Provision record
GitHub · GitHub Terms of Service · View original document ↗

User Responsibility for Account Security

Medium severity High confidence Explicit document language Common · 277 of 352 platforms
Stay ahead of the changes
Track GitHub and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

You are fully responsible for keeping your GitHub account secure and for everything that happens under your account, even if someone else posts content using your credentials.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The account responsibility clause assigns liability for all account activity to the account holder, including unauthorized access by third parties, which means users may be held responsible for policy violations or content posted by others who gained access to their account.

Recent Activity

This document changed recently

Medium Apr 28, 2026

GitHub's updated Terms of Service now include an explicit section governing AI features, including Copilot. The new section establishes specific contractual terms for how user data may be collected, used, and retained for developing and improving AI and machine learning models, and identifies what controls are available to users. The practical effect is that AI-related data practices are now consolidated under dedicated contractual language rather than dispersed across general service terms.

View change record →
Medium Apr 19, 2026

GitHub's Terms of Service update on April 19, 2026 involved substantial revisions across 54 sentences, with 40 sentences removed and 4 added. The extent of change suggests modifications to core service provisions; however, without access to the specific language that was modified, removed, or added, the precise operational implications for users cannot be determined. Users should review the updated Terms directly to understand how the changes affect their usage rights, account obligations, or dispute resolution procedures.

View change record →

Clause Stability Stable

0
Changes
5
Months Monitored
Apr 3, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 1874 other provisions on other platforms.

Change history

modified Jul 11, 2026

Previous version had no excerpt; current version includes full language clarifying user liability for account security and all activities under that account.

View full change record →

Consumer impact (what this means for users)

All activity under your GitHub account is your responsibility under these terms, even if your account is accessed without your permission by a third party. Enabling two-factor authentication and monitoring account activity are the primary ways to reduce exposure under this provision.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Navigate to GitHub Settings, then Security, and enable two-factor authentication to reduce the risk of unauthorized account access. Review authorized applications and active sessions regularly.

How other platforms handle this

Skillshare Medium

If we learn that we've collected the personal data of a child under the age of 13 or 16, as applicable, we'll take reasonable steps to delete the personal data. This may require us to delete the Skillshare account...

Mailchimp Medium

If our moderators decide to remove content, or suspend or terminate the Member's account, we will notify the Member and explain how to contact us.

Glassdoor Medium

If we become aware that a child has provided us with personal data without parental consent, we remove such data and terminate the child's account (except where we are required to retain all or a portion of such data for compliance purposes).

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
You are responsible for maintaining the security of your account and password. GitHub cannot and will not be liable for any loss or damage from your failure to comply with this security obligation. You are responsible for all content posted and activity that occurs under your account (even when content is posted by others who have access to your account). You may not use another User's account without permission.

Excerpt from GitHub's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

REGULATORY LANDSCAPE: The account holder responsibility clause may interact with data protection obligations under GDPR where a compromised account is used to process or expose personal data.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Applicable regulations

DMCA
United States Federal
DSA
European Union
FTC Act Section 5
United States Federal

Provision details

Document information
Document
GitHub Terms of Service
Entity
GitHub
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 12, 2026
Record ID
CA-P-001339
Document ID
CA-D-00253
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
610460507af6f60333f6195921a4e0d9629d1fea528d1220cda7340159b5b46b
Analysis generated
May 10, 2026 17:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Terms of Service
Record ID: CA-P-001339
Captured: 2026-05-10 17:12:21 UTC
SHA-256: 610460507af6f603…
URL: https://conductatlas.com/platform/github/github-terms-of-service/provision/CA-P-001339/user-responsibility-for-account-security/
Accessed: Sept. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does GitHub's User Responsibility for Account Security clause do?

The account responsibility clause assigns liability for all account activity to the account holder, including unauthorized access by third parties, which means users may be held responsible for policy violations or content posted by others who gained access to their account.

How does this clause affect you?

All activity under your GitHub account is your responsibility under these terms, even if your account is accessed without your permission by a third party. Enabling two-factor authentication and monitoring account activity are the primary ways to reduce exposure under this provision.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 277 platforms. See the full comparison.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.