GitHub

Last Reviewed: 04 Jun 2026

Data Use Review

At a Glance

GitHub's DPA reserves rights to process Customer Personal Data as an independent controller for purposes including aggregated statistical analysis for revenue planning and product strategy. These uses extend beyond processing on Customer instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United States

Products

GitHub Enterprise Cloud / Teams / Copilot

Product description

Hosted software development and collaboration services, including code hosting, project collaboration and AI coding assistance where the DPA applies.

What data is being processed?

Customer personal data provided through the online services, including repository / collaboration content, account data, user profile data, issues, tickets and related service data.

Document Details

Date of DPA

01 Oct 2025

Additional date information

GitHub Data Protection Agreement (October 2025)

What jurisdictions are covered?

EU GDPR, UK GDPR, Swiss Data Protection Act, and US CCPA are all expressly covered with dedicated provisions. Educational privacy laws (FERPA) and special data categories (CJIS, HIPAA, biometrics) are addressed through restrictions on what data may be provided to GitHub. (sections 1.D–E; 7.B; 10; 11; 12)

Is the DPA incorporated into service or customer agreements?

Yes
This DPA forms part of the GitHub Customer Agreement covering Customer's use of Online Services, and supersedes any conflicting provisions with respect to the processing of Customer Personal Data. It applies to all Online Services except products specifically identified as excluded in bespoke product terms or Previews not expressly designated as DPA-governed. (preamble; sections 2.A, 2.B)

Location & Transfers

Where is data held or processed?

Customer Selected, United States Customer Personal Data may be transferred to the United States or any other country where GitHub or its sub-processors operate. Where an Online Service offers data storage at rest in a specific geographic area, GitHub will store the applicable data in that location based on Customer instruction. (section 7.A)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU SCCs apply in three modules: Module 1 (Controller-to-Controller) for GitHub's independent processing under section 3.C, and Modules 2 and 3 (Controller-to-Processor and Processor-to-Processor) for Customer Instructions, all governed by Netherlands law with disputes before Dutch courts. A UK Addendum applies for UK GDPR transfers. Swiss transfers use the EU SCC mechanism with Swiss-specific modifications. GitHub is also certified under the EU-US, UK Extension to EU-US, and Swiss-US Data Privacy Frameworks. (sections 7.B, 7.C)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

GitHub implements TOMs including pseudonymisation and encryption, confidentiality/integrity/availability controls, timely data restoration, regular testing, access controls, incident logging, security training, and a vendor risk management programme. Annex II sets out detailed practices across access control, asset management, business continuity, event logging, and physical security. GitHub holds SOC 1 Type 2, SOC 2 Type 2, and ISO 27001:2013 certifications. (section 4; Annex II)

Non Processor Data Use

Does the company process data solely as a processor?

No
GitHub explicitly reserves the right to process Customer Personal Data as an independent Controller for five stated purposes: account and billing management, staff compensation calculations, legal compliance obligations, abuse and security detection, and creating aggregated statistical data for internal reporting, financial planning, revenue/capacity planning, and product strategy. Customer is required to agree to this processing. GitHub undertakes not to use the data for user profiling, advertising, or data selling or brokering beyond these stated purposes. (section 3.C)

Subprocessing

General authorization

General
GitHub operates under a general authorisation to engage sub-processors from the Subprocessor List at https://github.com/subprocessors. GitHub provides 30 days' notice before a new sub-processor accesses Customer Personal Data. Customers who do not approve may terminate the relevant subscription without penalty before the notice period ends. (sections 9.A, 9.B, 9.C)

Do all the DPA terms flow down to sub-processors?

Yes
GitHub is responsible for sub-processors' compliance with GitHub's obligations under this DPA, and must engage them under written agreements compliant with GDPR requirements. GitHub will oversee sub-processors to ensure their contractual obligations are met. (section 9.D)

Is data only processed on the instruction of the controller?

Yes
GitHub acts as Processor on Customer's documented Instructions, including to provide and update Online Services, troubleshoot, and enhance performance. GitHub must not disclose Customer Personal Data except in accordance with Instructions, the DPA, or law, and will notify Customer if it believes an instruction violates Data Protection Requirements. The CCPA section further restricts processing to documented Instructions only. (sections 3.B, 3.D, 3.F, 10)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
If GitHub receives a data subject request relating to an Online Service where it acts as Processor or Subprocessor, GitHub will redirect the data subject to Customer and cooperate to provide the means necessary to respond. Customer is solely responsible for responding to such requests. (section 3.G)

Does the contract include staff confidentiality clauses?

Yes
GitHub personnel with access to Customer Personal Data are obligated to maintain confidentiality of that data, and this obligation continues after their engagement ends. GitHub provides security and privacy training to all new hires and requires annual refresher training for all employees. (section 4; Annex II)

Are there audit rights for the data?

Structured
GitHub provides SOC 1 Type 2, SOC 2 Type 2, and ISO 27001 compliance reports on written request. Where Customer's audit obligations cannot be satisfied by standard reports, GitHub will accommodate additional access: during business hours, with 30 days' advance notice, limited to Customer's data and relevant systems, conducted by an accredited third-party auditor (where regulatorily required), at Customer's expense. (section 5)

Is there assistance with DPIA requests?

Yes
GitHub will assist Customer to the extent required under applicable law in fulfilling notification obligations to relevant authorities and data subjects following a Security Incident. GitHub will also cooperate with regulatory or supervisory requests that require GitHub's participation. (sections 5, 6.C)

How much notice is provided for data breaches?

Without undue delay after becoming aware of a Security Incident, GitHub will notify Customer, investigate and provide detailed information, and take reasonable steps to mitigate effects and minimise damage. GitHub also assists Customer in fulfilling notification obligations to relevant authorities and data subjects as required by law. (sections 6.A, 6.C)

What happens to the data on termination?

Following completion of the Online Services, GitHub will delete or return all Customer Personal Data at Customer's election, and delete existing copies in accordance with GitHub's retention and deletion policy, unless prohibited by law. (section 8)