GitHub Copilot procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ GitHub also complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. GitHub has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. GitHub has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy statement and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/ .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “- Consent: We process data when you have explicitly consented to such processing. When we rely on consent as the legal basis, you have the right to withdraw your consent for data processing at any time. The procedures for withdrawal are detailed in this Statement and available on our website.” | Captured 2026-08-14Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “- Legal Obligation: We process data when it's necessary to comply with applicable laws or to protect the rights, safety, and property of GitHub, our affiliates, users, or third parties.” | Captured 2026-08-14Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ GitHub is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). Under Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45), an organization's failure to abide by commitments to implement the DPF Principles may be challenged as deceptive by the FTC. The FTC has the power to prohibit such misrepresentations through administrative orders or by seeking court orders.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “In cases where your organization grants access to GitHub products, GitHub acts as the Data Controller solely for specific processing activities. These activities are clearly defined in a contractual agreement with your organization, known as a Data Protection Agreement. You can review our standard Data Protection Agreement at [GitHub Data Protection Agreement](https://github.com/customer-terms/github-data-protection-agreement). For those limited purposes, this Statement governs the handling of your Personal Data. For all other aspects of GitHub product usage, your organization's policies apply.” | Captured 2026-08-14Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ In cases where your organization grants access to GitHub products, GitHub acts as the Data Controller solely for specific processing activities. These activities are clearly defined in a contractual agreement with your organization, known as a Data Protection Agreement. You can review our standard Data Protection Agreement at GitHub Data Protection Agreement . For those limited purposes, this Statement governs the handling of your Personal Data. For all other aspects of GitHub product usage, your organization's policies apply.” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Should you access a GitHub Service through an account provided by an organization, such as your employer or school, the organization becomes the Data Controller, and this Privacy Statement's direct applicability to you changes. Even so, GitHub remains dedicated to preserving your privacy rights. In such circumstances, GitHub functions as a Data Processor, adhering to the Data Controller's instructions regarding your Personal Data's processing. A Data Protection Agreement governs the relationship between GitHub and the Data Controller. For further details regarding their privacy practices, please refer to the privacy statement of the organization providing your account.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ GitHub stores and processes Personal Data in a variety of locations, including your local region, the United States, and other countries where GitHub, its affiliates, subsidiaries, or subprocessors have operations. We transfer Personal Data from the European Union, the United Kingdom, and Switzerland to countries that the European Commission has not recognized as having an adequate level of data protection. When we engage in such transfers, we generally rely on the standard contractual clauses published by the European Commission under Commission Implementing Decision 2021/914 , to help protect your rights and enable these protections to travel with your data. To learn more about the European Commission’s decisions on the adequacy of the protection of personal data in the countries where GitHub processes personal data, see this article on the European Commission website .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “GitHub also complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. GitHub has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. GitHub has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy statement and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit [https://www.dataprivacyframework.gov/](https://www.dataprivacyframework.gov/).” | Captured 2026-08-14Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “- Legitimate Interests: We process data for purposes that are in our legitimate interests, such as securing our Services, communicating with you, and developing and improving our Services, which include artificial intelligence and machine learning technologies. This is done only when these interests are not overridden by your data protection rights or your fundamental rights and freedoms.” | Captured 2026-08-14Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “GitHub stores and processes Personal Data in a variety of locations, including your local region, the United States, and other countries where GitHub, its affiliates, subsidiaries, or subprocessors have operations. We transfer Personal Data from the European Union, the United Kingdom, and Switzerland to countries that the European Commission has not recognized as having an adequate level of data protection. When we engage in such transfers, we generally rely on the standard contractual clauses published by the European Commission under Commission Implementing Decision 2021/914 , to help protect your rights and enable these protections to travel with your data.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “GitHub processes Personal Data in compliance with the GDPR, ensuring a lawful basis for each processing activity. The basis varies depending on the data type and the context, including how you access the services. Our processing activities typically fall under these lawful bases:” | Captured 2026-08-14Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “- Contractual Necessity: Processing is required to fulfill our contractual duties to you, in accordance with the GitHub Terms of Service.” | Captured 2026-08-14Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, GitHub commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF should first contact GitHub at: dpo[at]github[dot]com.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In cases where your organization grants access to GitHub products, GitHub acts as the Data Controller solely for specific processing activities. These activities are clearly defined in a contractual agreement with your organization, known as a Data Protection Agreement. You can review our standard Data Protection Agreement at GitHub Data Protection Agreement . For those limited purposes, this Statement governs the handling of your Personal Data. For all other aspects of GitHub product usage, your organization's policies apply.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements, but barring legal requirements, we will delete your full profile and the Content of your repositories within 90 days of cancellation or termination (though some information may remain in encrypted backups). This information cannot be recovered once your Account is canceled.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “The length of time a cookie will stay on your browser or device depends on whether it is a “persistent” or “session” cookie. Session cookies will only stay on your device until you stop browsing. Persistent cookies stay until they expire or are deleted. The expiration time or retention period applicable to persistent cookies depends on the purpose of the cookie collection and tool used. You may be able to delete cookie data. For more information, see [GitHub General Privacy Statement](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement#what-are-your-cookie-choices-and-controls).” | Captured 2026-08-14Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ GitHub uses appropriate administrative, technical, and physical security controls to protect your Personal Data. We’ll retain your Personal Data as long as your account is active and as needed to fulfill contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements. The retention duration depends on the purpose of data collection and any legal obligations.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We will not delete Content that you have contributed to other Users' repositories or that other Users have forked.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Right to request Deletion: You reserve the right to request the deletion of your data, barring a few exceptions. Such exceptions include circumstances where we are required to retain data to comply with legal obligations, detect fraudulent activity, investigate reports of abuse or other violations of our Terms of Service, or rectify security issues. Upon receiving your verified request, we will promptly delete your personal information (unless an exception applies), and instruct our service providers to do the same. We employ brief retention terms by design.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ The length of time a cookie will stay on your browser or device depends on whether it is a “persistent” or “session” cookie. Session cookies will only stay on your device until you stop browsing. Persistent cookies stay until they expire or are deleted. The expiration time or retention period applicable to persistent cookies depends on the purpose of the cookie collection and tool used. You may be able to delete cookie data. For more information, see GitHub General Privacy Statement .” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ Upon request, we will make a reasonable effort to provide an Account owner with a copy of your lawful, non-infringing Account contents after Account cancellation, termination, or downgrade. You must make this request within 90 days of cancellation, termination, or downgrade.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “- Right to request Deletion: You reserve the right to request the deletion of your data, barring a few exceptions. Such exceptions include circumstances where we are required to retain data to comply with legal obligations, detect fraudulent activity, investigate reports of abuse or other violations of our Terms of Service, or rectify security issues. Upon receiving your verified request, we will promptly delete your personal information (unless an exception applies), and instruct our service providers to do the same. We employ brief retention terms by design.” | Captured 2026-08-14Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We aim to promptly respond to requests in compliance with legal requirements. Please note that we may retain certain data as necessary for legal obligations or for establishing, exercising, or defending legal claims.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may share Personal Data with the following recipients:” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- Affiliates: Personal Data may be shared with GitHub affiliates, including Microsoft, to facilitate customer service, marketing and advertising, order fulfillment, billing, technical support, legal and compliance obligations, product development and improvement (including training and improving artificial intelligence and machine learning technologies), and for other purposes described in their respective privacy statements. When we share data with affiliates, they will process it in accordance with applicable law and their privacy commitments.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Subprocessors and Service Providers: We may use vendors to provide services on our behalf, including hosting, marketing, advertising, social, analytics, support ticketing, credit card processing, or security services. They are bound by contractual obligations to ensure the security, privacy, and confidentiality of your information. Please visit https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors to see our list of Subprocessors.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The business or commercial purposes of collecting personal information are as summarized above and in our Privacy Statement under Processing Purposes.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- GitHub Organization Accounts: If an organization adds you to their GitHub account, we might share Personal Data with that organization to fulfill the commercial relationship. In such a case, your use of the Services is protected by a data protection agreement and terms between your organization and GitHub” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Other Third-party Applications: Upon your instruction, we may share Personal Data with third-party applications available on our Marketplace. You are responsible for the data you instruct us to share with these applications.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ GitHub stores and processes Personal Data in a variety of locations, including your local region, the United States, and other countries where GitHub, its affiliates, subsidiaries, or subprocessors have operations. We transfer Personal Data from the European Union, the United Kingdom, and Switzerland to countries that the European Commission has not recognized as having an adequate level of data protection. When we engage in such transfers, we generally rely on the standard contractual clauses published by the European Commission under Commission Implementing Decision 2021/914 , to help protect your rights and enable these protections to travel with your data. To learn more about the European Commission’s decisions on the adequacy of the protection of personal data in the countries where GitHub processes personal data, see this article on the European Commission website .” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Other Users and the Public: Depending on your account settings, we may share Personal Data with other users of the Services and the public. You control what information is made public. To adjust your settings, visit User Settings in your profile. Please be aware that any information you share in a collaborative context may become publicly accessible.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Web beacons are electronic images (also called “single-pixel” or “clear GIFs”) that are contained within a website or email. When your browser opens a webpage or email that contains a web beacon, it automatically connects to the web server that hosts the image (typically operated by a third party). This allows that web server to log information about your device and to set and read its own cookies. In the same way, third-party content on our websites (such as embedded videos, plug-ins, or ads) results in your browser connecting to the third-party web server that hosts that content.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- As defined by applicable law, we “shared” the following categories of personal information in the last 12 months: identifiers/contact information, Internet or other electronic network activity information, and inferences drawn from the above. We shared each category to or with advertising networks, data analytics providers, and social networks.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ By choosing to contribute Content to a public repository, you are choosing to and directing us to make such Content accessible to everyone on the internet. Unless specifically set forth herein, these Terms do not restrict lawful access to or use of the contents of public repositories by third parties, or by GitHub or its Affiliates.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Corporate Transaction Entities: we might disclose Personal Data within the limits of the law and in accordance with this Privacy Statement for strategic business transactions such as sales or a merger.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Services you linked to your GitHub account: When you or your administrator integrate third-party apps or services with our Services, we receive information based on your settings with those services. This can include details like your name and email from services like Google for authentication. The information we receive depends on the third-party's settings and privacy policies. Always review these to understand what data is shared with our Services.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- Partners and Resellers: We cooperate with third-parties that offer sales, consulting, support, and technical services for our Services. We may share your data with these partners and resellers where allowed, and with your consent when required.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Competent Authorities: We may disclose Personal Data to authorized law enforcement, regulators, courts, or other public authorities in response to lawful requests or to protect our rights and safety. Please refer to our Guidelines for Legal Requests of User Data for more information.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- We disclosed the following categories of personal information for a business purpose in the last 12 months: identifiers/contact information, demographic information (such as gender and rough geographic location), payment information, commercial information, Internet or other electronic network activity information, geolocation data, audio, electronic, visual or similar information, and inferences drawn from the above. We disclosed each category to third-party business partners and service providers, third-party sites or platforms such as social networking sites, and other third parties as described in the Sharing of Personal Data section of our Privacy Statement.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “Under California Civil Code section 1798.83, also known as the “Shine the Light” law, California residents who have provided personal information to a business with which the individual has established a business relationship for personal, family, or household purposes (“California Customers”) may request information about whether the business has disclosed personal information to any third parties for the third parties’ direct marketing purposes. Please be aware that we do not disclose personal information to any third parties for their direct marketing purposes as defined by this law. California Customers may request further information about our compliance with this law by emailing (privacy\[at\]github\[dot\]com). Please note that businesses are required to respond to one request per California Customer each year and may not be required to respond to requests made by means other than through the designated email address.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We do not sell your covered information, as defined under Chapter 603A of the Nevada Revised Statutes. If you still have questions about your covered information or anything else in our Privacy Statement, please send an email to privacy[at]github[dot]com.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Upon your instruction, we may share Personal Data with third-party applications available on our Marketplace. You are responsible for the data you instruct us to share with these applications.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ To opt out of the sharing of your personal information, you can click on the "Do Not Share My Personal Information" link on the footer of our Websites or use the Global Privacy Control ("GPC") if available. Authorized agents can also submit opt-out requests on your behalf.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The GitHub Services use cookies and similar technologies for a variety of purposes, including to store your preferences and settings, enable you to sign-in, analyze how our Services perform, track your interaction with the Services, develop inferences, combat fraud, and fulfill other legitimate purposes. Some of these cookies and technologies may be provided by third parties, including service providers and advertising partners. For example, our analytics and advertising partners may use these technologies in our Services to collect personal information (such as the pages you visit, the links you click on, and similar usage information, identifiers, and device information) related to your online activities over time and across Services for various purposes, including targeted advertising. GitHub will place non-essential cookies on pages where we market products and services to enterprise customers, for example, on resources.github.com.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Services you linked to your GitHub account: When you or your administrator integrate third-party apps or services with our Services, we receive information based on your settings with those services. This can include details like your name and email from services like Google for authentication. The information we receive depends on the third-party's settings and privacy policies. Always review these to understand what data is shared with our Services.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Vendors, Partners, and Affiliates: We may receive information about you from third parties, like vendors, resellers, partners, or affiliates for the purposes outlined in this statement.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Under California Civil Code section 1798.83, also known as the “Shine the Light” law, California residents who have provided personal information to a business with which the individual has established a business relationship for personal, family, or household purposes (“California Customers”) may request information about whether the business has disclosed personal information to any third parties for the third parties’ direct marketing purposes. Please be aware that we do not disclose personal information to any third parties for their direct marketing purposes as defined by this law. California Customers may request further information about our compliance with this law by emailing (privacy[at]github[dot]com). Please note that businesses are required to respond to one request per California Customer each year and may not be required to respond to requests made by means other than through the designated email address.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- Right to Know Data Recipients: We share your information with service providers for legitimate business operations, such as data storage and hosting. For more details, please see “Sharing Your Information” below.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “- Vendors, Partners, and Affiliates: We may receive information about you from third parties, like vendors, resellers, partners, or affiliates for the purposes outlined in this statement.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- The business or commercial purpose of sharing personal information is to assist us with marketing, advertising, and audience measurement.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Corporate Transaction Entities: we might disclose Personal Data within the limits of the law and in accordance with this Privacy Statement for strategic business transactions such as sales or a merger.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Other Third-party Applications: Upon your instruction, we may share Personal Data with third-party applications available on our Marketplace. You are responsible for the data you instruct us to share with these applications.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Services you linked to your GitHub account: When you or your administrator integrate third-party apps or services with our Services, we receive information based on your settings with those services. This can include details like your name and email from services like Google for authentication. The information we receive depends on the third-party's settings and privacy policies. Always review these to understand what data is shared with our Services.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ When you use third-party extensions, integrations, or follow references and links within our Services, the privacy policies of these third parties apply to any Personal Data you provide or consent to share with them. Their privacy statements will govern how this data is processed.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Additionally, we may be compelled by law to disclose the contents of your private repositories.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ to comply with our legal obligations if we have reason to believe the contents are in violation of the law.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Right to Know Data Recipients: We share your information with service providers for legitimate business operations, such as data storage and hosting. For more details, please see “Sharing Your Information” below.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “GitHub stores and processes Personal Data in a variety of locations, including your local region, the United States, and other countries where GitHub, its affiliates, subsidiaries, or subprocessors have operations. We transfer Personal Data from the European Union, the United Kingdom, and Switzerland to countries that the European Commission has not recognized as having an adequate level of data protection. When we engage in such transfers, we generally rely on the standard contractual clauses published by the European Commission under [Commission Implementing Decision 2021/914](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj), to help protect your rights and enable these protections to travel with your data. To learn more about the European Commission’s decisions on the adequacy of the protection of personal data in the countries where GitHub processes personal data, see this article on the [European Commission website](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en).” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Buttons, Tools, and Content from Other Companies: Our Services may contain links or buttons that lead to third-party services like Twitter or LinkedIn. Use of these features may result in data collection. Engaging with these buttons, tools, or content may automatically send certain browser information to these companies. Please review the privacy statements of these companies for more information.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Abuse and Fraud Prevention Entities: We may disclose Personal Data based on a good faith belief it is needed to prevent fraud, abuse, or attacks on our Services, or to protect the safety of GitHub and our users.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Subprocessors and Service Providers: We may use vendors to provide services on our behalf, including hosting, marketing, advertising, social, analytics, support ticketing, credit card processing, or security services. They are bound by contractual obligations to ensure the security, privacy, and confidentiality of your information. Please visit [https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors](https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors) to see our list of Subprocessors.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Depending on your account settings, we may share Personal Data with other users of the Services and the public. You control what information is made public. To adjust your settings, visit User Settings in your profile. Please be aware that any information you share in a collaborative context may become publicly accessible.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Mobile identifiers for analytics can be accessed and used by apps on mobile devices in much the same way that websites access and use cookies. When visiting Enterprise Marketing pages, like resources.github.com, on a mobile device these may allow us and our third-party analytics and advertising partners to collect data for sales and marketing purposes.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ GitHub has the responsibility for the processing of Personal Data it receives under the Data Privacy Framework (DPF) Principles and subsequently transfers to a third party acting as an agent on GitHub’s behalf. GitHub shall remain liable under the DPF Principles if its agent processes such Personal Data in a manner inconsistent with the DPF Principles, unless the organization proves that it is not responsible for the event giving rise to the damage.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Buttons, Tools, and Content from Other Companies: Our Services may contain links or buttons that lead to third-party services like Twitter or LinkedIn. Use of these features may result in data collection. Engaging with these buttons, tools, or content may automatically send certain browser information to these companies. Please review the privacy statements of these companies for more information.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ You may use the Global Privacy Control (GPC) to communicate your privacy preferences. If GitHub detects the GPC signal from your device, GitHub will not share your data (we do not sell your data). To learn more, visit Global Privacy Control — Take Control Of Your Privacy ” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “- Competent Authorities: We may disclose Personal Data to authorized law enforcement, regulators, courts, or other public authorities in response to lawful requests or to protect our rights and safety. Please refer to our [Guidelines for Legal Requests of User Data](https://docs.github.com/en/site-policy/other-site-policies/guidelines-for-legal-requests-of-user-data) for more information.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Partners and Resellers: We cooperate with third-parties that offer sales, consulting, support, and technical services for our Services. We may share your data with these partners and resellers where allowed, and with your consent when required.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ GitHub Organization Accounts: If an organization adds you to their GitHub account, we might share Personal Data with that organization to fulfill the commercial relationship. In such a case, your use of the Services is protected by a data protection agreement and terms between your organization and GitHub” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Should you access a GitHub Service through an account provided by an organization, such as your employer or school, the organization becomes the Data Controller, and this Privacy Statement's direct applicability to you changes. Even so, GitHub remains dedicated to preserving your privacy rights. In such circumstances, GitHub functions as a Data Processor, adhering to the Data Controller's instructions regarding your Personal Data's processing. A Data Protection Agreement governs the relationship between GitHub and the Data Controller. For further details regarding their privacy practices, please refer to the privacy statement of the organization providing your account.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Required Cookies GitHub uses required cookies to perform essential website functions and to provide the services. For example, cookies are used to log you in, save your language preferences, provide a shopping cart experience, improve performance, route traffic between web servers, detect the size of your screen, determine page load times, improve user experience, and for audience measurement. These cookies are necessary for our websites to work. Analytics We allow third parties to use analytics cookies to understand how you use our websites so we can make them better. For example, cookies are used to gather information about the pages you visit and how many clicks you need to accomplish a task. We also use some analytics cookies to provide personalized advertising. Social Media GitHub and third parties use social media cookies to show you ads and content based on your social media profiles and activity on GitHub’s websites. This ensures that the ads and content you see on our websites and on social media will better reflect your interests. This also enables third parties to develop and improve their products, which they may use on websites that are not owned or operated by GitHub. Advertising In addition, GitHub and third parties use advertising cookies to show you new ads based on ads you've already seen. Cookies also track which ads you click or purchases you make after clicking an ad. This is done both for payment purposes and to show you ads that are more relevant to you. For example, cookies are used to detect when you click an ad and to show you ads based on your social media interests and website browsing history. ” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Abuse and Fraud Prevention Entities: We may disclose Personal Data based on a good faith belief it is needed to prevent fraud, abuse, or attacks on our Services, or to protect the safety of GitHub and our users.” | Captured 2026-06-07Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ We will immediately bill you when you upgrade from the free plan to any paying plan.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ GitHub may offer subscription-based access to our API for those Users who require high-throughput access or access that would result in resale of GitHub's Service.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ One person or legal entity may maintain no more than one free Account (if you choose to control a machine account as well, that's fine, but it can only be used for running a machine).” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ Your login may only be used by one person — i.e., a single login may not be shared by multiple people. A paid Organization may only provide access to as many Personal Accounts as your subscription allows.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ If you upgrade to a higher level of service, we will bill you for the upgraded plan immediately.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ If you have signed up for GitHub Enterprise Cloud, the Enterprise Cloud Addendum applies to you, and you agree to its provisions.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | low | “ Payment Based on Usage Some Service features are billed based on your usage. A limited quantity of these Service features may be included in your plan for a limited term without additional charge. If you choose to use paid Service features beyond the quantity included in your plan, you pay for those Service features based on your actual usage in the preceding month. Monthly payment for these purchases will be charged on a periodic basis in arrears. See GitHub Additional Product Terms for Details .” | Captured 2026-06-07Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ Invoicing For invoiced Users, User agrees to pay the fees in full, up front without deduction or setoff of any kind, in U.S. Dollars. User must pay the fees within thirty (30) days of the GitHub invoice date. Amounts payable under this Agreement are non-refundable, except as otherwise provided in this Agreement. If User fails to pay any fees on time, GitHub reserves the right, in addition to taking any other action at law or equity, to (i) charge interest on past due amounts at 1.0% per month or the highest interest rate allowed by law, whichever is less, and to charge all expenses of recovery, and (ii) terminate the applicable order form. User is solely responsible for all taxes, fees, duties and governmental assessments (except for taxes based on GitHub's net income) that are imposed or become due in connection with this Agreement.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | low | “ If you are a government User or otherwise accessing or using any GitHub Service in a government capacity, this Government Amendment to GitHub Terms of Service applies to you, and you agree to its provisions.” | Captured 2026-06-07Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ "Beta Previews" mean software, services, or features identified as alpha, beta, preview, early access, or evaluation, or words or phrases with similar meanings.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ Payment Based on Plan For monthly or yearly payment plans, the Service is billed in advance on a monthly or yearly basis respectively and is non-refundable. There will be no refunds or credits for partial months of service, downgrade refunds, or refunds for months unused with an open Account; however, the service will remain active for the length of the paid billing period. In order to treat everyone equally, no exceptions will be made.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ By agreeing to these Terms, you are giving us permission to charge your on-file credit card, PayPal account, or other approved methods of payment for fees that you authorize for GitHub.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ You may change your level of service at any time by choosing a plan option or going into your Billing settings . If you choose to downgrade your Account, you may lose access to Content, features, or capacity of your Account. Please see our section on Cancellation for information on getting a copy of that Content.” | Captured 2026-06-07Open source →Finding permalink → |
| Tier differences | All applicable tiers | medium | “ This section applies to all AI Features unless a specific feature has additional terms that expressly modify them. The training and data-use provisions in Section J.3 apply only to individual licenses. If your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement, those agreements govern the use of your data in connection with AI Features and Section J.3 does not apply to you.” | Captured 2026-06-07Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ If you change from a monthly billing plan to a yearly billing plan, GitHub will bill you for a full year at the next monthly billing date.” | Captured 2026-07-20Open source →Finding permalink → |
| Tier differences | All applicable tiers | unknown | “ Our pricing and payment terms are available at github.com/pricing . If you agree to a subscription price, that will remain your price for the duration of the payment term; however, prices are subject to change at the end of a payment term.” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.