Monitor GitHub compliance pages

Microsoft-owned code hosting and collaboration platform โ€” Git repositories, Actions CI/CD, Codespaces, Copilot AI, and Advanced Security.

GitHub publishes several compliance and legal pages that change over time. Under GDPR Article 28, data controllers using GitHub as a processor must continuously verify that "sufficient guarantees" remain in place โ€” which means tracking changes to these pages as they happen. Below are the 4 most relevant pages, what typically changes on each, and ready-to-paste monitoring prompts.

Monitor all 4 pages automatically

Choose the pages that matter most and get an alert when something meaningful changes. The free plan covers 3 monitors.

Start with 3 free monitors โ†’

Pages to monitor

Sub-processor list

https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors โ†—

Typical change frequency: quarterly

What to monitor

  • Copilot AI model provider sub-processors (OpenAI primary, evolving)
  • Microsoft affiliate sub-processor additions
  • Changes to support, customer success, and training partners
  • New sub-processors for enterprise features (Advanced Security, Enterprise Cloud)

Suggested monitoring prompt

Alert me when GitHub updates sub-processors, especially Copilot AI providers and Microsoft affiliate additions. Report name and purpose.

Data Processing Agreement

https://github.com/customer-terms/github-data-protection-agreement โ†—

Typical change frequency: yearly

What to monitor

  • Changes to Copilot data handling (training opt-outs, telemetry)
  • Updates to Enterprise Cloud data residency options
  • Modifications to audit log retention
  • Transfer mechanism changes (post-Microsoft acquisition consolidation)

Suggested monitoring prompt

Monitor the GitHub DPA for changes to Copilot data handling, enterprise residency, audit log retention, or transfer mechanisms.

Privacy policy

https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement โ†—

Typical change frequency: yearly

What to monitor

  • Changes to Copilot training data policies (public code, private repos)
  • Updates to cross-Microsoft data sharing
  • New AI features and their data practices
  • Changes to telemetry from GitHub Desktop, CLI, and editors

Suggested monitoring prompt

Alert me when GitHub changes Copilot training policies, Microsoft data sharing, or client telemetry. These are contentious areas โ€” report in detail.

Status page

https://www.githubstatus.com/ โ†—

Typical change frequency: weekly

What to monitor

  • Git operation incidents (push, pull, clone)
  • Actions CI/CD delays and outages
  • API rate limiting or availability issues
  • Copilot service disruptions
  • Codespaces incidents

Suggested monitoring prompt

Alert me on GitHub incidents affecting Git operations, Actions, API, Copilot, or Codespaces. Ignore minor UI issues.

Compliance certifications

SOC 2 Type IIISO 27001ISO 27017ISO 27018FedRAMP (GitHub Enterprise Cloud)GDPR

Data location

Hosting locations: United States, European Union (Enterprise data residency)

EU-US Data Privacy Framework: Certified

Related

Ready to start monitoring GitHub?

Set up monitoring free โ†’