Home Blog Is Zapier GDPR Compliant? DPA, Transfers, Subprocessors

GDPR

Is Zapier GDPR Compliant? DPA, Transfers, Subprocessors

Posted by Kevin Yun|August 19, 2026

Zapier provides the processor-side contract GDPR requires, and unusually it will give you a signed copy of it. Its data processing addendum is already incorporated into its Terms of Service, so nothing needs signing — but if you need a standalone executed copy for your records, Zapier lets you generate one electronically. Its addendum relies on the EU-US Data Privacy Framework for transfers, with Standard Contractual Clauses behind it as a fallback.

This article covers how to get that signed copy, how the transfer position is structured, the subprocessor notice window, and the question that matters most and gets asked least: what your zaps are actually moving, and to whom.

The DPA Is Automatic, And A Signed Copy Is Self-Serve

Zapier's addendum lives at zapier.com/legal/data-processing-addendum. The version live when we checked, on 7 August 2026, was updated 1 April 2026 and effective 7 April 2026.

Zapier's own wording is that because its Terms of Service already incorporate the DPA, you do not need to sign a separate copy. Then it does something most vendors in this cluster do not: it states that if you need a standalone copy for your records or other compliance purposes, you can generate an electronically signed one. Zapier documents the flow — two emails from Zapier Dropbox Sign, the first requesting signature, the second confirming and carrying a fully signed PDF.

If you have ever lost a week to a buyer who would not accept "it is in the terms," that is the feature to know about. It costs nothing and it produces the artefact procurement asks for. Note the flip side, also stated by Zapier: it cannot sign DPAs issued by other companies, so if your customer sends you their paper expecting you to flow it down, that is not a route Zapier offers.

Worth knowing on the same theme: Zapier states it has appointed EU and UK representatives, which is the Article 27 mechanism that gives European individuals and supervisory authorities a contactable point inside their own jurisdiction.

Transfers: The Data Privacy Framework, With SCCs Behind It

Zapier states that it has certified compliance with the EU-US Data Privacy Framework, the UK Extension and the Swiss-US Framework, and points readers to the Data Privacy Framework Program participant list to confirm it — advice worth taking, since certification is a status that can lapse and the register is public.

The structure of the addendum is the interesting part. Clause 10.2.1 uses the Data Privacy Framework as the primary route for receiving European data in the US. Clause 10.2.2 then provides that if the Framework is invalidated, or does not cover a particular transfer, the applicable Standard Contractual Clauses are incorporated by reference automatically — controller-to-processor where Zapier acts as your processor, processor-to-processor where it acts as your subprocessor, plus the Swiss amendments, the UK Addendum, and Brazilian clauses for LGPD transfers.

That is a belt-and-braces design and it is worth understanding rather than skimming, because the Framework's durability has been questioned since it was adopted. A vendor whose transfer position collapses if the Framework falls is a vendor with a problem. One with pre-agreed fallback clauses is not. When you write your transfer impact assessment, the fallback structure is the fact to record.

Zapier's published transfer documentation states that it stores and processes personal data in the United States, and that data is also stored with its subprocessors. Its addendum contemplates processing in the US and other jurisdictions where Zapier and its subprocessors operate. If you have seen claims about EU data residency options, treat them as something to confirm directly with Zapier for your plan and get in writing, rather than as an established fact.

Subprocessors And The Fourteen-Day Window

Zapier maintains a subprocessors page listing each subprocessor and the locations where processing happens, and offers change notifications through its trust centre.

The current addendum sets out the mechanics at clauses 9.4 and 9.5: Zapier gives fourteen days' advance written notice of an update to the subprocessor list, by email, posting, portal notification or other reasonable means, and you may notify Zapier within fourteen days of that notice that you do not consent, on reasonable data protection grounds, after which the parties discuss the concerns in good faith.

One caution that applies to any vendor and bit us while researching this article. Older copies of Zapier's addendum are still findable and still hosted, and they set the objection window at ten business days rather than fourteen days. Ten business days and fourteen calendar days are different periods, and the older documents are not the current agreement. Always read the version on the live legal page and record its effective date — our guide to subprocessor management covers building that check into a routine.

What Zapier Is In Your Chain, And What It Is Not

Under a normal deployment you are the controller and Zapier is the processor, and its documentation describes processing personal data governed by European law on behalf of its customers. Where you are yourself a processor for your own customers, Zapier is your subprocessor — its addendum explicitly contemplates that arrangement in its transfer clauses.

That allocation carries the usual consequence for data subject requests: as controller, responding is your obligation, and the operational work of finding, exporting and deleting one person's data across your zaps and their destinations falls to you. Check the request-handling clause in the current version of the addendum rather than an older copy, for the reason set out above.

The Part Nobody Reads: A Zap Is A Transfer

Here is the thing that makes Zapier different from every other tool in this cluster, and it has nothing to do with Zapier's paperwork.

Zapier is not primarily a place where data rests. It is a mechanism for moving data between other people's systems. Every zap you build is a data flow from one processor to another, created by someone in your organisation, usually in a few minutes, usually without a review.

That has three consequences. Your Article 30 record needs to describe the flows, not the tool — "we use Zapier" says nothing, while "form submissions containing name and email pass from our form provider to our CRM and to a spreadsheet" describes a processing activity. Zapier's DPA covers Zapier's leg of the journey and does nothing for the destination, so a zap that drops personal data into a service you have no DPA with has created a gap that Zapier's compliance cannot close. And zaps built by whoever needed them accumulate: the person who built it leaves, the zap keeps running, and personal data keeps arriving somewhere nobody is reviewing.

Auditing your zaps is the single highest-value hour in this article, and your record of processing activities is where the results belong.

Common Mistakes With Zapier And GDPR

Not generating the signed copy. Zapier will produce an electronically signed standalone DPA on request. Teams spend days arguing that incorporation by reference is sufficient when a two-minute self-serve flow ends the conversation.

Reading an old version of the addendum. Superseded copies remain online and set a different subprocessor objection period. Read the version on the live legal page and record its effective date.

Documenting the tool instead of the flows. "We use Zapier" is not an entry in a processing record. Each zap moves specified categories of data between named systems, and that is the thing to describe.

Assuming Zapier's DPA covers the destination. It governs Zapier's processing. If a zap delivers personal data to a service you have no agreement with, that gap is yours.

Leaving orphaned zaps running. Automations outlive the people who built them. Review who owns each one and switch off the ones nobody can justify.

FAQ

Do I need to sign a DPA with Zapier?

No. Zapier states that its Terms of Service already incorporate its data processing addendum, so no separate signature is required. If you need a standalone executed copy for your records or for a customer's procurement process, Zapier lets you generate an electronically signed version, delivered as a signed PDF by email.

Does Zapier rely on the Data Privacy Framework or Standard Contractual Clauses?

Both, in a defined order. Zapier states it has certified to the EU-US Data Privacy Framework, the UK Extension and the Swiss-US Framework, and uses that as the primary route. Its addendum then incorporates the applicable Standard Contractual Clauses automatically if the Framework is invalidated or does not cover a given transfer.

How much notice does Zapier give before adding a subprocessor?

The current addendum provides fourteen days' advance written notice of an update to the subprocessor list, and gives you fourteen days from that notice to say you do not consent on reasonable data protection grounds, after which the parties discuss it in good faith. Older published copies state a different period — check the live version.

Where does Zapier process my data?

Zapier's published transfer documentation states that it stores and processes personal data in the United States and with its subprocessors, and its addendum contemplates the US and other jurisdictions where Zapier and its subprocessors operate. Its subprocessors page lists processing locations. Confirm anything you have heard about regional options directly, for your plan, in writing.

Closing Thought

Automation platforms are the quietest source of compliance drift in a small SaaS, because building a zap does not feel like a decision. Nobody convenes a review to connect a form to a spreadsheet. But every one of those connections is a route by which personal data leaves a system you documented and arrives in one you did not, and they are built by the people furthest from the privacy conversation, which is exactly why they work.

The vendor's paperwork is the easy part, and Zapier's is better than most — it will even hand you a signed copy, the same way ComplyDog hands your customers theirs through DocuSign and Dropbox Sign from a portal on your own domain. What neither can do is tell you what your zaps are moving. That is an hour with the list, and it is overdue on most teams reading this.