GitHub
Last Reviewed: 04 Jun 2026
At a Glance
GitHub's DPA reserves rights to process Customer Personal Data as an independent controller for purposes including aggregated statistical analysis for revenue planning and product strategy. These uses extend beyond processing on Customer instructions. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Company & Product Details
HQ
United States
Products
GitHub Enterprise Cloud / Teams / Copilot
Product description
Hosted software development and collaboration services, including code hosting, project collaboration and AI coding assistance where the DPA applies.
What data is being processed?
Customer personal data provided through the online services, including repository / collaboration content, account data, user profile data, issues, tickets and related service data.
Document Details
Date of DPA
01 Oct 2025
Additional date information
GitHub Data Protection Agreement (October 2025)
What jurisdictions are covered?
EU GDPR, UK GDPR, Swiss Data Protection Act, and US CCPA are all expressly covered with dedicated provisions. Educational privacy laws (FERPA) and special data categories (CJIS, HIPAA, biometrics) are addressed through restrictions on what data may be provided to GitHub. (sections 1.D–E; 7.B; 10; 11; 12)
Is the DPA incorporated into service or customer agreements?
Link
https://github.com/customer-terms/github-data-protection-agreement
Location & Transfers
Where is data held or processed?
Customer Selected, United States Customer Personal Data may be transferred to the United States or any other country where GitHub or its sub-processors operate. Where an Online Service offers data storage at rest in a specific geographic area, GitHub will store the applicable data in that location based on Customer instruction. (section 7.A)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
GitHub implements TOMs including pseudonymisation and encryption, confidentiality/integrity/availability controls, timely data restoration, regular testing, access controls, incident logging, security training, and a vendor risk management programme. Annex II sets out detailed practices across access control, asset management, business continuity, event logging, and physical security. GitHub holds SOC 1 Type 2, SOC 2 Type 2, and ISO 27001:2013 certifications. (section 4; Annex II)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Without undue delay after becoming aware of a Security Incident, GitHub will notify Customer, investigate and provide detailed information, and take reasonable steps to mitigate effects and minimise damage. GitHub also assists Customer in fulfilling notification obligations to relevant authorities and data subjects as required by law. (sections 6.A, 6.C)
What happens to the data on termination?
Following completion of the Online Services, GitHub will delete or return all Customer Personal Data at Customer's election, and delete existing copies in accordance with GitHub's retention and deletion policy, unless prohibited by law. (section 8)