GitHub · GitHub Privacy Statement

Data Retention

Medium severity
Share 𝕏 Share in Share 🔒 PDF

What it is

GitHub keeps your personal data for as long as it needs it for business, legal, or operational purposes, without specifying a fixed maximum retention period.

Clause Stability Highly Volatile

1
Change
1
Month Monitored
Apr 27, 2026
First Seen
Apr 27, 2026
Last Seen
This clause has changed once in 1 month of monitoring.

Change history

added Apr 28, 2026

This new provision establishes a general indefinite retention standard with multiple qualifying factors, replacing the previous vague reference to data retention.

View full change record →

Consumer impact (what this means for users)

GitHub does not commit to specific maximum retention periods for your personal data, meaning your account information, repository activity, and communications could be retained indefinitely as long as GitHub identifies a business or legal purpose.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Within 30 days
    To request deletion of your data and to limit retention, email privacy@github.com invoking your right to erasure under GDPR Art. 17 or your deletion right under CCPA. Request confirmation of deletion from backups and sub-processors.

Cross-platform context

See how other platforms handle Data Retention and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

The absence of specific retention periods for different data categories means GitHub could retain your data for many years, increasing your exposure to data breaches and unauthorized use over time.

View original clause language
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: GDPR Art. 5(1)(e) (storage limitation principle — personal data must not be kept longer than necessary); GDPR Art. 13(2)(a) requires disclosure of retention periods or criteria used; CCPA/CPRA does not specify maximum retention periods but requires disclosure of retention practices; UK GDPR mirrors GDPR storage limitation requirements.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    FTC enforces against unreasonable or deceptive data retention practices as unfair practices under FTC Act Section 5.
    File a complaint →

Provision details

Document information
Document
GitHub Privacy Statement
Entity
GitHub
Document last updated
April 29, 2026
Tracking information
First tracked
April 27, 2026
Last verified
April 27, 2026
Record ID
CA-P-003601
Document ID
CA-D-00254
Evidence Provenance
Source URL
Wayback Machine
SHA-256
6b5f0a9a524d3261cfe25f12abc65ee86bfcca11dcb979d0a2c6fa30d7aa36e8
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: GitHub | Document: GitHub Privacy Statement | Record: CA-P-003601
Captured: 2026-04-27 14:59:43 UTC | SHA-256: 6b5f0a9a524d3261…
URL: https://conductatlas.com/platform/github/github-privacy-statement/data-retention/
Accessed: May 2, 2026
Classification
Severity
Medium
Categories

Other provisions in this document