Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document establishes Dropbox's data collection, use, and sharing practices for its file storage and collaboration services. Dropbox collects personal data including account information, device identifiers, usage patterns, and file content, and the policy authorizes disclosure of this data to third-party service providers and partners. The policy establishes differentiated data subject rights for users in the EU, UK, and California, including rights to access, correct, delete, and port personal data, exercisable through Dropbox's privacy request mechanism.
This document is Dropbox's global Privacy Policy, governing how Dropbox, Inc. collects, uses, stores, shares, and protects personal data across its file storage, collaboration, and productivity services, with the stated legal basis varying by jurisdiction (contract performance, legitimate interests, and consent as applicable under GDPR for EEA users). The policy states that Dropbox collects account information, payment details, usage data, device identifiers, location data, and the content users upload and store, and the terms authorize sharing of personal data with third-party service providers, advertising partners, and in connection with business transfers such as mergers or acquisitions. Notably, the policy asserts broad authority to scan and analyze user content for purposes including safety, spam detection, and service improvement, and it reserves the right to share aggregated or de-identified data without restriction; the scope of content analysis for AI or machine learning purposes warrants close reading, as applicable law in certain jurisdictions may constrain how these terms apply in practice. The policy engages GDPR and the EU-U.S. Data Privacy Framework for international data transfers, CCPA/CPRA for California residents, and the UK GDPR post-Brexit; material compliance considerations include the adequacy of transfer mechanisms for EEA-to-US data flows, the sufficiency of consent mechanisms for cookie-based tracking, and the operationalization of data subject rights including access, deletion, and portability.
Institutional analysis available with Professional
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Start Professional free trialMonitoring
Dropbox has updated this document before.
Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
Professional Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Professional free trialCross-platform context
See how other platforms handle Administrator Access to Business Accounts and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.