California residents have additional rights under the CCPA/CPRA including the right to know what data is collected, the right to opt out of the sale or sharing of personal information, and the right to limit use of sensitive personal information.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This disclosure fulfills California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) requirements that businesses inform residents about the specific categories of personal information collected. The enumeration establishes the scope of data collection activities subject to California privacy law protections and consumer rights.
The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other GitHub affiliates for purposes including training and improving artificial intelligence and machine learning technologies. The privacy statement indicates that aggregate and de-identified data will be used where feasible, but the updated language establishes broader authority for affiliate data sharing and AI model development than the previous version stated. The revised terms also remove specific disclosure of the conditions under which GitHub personnel may access private repositories, replacing that detail with a cross-reference to the Terms of Service, which means the scope of internal GitHub access to private repositories is now defined in a separate contract document rather than the privacy statement itself.
View change record →If you are a California resident, you can request a full disclosure of what personal data GitHub holds about you, opt out of data sharing for advertising, and limit how sensitive personal information is used. These rights are enforceable under state law and GitHub is obligated to respond to verified requests.
How other platforms handle this
If you are a California resident, you have the right to: Know what personal information is being collected about you; Know whether your personal information is sold or disclosed and to whom; Say no to the sale of personal information; Access your personal information; Request deletion of your person...
If you are a California resident, you have the right to know what personal information we collect, use, and disclose about you; the right to request deletion of your personal information; the right to opt out of the sale or sharing of your personal information; the right to correct inaccurate person...
Depending on where you are located, you may have certain rights regarding your personal information, including the right to access, correct, delete, or restrict processing of your personal information, the right to data portability, and the right to object to or withdraw consent for certain processi...
Monitoring
GitHub has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We collected the following categories of personal information in the last 12 months: identifiers/contact information, demographic information (such as gender), payment card information associated with you, commercial information, Internet or other electronic network activity information, geolocation data, audio, electronic, visual or similar information, and inferences drawn from the above.— Excerpt from GitHub's GitHub Privacy Statement
CPRA compliance obligations include responding to verifiable consumer requests within 45 days, maintaining a 'Do Not Sell or Share My Personal Information' mechanism, and limiting retention of sensitive personal information. Businesses using GitHub with California-based employees or customers should confirm whether their use of GitHub creates downstream CPRA obligations.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This disclosure fulfills California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) requirements that businesses inform residents about the specific categories of personal information collected. The enumeration establishes the scope of data collection activities subject to California privacy law protections and consumer rights.
If you are a California resident, you can request a full disclosure of what personal data GitHub holds about you, opt out of data sharing for advertising, and limit how sensitive personal information is used. These rights are enforceable under state law and GitHub is obligated to respond to verified requests.
ConductAtlas has identified this type of provision across 17 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.