Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The Data Processing Agreement activates when Sourcegraph processes Customer Personal Data on behalf of a customer, establishing a controller-processor relationship for the purposes of applicable data protection law.
This analysis describes what Sourcegraph Cody's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision triggers the activation of the Data Processing Agreement when Sourcegraph processes personal data on a customer's behalf, which is a required contractual mechanism under GDPR Article 28 and analogous data protection frameworks for controller-processor relationships.
Interpretive note: The full terms of the Data Processing Agreement are not reproduced in this document; whether it satisfies GDPR Article 28 and equivalent requirements cannot be assessed from this summary document alone.
Under this clause, enterprise customers for whom Sourcegraph processes personal data are subject to the terms of the Data Processing Agreement. This provision establishes the contractual basis for Sourcegraph's processing of Customer Personal Data, which is relevant to GDPR, UK GDPR, and CCPA compliance for affected organizations.
Cross-platform context
See how other platforms handle Data Processing Agreement Activation and similar clauses.
Compare across platforms →Monitoring
Sourcegraph Cody has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We process any Customer Personal Data on your behalfExcerpt from Sourcegraph Cody's Sourcegraph Terms of Service
1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 28, which requires a binding contract between a data controller and data processor governing the processing of personal data. UK GDPR imposes equivalent requirements. CCPA requires service provider agreements to restrict downstream use of personal data. Failure to have an adequate DPA in place may constitute a violation of GDPR independent of the agreement's own terms. 2. GOVERNANCE EXPOSURE: High. Enterprise organizations subject to GDPR or UK GDPR that have Sourcegraph processing personal data on their behalf must confirm that the activated DPA satisfies Article 28 requirements, including provisions on processing instructions, sub-processor obligations, data subject rights assistance, and return or deletion of personal data upon termination. 3. JURISDICTION FLAGS: EU and UK organizations face the highest exposure. California-based organizations should confirm the DPA satisfies CCPA service provider restrictions. Organizations in other U.S. states with comprehensive privacy laws (Virginia, Colorado, Texas) should assess whether the DPA addresses processor obligations under those frameworks. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should obtain and review the full Data Processing Agreement before any personal data is processed through Sourcegraph. Key review areas include sub-processor lists and notification procedures, data transfer mechanisms for international transfers (Standard Contractual Clauses, adequacy decisions), data retention and deletion terms, and audit rights. The DPA should be reviewed against standard commercial DPA benchmarks. 5. COMPLIANCE CONSIDERATIONS: Legal teams should confirm that the DPA is executed before Sourcegraph begins processing any Customer Personal Data, document the processing activities covered, and verify that any international data transfers are covered by adequate transfer mechanisms. Annual reviews should confirm that Sourcegraph's sub-processor list and DPA terms remain current.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision triggers the activation of the Data Processing Agreement when Sourcegraph processes personal data on a customer's behalf, which is a required contractual mechanism under GDPR Article 28 and analogous data protection frameworks for controller-processor relationships.
Under this clause, enterprise customers for whom Sourcegraph processes personal data are subject to the terms of the Data Processing Agreement. This provision establishes the contractual basis for Sourcegraph's processing of Customer Personal Data, which is relevant to GDPR, UK GDPR, and CCPA compliance for affected organizations.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Sourcegraph Cody.