tollwerk / data-processing-agreements

Collection of Data Processing Agreement (DPA) and GDPR compliance resources

Home Page:https://tollwerk.github.io/data-processing-agreements/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Data Processors and their DPA resources

This collection aims to help you with establishing GDPR compliance by concluding the required Data Processing Agreements (DPA) between you and the services processing personal data on your behalf ("Data Processors").

The list is curated by Joschi Kuphal, Sebastian Greger and Baltasar Cevc and complements their current workshop series about data protection and ethical design issues. ⚠ It is meant as a tool to get a quick entry and first orientation only. It does not replace a thorough and independent check of your individual legal requirements. ⚠

Contribute

Please send in pull requests (learn how) for updates and additions. For instance, you may suggest additional data processors, resources or URLs to conversations and official statements on the web. Please understand that we can only accept URLs that point to the data processors' official websites or social media profiles (we will only quote non-published information as comments that we have retrieved ourselves first-hand). Thanks for your support! πŸ™‡

Alphabetical list

Data Processor Status Resources Comment
1und1 πŸ” German DPA
Adobe πŸ” English Online Form
Algolia βœ… English DPA (PDF)
GDPR information
All-Inkl.com βœ… Pre-filled download from customer's Members Area (Stammdaten β€Ί Auftragsverarbeitung).
Amazon AWS βœ… English website
German website
Atlassian Cloud βœ… English website DPA available on request for Atlassian Cloud customers
Automattic βœ… English Support Article, DPA on individual request for paid plans of WordPress.com, Jetpack, WooCommerce.com, Akismet, PollDaddy
billbee βŒ› German blog post about their future plans regarding their GDPR implementation.
Cloudflare βœ… English DPA (PDF)
DigitalOcean βœ… English DPA
Detailed information about data security
DomainFactory βœ… German DPA (PDF)
German blog posts 1, 2
Dropbox πŸ” English DPA for Business Accounts (PDF) Only Business accounts are supported; Standard, Plus and Professional accounts do not have the ability to sign a DPA.
etracker βœ… German DPA The DPA can be concluded online under account settings
Eventbrite βœ… Data Processing Addendum (DPA) for Organizers Privacy Shield; It should be double-checked in how far the addendum is truly and reliably binding
Fullstory βœ… Online Form Privacy Shield
Gravatar βŒ› English Support Article Part of Automattic
Github βŒ› English forum entry
Contact form
Privacy Shield.
DPA for organisations available on request via support contact.
Gmail (via G Suite) βœ… G Suite Administrator Help (multiple languages)
Google Analytics βœ… DPA instructions
Google Maps API βœ… Controller-Controller Data Protection Terms Joint Control Contract (JCC, Art. 26)
Hetzner βœ… English news article
German news article
Host Europe βœ… German DPA
Hotjar βœ… English DPA
Hubspot βœ… English DPA
Issuu βŒ› β€” "we are working on becoming GDPR compliant" and we "will update them as soon as we have all of our changes and new policies in place"
KeyCDN βŒ› General Information
English Tweet stating they will provide a DPA which will be available in May
"Our privacy team is continually reviewing our features and practices to ensure we support our customers with their GDPR compliance requirements."
LinkedIn βœ… English DPA
French DPA
German DPA
Spanish DPA
Portuguese DPA
Privacy Shield; DPA incorporated into the "LinkedIn Contract"
Mailjet βœ… English FAQ
Mailchimp βœ… English Online Form Privacy Shield
Mandrill βœ… English Online Form
Manitu βœ… German website DPA available online
Mapbox βœ… Can be obtained via email to privacy@mapbox.com
MaxCDN βœ… English website
MaxCluster βœ… Download via Customer Backend
micropayment βœ… Online Form for registered / logged-in users
Mittwald βœ… Comment in German blog post, available from customer service
Mouseflow βœ… Contact form
Netcup βœ… German Wiki
Netlify βœ… English DPA Privacy Shield
Newsletter2Go βœ… German Website
Postmark βœ… English Website, DPA available online Privacy Shield
"We reviewed our data processing activities, and are making any changes that are needed in advance of the GDPR effective date."
Salesforce βœ… English Website, English DPA (PDF) Privacy Shield
Scopevisio βœ… German DPA
Simplecast βœ… Data Processing Addendum DPA – Including EU Standard Contractual Clauses)
Slack βœ… Data Processing Addendum Privacy Shield
Strato βœ… German Website
Stripe βœ… Data Processing Addendum (you need to be logged into your account to accept it)
English Privacy Shield Policy
Stripe Services Agreement (multilingual)
Privacy Shield
TinyLetter βœ… English Online Form Privacy Shield; part of Mailchimp
Toggl βŒ› β€” Promises to be "fully be GDPR compliant by the May deadline", but "doesn't feel that a DPA is needed at this time". At the moment it's unclear how this solution will look like and whether it's going to be truly GDPR compliant.
Trello βŒ› English forum entry stating that there will be a DPA until May 2018
Trello and GDPR (multiple languages)
Revised Privacy Policy (multiple languages; effective as of May 25th, 2018)
Trust @ Trello
Privacy Shield; part of Atlassian
Twilio πŸ” Online Form (Preview) (English) Privacy Shield
TypeKit πŸ” Online Form (English) Part of Adobe
Travis CI βœ… English DPA
Uberspace βœ… German DPA, can be signed via the dashboard
Vercel βœ… English DPA
Webgo βœ… Online Form
WebhostOne βœ… German FAQ
Wordpress.com βœ… English Support Article, DPA available on request for paid plans Run by Automattic
WPengine βŒ› English DPA
Zapier βŒ› English support article
GDPR Compliance Updates
"We at Zapier wholeheartedly support the privacy rights of our customers and our users and are proactively working toward GDPR compliance by May 25th, 2018."
Zendesk βŒ› English FAQ support article "Zendesk will be compliant with the GDPR when it becomes enforceable in May 2018."

Legend

Symbol Meaning
❓ It's currently unknown whether or not this service provides a GDPR compliant DPA
βŒ› As far as the curators know, the data processor is busy with unspecified preparations for what they believe is GDPR-compliant; this may or may not include a DPA
πŸ” The curators are currently reviewing the specified resources
βœ… This service provides a DPA that it declares to be GDPR compliant
❌ This service doesn't provide a GDPR compliant DPA (whether or not that's a valid state)

About

Collection of Data Processing Agreement (DPA) and GDPR compliance resources

https://tollwerk.github.io/data-processing-agreements/

License:The Unlicense


Languages

Language:SCSS 100.0%