BrowserStack Software

Last Reviewed: 03 Jun 2026

Gaps Identified

At a Glance

BrowserStack's DPA contains core GDPR processor obligations and incorporates SCCs, but does not include explicit audit rights for customers or any provision for DPIA assistance. BrowserStack's main terms (clause 4.3.2) expressly prohibit the inclusion of personal data within the "Customer Content". We recommend this contract is manually reviewed to ensure the terms are acceptable to you.

Company & Product Details

HQ

India, Ireland

Products

BrowserStack testing platform

Product description

Cloud software testing platform for websites and mobile applications across browsers, devices and operating systems.

What data is being processed?

Primarily account-related information and limited service data. Public terms say the services are not designed for customer content containing personal information, other than account-related information.

Document Details

Date of DPA

13 Feb 2026

Additional date information

Terms of Service effective 13 February 2026; data protection addendum contained in Exhibit A

What jurisdictions are covered?

The DPA defines "Data Protection Legislation" broadly to include GDPR (EU 2016/679), the Irish Data Protection Acts 1988–2018, the E-Privacy Directive 2002/58/EC, and related Irish E-Privacy Regulations, as supplemented or amended from time to time. The DPA addresses Restricted Transfers outside the EEA with SCCs as the primary mechanism. (Exhibit A, clause 1(j))

Is the DPA incorporated into service or customer agreements?

Yes
The Data Protection Addendum is incorporated as Exhibit A to the Terms of Service. In the event of conflict, Exhibit A prevails for matters of data protection. Standard Contractual Clauses take precedence over other Agreement provisions in the event of conflict. (Main terms, Section 5; Exhibit A, clause 10.6)

Location & Transfers

Where is data held or processed?

Not explicitly stated The DPA does not specify particular storage locations. BrowserStack publishes a list of sub-processors at https://www.browserstack.com/sub-processors indicating where processing may occur. Restricted Transfers outside the EEA require Appropriate Safeguards under Article 46 GDPR, with SCCs as the primary mechanism. (Exhibit A, clauses 10.1, 11.1)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU Standard Contractual Clauses are directly incorporated into the Agreement by reference at https://browserstack.wpenginepowered.com/wp-content/uploads/2021/10/Standard-Contractual-Clauses.pdf. SCCs must also be entered into with sub-processors for Restricted Transfers. There is specific provision for UK-to-EEA transfers if considered a third country transfer. No explicit mention of UK Addendum or Swiss Addendum. (Exhibit A, clauses 10.1–10.4)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

BrowserStack must implement Appropriate Technical and Organisational Measures to safeguard Account-Related Information from unauthorised or unlawful processing or accidental loss, alteration, disclosure, destruction or damage. Measures must be proportionate to the risk, having regard to the state of technological development and implementation costs. BrowserStack must also maintain administrative, physical and technical safeguards ensuring access only by authorised persons and systems. (Exhibit A, clauses 7.1, 7.2)

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA restricts BrowserStack to processing Account-Related Information for the Business Purpose only and in compliance with Customer instructions. The main terms' usage data clause (Section 6.3) is expressly limited to non-personally identifiable data. No independent controller rights are claimed over personal data. (Exhibit A, clause 2.2; main terms, clause 6.3)

Subprocessing

General authorization

General
General authorisation for BrowserStack Affiliates and other third-party sub-processors. A current list of sub-processor categories is maintained at https://www.browserstack.com/sub-processors. BrowserStack updates the list 10 days before authorising any new sub-processor. Customer may object in writing within 10 days; if unresolved within 30 days, Customer may terminate the affected Order Form. (Exhibit A, clauses 11.1, 11.2)

Do all the DPA terms flow down to sub-processors?

Yes
Before a sub-processor first processes Account-Related Information, BrowserStack must ensure the sub-processor is capable of providing the required level of protection. BrowserStack remains fully liable to Customer for any failure by a sub-processor to fulfil its data protection obligations regarding Account-Related Information. (Exhibit A, clauses 11.3, 11.4)

Is data only processed on the instruction of the controller?

Yes
BrowserStack processes Account-Related Information for the Business Purpose only and in compliance with Customer instructions, either Specific Instructions (written, from an Authorised Person) or the general instructions in the Agreement. BrowserStack may only deviate where required by law, informing Customer beforehand where legally permitted. BrowserStack will not respond to data subject requests except on Customer's documented instructions or as required by law. (Exhibit A, clauses 2.2, 6.4)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
BrowserStack assists Customer with data subject rights requests relating to Account-Related Information using Appropriate Technical and Organisational Measures, at Customer's cost. BrowserStack will promptly notify Customer of data subject requests, complaints or compensation claims. BrowserStack will not respond to such requests except on Customer's documented instructions or as required by law. (Exhibit A, clauses 6.1, 6.2, 6.4)

Does the contract include staff confidentiality clauses?

Yes
BrowserStack must take reasonable steps to ensure the reliability of employees with access to Account-Related Information and ensure those employees have committed to a binding duty of confidentiality in respect of Account-Related Information. (Exhibit A, clause 4.1)

Are there audit rights for the data?

No
The DPA does not include explicit audit rights for Customer. BrowserStack is required to maintain internal records of processing activities including security measures, categories of processing, and data transfer details, but no clause grants Customer the right to access those records or inspect BrowserStack's systems or processes. (Exhibit A, clause 5)

Is there assistance with DPIA requests?

No
The DPA makes no provision for assistance with DPIAs or prior consultations with supervisory authorities. The topic is not addressed. (Exhibit A)

How much notice is provided for data breaches?

BrowserStack will notify Customer without undue delay if Account-Related Information is lost, destroyed, damaged, corrupted or unusable, or if there is any accidental, unauthorised or unlawful disclosure or access. BrowserStack must also assist Customer with its 72-hour supervisory authority notification obligation and with communicating breaches to data subjects where there is a high risk to their rights. (Exhibit A, clauses 8.1, 8.2)

What happens to the data on termination?

Account-Related Information is retained for such period as BrowserStack determines to be reasonably necessary, including maintaining the account while active and for a reasonable period after termination in case of reactivation. BrowserStack may also retain data to comply with legal obligations, resolve disputes, enforce agreements, support business operations, or develop or improve the Services. No specific deletion timeline is stated. (Exhibit A, clause 13)