RoPA Pilot

CircleCI and GDPR: hosting, non-EU transfer and DPA

CircleCI is published by Circle Internet Services, Inc.. If your teams use it, it is a processor within the meaning of Article 28 GDPR and it must appear in your record of processing activities.

Vendor (processor)
Circle Internet Services, Inc.
Headquarters
United States
EU hosting
Non-EU
Non-EU transfer
Yes
Transfer mechanism
United States — EU-US DPF
Category
Development
Typical personal data
identity, technical data, content
Detected domains
app.circleci.com, circleci.com

Does using CircleCI mean a non-EU transfer?

Yes. Circle Internet Services, Inc. is a US vendor listed under the EU-US Data Privacy Framework: the transfer is lawful as long as the certification is active — check it on dataprivacyframework.gov and record the date of your check.

What to write in your Article 30 record

Purpose: Development. Categories of personal data: identity, technical data, content. Recipient: Circle Internet Services, Inc.. Transfer: United States — EU-US DPF. Retention: aligned with the contract or the account lifetime, whichever is shorter.

How RoPA Pilot handles it

RoPA Pilot detects CircleCI from the domain name of the tab — never from page content — and pre-fills the record above in one click. The extension flags the record if the transfer mechanism is missing or unverified.

Indicative information from public sources. The transfer mechanism actually applicable to you is the one written in your contract.