GitHub · GitHub Privacy Statement · View original document ↗

International Data Transfers (SCCs)

Medium severity Rare · 1 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity GitHub recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for GitHub Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The legal validity of these transfers depends on SCCs being properly executed and supplemented with technical safeguards, following the Schrems II ruling — failure could expose EU users' data to US government access without adequate protection.

Recent Activity

This document changed recently

High Apr 28, 2026

The updated terms now explicitly authorize GitHub to collect AI outputs generated within the platform alongside user-provided code and content, and to share personal data with Microsoft and other Git…

Consumer impact (what this means for users)

The policy states GitHub collects identifiers, device information, usage activity, payment data, and user-generated content, and authorizes sharing this data with Microsoft affiliates, service providers, and analytics and advertising partners. Public repository content is described as globally visible and potentially indexed by search engines, meaning code and associated metadata posted publicly is not treated as private personal data under the policy. You can submit data access, deletion, or correction requests through GitHub's privacy contact form at https://support.github.com/contact/privacy.

How other platforms handle this

OneLogin Medium

If you are located in the European Economic Area, the United Kingdom, or Switzerland, please be aware that we may transfer your personal information to countries outside of these regions, including to the United States, where data protection laws may not provide the same level of protection as those...

PlanetScale Medium

You will provide personal information directly to our website in the United States. We may also transfer personal information to our partners and service providers in the United States and other jurisdictions. Please note that such jurisdictions may not provide the same protections as the data prote...

ClickUp Medium

ClickUp is based in the United States and the information we collect is governed by U.S. law. By accessing or using our Services or otherwise providing information to us, you consent to the processing and transfer of information in and to the U.S. and other countries, where you may not have the same...

See all platforms with this clause type →

Monitoring

GitHub has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we transfer your personal data to countries outside of your jurisdiction, including to the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms, as the legal basis for such transfers.

— Excerpt from GitHub's GitHub Privacy Statement

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union
UK GDPR
United Kingdom

Provision details

Document information
Document
GitHub Privacy Statement
Entity
GitHub
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 12, 2026
Record ID
CA-P-005605
Document ID
CA-D-00254
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d21b58443ca0b4402240dbd06996ada072c72ed842fcccc6b13acab2d7bc6c4d
Analysis generated
May 10, 2026 09:46 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Privacy Statement
Record ID: CA-P-005605
Captured: 2026-05-10 09:46:36 UTC
SHA-256: d21b58443ca0b440…
URL: https://conductatlas.com/platform/github/github-privacy-statement/international-data-transfers-sccs/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does GitHub's International Data Transfers (SCCs) clause do?

The legal validity of these transfers depends on SCCs being properly executed and supplemented with technical safeguards, following the Schrems II ruling — failure could expose EU users' data to US government access without adequate protection.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 1 platforms. See the full comparison.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.