The agreement prohibits posting another person's personal information without their consent, characterizing such conduct as a privacy violation subject to enforcement under the AUP.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a consent-based standard for posting third-party personal information, which has operational significance for repositories that include user-generated data, research datasets, or scraped data that may contain personal identifiers.
Interpretive note: The definition of 'personal information' and the scope of the consent requirement varies across jurisdictions, and the provision's interaction with applicable data protection law depends on the location of the data subject and the nature of the information posted.
Under this clause, posting personal information about another person without their consent is prohibited on GitHub. This restriction applies to all content hosted on GitHub's platform, including repositories, issues, comments, and wiki pages.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
You can contact us in order to (1) update or correct your personally identifiable information, (2) change your preferences with respect to communications and other information you receive from us, or (3) delete the personally identifiable information maintained about you...
Access information about you consistent with legal requirements. In addition, you may have the right in some cases to receive or have your electronic information transferred to another party.
"You may not violate the privacy of any third party, such as by posting another person's personal information without their consent.Excerpt from GitHub's Acceptable Use Policies
1) REGULATORY LANDSCAPE: This provision engages GDPR for EU-based users and data subjects, CCPA for California residents, and various US state privacy laws.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a consent-based standard for posting third-party personal information, which has operational significance for repositories that include user-generated data, research datasets, or scraped data that may contain personal identifiers.
Under this clause, posting personal information about another person without their consent is prohibited on GitHub. This restriction applies to all content hosted on GitHub's platform, including repositories, issues, comments, and wiki pages.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.