10 Total
3 High severity
7 Medium severity
0 Low severity
Summary

This document establishes GitHub's data collection, processing, and sharing practices for users of its platform. GitHub collects personal identifiers (name, email address), payment information, device identifiers, IP addresses, browsing activity, and user-generated content, with authorization to share this data with Microsoft affiliates, service providers, and analytics and advertising partners. The policy designates public repository content as globally visible material not subject to private data protections, permitting indexing by search engines and third-party access.

Technical / Legal Breakdown

This document is GitHub's General Privacy Statement, governing the collection, use, storage, sharing, and protection of personal data across GitHub's products and services, with Microsoft Corporation as GitHub's parent entity and data controller for certain processing activities. The statement asserts that GitHub collects registration information (name, email, password), profile data, payment information, device and usage data, cookies and tracking data, and content users upload; the terms authorize use of this data for service delivery, security, legal compliance, personalization, and to improve GitHub products including AI features such as GitHub Copilot. The policy discloses that personal data may be shared with Microsoft affiliates, service providers, advertising partners, and third parties in the context of business transactions, and that public repository content is visible globally and may be indexed by search engines, which is operationally distinct from platforms where user-generated content defaults to private. The statement engages GDPR for EU/EEA users (including rights of access, rectification, erasure, portability, and objection), the California Consumer Privacy Act for California residents, and additional state privacy laws; GitHub designates a Data Protection Officer and commits to Standard Contractual Clauses for international transfers. Compliance teams should note that the policy's AI training data provisions, the breadth of affiliate data sharing with Microsoft, and the treatment of public repository content as non-private warrant specific review under applicable data minimization and purpose limitation obligations.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

1 important change detected

3 versions captured · Last updated: April 2026

What changed GitHub updated its Privacy Statement on April 28, 2026 to explicitly authorize collection and use of AI outputs from user-provided content, and to broaden the scope of personal data sharing with affiliates to include product development and AI/machine learning training. The statement also removed specific language describing the conditions under which GitHub personnel may access private repositories and replaced it with a reference to the Terms of Service. These changes expand the stated purposes for data use and affiliate sharing without adding explicit opt-out mechanisms.
Why this matters The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other GitHub affiliates for purposes including training and improving artificial intelligence and machine learning technologies. The privacy statement indicates that aggregate and de-identified data will be used where feasible, but the updated language establishes broader authority for affiliate data sharing and AI model development than the previous version stated. The revised terms also remove specific disclosure of the conditions under which GitHub personnel may access private repositories, replacing that detail with a cross-reference to the Terms of Service, which means the scope of internal GitHub access to private repositories is now defined in a separate contract document rather than the privacy statement itself.
View full change record →
High — 3 provisions
Medium — 7 provisions

Monitoring

GitHub has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Affiliate Data Sharing with Microsoft and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 28, 2026 06:21 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000254
Version ID CA-V-001994
SHA-256 b36cbcc068012375c4a0d88eb7699d8a007a4c8b93ea435d81210244c50bf16d
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans