Hosting and network
GDPR Netlify
In an indie stack, Netlify is used for Hosting for sites and functions. Entity cited: Netlify, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Netlify
Yes. DPA incorporated into the terms, public PDF (stated update: 9 June 2026).
Stated role
The DPA applies when Netlify processes Customer Data as a processor. It states that Netlify is not the controller of that Customer Data. The privacy statement covers, separately, the cases where Netlify is controller of account data and of the netlify.com site.
Personal data
The DPA cites first name and last name, title, position, employer, contact details (company, email, phone, business address), identity data, professional-life data, location data, and IP address.
Sub-processors of Netlify
Public list, with activities and countries.
Transfers outside the EU
Hosting / location
The DPA indicates that processing may take place outside the EEA, Switzerland, and the United Kingdom. The public sub-processor list shows locations overwhelmingly “US” (NS1: “Global, US”). For functions, the documentation indicates a region choice in the interface, for all functions of the site. By default, new sites are in cmh (US East, Ohio). Self-service regions: Ohio, Ireland, Frankfurt, São Paulo, Northern Virginia, London, Tokyo, Oregon, Northern California, Singapore, Sydney, and Canada (Central). Paris (cdg) and Milan (mxp) go through support.
EU–United States Data Privacy Framework
Netlify, Inc. is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). United Kingdom extension and Swiss-U.S. DPF: Active.
Cookies
The privacy statement describes cookies of the Netlify site and services. Cookies set on a customer's site: not disclosed.
Typical use, written by StackLégal and not by the vendor: Hosting for sites and functions.
History
Last update: October 4, 2026.
Hosting: clarification based on the DPA and the public sub-processor list.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Netlify a processor within the meaning of the GDPR?
The DPA applies when Netlify processes Customer Data as a processor. It states that Netlify is not the controller of that Customer Data. The privacy statement covers, separately, the cases where Netlify is controller of account data and of the netlify.com site.
What DPA does Netlify publish?
Yes. DPA incorporated into the terms, public PDF (stated update: 9 June 2026). https://www.netlify.com/pdf/netlify-dpa.pdf
Which further sub-processors does Netlify publish?
Public list, with activities and countries. https://www.netlify.com/legal/subprocessors/
Where does Netlify state that it processes data, including outside the EU?
The DPA indicates that processing may take place outside the EEA, Switzerland, and the United Kingdom. The public sub-processor list shows locations overwhelmingly “US” (NS1: “Global, US”). For functions, the documentation indicates a region choice in the interface, for all functions of the site. By default, new sites are in cmh (US East, Ohio). Self-service regions: Ohio, Ireland, Frankfurt, São Paulo, Northern Virginia, London, Tokyo, Oregon, Northern California, Singapore, Sydney, and Canada (Central). Paris (cdg) and Milan (mxp) go through support.
Is Netlify registered under the EU–United States Data Privacy Framework?
Netlify, Inc. is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). United Kingdom extension and Swiss-U.S. DPF: Active. https://www.dataprivacyframework.gov/participant/6208
Which personal data does Netlify mention?
The DPA cites first name and last name, title, position, employer, contact details (company, email, phone, business address), identity data, professional-life data, location data, and IP address.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.