Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement places sole responsibility on site operators for compliance with applicable data protection laws, including GDPR and the EU e-Privacy Directive, covering End User Data collection and processing, marketing communications, and cookie consent obligations. This includes cookies placed by Squarespace on the operator's behalf, such as for analytics purposes.
This analysis describes what Squarespace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision expressly assigns data protection compliance obligations to Squarespace site operators, including for cookies placed by Squarespace on the operator's request. Operators who fail to implement required consent mechanisms or privacy disclosures on their hosted sites bear the compliance risk under this contractual allocation.
This provision establishes that Squarespace site operators are solely responsible for data protection compliance on their hosted sites, including consent capture for cookies placed by Squarespace for analytics or other purposes at the operator's request. End users of Squarespace-hosted sites should be aware that their data protection rights are to be addressed by the site operator rather than Squarespace directly in this context.
Cross-platform context
See how other platforms handle Operator Data Protection Compliance Obligations and similar clauses.
Compare across platforms →Monitoring
Squarespace has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"You agree and warrant that when using the Services or operating Your Sites you are solely responsible for complying with applicable data protection, security or privacy laws and regulations (including, where applicable, the EU General Data Protection Regulation and the EU e-Privacy Directive/Regulation), including any notice and consent requirements. This includes without limitation the collection and processing by you of any End User Data or other personal data, when you use Your Sites and the Services to send marketing and other electronic communications to individuals and when using cookies and similar technologies on Your Sites (including, in particular, those which we place for you at your request as part of the Services, such as to undertake analytics for you).Excerpt from Squarespace's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 4(7) (controller definition), 6 (lawful basis), 7 (consent), and 13/14 (transparency obligations), as well as the EU e-Privacy Directive's cookie consent requirements and national implementations. The allocation of sole compliance responsibility to operators does not alter the regulatory analysis of who qualifies as a data controller under GDPR; regulatory enforcement authorities would assess controller status independently of contractual allocation. The Data Processing Addendum referenced in Section 7.2 governs the processor relationship for End User Data. (2) GOVERNANCE EXPOSURE: High for business operators. Site operators using Squarespace analytics, marketing integrations, or form-based data collection tools bear direct GDPR and e-Privacy compliance risk for their end users' data, including the obligation to obtain valid consent for analytics cookies placed by Squarespace at the operator's request. Failure to implement compliant consent mechanisms exposes operators to enforcement by their applicable Data Protection Authority. (3) JURISDICTION FLAGS: EU/EEA site operators face the highest exposure given GDPR and e-Privacy Directive requirements. California-based operators or those with California-resident end users face CCPA compliance obligations for End User Data collection. The UK post-Brexit maintains comparable requirements under UK GDPR and the Privacy and Electronic Communications Regulations. (4) CONTRACT AND VENDOR IMPLICATIONS: The Data Processing Addendum (DPA) referenced in Section 7.2 and incorporated into the Agreement governs the processor relationship between Squarespace and operators for End User Data; legal teams should review the DPA to assess GDPR Article 28 compliance, including sub-processor disclosure, data transfer mechanisms, and security obligations. The independent data controller designation for Independently Controlled Information (Section 7.3.3) means operators must also disclose Squarespace's data practices in their privacy policies. (5) COMPLIANCE CONSIDERATIONS: Operators should audit cookie consent mechanisms on their Squarespace-hosted sites to ensure that analytics and other cookies placed by Squarespace at the operator's request are covered by valid consent, review their privacy policies to include required disclosures about Squarespace's processing of Independently Controlled Information as defined in Section 7.3.3, and assess whether their End User Data handling practices satisfy applicable GDPR lawful basis requirements.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision expressly assigns data protection compliance obligations to Squarespace site operators, including for cookies placed by Squarespace on the operator's request. Operators who fail to implement required consent mechanisms or privacy disclosures on their hosted sites bear the compliance risk under this contractual allocation.
This provision establishes that Squarespace site operators are solely responsible for data protection compliance on their hosted sites, including consent capture for cookies placed by Squarespace for analytics or other purposes at the operator's request. End users of Squarespace-hosted sites should be aware that their data protection rights are to be addressed by the site operator rather than Squarespace directly …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Squarespace.