Clio

Last Reviewed: 27 Jul 2026

GDPR Addressed

At a Glance

Clio's DPA addresses the key GDPR requirements, including SCCs for international transfers, a 72-hour breach notification commitment, and subprocessor flow-down obligations. The main practical point to note is that technical security measures are described only in general terms rather than an itemised list.

Company & Product Details

HQ

Canada

Products

Legal Practice Management Software

Product description

Cloud-based case management, billing, and client intake software for law firms.

What data is being processed?

Names, email addresses, personal and professional information, and other personal data relating to clients and business contacts provided by the Subscriber in connection with use of the Service

Document Details

Date of DPA

18 Aug 2022

Additional date information

Effective date stated at the top of the document as August 18, 2022; the DPA is Exhibit B to Clio's Terms of Service.

What jurisdictions are covered?

Applies where Subscriber Personal Data relates to individuals in the EEA, or where the Subscriber is established in the EEA or UK; a UK Addendum (ICO Mandatory Clauses) applies for UK-related data. Governing law is Ireland (Preamble, clauses 1(h), 8.1).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA is Exhibit B to Clio's Terms of Service and forms part of the Agreement; it prevails over the remainder of the Agreement in case of conflict (Preamble).

Location & Transfers

Where is data held or processed?

EEA Themis commits to processing Subscriber Personal Data within the EEA. Transfers outside the EEA are permitted only to countries with an EU adequacy decision, to recipients under a recognised compliance scheme, or under the Standard Contractual Clauses (clause 3.4).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
SCCs (Module Two, Controller-to-Processor, EU Commission Decision 2021/914) apply to transfers outside the EEA, with Themis appointed as Subscriber's agent to execute them. For UK-related data, the parties adopt the ICO's international data transfer Addendum (template B.1.0) as Mandatory Clauses (clauses 1(h), 3.4).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Themis will implement and maintain appropriate technical and organisational security measures appropriate to the risk, including measures referenced in Article 32(1) GDPR; personnel with data access are bound by written confidentiality obligations (clauses 4.1, 4.4).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA is silent on any right for Themis to use Subscriber Personal Data for its own purposes; clause 2.1 confirms Themis acts solely as Processor and Subscriber as Controller, with no controller rights or independent-use provisions identified (clause 2.1).

Subprocessing

General authorization

General
Themis may engage subprocessors from a published list (Exhibit C) and must notify Subscriber of new subprocessors. Subscriber may object on data-protection grounds; if unresolved, either party may terminate on 30 days' notice, and failure to object within 30 days constitutes acceptance (clauses 3.1–3.3).

Do all the DPA terms flow down to sub-processors?

Yes
Themis must enter into a written agreement with each subprocessor imposing obligations equivalent to those in this DPA, and remains liable for subprocessor acts and omissions as if they were its own (clause 3.3).

Is data only processed on the instruction of the controller?

Yes
Themis processes Subscriber Personal Data only on Subscriber's written instructions, with the Agreement and this DPA constituting the complete and final instructions; processing outside this scope requires prior written agreement (clauses 2.2, 2.3).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Themis will use reasonable endeavours to implement appropriate technical and organisational measures to help Subscriber respond to data subject rights requests (clause 5.1).

Does the contract include staff confidentiality clauses?

Yes
Themis treats Subscriber Personal Data as confidential and requires employees and personnel to agree in writing to protect its confidentiality and security (clause 4.4).

Are there audit rights for the data?

Structured
Subscriber (or a mandated third-party auditor) may audit Themis on reasonable request, but only once per year unless a Supervisory Authority requires more, during business hours only, at Subscriber's expense, and with minimal disruption; Themis must be given a copy of the results (clause 4.5).

Is there assistance with DPIA requests?

Yes
Themis will provide Subscriber with reasonably requested information about its Service to support data protection impact assessments or prior consultations with a Supervisory Authority (clause 6.1).

How much notice is provided for data breaches?

Themis must notify Subscriber within 72 hours of becoming aware of a Security Incident, and will investigate and provide reasonable assistance to Subscriber, law enforcement, and regulators as required (clause 4.3).

What happens to the data on termination?

Within 90 days of termination, at Subscriber's election, Themis will make Subscriber Personal Data available for retrieval and then delete all other copies, or delete it outright. Themis and its subprocessors may retain data only where required by law, keeping it confidential and used solely for that legal purpose (clauses 7.1, 7.2).