GitHub · GitHub Privacy Statement

Law Enforcement and Government Disclosure

High severity
Share 𝕏 Share in Share 🔒 PDF

What it is

GitHub can hand over your personal data to police, government agencies, or other third parties when it believes there is a legal requirement or when it decides it is appropriate, without necessarily telling you first.

Clause Stability Highly Volatile

1
Change
1
Month Monitored
Apr 27, 2026
First Seen
Apr 27, 2026
Last Seen
This clause has changed once in 1 month of monitoring.

Change history

modified Apr 28, 2026

Previous version had no excerpt provided; current version now includes detailed disclosure conditions and explicit mention of law enforcement discretion.

View full change record →

Consumer impact (what this means for users)

Your GitHub account data — including repository contents, IP address, and communications — can be disclosed to law enforcement or government entities at GitHub's discretion, potentially without any notice to you.

Cross-platform context

See how other platforms handle Law Enforcement and Government Disclosure and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

This provision means your code, account activity, IP address, and identity could be disclosed to government authorities without your prior knowledge, which is particularly significant for developers working on sensitive or politically contentious projects.

View original clause language
We may share your personal data with law enforcement, government officials, or other third parties when: compliance with applicable law or legal process is required; we believe disclosure is necessary to prevent harm or financial loss, or in connection with an investigation of suspected or actual illegal activity; or enforcement of our agreements, policies, or terms of service is needed. We reserve the right to disclose your information to law enforcement in circumstances we deem appropriate in our sole discretion.

Institutional analysis (Compliance & legal intelligence)

REGULATORY FRAMEWORK: This provision implicates GDPR Art. 6(1)(c) (legal obligation) and Art. 6(1)(f) (legitimate interests) as lawful bases for disclosure; 18 U.S.C. §2703 (Stored Communications Act/ECPA) governs the procedural requirements for compelled government access to stored communications in the US; GDPR Art. 48 restricts transfers to foreign authorities not based on EU legal instruments. The FTC (Section 5) and state AGs retain authority over deceptive disclosure practices.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    FTC has authority under Section 5 of the FTC Act over unfair or deceptive practices in government data disclosures by technology platforms.
    File a complaint →
  • State AG
    State attorneys general may investigate discretionary law enforcement disclosures that exceed legal requirements under state consumer protection statutes.
    File a complaint →

Provision details

Document information
Document
GitHub Privacy Statement
Entity
GitHub
Document last updated
April 29, 2026
Tracking information
First tracked
April 27, 2026
Last verified
April 27, 2026
Record ID
CA-P-003595
Document ID
CA-D-00254
Evidence Provenance
Source URL
Wayback Machine
SHA-256
6b5f0a9a524d3261cfe25f12abc65ee86bfcca11dcb979d0a2c6fa30d7aa36e8
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: GitHub | Document: GitHub Privacy Statement | Record: CA-P-003595
Captured: 2026-04-27 14:59:43 UTC | SHA-256: 6b5f0a9a524d3261…
URL: https://conductatlas.com/platform/github/github-privacy-statement/law-enforcement-and-government-disclosure/
Accessed: May 2, 2026
Classification
Severity
High
Categories

Other provisions in this document