The DPA establishes Greenhouse's role as a data processor acting on behalf of the subscribing customer company, and sets out both parties' data protection and privacy obligations under that processor relationship.
This analysis describes what Greenhouse's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal framework under which Greenhouse processes personal data on behalf of business customers, a relationship that carries specific regulatory obligations under GDPR and analogous frameworks, including requirements for documented processing instructions, data subject rights facilitation, and breach notification.
Interpretive note: The DPA's specific terms, including processing purposes, data categories, breach notification timelines, and sub-processing approval mechanisms, are not disclosed in this index document and require separate review.
Under this clause, Greenhouse processes personal data as a processor on behalf of the business customer, meaning the customer retains controller responsibilities while Greenhouse's obligations are defined by the DPA terms.
Cross-platform context
See how other platforms handle Data Processing Addendum and Processor Obligations and similar clauses.
Compare across platforms →"If your company has a Greenhouse subscription, the Greenhouse Data processing addendum (DPA) is the agreement describing the respective data processing responsibilities and obligations of the parties including Greenhouse's data protection and privacy commitments as a processor on your company's behalf.Excerpt from Greenhouse's Terms of Service
1) REGULATORY LANDSCAPE: The processor designation directly engages GDPR Articles 28 and 29 (processor obligations and sub-processing), as well as analogous provisions under UK GDPR and CCPA/CPRA service provider frameworks.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the legal framework under which Greenhouse processes personal data on behalf of business customers, a relationship that carries specific regulatory obligations under GDPR and analogous frameworks, including requirements for documented processing instructions, data subject rights facilitation, and breach notification.
Under this clause, Greenhouse processes personal data as a processor on behalf of the business customer, meaning the customer retains controller responsibilities while Greenhouse's obligations are defined by the DPA terms.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Greenhouse.