-processor performance to the extent required by applicable law. If a sub-processor fails to fulfil its obligations, Apple bears responsibility for those obligations where required by law. (clause 9.1)

Is data only processed on the instruction of the controller?

Yes
Apple, as data processor, processes personal data only on documented instructions — through the Agreement terms, use of the Service, or other written instructions accepted and acknowledged by Apple. Apple may deviate from instructions only where required by law, informing Institution beforehand unless prohibited by law. Apple will also inform Institution if it believes any instruction infringes the GDPR or equivalent law. (clauses 9.1, 9.3)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Apple assists Institution with GDPR Articles 32 (security), 33–34 (breach notification to authorities and data subjects), 35–36 (DPIAs and prior regulatory consultation), and with data subject rights requests, taking into account the nature of the processing. Apple also assists with investigations by data protection regulators or similar authorities regarding personal data. (clause 9.3)

Does the contract include staff confidentiality clauses?

Yes
Apple takes appropriate steps to ensure its employees, contractors and sub-processors comply with applicable laws regarding the confidentiality and security of personal data in connection with the Service. Persons authorised to process personal data must comply with applicable confidentiality and security requirements. (clause 9.3)

Are there audit rights for the data?

Structured
Audit rights are structured and channelled through certifications: Apple's ISO 27001 and ISO 27018 certifications are expressly stated as sufficient for required audit purposes under Article 28 GDPR. Apple will make available all information necessary to demonstrate compliance. Apple will also inform Institution if it believes any instruction infringes the GDPR or equivalent law. No broad open-ended right to onsite inspection is provided. (clause 9.3)

Is there assistance with DPIA requests?

Yes
Apple assists with DPIAs and prior consultation with supervisory authorities under GDPR Articles 35–36 or equivalent obligations, and with investigations by data protection regulators regarding personal data. DPIA/consultation assistance is in addition to obligations on data subject rights, breach notification, and security compliance. (clause 9.3)

How much notice is provided for data breaches?

Apple will notify Institution without undue delay if required by law after becoming aware of a Data Incident (defined as unauthorised access resulting in personal data being altered, deleted, or lost). Apple will take reasonable steps to minimise harm and secure data. Notification does not constitute an acknowledgment of liability. Institution remains responsible for complying with applicable incident notification laws and third-party obligations. (clause 9.2)

What happens to the data on termination?

Upon termination of the Agreement for any reason, Apple will securely destroy personal data stored in connection with the Service within a reasonable period of time, except where retention is necessary to prevent fraud or is required by law. No specific deletion timeline is stated. (clause 9.4)