StackLégal

Hosting and network

GDPR Vercel

For “GDPR Vercel”, the entry records that Vercel Inc. is the processor of Customer Data on the Enterprise and Pro plans, that the DPA is public, and that the primary facilities are in the United States, with reliance on AWS, Microsoft Azure, and Google Cloud Platform. Vercel Inc. is registered under the Data Privacy Framework, status Active.

In an indie stack, Vercel is used for Hosting, CDN, and front-end deployments. Entity cited: Vercel Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Vercel

Yes. Published Data Processing Addendum, applicable to processing as a processor for Enterprise and Pro customers.

Read the DPA

Stated role

For the Enterprise and Pro plans, the customer is the controller (or processor) and Vercel is the processor of Customer Data. Vercel also presents itself as controller for contact data and for certain data generated by the service when that data is personal data.

Personal data

The DPA and the privacy policy cite in particular the IP address, configuration information, name, email, phone, account preferences, the content of support exchanges, and, for end users, the IP address and a location derived from the IP.

Sub-processors of Vercel

The DPA points to the list, with functions and locations, on the Trust Center. The named table is not copied here.

List published by the vendor

Transfers outside the EU

Hosting / location

The DPA states that the primary processing facilities are in the United States as of the effective date, and that Customer Data may be processed in the United States and anywhere Vercel or its sub-processors operate. The services rely on AWS, Microsoft Azure, and Google Cloud Platform.

EU–United States Data Privacy Framework

Vercel Inc. is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). The United Kingdom extension and the Swiss-U.S. DPF are also Active.

Data Privacy Framework sheet

Cookies

The Cookie Policy (stated update: 21 April 2020) describes, on the Vercel site and platform, essential authentication cookies, functionality cookies (preferences, support, payment), and performance cookies, including Google Analytics. It does not publish the names. Cookies a customer sets on a site hosted at Vercel are the customer's responsibility. Names set by Vercel on the customer's domain: not disclosed.

Typical use, written by StackLégal and not by the vendor: Hosting, CDN, and front-end deployments.

History

Last update: October 4, 2026.

  1. Cookies: description from the Cookie Policy, in place of "not disclosed" for the names.

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Vercel a processor within the meaning of the GDPR?

For the Enterprise and Pro plans, the customer is the controller (or processor) and Vercel is the processor of Customer Data. Vercel also presents itself as controller for contact data and for certain data generated by the service when that data is personal data.

What DPA does Vercel publish?

Yes. Published Data Processing Addendum, applicable to processing as a processor for Enterprise and Pro customers. https://vercel.com/legal/dpa

Which further sub-processors does Vercel publish?

The DPA points to the list, with functions and locations, on the Trust Center. The named table is not copied here. https://security.vercel.com

Where does Vercel state that it processes data, including outside the EU?

The DPA states that the primary processing facilities are in the United States as of the effective date, and that Customer Data may be processed in the United States and anywhere Vercel or its sub-processors operate. The services rely on AWS, Microsoft Azure, and Google Cloud Platform.

Is Vercel registered under the EU–United States Data Privacy Framework?

Vercel Inc. is registered. EU-U.S. Data Privacy Framework status: Active (non-HR data). The United Kingdom extension and the Swiss-U.S. DPF are also Active. https://www.dataprivacyframework.gov/participant/6847

Which personal data does Vercel mention?

The DPA and the privacy policy cite in particular the IP address, configuration information, name, email, phone, account preferences, the content of support exchanges, and, for end users, the IP address and a location derived from the IP.

Stacks that cite Vercel

These pages assemble the sheets of a common stack and state what to write in the privacy policy.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets hosting and network

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.