Data
GDPR Firebase
In an indie stack, Firebase is used for Google application backend (auth, database, storage). Entity cited: For Firebase Paid Services, the entity is the one in the contracting-entities table for the billing address: Google Cloud France (8 Rue de Londres, Paris 75009) if it is in France; Google Cloud EMEA Limited for EMEA outside France, Italy and Poland; Google Cloud Italy S.r.l. in Italy; Google Cloud Poland Sp. z o.o. in Poland; Google LLC for the United States and any place not listed.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Firebase
Yes. Google Cloud Data Processing Addendum.
Stated role
The Google Cloud Data Processing Addendum, which covers services including Firebase services, designates Google as processor and the customer as controller or processor. For the Firebase Paid Services, the “Google” entity is the one on the contracting entities page, according to the billing address.
Personal data
Data relating to individuals provided to Google through the services, by the customer or on the customer's instruction, or by end users.
Sub-processors of Firebase
Google Cloud sub-processor list.
Transfers outside the EU
Hosting / location
The privacy page (stated last modification: 15 September 2026) states that Firebase Authentication processes data only in data centers in the United States. Most other services are global and may process data in any Google Cloud location or Google data center, unless a location is chosen when the service allows it. Identifiers of those locations: not disclosed.
EU–United States Data Privacy Framework
No “Firebase” organization on the list. Google LLC is registered, EU-U.S. Data Privacy Framework status: Active. The certification states that it applies to Google LLC and its 100%-owned US subsidiaries.
Cookies
not disclosed
Typical use, written by StackLégal and not by the vendor: Google application backend (auth, database, storage).
History
Last update: October 4, 2026.
Contracting entity, role, and hosting cross-checked against the Google Cloud and Firebase pages.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Firebase a processor within the meaning of the GDPR?
The Google Cloud Data Processing Addendum, which covers services including Firebase services, designates Google as processor and the customer as controller or processor. For the Firebase Paid Services, the “Google” entity is the one on the contracting entities page, according to the billing address.
What DPA does Firebase publish?
Yes. Google Cloud Data Processing Addendum. https://cloud.google.com/terms/data-processing-addendum
Which further sub-processors does Firebase publish?
Google Cloud sub-processor list. https://cloud.google.com/terms/subprocessors
Where does Firebase state that it processes data, including outside the EU?
The privacy page (stated last modification: 15 September 2026) states that Firebase Authentication processes data only in data centers in the United States. Most other services are global and may process data in any Google Cloud location or Google data center, unless a location is chosen when the service allows it. Identifiers of those locations: not disclosed.
Is Firebase registered under the EU–United States Data Privacy Framework?
No “Firebase” organization on the list. Google LLC is registered, EU-U.S. Data Privacy Framework status: Active. The certification states that it applies to Google LLC and its 100%-owned US subsidiaries. https://www.dataprivacyframework.gov/participant/5780
Which personal data does Firebase mention?
Data relating to individuals provided to Google through the services, by the customer or on the customer's instruction, or by end users.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.