Squarespace · Squarespace Privacy Policy · View original document ↗

EU and UK Data Subject Rights

Low severity High confidence Explicitdocumentlanguage Rare · 3 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Squarespace Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

EU and UK users have legal rights under GDPR to access, correct, delete, or move their personal data, and can object to certain types of processing, exercisable by contacting Squarespace directly.

This analysis describes what Squarespace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

These rights are among the strongest data protection rights globally and are legally enforceable, meaning Squarespace is obligated to respond to valid requests within specific regulatory timeframes.

Consumer impact (what this means for users)

EU and UK users can formally request a copy of their personal data, ask for corrections or deletion, restrict processing, or object to data use for marketing, with enforceable response obligations on Squarespace under GDPR.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    Email privacy@squarespace.com with your data portability or access request, identifying your account and the specific data you are requesting. Alternatively, use the Privacy Request Form at squarespace.com/privacy. Squarespace must respond within one month under GDPR.

Cross-platform context

See how other platforms handle EU and UK Data Subject Rights and similar clauses.

Compare across platforms →

Monitoring

Squarespace has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Economic Area or the United Kingdom, you have certain rights in relation to your personal information under the General Data Protection Regulation (GDPR) or equivalent laws, including: the right to access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object, and rights in relation to automated decision-making and profiling. To exercise any of these rights, please contact us at privacy@squarespace.com or submit a request through our Privacy Request Form.

— Excerpt from Squarespace's Squarespace Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision directly implements GDPR Articles 15-22, which establish data subject rights for EU/EEA residents, and equivalent UK GDPR provisions. The Irish Data Protection Commission is the lead supervisory authority given Squarespace's EU establishment in Ireland. GDPR requires responses to data subject requests within one month, extendable by two additional months in complex cases, with notification obligations if requests are denied. GOVERNANCE EXPOSURE: Medium. Squarespace's explicit enumeration of GDPR rights is a positive compliance indicator, but the operational capacity to fulfill rights requests at scale, particularly for erasure and portability, requires robust internal processes. Failure to respond within statutory timeframes or to implement erasure effectively creates regulatory exposure to enforcement by the Irish DPC. JURISDICTION FLAGS: Applies to EU/EEA and UK users. Squarespace's dual controller/processor role means that for visitors to customer-hosted sites, rights must be directed to the website owner rather than Squarespace, which the policy acknowledges but which may not be clear to all users in practice. CONTRACT AND VENDOR IMPLICATIONS: B2B customers using Squarespace should confirm that their DPA with Squarespace obligates Squarespace to assist with data subject requests received by the customer, as required by GDPR Article 28(3)(e). Procurement teams should assess whether Squarespace's data subject request processes integrate with the customer's own workflows. COMPLIANCE CONSIDERATIONS: Compliance teams should audit the Privacy Request Form and email channel for GDPR request intake to confirm identity verification, response tracking, and escalation procedures are in place. Records of rights requests and responses should be maintained. For erasure requests, teams should verify that deletion extends to backup systems and third-party processors within appropriate timeframes.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    While the Irish DPC is the primary EU authority, the FTC has jurisdiction over US-based companies' representations about privacy practices including GDPR compliance claims.
    File a complaint →

Provision details

Document information
Document
Squarespace Privacy Policy
Entity
Squarespace
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-010306
Document ID
CA-D-00569
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
760bf733870bf1e90c2b2bf49c4348155254bff4634889f1fc7c14a16d9a81e0
Analysis generated
May 8, 2026 14:38 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Squarespace
Document: Squarespace Privacy Policy
Record ID: CA-P-010306
Captured: 2026-05-08 14:38:54 UTC
SHA-256: 760bf733870bf1e9…
URL: https://conductatlas.com/platform/squarespace/squarespace-privacy-policy/eu-and-uk-data-subject-rights/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Squarespace's EU and UK Data Subject Rights clause do?

These rights are among the strongest data protection rights globally and are legally enforceable, meaning Squarespace is obligated to respond to valid requests within specific regulatory timeframes.

How does this clause affect you?

EU and UK users can formally request a copy of their personal data, ask for corrections or deletion, restrict processing, or object to data use for marketing, with enforceable response obligations on Squarespace under GDPR.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 3 platforms. See the full comparison.

Is ConductAtlas affiliated with Squarespace?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Squarespace.