Old version
March 22, 2026 06:07 UTC
76881f2024d14f9e996879cd02ed06524957e0c2f9d73f4fb49afc96c16c447f
CA-V-000254
New version
April 16, 2026 06:06 UTC
f56de72310d457b0b74b985f28c2c03143c452689525b5390dc7ff3d5aeff402
CA-V-001822
Share 𝕏 Share in Share
Change Summary
Gusto updated its Data Processing Addendum on April 16, 2026, adding 60 sentences that clarify how the company handles employer data under data protection laws. The new language specifies the scope of the addendum (it applies only to employers subject to data protection laws), defines key terms, establishes when the agreement becomes binding, and clarifies that the addendum takes precedence over the base service agreement if there is a conflict. For employers, this means clearer rules about how their employee and payroll data is processed and protected.
medium severity
60 Sentences added
0 Sentences removed
1 Sentences modified
18913 Sentences before
18973 Sentences after
Added
Removed
Modified
BeforeAfter
7512Employer Data Processing Addendum Version Version 2.0 (Current) Version 1.0 Effective September 17th 2025 Download Table of Contents Last updated September 17, 2025 This Data Processing Addendum (“ Addendum ”) forms part of and is subject to the terms and conditions of either (i) the Embedded Payroll Service Agreement for users of Embedded Payroll Services offered by a third-party Platform Provider or (ii) the Employer Terms of Service (each of (i) and (ii) individually a “ Base Agreement ”) and this Addendum together with the applicable Base Agreement forms an “ Agreement ” by and between the Employer or Company (as defined in the applicable Base Agreement) (“ Company ”) and Gusto, Inc. and its subsidiaries and affiliates (“ Service Provider ”).7512Employer Data Processing Addendum Version Version 3.0 (Current) Version 2.0 Version 1.0 Effective April 14th 2026 Download Table of Contents Last updated September 17, 2025 This Data Processing Addendum (“ Addendum ”) forms part of and is subject to the terms and conditions of either (i) the Embedded Payroll Service Agreement for users of Embedded Payroll Services offered by a third-party Platform Provider or (ii) the Employer Terms of Service (each of (i) and (ii) individually a “ Base Agreement ”) and this Addendum together with the applicable Base Agreement forms an “ Agreement ” by and between the Employer or Company (as defined in the applicable Base Agreement) (“ Company ”) and Gusto, Inc. and its subsidiaries and affiliates (“ Service Provider ”).
7513Subject Matter and Duration.
7514Subject Matter.
7515This Addendum reflects the parties’ commitment to abide by Data Protection Laws concerning the Processing of Company Personal Data in connection with Service Provider’s execution of the Agreement- but, only to the extent that Employer is subject to Data Protection Laws and they apply to the Processing of Company Personal Data.
7516All capitalized terms that are not expressly defined in this Addendum will have the meanings given to them in the applicable Base Agreement.
7517If and to the extent language in this Addendum or any of its Exhibits conflicts with the applicable Base Agreement, this Addendum shall control.
7518Duration and Survival.
7519This Addendum will become legally binding upon the effective date of the Agreement or upon the date that the parties sign this Addendum if it is completed after the effective date of the Agreement.
7520Service Provider will Process Company Personal Data until the relationship terminates as specified in the Agreement.
7521Definitions.
7522For the purposes of this Addendum, the following terms and those defined within the body of this Addendum apply. “ Company Personal Data ” means any Employer Data or Company Data that is Personal Data Processed by Service Provider on behalf of Company. “ Data Protection Laws ” means the applicable data privacy, data protection, and cybersecurity laws, rules, and regulations to which the Company Personal Data are subject. “Data Protection Laws” may include, but are not limited to, the California Consumer Privacy Act of 2018 (“CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, Connecticut’s Act Concerning Data Privacy and Online Monitoring, and the Utah Consumer Privacy Act (in each case as supplemented by implementing regulations and as amended, adopted, or superseded from time to time). “ Personal Data ” has the meaning assigned to the term “personal data” or “personal information” under applicable Data Protection Laws. “ Process ” or “ Processing ” means any operation or set of operations which is performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction. “ Security Incident(s) ” means the breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Company Personal Data attributable to Service Provider. “ Services ” means the services that Service Provider performs under the Agreement. “ Subprocessor(s) ” means Service Provider’s authorized vendors and third-party service providers that Process Company Personal Data.
7523Processing Terms for Company Personal Data.
7524Documented Instructions .
7525Service Provider shall Process Company Personal Data to provide the Services in accordance with the Agreement, this Addendum, any applicable Statement of Work, and any instructions agreed upon by the parties.
7526Service Provider will, unless legally prohibited from doing so, inform Company in writing if it reasonably believes that there is a conflict between Company’s instructions and applicable law or otherwise seeks to Process Company Personal Data in a manner that is inconsistent with Company’s instructions.
7527Authorization to Use Subprocessors .
7528To the extent necessary to fulfill Service Provider’s contractual obligations under the Agreement, Company hereby authorizes Service Provider to engage Subprocessors.
7529Service Provider and Subprocessor Compliance .
7530Service Provider shall (i) enter into a written agreement with Subprocessors regarding such Subprocessors’ Processing of Company Personal Data that imposes on such Subprocessors data protection requirements for Company Personal Data that are consistent with this Addendum; and (ii) remain responsible to Company for Service Provider’s Subprocessors’ failure to perform their obligations with respect to the Processing of Company Personal Data.
7531Confidentiality .
7532Any person authorized to Process Company Personal Data must contractually agree to maintain the confidentiality of such information or be under an appropriate statutory obligation of confidentiality.
7533Personal Data Inquiries and Requests .
7534Where required by Data Protection Laws, Service Provider agrees to provide reasonable assistance and comply with reasonable instructions from Company related to any requests from individuals exercising their rights in Company Personal Data granted to them under Data Protection Laws.
7535Prohibited Uses of Personal Data .
7536Service Provider shall not (i) sell or share Company Personal Data as the terms "sell" or “share” are defined by the CCPA; or (ii) retain, use, combine, or disclose Company Personal Data for any purpose other than as described in this Addendum, the Agreement, or permitted under Data Protection Laws.
7537Data Protection Impact Assessment and Prior Consultation .
7538Where required by Data Protection Laws, Service Provider agrees to provide reasonable assistance at Company’s expense to Company where, in Company’s judgement, the type of Processing performed by Service Provider requires a data protection impact assessment and/or prior consultation with the relevant data protection authorities.
7539Demonstrable Compliance .
7540Upon Company’s reasonable request Service Provider agrees to provide information reasonably necessary to demonstrate compliance with this Addendum and permit Company to take reasonable steps to stop and remediate unauthorized use of Company Personal Data.
7541Service Optimization .
7542Where permitted by Data Protection Laws, Service Provider may Process Company Personal Data: (i) for its internal uses to build or improve the quality of its services; (ii) to detect Security Incidents; and (iii) to protect against fraudulent or illegal activity.
7543Aggregation and De-Identification .
7544Service Provider may: (i) compile aggregated and/or de-identified information in connection with providing the Services provided that such information cannot reasonably be used to identify Company or any data subject to whom Company Personal Data relates (“Aggregated and/or De-Identified Data”); and (ii) use Aggregated and/or De-Identified Data for its lawful business purposes.Information Security Program.
7545Security Measures .
7546Service Provider shall use commercially reasonable efforts to implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Company Personal Data.
7547Security Incidents.
7548Notice .
7549Upon becoming aware of a Security Incident, Service Provider agrees to provide written notice without undue delay and within the time frame required under Data Protection Laws to Employer Account or Administrator.
7550Where possible, such notice will include all available details required under Data Protection Laws for the Company to comply with its own notification obligations to regulatory authorities or individuals affected by the Security Incident.
7551Audits.
7552Company Audit .
7553Where Data Protection Laws afford Company an audit right, Company (or its appointed representative) may carry out an audit of Service Provider’s policies, procedures, and records relevant to the Processing of Company Personal Data.
7554Any audit must be: (i) conducted during Service Provider’s regular business hours; (ii) with reasonable advance notice to Service Provider; (iii) carried out in a manner that prevents unnecessary disruption to Service Provider’s operations; and (iv) subject to reasonable confidentiality procedures.
7555In addition, any audit shall be limited to once per year, unless an audit is carried out at the direction of a government authority having proper jurisdiction.
7556Company Personal Data Deletion.
7557Data Deletion .
7558At the expiry or termination of the Agreement, Service Provider will retain and delete Company Personal Data in accordance with the Agreement.
7559Company’s Obligations.
7560Company represents and warrants that: (i) it has complied and will comply with Data Protection Laws; (ii) it has provided data subjects whose Company Personal Data will be Processed in connection with the Agreement with a privacy notice or similar document that clearly and accurately describes Company’s practices with respect to the Processing of Company Personal Data; (iii) it has obtained and will obtain and continue to have, during the term, all necessary rights, lawful bases, authorizations, consents, and licenses for the Processing of Company Personal Data as contemplated by the Agreement; and (iv) Service Provider’s Processing of Company Personal Data in accordance with the Agreement will not violate Data Protection Laws or cause a breach of any agreement or obligations between Company and any third party.
7561Processing Details.
7562Subject Matter and Business Purpose .
7563The subject matter and business purpose of the Processing is the Services pursuant to the Agreement, including payroll services.
7564Duration .
7565The Processing will continue until the expiration or termination of the Agreement.
7566Categories of Data Subjects .
7567Data subjects whose Company Personal Data will be Processed pursuant to the Agreement, including Company employees and workers.
7568Nature and Purpose of the Processing .
7569The purpose of the Processing of Company Personal Data by Service Provider is the performance of the Services, including payroll services.
7570Types of Company Personal Data .
7571Company Personal Data that is Processed pursuant to the Agreement, including payroll information of Company workers.
7572Effective September 17th 2025 to April 14th 2026 Download Table of Contents Last updated September 17, 2025 This Data Processing Addendum (“ Addendum ”) forms part of and is subject to the terms and conditions of either (i) the Embedded Payroll Service Agreement for users of Embedded Payroll Services offered by a third-party Platform Provider or (ii) the Employer Terms of Service (each of (i) and (ii) individually a “ Base Agreement ”) and this Addendum together with the applicable Base Agreement forms an “ Agreement ” by and between the Employer or Company (as defined in the applicable Base Agreement) (“ Company ”) and Gusto, Inc. and its subsidiaries and affiliates (“ Service Provider ”).
Stay ahead of the changes

Watch this before it changes again

Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.