Provision record
Dropbox · Dropbox Privacy Policy · View original document ↗

Data Privacy Framework Compliance and FormSwift Carve-Out

Medium severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Dropbox and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Dropbox, Inc. certifies compliance with the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, and UK Extension for personal data transferred from the EU, EEA, UK, and Switzerland to the U.S., but explicitly excludes the FormSwift portion of its services from this certification.

This analysis describes what Dropbox's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the legal transfer mechanisms Dropbox relies on for transatlantic data flows and identifies JAMS as the independent dispute resolution body for framework-related complaints at no cost to the complainant. The explicit exclusion of FormSwift from Data Privacy Framework coverage creates a discrete compliance boundary that requires separate data transfer mechanism documentation for organizations using that service component.

Clause Stability Stable

0
Changes
5
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, EU, EEA, UK, and Swiss users whose data is transferred to the United States are covered by Data Privacy Framework protections and may escalate unresolved complaints to JAMS at no charge, with potential recourse to binding arbitration under Annex I of the Framework Principles. Users of the FormSwift portion of Dropbox's services are not covered by this framework certification.

Cross-platform context

See how other platforms handle Data Privacy Framework Compliance and FormSwift Carve-Out and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Dropbox, Inc. complies with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, as well as the UK Extension to the EU-U.S. Data Privacy Framework, as set forth by the U.S. Department of Commerce regarding the processing of personal data transferred from the European Union, the European Economic Area, the United Kingdom, and Switzerland to the United States. Dropbox, Inc. has certified to the U.S. Department of Commerce that it adheres to the Principles of these Data Privacy Frameworks with respect to such data, but this does not include the FormSwift portion of the Services.

Excerpt from Dropbox's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly engages the EU-U.S.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
Dropbox Privacy Policy
Entity
Dropbox
Document last updated
May 5, 2026
Tracking information
First tracked
March 20, 2026
Last verified
July 9, 2026
Record ID
CA-P-014666
Document ID
CA-D-00196
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
dafeccda2e497f0720e8f9dbe87da437c7024fc64e8bacf7efaa010a8354782f
Analysis generated
March 20, 2026 04:47 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Dropbox
Document: Dropbox Privacy Policy
Record ID: CA-P-014666
Captured: 2026-03-20 04:47:54 UTC
SHA-256: dafeccda2e497f07…
URL: https://conductatlas.com/platform/dropbox/dropbox-privacy-policy/provision/CA-P-014666/data-privacy-framework-compliance-and-formswift-carve-out/
Accessed: Aug. 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Dropbox's Data Privacy Framework Compliance and FormSwift Carve-Out clause do?

This provision establishes the legal transfer mechanisms Dropbox relies on for transatlantic data flows and identifies JAMS as the independent dispute resolution body for framework-related complaints at no cost to the complainant. The explicit exclusion of FormSwift from Data Privacy Framework coverage creates a discrete compliance boundary that requires separate data transfer mechanism documentation for organizations using that service component.

How does this clause affect you?

Under this clause, EU, EEA, UK, and Swiss users whose data is transferred to the United States are covered by Data Privacy Framework protections and may escalate unresolved complaints to JAMS at no charge, with potential recourse to binding arbitration under Annex I of the Framework Principles. Users of the FormSwift portion of Dropbox's services are not covered by this …

Is ConductAtlas affiliated with Dropbox?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Dropbox.