StackLégal

Authentication

GDPR Clerk

For “GDPR Clerk”, Clerk, Inc. is the processor, or a sub-processor if you already are one. The entry indicates hosting in the United States, with no regional residency, and a transfer from the EU under the Data Privacy Framework, status Active. The DPA is public.

In an indie stack, Clerk is used for Authentication and user accounts. Entity cited: Clerk, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Clerk

Yes. Public DPA. Clerk states there that it is self-certified under the DPF.

Read the DPA

Stated role

For the GDPR, the customer is generally controller and Clerk is processor, or sub-processor if the customer is a processor. Account Information is excluded from Customer Personal Data.

Personal data

Depending on the configuration: name, phone, email, address, IP address, device identifiers, usage data (interactions, browser, system, referring URL).

Sub-processors of Clerk

Legal page, which points the up-to-date list to the Trust Center.

List published by the vendor

Transfers outside the EU

Hosting / location

United States. Clerk states that it does not offer regional residency. The security page indicates hosting on US infrastructure (Google Cloud and Cloudflare), all sub-processors in the United States, and a transfer of EU, United Kingdom, and Swiss data to the United States under the Data Privacy Framework.

EU–United States Data Privacy Framework

Clerk, Inc. is registered. EU-U.S. Data Privacy Framework status: Active.

Data Privacy Framework sheet

Cookies

The documentation states that Clerk sets cookies when a user signs in or signs up, that they are necessary for operation, and that they do not store identifying data by default. In production: __client (HttpOnly, issued by the Frontend API), __client_uat, and __session. In development: __clerk_db_jwt, __client_uat, and __session. The cookies page also cites, on Clerk domains, __session, __client_uat, and the Cloudflare cookie _cfuvid.

Typical use, written by StackLégal and not by the vendor: Authentication and user accounts.

History

Last update: October 4, 2026.

  1. Cookies: description taken from the Clerk documentation, in place of "not disclosed".

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Clerk a processor within the meaning of the GDPR?

For the GDPR, the customer is generally controller and Clerk is processor, or sub-processor if the customer is a processor. Account Information is excluded from Customer Personal Data.

What DPA does Clerk publish?

Yes. Public DPA. Clerk states there that it is self-certified under the DPF. https://clerk.com/legal/dpa

Which further sub-processors does Clerk publish?

Legal page, which points the up-to-date list to the Trust Center. https://clerk.com/legal/subprocessors

Where does Clerk state that it processes data, including outside the EU?

United States. Clerk states that it does not offer regional residency. The security page indicates hosting on US infrastructure (Google Cloud and Cloudflare), all sub-processors in the United States, and a transfer of EU, United Kingdom, and Swiss data to the United States under the Data Privacy Framework.

Is Clerk registered under the EU–United States Data Privacy Framework?

Clerk, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. https://www.dataprivacyframework.gov/participant/2718

Which personal data does Clerk mention?

Depending on the configuration: name, phone, email, address, IP address, device identifiers, usage data (interactions, browser, system, referring URL).

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets authentication

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.