Kaseya

Last Reviewed: 17 Jun 2026

GDPR Addressed

At a Glance

Kaseya's DPA addresses GDPR, UK, Swiss and US requirements with EU SCCs, UK IDTA and Data Privacy Frameworks in place for international transfers. TOMs are detailed and contractually binding. Audit rights are structured: capped at once per year, with third-party audit reports substituted for direct inspection.

Company & Product Details

HQ

United States

Products

IT Management & Security Platform

Product description

Provides IT management, endpoint security, backup, and compliance software for MSPs and corporate IT departments.

What data is being processed?

Name, title, employer, contact information (email, phone, address), ID data, professional life data, personal life data, connection data, localization data, and other electronic data submitted by customers and end users via the Products.

Document Details

Date of DPA

04 Feb 2026

Additional date information

The DPA document itself does not display an explicit effective date. The page metadata shows a last-modified date of 4 February 2026, which is used as the DPA date. The page was originally published on 7 October 2025.

What jurisdictions are covered?

EU/EEA (GDPR, Regulation (EU) 2016/679), UK (UK GDPR), Switzerland (Swiss Federal Data Protection Act), and United States (CCPA and other US federal and state laws). The DPA also references the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, and UK Extension to the EU-U.S. Data Privacy Framework as adequacy mechanisms for international transfers. (clauses 1, 4, 12)

Is the DPA incorporated into service or customer agreements?

Yes
The Addendum is stated to be incorporated into and forming part of the Agreement in the preamble. The Agreement is defined as the Kaseya Master Agreement or such other agreement under which Kaseya provides Products, including Orders, Statements of Work, exhibits, addenda, and amendments. The order of precedence is: (a) Standard Contractual Clauses, (b) this Addendum, (c) the Agreement. (preamble, clause 17)

Location & Transfers

Where is data held or processed?

Not Explicitly Stated Data is stored and processed at the locations of Kaseya's applicable data centres for the relevant Products, at sub-processor locations, and wherever necessary for implementation, support, maintenance, incident management, and backup and recovery. No specific countries are named in the DPA body. The competent supervisory authority identified is the Data Protection Commission of Ireland, indicating primary EEA processing there. Customers cannot select the data location under this DPA. (clause 5.c.iii, Appendix 1.C)

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU SCCs (Commission Implementing Decision 2021/914) apply for EEA transfers, with Module 2 for controller-to-processor and Module 3 for processor-to-processor relationships. The UK International Data Transfer Addendum (UK IDTA, version B1.0, effective 21 March 2022) applies for UK transfers. Swiss SCCs apply for Swiss transfers where EU SCCs cannot be used. Kaseya also participates in the EU-U.S., Swiss-U.S., and UK Extension Data Privacy Frameworks as adequacy mechanisms, which take precedence over SCCs while those Frameworks remain valid. Alternative Transfer Mechanisms may automatically replace SCCs if adopted. (clause 12, Appendix 3)

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Extensive TOMs are set out in Appendix 2, aligned with ISO/IEC 27000 standards and the NIST Cybersecurity Framework. Measures include: encryption in transit and at rest using state-of-the-art protocols; least-privilege access controls with MFA; geographically distributed redundant data centres; business continuity and disaster recovery testing; intrusion detection and prevention systems; annual AICPA SOC 2 Type II audits and penetration testing; CIS Level 1 benchmark configuration baselines; NIST 800-88 data destruction within 45 days of agreement end; mandatory annual security awareness training for all staff; and a formal vulnerability disclosure policy. (Appendix 2)

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Clause 2 establishes Kaseya as Processor (and Service Provider) for Customer Personal Data processed under the Agreement. CCPA provisions (clause 5.g) explicitly prohibit Kaseya from Selling, Sharing, or using Customer Personal Data for commercial purposes beyond the Business Purposes under the Agreement. Note: clause 5.f contains a carve-out for "Administrative Data" (account management and operational data about the customer relationship), for which Kaseya acts as an independent Controller for purposes compatible with the Agreement only. This carve-out does not extend to Customer Personal Data submitted by End Users via the Products. (clauses 2, 5.f, 5.g)

Subprocessing

General authorization

General
Customer gives general written authorisation for Kaseya to engage sub-processors, provided Kaseya enters a written contract with each sub-processor imposing equivalent data protection obligations. Kaseya maintains a publicly accessible sub-processor list at kaseya.com/subprocessors. Customers can register for email notifications of changes; upon receiving notice, Customer has 15 calendar days to object in good faith, and the parties must work together to resolve any objection. Where a sub-processor fails its obligations, Kaseya remains liable to Customer. (clause 7, Appendix 3.1.c)

Do all the DPA terms flow down to sub-processors?

Yes
Kaseya must enter a written contract with each sub-processor that includes data protection obligations equivalent to those in this Addendum. If a sub-processor fails to meet its obligations, Kaseya remains fully liable to Customer for that sub-processor's performance. (clause 7.a)

Is data only processed on the instruction of the controller?

Yes
Kaseya processes Customer Personal Data only on documented instructions from Customer, as set out in the Agreement and this Addendum. Kaseya must immediately inform Customer if it believes an instruction infringes Applicable Data Protection Laws. Where required by law to process without instruction, Kaseya must inform Customer before processing unless prohibited from doing so. (clauses 3, 5.h)

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Kaseya agrees to maintain appropriate measures to reasonably assist Customer in responding to data subject requests (access, erasure, portability, etc.). If Kaseya directly receives a data subject request that specifically names Customer, it will redirect the data subject to Customer, promptly notify Customer, and not otherwise respond without Customer's express authorisation. (clause 8)

Does the contract include staff confidentiality clauses?

Yes
Kaseya ensures that all personnel authorised to process Customer Personal Data are bound by a duty of confidentiality and have received reasonable and appropriate privacy and security training. (clause 6)

Are there audit rights for the data?

Structured
Audit rights are available on written request, limited to once per year unless otherwise required by law. Kaseya will make available information reasonably necessary to demonstrate compliance with the Addendum and Applicable Data Protection Laws. As an alternative, Kaseya may provide relevant third-party audit reports (such as SOC 2 Type II), which Customer agrees are sufficient unless more detailed information is reasonably necessary to demonstrate compliance. Where more detail is needed, scope and timing must be agreed between the parties. Any information provided to Customer is treated as Kaseya's Confidential Information. (clause 13)

Is there assistance with DPIA requests?

Yes
Upon Customer's reasonable request, Kaseya will assist Customer in complying with obligations to carry out privacy or data protection impact assessments (DPIAs) and regulatory consultations under Applicable Data Protection Laws. (clause 9)

How much notice is provided for data breaches?

Kaseya will notify Customer without undue delay, and in any event within the notification period required by Applicable Data Protection Laws, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. No specific hour threshold is stated beyond the statutory obligation. Kaseya will provide information necessary for Customer to notify supervisory authorities and affected data subjects, and will cooperate with Customer's breach response, subject to any law enforcement limitations. (clause 11)

What happens to the data on termination?

Kaseya will delete all Customer Personal Data after expiration or termination of the Agreement or Service Subscription. Customer may request return of all Personal Data by written notice within 30 days after the Termination Date. Appendix 2 specifies a NIST 800-88 based data destruction process completed within 45 days after the end of the agreement. Retention beyond these timelines is permitted only where required by applicable law or regulation. (clause 14, Appendix 2)