Clio
Last Reviewed: 27 Jul 2026
At a Glance
Clio's DPA addresses the key GDPR requirements, including SCCs for international transfers, a 72-hour breach notification commitment, and subprocessor flow-down obligations. The main practical point to note is that technical security measures are described only in general terms rather than an itemised list.
Company & Product Details
HQ
Canada
Products
Legal Practice Management Software
Product description
Cloud-based case management, billing, and client intake software for law firms.
What data is being processed?
Names, email addresses, personal and professional information, and other personal data relating to clients and business contacts provided by the Subscriber in connection with use of the Service
Document Details
Date of DPA
18 Aug 2022
Additional date information
Effective date stated at the top of the document as August 18, 2022; the DPA is Exhibit B to Clio's Terms of Service.
What jurisdictions are covered?
Applies where Subscriber Personal Data relates to individuals in the EEA, or where the Subscriber is established in the EEA or UK; a UK Addendum (ICO Mandatory Clauses) applies for UK-related data. Governing law is Ireland (Preamble, clauses 1(h), 8.1).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
EEA Themis commits to processing Subscriber Personal Data within the EEA. Transfers outside the EEA are permitted only to countries with an EU adequacy decision, to recipients under a recognised compliance scheme, or under the Standard Contractual Clauses (clause 3.4).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Themis will implement and maintain appropriate technical and organisational security measures appropriate to the risk, including measures referenced in Article 32(1) GDPR; personnel with data access are bound by written confidentiality obligations (clauses 4.1, 4.4).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Themis must notify Subscriber within 72 hours of becoming aware of a Security Incident, and will investigate and provide reasonable assistance to Subscriber, law enforcement, and regulators as required (clause 4.3).
What happens to the data on termination?
Within 90 days of termination, at Subscriber's election, Themis will make Subscriber Personal Data available for retrieval and then delete all other copies, or delete it outright. Themis and its subprocessors may retain data only where required by law, keeping it confidential and used solely for that legal purpose (clauses 7.1, 7.2).