Dropbox

Last Reviewed: 04 Jun 2026

GDPR Addressed

At a Glance

Dropbox's DPA covers GDPR processor requirements, including restricting Customer Data processing to service provision on instructions; SOC 2 Type II security and liability for sub-processors. SCCs and Data Privacy Framework certification are in place for overseas transfers. One point to note is that security measures vary depending on the product and plan purchased, so users should check that these are suitable for their specific requirements.

Company & Product Details

HQ

United States

Products

Dropbox cloud storage, file synchronisation and collaboration services

Product description

Cloud Storage

What data is being processed?

Unrestricted - users can store files and data of any nature

Document Details

Date of DPA

23 Aug 2024

Additional date information

Document header states "Posted: August 23, 2024" and document footer and title reference "v.Aug-23-2024". This DPA supersedes the prior version dated October 28, 2022. Fetched directly from https://assets.dropbox.com/documents/en/legal/dfb-data-processing-agreement.pdf.

What jurisdictions are covered?

EU GDPR, UK GDPR, Swiss Federal Act on Data Protection (FADP). Dropbox also adheres to the EU-US Data Privacy Framework, Swiss-US Data Privacy Framework, and the UK Extension to the EU-US Data Privacy Framework.

Is the DPA incorporated into service or customer agreements?

Yes
The DPA supplements the Dropbox Business Agreement (Services Agreement) between Dropbox and the Customer. In the event of a conflict between the DPA and the Agreement, the DPA controls with respect to the processing of Personal Data.

Location & Transfers

Where is data held or processed?

Not Explicitly Stated The DPA does not explicitly state where Customer Data is held. It references that Dropbox International (EEA entity) may transfer European Data to Dropbox, Inc. (US) to provide the Services. Specific storage regions are not defined in the DPA.

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The DPA is titled "Data Processing Agreement with Model Clauses" and incorporates EU Standard Contractual Clauses. It includes provisions for UK GDPR compliance (UK Addendum) and Swiss FADP compliance. Dropbox additionally adheres to the EU-US Data Privacy Framework, the Swiss-US DPF, and the UK Extension to the EU-US DPF.

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Dropbox will implement the technical and organisational measures (TOMs) set forth in the Agreement for the applicable Services. Dropbox undergoes regular SOC 2 Type II audits. The DPA references compliance with security, confidentiality, integrity and availability measures consistent with the SCCs. (clause 3)

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA restricts processing of Customer Data to service provision on Customer's instructions (clauses 2.1, 2.2).

Subprocessing

General authorization

General
Customer consents to Dropbox's use of Affiliates and Sub-processors to perform the Services. Dropbox maintains a public list of current Sub-processors and will inform Customer in advance of any new Sub-processors. Customer has 60 days from receipt of notice to raise a written objection to a new Sub-processor on data protection grounds. Dropbox will review and respond within 30 days and use commercially reasonable efforts to accommodate; if Dropbox cannot accommodate, Customer may terminate. (clauses 4.1, 4.2)

Do all the DPA terms flow down to sub-processors?

Yes
Dropbox remains liable for all acts or omissions of its Subcontractors and Sub-processors and for any subcontracted obligations. Dropbox and its personnel will only Process Customer Data to provide the Services and fulfil obligations under the Agreement.

Is data only processed on the instruction of the controller?

Yes
The Agreement and DPA together constitute the Customer's documented instructions to Dropbox to Process Customer Data. Dropbox and its personnel will only Process Customer Data as instructed in order to deliver the Services. (clauses 2.1, 2.2)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Dropbox will direct data subjects to the Customer to exercise their data subject rights without undue delay after verifying that the request pertains to Customer Data. The Customer remains responsible for responding to data subject requests. (clause 5)

Does the contract include staff confidentiality clauses?

Yes
Any Dropbox personnel who have access to Customer Data are bound by appropriate confidentiality obligations. Access to Customer Data is restricted to authorised personnel via elevated roles. (clause 2.3)

Are there audit rights for the data?

Structured
Dropbox provides SOC 2 (and other) audit reports upon written request (clause 8.1). If Customer reasonably requires further confirmation, Dropbox will respond to written questions about the audit reports using commercially reasonable efforts (clause 8.2). If Customer remains unsatisfied after the written-question process, Customer or an agreed representative may visit Dropbox's premises and discuss responses with Dropbox personnel, subject to confidentiality obligations and mutual agreement on scope, timing, and duration (clause 8.3). Dropbox may charge reasonable fees for obligations under clauses 8.2 or 8.3 (with advance estimate) and may object to unqualified or competitor representatives (clause 8.4). Audit reports limited to no more than once per year (clause 8 context). (clauses 8.1–8.4)

Is there assistance with DPIA requests?

Yes
Dropbox provides compliance assistance for data protection impact assessments and prior consultation with supervisory authorities by making available: (a) SOC 2 audit reports; (b) Exhibit A processing details; and (c) applicable security measures. If Customer reasonably believes further information is needed, Dropbox will use commercially reasonable efforts to respond to written questions. Dropbox will also comply with valid requests from relevant supervisory authorities to the extent required by applicable EU Data Protection Law. (clause 6)

How much notice is provided for data breaches?

Dropbox will notify Customer promptly and without undue delay upon becoming aware of a Security Incident, using commercially reasonable efforts to provide notice within 72 hours of confirming the existence of the incident. Notice is sent to the email address associated with the Customer's account. Dropbox will provide information including: the nature of the incident, categories and approximate number of personal data records concerned, likely consequences, measures taken or proposed, and DPO/contact details. Dropbox may limit disclosures to protect the integrity of an ongoing investigation. (clauses 3.2, 3.3)

What happens to the data on termination?

Upon termination of the Agreement, Dropbox will delete Stored Data in Customer's account within a commercially reasonable period following receipt of an Administrator's request to do so prior to termination. Notwithstanding this, Dropbox explicitly reserves the right to act as a controller and retain "certain Account Data" in accordance with applicable privacy laws, with Dropbox solely responsible for compliance with those laws in connection with its own processing of that retained data. (clause 7)