Customer agreements · GitHub
https://github.com/customer-terms/github-data-protection-agreement • 345 KB fetched
Open original page
Customer agreements · GitHub
Skip to content
Navigation Menu
Sign in
* Platform
* AI CODE CREATION
* GitHub Copilot Write better code with AI
* GitHub Copilot app Direct agents from issue to merge
* MCP Registry Integrate external tools
* DEVELOPER WORKFLOWS
* Actions Automate any workflow
* Codespaces Instant dev environments
* Issues Plan and track work
* Code Review Manage code changes
* Code Quality Enforce quality at merge
* APPLICATION SECURITY
* GitHub Advanced Security Find and fix vulnerabilities
* Code security Secure your code as you build
* Secret protection Stop leaks before they start
* EXPLORE
* Why GitHub
* Documentation
* Blog
* Changelog
* Marketplace
View all features
* Solutions
* BY COMPANY SIZE
* Enterprises
* Small and medium teams
* Startups
* Nonprofits
* BY USE CASE
* App Modernization
* DevSecOps
* DevOps
* CI/CD
* View all use cases
* BY INDUSTRY
* Healthcare
* Financial services
* Manufacturing
* Government
* View all industries
View all solutions
* Resources
* EXPLORE BY TOPIC
* AI
* Software Development
* DevOps
* Security
* View all topics
* EXPLORE BY TYPE
* Customer stories
* Events & webinars
* Ebooks & reports
* Business insights
* GitHub Skills
* SUPPORT & SERVICES
* Documentation
* Customer support
* Community forum
* Trust center
* Partners
View all resources
* Open Source
* COMMUNITY
* GitHub Sponsors Fund open source developers
* PROGRAMS
* Security Lab
* Maintainer Community
* GitHub Stars
* Archive Program
* REPOSITORIES
* Topics
* Trending
* Collections
* Enterprise
* ENTERPRISE SOLUTIONS
* Enterprise platform AI-powered developer platform
* AVAILABLE ADD-ONS
* GitHub Advanced Security Enterprise-grade security features
* Copilot for Business Enterprise-grade AI features
* Premium Support Enterprise-grade 24/7 support
* Pricing
Search /
Sign in
Sign up
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
* Customer Terms
* GitHub Data Protection Agreement
GitHub Data Protection Agreement
This GitHub Data Protection Agreement forms part of the GitHub Customer Agreement between Customer (“You”) and GitHub, Inc., (“GitHub”) covering Your legal entity’s use of the Online Services. It sets forth the parties’ obligations with respect to Customer Personal Data processed by GitHub. Capitalized terms not defined in this document shall have the meaning as provided elsewhere in your GitHub Customer Agreement.
1. Definitions.
A. “CCPA” means the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq) and its implementing regulations.
B. “Customer Personal Data” means all data, including all text, sound, video, or image files, and software, that are provided to GitHub by or on behalf of Customer through use of the Online Services.
C. “DPA” means this GitHub Data Protection Agreement.
D. “Data Protection Requirements” means the applicable obligations imposed on GitHub by the GDPR, any subordinate legislation or regulations implementing the GDPR, the CCPA, and any other applicable laws, regulations, and other legal requirements applicable to GitHub and relating to:
i. Privacy and data security; or
ii. The use, collection, retention, storage, security, disclosure, transfer, disposal, and other processing of any Personal Data.
E. “GDPR” means:
i. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016; and
ii. Regulation (EU) 2016/679 as transposed into national law of the United Kingdom by the UK European Union (Withdrawal) Act 2018 and amended by the UK Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (as may be amended from time to time).
F. “GitHub Affiliate” means any entity that controls GitHub, is controlled by GitHub, or is under common control with GitHub.
G. “GitHub Customer Agreement” or “Agreement” means Your agreement(s) for the Online Services.
H. “Instructions” mean the activities you instruct GitHub to perform as Processor acting on Your behalf.
I. “Online Services” means any service or software that GitHub provides You under a written and executed agreement.
J. “Preview” means Online Services provided for preview, evaluation, demonstration, or trial purposes, and any beta, technical preview, or other pre-release versions of the Online Services.
K. “Professional Services” means training, consulting or implementation services provided by GitHub. Professional Services do not include support.
L. “Professional Services Data” means all Customer Personal Data that are provided to GitHub, by or on behalf of a Customer or that Customer authorizes GitHub to obtain from an Online Service or otherwise obtained or processed by or on behalf of GitHub through an engagement with GitHub to obtain Professional Services.
M. “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by GitHub on Your behalf.
N. “Standard Contractual Clauses” or “SCCs” means:
i. where the GDPR applies the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (the “EU SCCs”);
ii. where the UK GDPR applies, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under s.119A(1) of the Data Protection Act 2018 (“UK Addendum”); and
iii. where the Swiss Data Protection Act (“Swiss DPA”) applies, the applicable standard data protection clauses issued, approved or otherwise recognized by the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) (the “Swiss SCCs”).
O. “Subprocessor” means a third-party Processor retained by GitHub to process Your data.
P. “Subprocessor List” means the list of Subprocessors identified on the GitHub website at https://github.com/subprocessors or a successor location.
Q. “Troubleshooting” means preventing, detecting, investigating, mitigating, and repairing problems, including Security Incidents and problems identified in the relevant products. Troubleshooting includes fixing software defects and otherwise keeping the Online Services up to date and performant.
R. “Controller,” “Data Subject,” “Personal Data,” “Process,” and “Processor” have the meanings ascribed to them in the GDPR.
2. Scope and Order of Precedence.
A. This DPA applies to all Online Services except:
i. Products specifically identified as excluded in bespoke GitHub product terms, in which case those terms shall control so long as such terms are compliant with Data Protection Requirements, and
ii. Previews, unless expressly designated by GitHub as being governed by this DPA. Previews may employ privacy and security measures that are different from those normally provided in Online Services and are offered under Preview Terms. Unless otherwise noted, Customers should not use Previews to process Personal Data or other data that is subject to legal or regulatory compliance requirements.
B. In the event of any other conflict or inconsistency between the terms of this DPA Terms and any other terms in the GitHub Customer Agreement, the terms of this DPA shall prevail. The terms of this DPA shall supersede any conflicting provisions with respect to the processing of Customer Personal Data or Professional Services Data.
3. Processing Roles and Responsibilities.
A. Roles. You are the Controller of Customer Personal Data, and we are the Processor of that data, unless:
i. You are the Processor of the Customer Personal Data. In that case, GitHub is a Subprocessor;
ii. GitHub is an independent Controller processing Customer Personal Data for the purposes listed in Section 3.C of this DPA; or
iii. Otherwise expressly stated in the specific terms applicable to a particular Online Service in accordance with Section 2.A.
B. Your Processing Instructions to GitHub. You instruct GitHub to perform the following activities as Processor acting on Your behalf:
i. Provide Online Services by:
a. Providing and updating the Online Services as configured and used by You or Your users, and to make ongoing personalized experiences and recommendations;
b. Troubleshooting; and
c. Keeping Online Services up to date and performant, and enhancing user productivity, reliability, efficacy, quality, privacy, accessibility and security.
ii. Provide Professional Services by:
a. Delivering the Professional Services, including providing technical support, professional planning, advice, guidance, data migration, deployment, and solution/software development services;
b. Troubleshooting in connection with Professional Services; and
c. Enhancing delivery, efficacy, quality, and security of Professional Services and the underlying product(s) based on issues identified while providing Professional Services, including fixing software defects, and otherwise keeping the Professional Services up to date and performant.
iii. Process Customer Personal Data as set out in:
a. Your GitHub Customer Agreement;
b. Annex I to the Standard Contractual Clauses; and
c. any other documented instruction provided by You and acknowledged in writing by GitHub as constituting instructions for purposes of this DPA.
C. GitHub’s Independent Processing of Data. GitHub Processes some Customer Personal Data as an independent Controller. GitHub conducts such processing in compliance with Data Protection Requirements generally, and the GDPR specifically, and in a manner consistent with the purposes outlined in the GitHub Privacy Statement. Those exhaustive purposes are restated here for transparency and convenience:
i. account, billing, and customer relationship management and related customer correspondence;
ii. compensation (e.g., calculating employee commissions and partner incentives);
iii. complying with and resolving legal obligations, including responding to Data Subject requests for Personal Data processed by GitHub as Controller (for example website data), tax requirements, agreements, and disputes;
iv. abuse detection, prevention, and protection, virus scanning, and scanning to detect violations of terms of service and,
v. creating aggregated statistical data for internal reporting, financial reporting, revenue planning, capacity planning, and forecast modeling (including product strategy).
GitHub will not use or otherwise process Customer Personal Data for: (a) user profiling, (b) advertising or similar commercial purposes, (c) data selling or brokering, or (d) any other purpose, other than for the purposes set out in this section. You agree that GitHub may conduct this Processing.
D. Lawfulness of Instructions.
i. It is Your responsibility to ensure that Your Instructions comply with Data Protection Requirements. GitHub is not responsible for determining what laws or regulations apply to Your business, or for determining whether GitHub’s provision of services meets the requirements of such laws.
ii. You will ensure that processing Customer Personal Data in accordance with your Instructions will not cause GitHub to violate any law or regulation, including Data Protection Requirements.
iii. GitHub will inform you if it becomes aware, or reasonably believes, that Your Instructions violate any applicable law or regulation.
E. Additional Instructions. The parties will agree to additional instructions outside the scope of the GitHub Customer Agreement or DPA in writing.
F. Disclosure of Customer Personal Data.
i. GitHub will not disclose or provide access to any Customer Personal Data unless it is:
a. in accordance with Your Instructions; or
b. as described in this DPA; or
c. required by law, in which case the Additional Safeguards Addendum in Annex IV to the Standard Contractual Clauses will apply.
ii. GitHub will not disclose or provide access to any Customer Personal Data to law enforcement unless required by law or compelled by legal process. Requests by law enforcement for Customer Personal Data will be directed to You where possible.
iii. GitHub will contact You if disclosure of Your Customer Personal Data is compelled and provide a copy of the legal process compelling the disclosure, unless we are legally prohibited from doing so.
G. Data Subject Rights. If GitHub receives a request from one of Your Data Subjects pertaining to an Online Service where GitHub functions as Your Processor or Subprocessor, GitHub will redirect the Data Subject to You. Consistent with the functionality of the Online Services and GitHub's role, we will cooperate with You and provide You the necessary means to respond. You are solely responsible for responding to these requests.
4. Security.
GitHub will implement and maintain appropriate technical and organizational measures and security safeguards as set out in Annex II to the Standard Contractual Clauses. You and GitHub shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate:
A. the pseudonymisation and encryption of Personal Data;
B. the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
C. the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and,
D. a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
5. Audit. GitHub will provide You with security compliance reporting, such as external SOC1 Type 2 and SOC2 Type 2 and ISO 27001 audit reports, upon Your request. Should You be required to respond to a regulatory or supervisory request that requires GitHub’s participation, and Your obligations cannot reasonably be satisfied with GitHub’s standard security compliance reports, GitHub will promptly respond to Your additional Instructions and requests for information, in accordance with the following terms and conditions:
A. GitHub will provide access to relevant knowledgeable personnel, documentation, and application software.
B. You and GitHub will agree in writing upon the scope, timing, duration, control, and evidence requirements.
C. Unless GitHub is otherwise required by law or a supervisory authority of competent jurisdiction, GitHub will provide such access:
i. if the regulator or supervisory authority uses an independent and accredited third-party audit firm;
ii. during regular business hours;
iii. on 30 days advance written notice; and
iv. only to Your data and to those GitHub systems or facilities involved in the relevant Online Services. Neither You, Your regulators, or Your regulators’ delegates shall have access to any data from GitHub’s other customers or to GitHub systems or facilities not involved in the Online Services.
D. You will compensate GitHub for the expenses incurred by our cooperation, including all out-of-pocket costs and reasonable costs and fees for time GitHub expends, or services GitHub provides, in connection with such cooperation.
E. Unless prohibited by law from doing so, You will share with GitHub any reports, findings, or recommended actions pertaining to GitHub.
6. Security Incidents.
A. If GitHub becomes aware of a Security Incident, GitHub will without undue delay:
i. notify You of the Security Incident, in accordance with the notice provisions in this DPA;
ii. investigate the Security Incident and provide detailed information about it; and,
iii. take reasonable steps to mitigate its effects and minimize any resulting damage.
B. GitHub’s notification of or response to a Security Incident under this section is not an acknowledgement of any fault or liability.
C. You are solely responsible for complying with Your obligations under any incident notification laws. GitHub will assist you to the extent required under applicable law in fulfilling Your obligation to notify the relevant authorities and data subjects.
D. You must notify GitHub promptly about any possible misuse of Your accounts or authentication credentials, or any Security Incident related to an Online Service.
7. Data Transfers and Location. You appoint GitHub to transfer Customer Personal Data to the United States or any other country in which GitHub or its Subprocessors operate, and to store and process Customer Personal Data to provide the Online Services, subject to the safeguards below and described elsewhere in this DPA.
A. GitHub may transfer and process Customer Personal Data to and in the United States, to third-party countries (including those outside of the European Economic Area (“EEA”) without an adequacy statement from the European Commission), and to Subprocessors, GitHub Affiliates, and our professional advisors. GitHub shall ensure that such transfers are made in compliance with Data Protection Requirements and this DPA. If you select and use an Online Service where certain data is stored at rest in a specific geographic area, GitHub will store the applicable data based on that instruction.
B. Any transfer of Customer Personal Data subject to this DPA from member states of the EU, EEA, Switzerland, or the United Kingdom to any countries where the European Commission, the FDPIC, or the UK Information Commissioner's Office has not decided that the third country or more specified sectors within that third country ensures an adequate level of protection, shall be undertaken:
i. subject to GitHub’s self-certification to the EU-US Data Privacy Framework and, as applicable, the UK Extension to the EU-US Data Privacy Framework and/or the Swiss-US Data Privacy Framewor
Links found on this page
- Skip to content [direct]
- Sign in [direct]
- GitHub Copilot Write better code with AI [direct]
- GitHub Copilot app Direct agents from issue to merge [direct]
- MCP Registry Integrate external tools [direct]
- Actions Automate any workflow [direct]
- Codespaces Instant dev environments [direct]
- Issues Plan and track work [direct]
- Code Review Manage code changes [direct]
- Code Quality Enforce quality at merge [direct]
- GitHub Advanced Security Find and fix vulnerabilities [direct]
- Code security Secure your code as you build [direct]
- Secret protection Stop leaks before they start [direct]
- Why GitHub [direct]
- Documentation [direct]
- Blog [direct]
- Changelog [direct]
- Marketplace [direct]
- View all features [direct]
- Enterprises [direct]
- Small and medium teams [direct]
- Startups [direct]
- Nonprofits [direct]
- App Modernization [direct]
- DevSecOps [direct]
- DevOps [direct]
- CI/CD [direct]
- View all use cases [direct]
- Healthcare [direct]
- Financial services [direct]
- Manufacturing [direct]
- Government [direct]
- View all industries [direct]
- View all solutions [direct]
- AI [direct]
- Software Development [direct]
- DevOps [direct]
- Security [direct]
- View all topics [direct]
- Customer stories [direct]
- Events & webinars [direct]
- Ebooks & reports [direct]
- Business insights [direct]
- GitHub Skills [direct]
- Customer support [direct]
- Community forum [direct]
- Trust center [direct]
- Partners [direct]
- View all resources [direct]
- GitHub Sponsors Fund open source developers [direct]
- Security Lab [direct]
- Maintainer Community [direct]
- GitHub Stars [direct]
- Archive Program [direct]
- Topics [direct]
- Trending [direct]
- Collections [direct]
- Copilot for Business Enterprise-grade AI features [direct]
- Premium Support Enterprise-grade 24/7 support [direct]
- Pricing [direct]
- Sign up [direct]
- Customer Terms [direct]
- https://github.com/subprocessors [direct]
- https://gh.io/subscribe [direct]
- https://support.github.com/contact/privacy [direct]
- https://github.com/github-subprocessors-list [direct]
- Subscribe [direct]
- AI [direct]
- Security [direct]
- Roadmap [direct]
- Compare GitHub [direct]
- Developer API [direct]
- Education [direct]
- GitHub CLI [direct]
- GitHub Desktop [direct]
- GitHub Mobile [direct]
- Community Forum [direct]
- Professional Services [direct]
- Status [direct]
- Contact GitHub [direct]