HubSpot · HubSpot Terms of Service · View original document ↗

Data Processing Agreement and GDPR Compliance

High severity Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for HubSpot Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you use HubSpot to handle personal data covered by privacy laws like GDPR, you must sign a separate Data Processing Agreement with HubSpot — and it's your responsibility to make sure you're allowed to share that data with HubSpot in the first place.

This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The provision clarifies the operational framework for data handling compliance by designating a separate DPA as the governing instrument for regulated data processing and allocating the compliance obligation for pre-transfer authorization to the customer organization.

Consumer impact (what this means for users)

Business customers processing EU, UK, or other regulated personal data through HubSpot must separately execute the DPA to maintain legal compliance — failure to do so creates significant GDPR enforcement risk that falls entirely on the business customer.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Visit https://legal.hubspot.com/dpa to review and execute HubSpot's Data Processing Agreement. Complete the online form to generate a signed DPA for your organization before processing any EU, UK, or other regulated personal data through HubSpot.

How other platforms handle this

Figma Medium

If you are using our Services pursuant to a separate agreement with Figma that includes data processing terms, such as an enterprise agreement, those terms will govern the processing of personal data to the extent they conflict with this Privacy Policy.

Signal Medium

Signal can optionally discover which contacts in your address book are Signal users, using a service designed to protect the privacy of your contacts. Information from the contacts on your device may be cryptographically hashed and transmitted to the server in order to determine which of your contac...

Runway Medium

Runway is considered the "data controller" of the "personal data" (as defined under the General Data Protection Regulation) we handle under this Privacy Policy. In other words, Runway is responsible for deciding how to collect, use, and disclose personal data, subject to applicable law. The laws of ...

See all platforms with this clause type →

Monitoring

HubSpot has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
To the extent that HubSpot processes any Customer Data that is subject to Data Protection Laws on Customer's behalf, the terms of the HubSpot Data Processing Agreement ('DPA'), which are incorporated into this Agreement by reference, shall apply. The DPA is available at https://legal.hubspot.com/dpa. Customer is responsible for ensuring that it has all necessary rights, consents, and legal bases required under applicable Data Protection Laws to transfer Customer Data to HubSpot for processing.

— Excerpt from HubSpot's HubSpot Terms of Service

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY FRAMEWORK: GDPR Art. 28 requires that data controllers only use processors providing sufficient guarantees, and that processing is governed by a binding contract (the DPA). Standard Contractual Clauses (SCCs, Commission Decision 2021/914) are required for transfers to the US from the EU/EEA under GDPR Chapter V. UK GDPR and the UK International Data Transfer Agreement (IDTA) apply to UK-to-US transfers. CCPA §1798.140(ag) requires service provider agreements for businesses disclosing personal information to service providers. Primary enforcement: Irish DPC (EU lead authority for HubSpot), UK ICO, California Privacy Protection Agency. (2)

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC enforces against companies that misrepresent their data protection practices, and failure to maintain adequate processor agreements may constitute an unfair or deceptive practice under FTC Act Section 5.
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union

Provision details

Document information
Document
HubSpot Terms of Service
Entity
HubSpot
Document last updated
May 5, 2026
Tracking information
First tracked
April 18, 2026
Last verified
April 18, 2026
Record ID
CA-P-002968
Document ID
CA-D-00207
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9927299c7582997f7d7d4ec9af87291e8942c38b96b84ff4e2ea6e359778795c
Analysis generated
April 18, 2026 11:17 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: HubSpot
Document: HubSpot Terms of Service
Record ID: CA-P-002968
Captured: 2026-04-18 11:17:02 UTC
SHA-256: 9927299c7582997f…
URL: https://conductatlas.com/platform/hubspot/hubspot-terms-of-service/data-processing-agreement-and-gdpr-compliance/
Accessed: June 17, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does HubSpot's Data Processing Agreement and GDPR Compliance clause do?

The provision clarifies the operational framework for data handling compliance by designating a separate DPA as the governing instrument for regulated data processing and allocating the compliance obligation for pre-transfer authorization to the customer organization.

How does this clause affect you?

Business customers processing EU, UK, or other regulated personal data through HubSpot must separately execute the DPA to maintain legal compliance — failure to do so creates significant GDPR enforcement risk that falls entirely on the business customer.

Is ConductAtlas affiliated with HubSpot?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.