Miro · Miro Terms of Service · View original document ↗

Customer Data Processing Addendum

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Miro recorded 10 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Miro Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The terms reference a Customer Data Processing Addendum (CDPA), accessible at miro.com/legal/customer-data-processing-addendum/, which governs Miro's processing of personal data on behalf of customers, particularly relevant for GDPR Article 28 compliance.

This analysis describes what Miro's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The CDPA establishes Miro's obligations as a data processor under GDPR and similar frameworks, defining the legal basis and conditions under which customer personal data is processed. Enterprise customers are required to assess the CDPA to satisfy their own controller-level compliance obligations.

Interpretive note: The CDPA is referenced by the Terms of Service but its substantive provisions are contained in a separate document; compliance implications depend on the CDPA's specific content.

Consumer impact (what this means for users)

The agreement incorporates a separate Customer Data Processing Addendum that governs how personal data processed through Miro boards and services is handled under data protection law. Business customers acting as data controllers under GDPR should review the CDPA in conjunction with the Subprocessors List.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Garmin Medium

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...

Strava Medium

We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified data for this purpose. We also use personal info...

See all platforms with this clause type →

Monitoring

Miro has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: The CDPA directly implicates GDPR Article 28, which requires a written contract between controllers and processors. CCPA service provider obligations are also relevant for California-based business customers. The CDPA's provisions on international data transfers may engage GDPR Chapter V requirements and applicable Standard Contractual Clauses. (2) GOVERNANCE EXPOSURE: High for enterprise customers in EU/EEA jurisdictions. The CDPA determines whether Miro's processing activities satisfy controller obligations, and any gaps in its coverage could create regulatory exposure for customer organizations. (3) JURISDICTION FLAGS: EU/EEA customers face the highest exposure; UK GDPR applies post-Brexit for UK customers; Swiss data protection law (nDSG) is relevant for Swiss operations. US healthcare and financial services customers should assess whether CDPA terms satisfy HIPAA Business Associate Agreement requirements or equivalent. (4) CONTRACT AND VENDOR IMPLICATIONS: The CDPA is a standard procurement requirement for enterprise SaaS; legal teams should confirm it includes audit rights, breach notification timelines, subprocessor change notification procedures, and data deletion obligations. The published Subprocessors List should be reviewed as part of vendor due diligence. (5) COMPLIANCE CONSIDERATIONS: Controllers should map all personal data categories processed through Miro and confirm the CDPA covers those categories. Transfer impact assessments may be required for international data transfers to Miro's subprocessors. Annual review of the Subprocessors List is advisable given permitted subprocessor changes.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC oversees data processing representations and consumer data protection practices for US-based users and businesses
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Miro Terms of Service
Entity
Miro
Document last updated
May 5, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-013030
Document ID
CA-D-00555
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
fde838f90b08bff38488a04b3026c97c0f05a90baa988746f46596f1b0fa41c1
Analysis generated
May 21, 2026 04:14 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Miro
Document: Miro Terms of Service
Record ID: CA-P-013030
Captured: 2026-05-21 04:14:00 UTC
SHA-256: fde838f90b08bff3…
URL: https://conductatlas.com/platform/miro/miro-terms-of-service/customer-data-processing-addendum/
Accessed: June 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Miro's Customer Data Processing Addendum clause do?

The CDPA establishes Miro's obligations as a data processor under GDPR and similar frameworks, defining the legal basis and conditions under which customer personal data is processed. Enterprise customers are required to assess the CDPA to satisfy their own controller-level compliance obligations.

How does this clause affect you?

The agreement incorporates a separate Customer Data Processing Addendum that governs how personal data processed through Miro boards and services is handled under data protection law. Business customers acting as data controllers under GDPR should review the CDPA in conjunction with the Subprocessors List.

Is ConductAtlas affiliated with Miro?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Miro.