Dropbox, Inc. certifies compliance with the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, and UK Extension for personal data transferred from the EU, EEA, UK, and Switzerland to the U.S., but explicitly excludes the FormSwift portion of its services from this certification.
This analysis describes what Dropbox's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal transfer mechanisms Dropbox relies on for transatlantic data flows and identifies JAMS as the independent dispute resolution body for framework-related complaints at no cost to the complainant. The explicit exclusion of FormSwift from Data Privacy Framework coverage creates a discrete compliance boundary that requires separate data transfer mechanism documentation for organizations using that service component.
Under this clause, EU, EEA, UK, and Swiss users whose data is transferred to the United States are covered by Data Privacy Framework protections and may escalate unresolved complaints to JAMS at no charge, with potential recourse to binding arbitration under Annex I of the Framework Principles. Users of the FormSwift portion of Dropbox's services are not covered by this framework certification.
Cross-platform context
See how other platforms handle Data Privacy Framework Compliance and FormSwift Carve-Out and similar clauses.
Compare across platforms →"Dropbox, Inc. complies with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, as well as the UK Extension to the EU-U.S. Data Privacy Framework, as set forth by the U.S. Department of Commerce regarding the processing of personal data transferred from the European Union, the European Economic Area, the United Kingdom, and Switzerland to the United States. Dropbox, Inc. has certified to the U.S. Department of Commerce that it adheres to the Principles of these Data Privacy Frameworks with respect to such data, but this does not include the FormSwift portion of the Services.Excerpt from Dropbox's Privacy Policy
1) REGULATORY LANDSCAPE: This provision directly engages the EU-U.S.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the legal transfer mechanisms Dropbox relies on for transatlantic data flows and identifies JAMS as the independent dispute resolution body for framework-related complaints at no cost to the complainant. The explicit exclusion of FormSwift from Data Privacy Framework coverage creates a discrete compliance boundary that requires separate data transfer mechanism documentation for organizations using that service component.
Under this clause, EU, EEA, UK, and Swiss users whose data is transferred to the United States are covered by Data Privacy Framework protections and may escalate unresolved complaints to JAMS at no charge, with potential recourse to binding arbitration under Annex I of the Framework Principles. Users of the FormSwift portion of Dropbox's services are not covered by this …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Dropbox.