Dropbox
Last Reviewed: 04 Jun 2026
At a Glance
Dropbox's DPA covers GDPR processor requirements, including restricting Customer Data processing to service provision on instructions; SOC 2 Type II security and liability for sub-processors. SCCs and Data Privacy Framework certification are in place for overseas transfers. One point to note is that security measures vary depending on the product and plan purchased, so users should check that these are suitable for their specific requirements.
Company & Product Details
HQ
United States
Products
Dropbox cloud storage, file synchronisation and collaboration services
Product description
Cloud Storage
What data is being processed?
Unrestricted - users can store files and data of any nature
Document Details
Date of DPA
23 Aug 2024
Additional date information
Document header states "Posted: August 23, 2024" and document footer and title reference "v.Aug-23-2024". This DPA supersedes the prior version dated October 28, 2022. Fetched directly from https://assets.dropbox.com/documents/en/legal/dfb-data-processing-agreement.pdf.
What jurisdictions are covered?
EU GDPR, UK GDPR, Swiss Federal Act on Data Protection (FADP). Dropbox also adheres to the EU-US Data Privacy Framework, Swiss-US Data Privacy Framework, and the UK Extension to the EU-US Data Privacy Framework.
Is the DPA incorporated into service or customer agreements?
Link
https://assets.dropbox.com/documents/en/legal/dfb-data-processing-agreement.pdf
Location & Transfers
Where is data held or processed?
Not Explicitly Stated The DPA does not explicitly state where Customer Data is held. It references that Dropbox International (EEA entity) may transfer European Data to Dropbox, Inc. (US) to provide the Services. Specific storage regions are not defined in the DPA.
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Dropbox will implement the technical and organisational measures (TOMs) set forth in the Agreement for the applicable Services. Dropbox undergoes regular SOC 2 Type II audits. The DPA references compliance with security, confidentiality, integrity and availability measures consistent with the SCCs. (clause 3)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Dropbox will notify Customer promptly and without undue delay upon becoming aware of a Security Incident, using commercially reasonable efforts to provide notice within 72 hours of confirming the existence of the incident. Notice is sent to the email address associated with the Customer's account. Dropbox will provide information including: the nature of the incident, categories and approximate number of personal data records concerned, likely consequences, measures taken or proposed, and DPO/contact details. Dropbox may limit disclosures to protect the integrity of an ongoing investigation. (clauses 3.2, 3.3)
What happens to the data on termination?
Upon termination of the Agreement, Dropbox will delete Stored Data in Customer's account within a commercially reasonable period following receipt of an Administrator's request to do so prior to termination. Notwithstanding this, Dropbox explicitly reserves the right to act as a controller and retain "certain Account Data" in accordance with applicable privacy laws, with Dropbox solely responsible for compliance with those laws in connection with its own processing of that retained data. (clause 7)