Sourcegraph Cody · Sourcegraph Terms of Service · View original document ↗

Data Processing Agreement Activation

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Sourcegraph Cody changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Sourcegraph Cody Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The Data Processing Agreement activates when Sourcegraph processes Customer Personal Data on behalf of a customer, establishing a controller-processor relationship for the purposes of applicable data protection law.

This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision triggers the activation of the Data Processing Agreement when Sourcegraph processes personal data on a customer's behalf, which is a required contractual mechanism under GDPR Article 28 and analogous data protection frameworks for controller-processor relationships.

Interpretive note: The full terms of the Data Processing Agreement are not reproduced in this document; whether it satisfies GDPR Article 28 and equivalent requirements cannot be assessed from this summary document alone.

Consumer impact (what this means for users)

Under this clause, enterprise customers for whom Sourcegraph processes personal data are subject to the terms of the Data Processing Agreement. This provision establishes the contractual basis for Sourcegraph's processing of Customer Personal Data, which is relevant to GDPR, UK GDPR, and CCPA compliance for affected organizations.

Cross-platform context

See how other platforms handle Data Processing Agreement Activation and similar clauses.

Compare across platforms →

Monitoring

Sourcegraph Cody has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We process any Customer Personal Data on your behalf

Excerpt from Sourcegraph Cody's Sourcegraph Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 28, which requires a binding contract between a data controller and data processor governing the processing of personal data. UK GDPR imposes equivalent requirements. CCPA requires service provider agreements to restrict downstream use of personal data. Failure to have an adequate DPA in place may constitute a violation of GDPR independent of the agreement's own terms. 2. GOVERNANCE EXPOSURE: High. Enterprise organizations subject to GDPR or UK GDPR that have Sourcegraph processing personal data on their behalf must confirm that the activated DPA satisfies Article 28 requirements, including provisions on processing instructions, sub-processor obligations, data subject rights assistance, and return or deletion of personal data upon termination. 3. JURISDICTION FLAGS: EU and UK organizations face the highest exposure. California-based organizations should confirm the DPA satisfies CCPA service provider restrictions. Organizations in other U.S. states with comprehensive privacy laws (Virginia, Colorado, Texas) should assess whether the DPA addresses processor obligations under those frameworks. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should obtain and review the full Data Processing Agreement before any personal data is processed through Sourcegraph. Key review areas include sub-processor lists and notification procedures, data transfer mechanisms for international transfers (Standard Contractual Clauses, adequacy decisions), data retention and deletion terms, and audit rights. The DPA should be reviewed against standard commercial DPA benchmarks. 5. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that the DPA is executed before Sourcegraph begins processing any Customer Personal Data, document the processing activities covered, and verify that any international data transfers are covered by adequate transfer mechanisms. Annual reviews should confirm that Sourcegraph's sub-processor list and DPA terms remain current.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data processing practices and unfair or deceptive conduct related to personal data handling by technology service providers operating in the U.S.
    File a complaint →
  • State AG
    State Attorneys General in California and other states with comprehensive privacy laws have enforcement authority over controller-processor agreements and service provider data handling obligations.
    File a complaint →

Provision details

Document information
Document
Sourcegraph Terms of Service
Entity
Sourcegraph Cody
Document last updated
May 12, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-016480
Document ID
CA-D-00798
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
dad75d49ec42e4dcb95115df4cffd9c23f9fd8521852c37fb825a6c4e1c61312
Analysis generated
July 9, 2026 14:41 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Sourcegraph Cody
Document: Sourcegraph Terms of Service
Record ID: CA-P-016480
Captured: 2026-07-09 14:41:59 UTC
SHA-256: dad75d49ec42e4dc…
URL: https://conductatlas.com/platform/sourcegraph-cody/sourcegraph-terms-of-service/provision/CA-P-016480/data-processing-agreement-activation/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Sourcegraph Cody's Data Processing Agreement Activation clause do?

This provision triggers the activation of the Data Processing Agreement when Sourcegraph processes personal data on a customer's behalf, which is a required contractual mechanism under GDPR Article 28 and analogous data protection frameworks for controller-processor relationships.

How does this clause affect you?

Under this clause, enterprise customers for whom Sourcegraph processes personal data are subject to the terms of the Data Processing Agreement. This provision establishes the contractual basis for Sourcegraph's processing of Customer Personal Data, which is relevant to GDPR, UK GDPR, and CCPA compliance for affected organizations.

Is ConductAtlas affiliated with Sourcegraph Cody?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.