StackLégal

Tools and automation

GDPR GitHub

In an indie stack, GitHub is used for Code repositories, issues, and Copilot depending on the plan. Entity cited: GitHub, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA GitHub

Yes. Public GitHub Data Protection Agreement.

Read the DPA

Stated role

The customer is the controller of Customer Personal Data and GitHub is the processor, unless the customer is a processor (GitHub is then a sub-processor) or GitHub is an independent controller for the purposes listed in section 3.C of the agreement. The GitHub DPA applies to processing for GitHub Enterprise Cloud, GitHub Enterprise (Unified), GitHub Teams, and GitHub Copilot.

Personal data

Basic data (name, email, address, phone, date of birth), authentication data, contact details, pseudonymous identifiers, device identification, and any other personal data the customer chooses to include. Sensitive data only if the customer or the person provides it.

Sub-processors of GitHub

Public list.

List published by the vendor

Transfers outside the EU

Hosting / location

The customer instructs GitHub to transfer, store, and process Customer Personal Data in the United States or in any other country where GitHub or its sub-processors operate. If the customer chooses an online service where certain data is stored at rest in a geographic area, GitHub follows that instruction.

EU–United States Data Privacy Framework

The “GitHub” participant is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). United Kingdom extension and Swiss-U.S. DPF: Active.

Data Privacy Framework sheet

Cookies

The GitHub Cookies page lists the cookies of its own sites. On the GitHub side: user_session (login, two weeks), __Host-user_session_same_site, logged_in, dotcom_user, _device_id, _octo, ghcc, and color_mode. The same page also names third-party cookies (Microsoft, Adobe, Google, LinkedIn, Meta, among others). This list covers GitHub sites, not a site published on the customer's domain.

Typical use, written by StackLégal and not by the vendor: Code repositories, issues, and Copilot depending on the plan.

History

Last update: October 4, 2026.

  1. Cookies: names taken from the GitHub Cookies page, in place of "not disclosed".

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is GitHub a processor within the meaning of the GDPR?

The customer is the controller of Customer Personal Data and GitHub is the processor, unless the customer is a processor (GitHub is then a sub-processor) or GitHub is an independent controller for the purposes listed in section 3.C of the agreement. The GitHub DPA applies to processing for GitHub Enterprise Cloud, GitHub Enterprise (Unified), GitHub Teams, and GitHub Copilot.

What DPA does GitHub publish?

Yes. Public GitHub Data Protection Agreement. https://github.com/customer-terms/github-data-protection-agreement

Which further sub-processors does GitHub publish?

Public list. https://github.com/subprocessors

Where does GitHub state that it processes data, including outside the EU?

The customer instructs GitHub to transfer, store, and process Customer Personal Data in the United States or in any other country where GitHub or its sub-processors operate. If the customer chooses an online service where certain data is stored at rest in a geographic area, GitHub follows that instruction.

Is GitHub registered under the EU–United States Data Privacy Framework?

The “GitHub” participant is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). United Kingdom extension and Swiss-U.S. DPF: Active. https://www.dataprivacyframework.gov/participant/6174

Which personal data does GitHub mention?

Basic data (name, email, address, phone, date of birth), authentication data, contact details, pseudonymous identifiers, device identification, and any other personal data the customer chooses to include. Sensitive data only if the customer or the person provides it.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets tools and automation

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.