Kaseya
Last Reviewed: 17 Jun 2026
At a Glance
Kaseya's DPA addresses GDPR, UK, Swiss and US requirements with EU SCCs, UK IDTA and Data Privacy Frameworks in place for international transfers. TOMs are detailed and contractually binding. Audit rights are structured: capped at once per year, with third-party audit reports substituted for direct inspection.
Company & Product Details
HQ
United States
Products
IT Management & Security Platform
Product description
Provides IT management, endpoint security, backup, and compliance software for MSPs and corporate IT departments.
What data is being processed?
Name, title, employer, contact information (email, phone, address), ID data, professional life data, personal life data, connection data, localization data, and other electronic data submitted by customers and end users via the Products.
Document Details
Date of DPA
04 Feb 2026
Additional date information
The DPA document itself does not display an explicit effective date. The page metadata shows a last-modified date of 4 February 2026, which is used as the DPA date. The page was originally published on 7 October 2025.
What jurisdictions are covered?
EU/EEA (GDPR, Regulation (EU) 2016/679), UK (UK GDPR), Switzerland (Swiss Federal Data Protection Act), and United States (CCPA and other US federal and state laws). The DPA also references the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, and UK Extension to the EU-U.S. Data Privacy Framework as adequacy mechanisms for international transfers. (clauses 1, 4, 12)
Is the DPA incorporated into service or customer agreements?
Link
https://www.kaseya.com/legal/kaseya-data-processing-addendum/
Location & Transfers
Where is data held or processed?
Not Explicitly Stated Data is stored and processed at the locations of Kaseya's applicable data centres for the relevant Products, at sub-processor locations, and wherever necessary for implementation, support, maintenance, incident management, and backup and recovery. No specific countries are named in the DPA body. The competent supervisory authority identified is the Data Protection Commission of Ireland, indicating primary EEA processing there. Customers cannot select the data location under this DPA. (clause 5.c.iii, Appendix 1.C)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Extensive TOMs are set out in Appendix 2, aligned with ISO/IEC 27000 standards and the NIST Cybersecurity Framework. Measures include: encryption in transit and at rest using state-of-the-art protocols; least-privilege access controls with MFA; geographically distributed redundant data centres; business continuity and disaster recovery testing; intrusion detection and prevention systems; annual AICPA SOC 2 Type II audits and penetration testing; CIS Level 1 benchmark configuration baselines; NIST 800-88 data destruction within 45 days of agreement end; mandatory annual security awareness training for all staff; and a formal vulnerability disclosure policy. (Appendix 2)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Kaseya will notify Customer without undue delay, and in any event within the notification period required by Applicable Data Protection Laws, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. No specific hour threshold is stated beyond the statutory obligation. Kaseya will provide information necessary for Customer to notify supervisory authorities and affected data subjects, and will cooperate with Customer's breach response, subject to any law enforcement limitations. (clause 11)
What happens to the data on termination?
Kaseya will delete all Customer Personal Data after expiration or termination of the Agreement or Service Subscription. Customer may request return of all Personal Data by written notice within 30 days after the Termination Date. Appendix 2 specifies a NIST 800-88 based data destruction process completed within 45 days after the end of the agreement. Retention beyond these timelines is permitted only where required by applicable law or regulation. (clause 14, Appendix 2)