Monitor GitLab compliance pages

DevSecOps platform โ€” Git repositories, CI/CD, container registry, security scanning, and GitLab Duo AI. Available as SaaS or self-managed.

GitLab publishes several compliance and legal pages that change over time. Under GDPR Article 28, data controllers using GitLab as a processor must continuously verify that "sufficient guarantees" remain in place โ€” which means tracking changes to these pages as they happen. Below are the 4 most relevant pages, what typically changes on each, and ready-to-paste monitoring prompts.

Monitor all 4 pages automatically

Choose the pages that matter most and get an alert when something meaningful changes. The free plan covers 3 monitors.

Start with 3 free monitors โ†’

Pages to monitor

Sub-processor list

https://handbook.gitlab.com/handbook/legal/subprocessors/ โ†—

Typical change frequency: quarterly

What to monitor

  • GitLab Duo AI provider sub-processors (Anthropic, Google Vertex, custom models)
  • Infrastructure sub-processor changes (Google Cloud primary)
  • Support and professional services partners
  • New sub-processors for Dedicated (single-tenant) customers

Suggested monitoring prompt

Alert me when GitLab updates sub-processors, especially Duo AI providers and Dedicated customer additions. Report name and purpose.

Data Processing Agreement

https://handbook.gitlab.com/handbook/legal/data-processing-agreement/ โ†—

Typical change frequency: yearly

What to monitor

  • Changes to GitLab Duo data handling (training opt-outs, enterprise guarantees)
  • Updates to Dedicated region-specific residency
  • Modifications to GitLab.com SaaS data retention
  • Transfer mechanism changes

Suggested monitoring prompt

Monitor the GitLab DPA for changes to Duo AI data handling, Dedicated residency, SaaS retention, or transfer mechanisms.

Privacy policy

https://about.gitlab.com/privacy/ โ†—

Typical change frequency: yearly

What to monitor

  • Changes to GitLab Duo training and telemetry data
  • Updates to Service Ping data collection
  • New data sharing with business partners
  • Changes to telemetry from self-managed instances

Suggested monitoring prompt

Alert me when GitLab changes Duo AI data practices, Service Ping collection, or self-managed telemetry. Ignore editorial changes.

Status page

https://status.gitlab.com/ โ†—

Typical change frequency: weekly

What to monitor

  • GitLab.com SaaS availability
  • CI/CD runner issues
  • Registry and package availability
  • GitLab Duo feature outages
  • Git operation delays

Suggested monitoring prompt

Alert me on GitLab incidents affecting SaaS availability, CI/CD, registry, Duo, or Git operations. Ignore minor UI issues.

Compliance certifications

SOC 2 Type IIISO 27001FedRAMP Moderate (GitLab Dedicated for Government)GDPR

Data location

Hosting locations: United States (GitLab.com), European Union, APAC (Dedicated)

EU-US Data Privacy Framework: Certified

Related

Ready to start monitoring GitLab?

Set up monitoring free โ†’