StackLégal

Combination

GDPR Next.js, Vercel, and Stripe

This page reuses the vendor entries for the stack. It says what to write in the privacy policy and in the processor list. Last update: October 5, 2026.

GDPR Next.js

Next.js is the application's framework. It is not a vendor that processes personal data on your behalf: this page assigns it neither a DPA nor a processor list. You do not name it as a processor. You name the host that runs the application and the payment provider.

Read the GDPR Next.js page

What the entries say

Location, DPA, further processors and transfer mechanism. Each block links to the entry, which keeps its own check date.

Vercel Inc.. Checked on October 4, 2026.

Hosting / location
The DPA states that the primary processing facilities are in the United States as of the effective date, and that Customer Data may be processed in the United States and anywhere Vercel or its sub-processors operate. The services rely on AWS, Microsoft Azure, and Google Cloud Platform.
DPA
Yes. Published Data Processing Addendum, applicable to processing as a processor for Enterprise and Pro customers. Source
Further processors
The DPA points to the list, with functions and locations, on the Trust Center. The named table is not copied here. Source
Transfer (Data Privacy Framework)
Vercel Inc. is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). The United Kingdom extension and the Swiss-U.S. DPF are also Active. Source

Stripe Payments Europe, Limited for accounts outside North and South America; Stripe, LLC for accounts located in North or South America. Checked on October 4, 2026.

Hosting / location
The DPA indicates a transfer to Stripe, LLC in the United States. The privacy policy states that the majority of providers are in the European Union, the United States, and India.
DPA
Yes. The DPA is part of the Stripe Services Agreement. Source
Further processors
Public list of providers, sub-processors, and affiliates. Source
Transfer (Data Privacy Framework)
Stripe, LLC is registered. EU-U.S. Data Privacy Framework status: Active. The European entity Stripe Payments Europe, Limited is not the name on that entry. Source

What to write in the policy

You remain the controller of the processing of your users' data. The processors section names the vendors, not the framework.

Name Vercel Inc. for hosting. The entry indicates primary facilities in the United States, possible processing anywhere Vercel or its sub-processors operate, and reliance on AWS, Microsoft Azure, and Google Cloud Platform. Cite the DPA, Vercel Inc.'s registration under the Data Privacy Framework (status Active), and the Trust Center for sub-processors.

Name the Stripe entity of your account: Stripe Payments Europe, Limited outside the Americas, Stripe, LLC in North or South America. The entry indicates a processor role on instruction and an independent-controller role for fraud and AML/CFT, a transfer to Stripe, LLC in the United States, the registration of Stripe, LLC (status Active), and a public list of providers.

Specify the cookies that your application sets itself. The Vercel and Stripe policies describe their own cookies. They do not list those of your domain.

History

  1. First publication. The facts are taken from the entries, which cite the official pages. What is not there stays “not disclosed”.

Clauses to paste

One clause per vendor, for the processors section. Review them: a “not disclosed” field must be completed before publication.

Sub-processor clause

Related entries

Full pack, from 39 € incl. VAT

The clauses above cover this stack only. StackLégal generates the legal notice, terms of use, terms of sale, privacy policy, Article 28 DPA and the public list, citing only the boxes you tick. One-time payment via Gumroad. This is not legal advice.