When enterprise customers send data to Datadog's monitoring platform, Datadog acts as a data processor on their behalf, and the privacy policy covering that data is the Data Processing Addendum in the customer's contract, not this public policy.
This analysis describes what Datadog's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that personal data transmitted within enterprise customers' monitoring payloads is governed by a separate contractual document, meaning individuals whose data appears in those payloads must look to the enterprise customer, not to Datadog's public privacy policy, for rights fulfillment.
If personal data about employees, end users, or third parties appears in monitoring data that an organization sends to Datadog, those individuals' data rights are governed by the enterprise contract and DPA, not by the publicly available privacy policy; this may limit the practical ability of those individuals to directly exercise access or deletion rights against Datadog.
How other platforms handle this
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
"When we provide services to our customers, we may process personal data on behalf of our customers. Our customers are generally the controllers of the data they submit to our services and we are the data processor. The processing of such data is governed by the applicable terms between Datadog and the customer, including our Data Processing Addendum. This Privacy Policy does not apply to the personal data we process on behalf of our customers in their capacity as data controllers.Excerpt from Datadog's Privacy Policy
REGULATORY LANDSCAPE: The controller/processor distinction directly engages GDPR Articles 4, 24, 28, and 29, which establish obligations for both controllers and processors and require a written data processing agreement.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that personal data transmitted within enterprise customers' monitoring payloads is governed by a separate contractual document, meaning individuals whose data appears in those payloads must look to the enterprise customer, not to Datadog's public privacy policy, for rights fulfillment.
If personal data about employees, end users, or third parties appears in monitoring data that an organization sends to Datadog, those individuals' data rights are governed by the enterprise contract and DPA, not by the publicly available privacy policy; this may limit the practical ability of those individuals to directly exercise access or deletion rights against Datadog.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Datadog.