Home Blog Is Vercel GDPR Compliant? The DPA and Your Deployment

GDPR

Is Vercel GDPR Compliant? The DPA and Your Deployment

Posted by Kevin Yun|August 21, 2026

Vercel publishes a data processing addendum at vercel.com/legal/dpa, relies on the EU Standard Contractual Clauses and the UK Addendum for transfers, and imposes an unusually strict condition on its own subprocessors. It also carries a detail most summaries omit: the addendum applies to customers on Enterprise and Pro plans. If you are on a free tier, there is no Article 28 contract covering your processing.

This article covers who the addendum actually applies to, the subprocessor clause worth quoting and the five-day window attached to it, where Vercel acts as controller rather than processor, and why a hosting platform belongs in your processing record even though nobody logs into it to look at data.

Where The DPA Is, And What It Attaches To

Vercel's addendum is published at vercel.com/legal/dpa. The version live when we checked, on 7 August 2026, was last updated 17 March 2026 with an effective date of 31 March 2026. The contracting entity is Vercel Inc., a Delaware corporation.

Read the first paragraph before anything else. The addendum forms part of Vercel's Enterprise Terms and Conditions or another executed agreement for Services on an Enterprise plan, and it states that it applies to Vercel's processing of personal data as a processor for customers on Enterprise and Pro plans. It becomes binding on entering the Agreement or on execution of the addendum itself.

The consequence is blunt and worth checking before you answer a questionnaire: a team running production on a free tier does not have this contract. "We use Vercel and they have a DPA" is true about Vercel and possibly not true about you. If you are unsure what the contract needs to contain once you have one, our guide to data processing agreements covers the required elements.

Vercel's compliance documentation sets out the processor commitments in plain terms: appropriate technical and organisational measures, notification of breaches without undue delay, similar data protection obligations imposed on subprocessors, assistance with data subject rights, and reliance on the EU Standard Contractual Clauses and the UK Addendum for transfers outside the EEA.

The Subprocessor Clause Is Stronger Than Most

This is the clause worth putting in front of a security reviewer, because it goes further than the standard flow-down.

Vercel's addendum commits it, when engaging a subprocessor, to require that subprocessor to protect customer data to the standard required by applicable law — including the Article 28(3) obligations and sufficient guarantees of appropriate technical and organisational measures. So far, standard.

Then it adds a geographic condition: Vercel will require any appointed subprocessor to agree in writing either to process data only in a country the European Union has declared to have an adequate level of protection, or to do so on terms equivalent to the Standard Contractual Clauses.

Most subprocessor clauses say the subprocessor must be bound to equivalent data protection terms and stop. This one addresses where the subprocessor operates as well as how it behaves, which is the question that actually matters for onward transfers. It is a good example of why reading the clause beats reading the summary — our guide to subprocessor management covers what else to look for in one.

The flow-down conditions go further still. Vercel's security schedule requires subprocessors to notify Vercel of security incidents, delete data on instruction, not engage further subprocessors without authorisation, and not change the location where data is processed. That last one closes the gap most subprocessor clauses leave open.

Now the part that costs you something. The subprocessor list, with functions and locations, is published at security.vercel.com. To receive notice of a new subprocessor you must email Vercel's privacy address to subscribe. Once notified, you have five calendar days to object in writing on reasonable data protection grounds. If the parties cannot agree a resolution, your sole and exclusive remedy is to terminate the Agreement for convenience — with no refunds, and remaining liable for any committed fees.

Five days is the shortest objection window in this cluster, and a remedy that costs you your prepaid fees is not really a remedy. Subscribe, route the notifications somewhere owned, and treat an objection as a commercial decision rather than a compliance one.

Transfers: Standard Contractual Clauses And The UK Addendum

Vercel's compliance documentation names the EU Standard Contractual Clauses and the UK Addendum as the mechanisms it relies on for transfers of personal data outside the EEA.

That is a different structure from several vendors in this cluster, which lead with the EU-US Data Privacy Framework and hold the Clauses in reserve. Neither approach is better in the abstract. What matters is that you write down the one your vendor actually uses, because a transfer impact assessment describing a mechanism your processor does not rely on is worse than no assessment.

If the Framework matters to your assessment either way, check the public Data Privacy Framework participant list rather than inferring participation from a marketing page, and record what you found and when.

Vercel Processes Whatever Your Application Processes

Here is the part that gets missed, and it is not a Vercel problem.

A hosting platform is not a tool people log into to look at customer records. It is the place your application runs. Every request your users make arrives there. Server-side rendering, API routes and serverless functions execute against real user input. Request logs carry IP addresses. Build and runtime logs carry whatever your code prints, which on a bad day includes a request body somebody added a debug line for and never removed.

None of that is a feature anyone enabled. It follows from deploying an application that handles personal data, and it means Vercel belongs in your Article 30 record as a processor with a purpose and a location beside it, in the same way your database does. Teams reliably list the CRM and forget the platform the whole product runs on. Keeping your record of processing activities honest means including the infrastructure.

The related discipline is log hygiene. Whatever your logging retention is, it applies to personal data captured incidentally as much as to data you meant to store, and "we did not intend to log that" is not a retention policy.

Where Vercel Is The Controller, Not Your Processor

The addendum splits Vercel's role, and the second half is easy to miss.

For Customer Data — the personal data inside your content, which the addendum describes as including things like IP addresses and system configuration information — you are the controller and Vercel is the processor. Standard.

But the addendum defines two other categories. Service-Generated Data means usage data and metadata generated through use of the Services, including through support. Contact Data means account information, payment information and event attendee information. For both, Vercel is the controller, processing them under its own privacy notice rather than your instructions — and it states it may use them to operate, improve and support the Services, to send marketing and service-related messages, and for other lawful business practices such as analytics, benchmarking and reporting.

That is not unusual and it is not hidden, but it changes what you can say. Requests about your account data are answered by Vercel as a controller, not routed through your DPA. And Vercel's own SCC schedule reflects this by applying Module One, controller to controller, to that category, alongside Modules Two and Three for Customer Data.

One further restriction sits in the same schedules: customers are prohibited from including sensitive data or special categories of data in Customer Data. If your application handles health, biometric or similar categories, that prohibition is a term you have agreed to, not just a risk to manage.

Common Mistakes With Vercel And GDPR

Leaving the hosting platform out of the processor inventory. The place your application runs processes everything your application processes. It belongs in the record next to the database.

Debug logging that outlives the debugging. A line added to print a request body during an incident becomes a standing collection of personal data in your logs. Retention applies to it regardless of intent.

Assuming the DPA covers your plan. It applies to Enterprise and Pro. A free-tier deployment handling personal data is running without the Article 28 contract you may be citing to customers.

Missing the five-day objection window. Notice requires you to subscribe by email, the window is five calendar days, and the only remedy is termination with no refunds. Unowned notifications make that decision by default.

Forgetting the controller half. Service-Generated Data and Contact Data are Vercel's to control under its own privacy notice. Those requests do not route through your DPA.

FAQ

Where is Vercel's DPA, and does it apply to me?

At vercel.com/legal/dpa, with Vercel Inc. as the contracting entity. Critically, it states that it applies to Vercel's processing as a processor for customers on Enterprise and Pro plans. If you are on a free tier, check your position before telling a customer you have a data processing agreement in place.

What transfer mechanism does Vercel use?

Its compliance documentation names the EU Standard Contractual Clauses and the UK Addendum as the mechanisms relied on for transfers of personal data outside the EEA. Record that in your transfer assessment rather than assuming a different route, and verify anything else on the public register.

Does Vercel place conditions on its subprocessors?

Yes, and they go beyond the usual. Its addendum requires appointed subprocessors to meet the Article 28(3) standard and, additionally, to agree in writing either to process data only in a country the EU has declared adequate, or to do so on terms equivalent to the Standard Contractual Clauses.

How much notice does Vercel give before adding a subprocessor?

You must email Vercel's privacy address to subscribe to notices. Once notified, you have five calendar days to object in writing on reasonable data protection grounds. If no resolution is agreed, the sole remedy is terminating the Agreement for convenience with no refunds, and you remain liable for committed fees.

Closing Thought

Developers and privacy teams describe the same system in languages that barely overlap. One says "we deploy to Vercel," meaning a build pipeline and a URL. The other hears nothing at all, because no name in that sentence sounds like a place where personal data lives.

It is the most reliable gap in a small SaaS privacy programme, and it closes with a conversation rather than a control: walk the request path with whoever owns it and write down every service it touches. ComplyDog gives you a compliance portal on your own domain covering your DPA, your subprocessor list — infrastructure included — your data subject request intake and your security page. It will not read your logs. It will mean the list exists somewhere other than in one engineer's head.