Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document establishes GitHub's data collection, processing, and sharing practices for users of its platform. GitHub collects personal identifiers (name, email address), payment information, device identifiers, IP addresses, browsing activity, and user-generated content, with authorization to share this data with Microsoft affiliates, service providers, and analytics and advertising partners. The policy designates public repository content as globally visible material not subject to private data protections, permitting indexing by search engines and third-party access.
This document is GitHub's General Privacy Statement, governing the collection, use, storage, sharing, and protection of personal data across GitHub's products and services, with Microsoft Corporation as GitHub's parent entity and data controller for certain processing activities. The statement asserts that GitHub collects registration information (name, email, password), profile data, payment information, device and usage data, cookies and tracking data, and content users upload; the terms authorize use of this data for service delivery, security, legal compliance, personalization, and to improve GitHub products including AI features such as GitHub Copilot. The policy discloses that personal data may be shared with Microsoft affiliates, service providers, advertising partners, and third parties in the context of business transactions, and that public repository content is visible globally and may be indexed by search engines, which is operationally distinct from platforms where user-generated content defaults to private. The statement engages GDPR for EU/EEA users (including rights of access, rectification, erasure, portability, and objection), the California Consumer Privacy Act for California residents, and additional state privacy laws; GitHub designates a Data Protection Officer and commits to Standard Contractual Clauses for international transfers. Compliance teams should note that the policy's AI training data provisions, the breadth of affiliate data sharing with Microsoft, and the treatment of public repository content as non-private warrant specific review under applicable data minimization and purpose limitation obligations.
Institutional analysis available with Professional
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Start Professional free trial1 important change detected
3 versions captured · Last updated: April 2026
Monitoring
GitHub has updated this document before.
Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
Professional Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Professional free trialCross-platform context
See how other platforms handle Affiliate Data Sharing with Microsoft and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.