RoPA Pilot

Copper CRM and GDPR: hosting, non-EU transfer and DPA

Copper CRM is published by Copper CRM, Inc.. If your teams use it, it is a processor within the meaning of Article 28 GDPR and it must appear in your record of processing activities.

Vendor (processor)
Copper CRM, Inc.
Headquarters
United States
EU hosting
Non-EU
Non-EU transfer
Yes
Transfer mechanism
Standard contractual clauses
Category
CRM / Sales
Typical personal data
identity, contact details, professional data
Detected domains
app.copper.com, copper.com

Does using Copper CRM mean a non-EU transfer?

Yes. The transfer relies on Standard Contractual Clauses. You must keep the signed SCC and, in principle, a transfer impact assessment.

What to write in your Article 30 record

Purpose: CRM / Sales. Categories of personal data: identity, contact details, professional data. Recipient: Copper CRM, Inc.. Transfer: Standard contractual clauses. Retention: aligned with the contract or the account lifetime, whichever is shorter.

How RoPA Pilot handles it

RoPA Pilot detects Copper CRM from the domain name of the tab — never from page content — and pre-fills the record above in one click. The extension flags the record if the transfer mechanism is missing or unverified.

Indicative information from public sources. The transfer mechanism actually applicable to you is the one written in your contract.