California residents have additional rights under the CCPA/CPRA including the right to know what data is collected, the right to opt out of the sale or sharing of personal information, and the right to limit use of sensitive personal information.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This disclosure fulfills California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) requirements that businesses inform residents about the specific categories of personal information collected. The enumeration establishes the scope of data collection activities subject to California privacy law protections and consumer rights.
The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other GitHub affiliates for purposes including training and improving artificial intelligence and machine learning technologies. The privacy statement indicates that aggregate and de-identified data will be used where feasible, but the updated language establishes broader authority for affiliate data sharing and AI model development than the previous version stated. The revised terms also remove specific disclosure of the conditions under which GitHub personnel may access private repositories, replacing that detail with a cross-reference to the Terms of Service, which means the scope of internal GitHub access to private repositories is now defined in a separate contract document rather than the privacy statement itself.
View change record →If you are a California resident, you can request a full disclosure of what personal data GitHub holds about you, opt out of data sharing for advertising, and limit how sensitive personal information is used. These rights are enforceable under state law and GitHub is obligated to respond to verified requests.
How other platforms handle this
We process marketing-related personal data to provide online advertising and other marketing communications on behalf of Oura and our partners. For example, as explained more fully in our Cookie Policy, we use cookies and similar technologies on our website to create audiences for online advertiseme...
Depending on where you live and subject to applicable exceptions, you may have the following privacy rights in relation to your Personal Data: The right to know information about our processing of your Personal Data, including the right to access your Personal Data, often in a portable format; The r...
If you are a California resident, you have certain rights with respect to your personal information under the California Consumer Privacy Act (CCPA). These rights include the right to know about the personal information we collect, use, disclose, and sell; the right to request deletion of your perso...
Monitoring
GitHub has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
"We collected the following categories of personal information in the last 12 months: identifiers/contact information, demographic information (such as gender), payment card information associated with you, commercial information, Internet or other electronic network activity information, geolocation data, audio, electronic, visual or similar information, and inferences drawn from the above.— Excerpt from GitHub's GitHub Privacy Statement
CPRA compliance obligations include responding to verifiable consumer requests within 45 days, maintaining a 'Do Not Sell or Share My Personal Information' mechanism, and limiting retention of sensitive personal information. Businesses using GitHub with California-based employees or customers should confirm whether their use of GitHub creates downstream CPRA obligations.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.
Professional Governance Intelligence
Need to monitor specific governance provisions?
Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This disclosure fulfills California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) requirements that businesses inform residents about the specific categories of personal information collected. The enumeration establishes the scope of data collection activities subject to California privacy law protections and consumer rights.
If you are a California resident, you can request a full disclosure of what personal data GitHub holds about you, opt out of data sharing for advertising, and limit how sensitive personal information is used. These rights are enforceable under state law and GitHub is obligated to respond to verified requests.
ConductAtlas has identified this type of provision across 15 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.