Monitored vendor

Datadoghq

datadoghq.com

Record begins
28 Aug 2026
Last change detected
12 Sept 2026
Recent changes
8

Documents monitored

We link to each document at its source. We don't reproduce it here.

What changed

Privacy policy · Read from the capture of 12 Sept 2026

The privacy policy has been reformatted and condensed, with many specific descriptions of data collection, use, sharing, and international transfer safeguards removed or shortened.

  • In "Information We Collect Automatically", the description of cookies and similar technologies was shortened. The previous version listed specific collected data (identifiers, usage data, session information, links clicked, pages visited, mouse movements) and referenced "web beacons and pixels". The new version now states only: "We use cookies and similar technologies to collect information about your interactions with the Datadog Products."
  • In "Information We Collect from Other Sources", the examples under "Other services linked to your account" were removed (previously mentioned Google Apps credentials and single sign-on). The new version simply states "We may collect information about you when you link your Datadog account with other services." Similarly, examples under "Our affiliates" and "Third parties" were shortened, removing specific types of information and the mention of combining information from public sources.
  • In "How We Use Personal Information", the description for research and improvement was shortened. The previous version included "monitor and analyze trends, usage, and other activities in connection with the Datadog Products so that we can continually improve them or create new ones. We may also link or combine information about you with information we get from others to help understand your needs and provide you with new and better services." The new version now says: "to improve and monitor the Datadog Products, and to link or combine information to help understand your needs."
  • In "How We Share Personal Information", the list of service providers and purposes was shortened, removing the detailed examples (e.g., "including to provide hosting services, authentication services, cybersecurity, anti-fraud services, and advertising" becomes "including for hosting, authentication, cybersecurity, anti-fraud, and advertising").
  • In "International Data Transfers" (Section 08), the DPF compliance description was significantly shortened. The previous version included a detailed explanation of the DPF and a reference to the U.S. Department of Commerce's list of participating organizations. The new version condenses this, removing the mention of the Swiss-U.S. DPF separately, the phrase "in reliance on the EU-U.S. DPF and from the United Kingdom...", the reference to the "DPF Principles", the statement about liability for onward transfers, the mention of the Datadog Transfer Impact Assessment, and the statement about disclosure to public authorities for national security or law enforcement.
  • In "International Data Transfers", the previous version had a sentence: "If we transfer your personal data onward to a third party, we will continue to remain liable under the DPF Principles if the information is processed in a manner inconsistent with the DPF Principles." This appears to have been removed entirely.
  • In "International Data Transfers", the previous version had a sentence: "In some cases, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements." This appears to have been removed.
  • In "Supplemental Notice for the United States", the category descriptions under "Categories of Personal Information Collected", "Categories of Personal Information Disclosed for a Business Purpose", and "Categories of Personal Information Shared for Cross-Context Behavioral Advertising" were shortened. Examples like "such as a real name, postal address, unique personal identifier..." were shortened to "such as name, postal address...". The detailed sub-descriptions (e.g., "information regarding your interaction with the Datadog Products") were removed, leaving only the category name or a simplified version.
  • In "Your Choices" (Section 07), the description under "Account information" was shortened: the previous version included "Subject to the terms of their agreements with us, customers may deactivate their accounts by emailing us at help@datadoghq.com, but we may retain certain personal information as necessary to comply with our legal obligations or for legitimate business purposes, such as to resolve disputes or enforce our agreements. We may also retain cached or archived copies of personal information for a certain period." The new version now says: "Customers may deactivate their accounts by emailing us, but we may retain certain personal information as necessary."
  • In "Your Choices" under "Advertising", the email address "help@datadoghq.com" was removed and replaced with "by emailing us". Also, the phrase "such as those about your account or our ongoing business relationship" was removed.
datadoghq.com/legal/privacy

Privacy policy · From before we started monitoring · 12 Mar 2026

The policy appears to update its effective date and add new provisions regarding advertising measurement, a commitment not to process for materially different purposes without opt-out, an affirmative statement that personal information is not shared except as listed, and expands the scope of sharing for marketing and analytics.

  • Effective date changed from "January 1, 2026" to "March 12, 2026".
  • New data use added in section 02: "To measure ad performance and attribute conversions effectively. We use information about you, in hashed form, to measure the effectiveness of our advertising campaigns and to improve campaign performance and attribution accuracy."
  • New commitment added at the end of section 02: "We will not process your personal information for purposes materially different from the above without providing you with the opportunity to opt out."
  • New introductory sentence in section 03: "We will not share your personal information with third parties except as follows."
  • Marketing and analytics sharing expanded in section 03: previously "analytics and search-engine providers that assist us in the improvement and optimization of our websites, subject to our Cookie Policy" now reads "analytics, advertising, and search-engine providers that assist us in measuring, improving, and optimizing our marketing campaigns and websites. Where such sharing involves the use of cookies or similar tracking technologies, it is further governed by our Cookie Policy." This explicitly adds advertising providers and extends scope to marketing campaigns.
datadoghq.com/legal/privacy

Privacy policy · From before we started monitoring · 1 Jan 2026

The policy has been updated with several substantive changes, including a new effective date, a broadened description of data sharing, the removal of a previous opt-out statement, and minor revisions to the DPF and US rights sections.

  • Effective date changed: The previous version was "Last updated September 3, 2025" at the top; the new version places "Last updated January 1, 2026" at the bottom.
  • Data sharing language broadened: The lead-in to Section 3 changed from "We will not share your personal information with third parties except as follows" to "We may share your personal information as follows," removing the previous limitation.
  • Opt-out statement removed: The sentence "We will not process your personal information for purposes materially different from the above without providing you with the opportunity to opt out" at the end of Section 2 has been deleted.
  • DPF description expanded: The International Data Transfers section now specifies that the UK Extension applies to "the United Kingdom (and Gibraltar)" and adds a reference to "A full list of all participating organizations is available on the U.S. Department of Commerce’s dedicated DPF website."
  • US rights terminology updated: The right previously labeled "Right to nondiscrimination" is now called "Right to nonretaliation" ("You have the right not to be retaliated against for exercising any of your above rights").
  • Formatting: Extra blank lines have been added, but these do not affect meaning.
datadoghq.com/legal/privacy/2026-01-01

Privacy policy · From before we started monitoring · 3 Sept 2025

The policy has been updated to add a commitment not to use personal information for materially different purposes without an opt-out, a commitment not to share personal information with third parties except as listed, and to expand the Data Privacy Framework (DPF) compliance language.

  • Last updated date changed from November 5, 2024 to September 3, 2025.
  • New commitment on processing purposes: Added the sentence "We will not process your personal information for purposes materially different from the above without providing you with the opportunity to opt out." (Section 02)
  • New commitment on sharing: Added the introductory sentence "We will not share your personal information with third parties except as follows." (Section 03)
  • DPF compliance language expanded: The new version now states that if there is any conflict between the policy and the DPF Principles, the Principles shall govern. It also now includes a direct link to the DPF certification page: https://www.dataprivacyframework.gov. The certification statements for EU/UK and Switzerland are now separately listed rather than combined.
datadoghq.com/legal/privacy/2025-09-03

DPA · From before we started monitoring · 3 Jan 2024

The DPA has been updated to remove the separate treatment of Account Data, simplify the data transfer provisions, and add a new appendix for CCPA compliance. Key changes:

  • Removed dual role for Account Data: The previous version treated Datadog as an independent Controller of Account Data; the new version no longer distinguishes Account Data roles and instead states Datadog is a Processor of Customer Personal Data only. The definition of "Account Data" is deleted.
  • Simplified data transfer section: Added a preliminary statement that transfers covered by an adequacy decision do not require a separate mechanism. Removed Module One (Controller-to-Controller) from the SCCs, so only Modules Two and Three apply. The new wording: "The parties acknowledge that transfers of Customer Personal Data to Datadog that are subject to an applicable adequacy decision do not require a separate approved transfer mechanism."
  • Added Appendix C – CCPA Terms: A new appendix imposes service-provider obligations under the California Consumer Privacy Act, including prohibitions on selling or sharing Covered Information and a requirement to assist with consumer requests. The CCPA is also referenced in Section 1.2 (Processing Details) as part of the Documented Instructions.
  • Consolidated Appendix A: Previously split into separate descriptions for Account Data and Customer Personal Data; now a single unified description of data subjects, categories, and purposes. The Data exporter's role is now "Processor or Controller" (was "Processor or Controller with respect to Customer Personal Data; Controller with respect to Account Data"), and the Data importer's role is now "Processor" (was "Processor with respect to Customer Personal Data; Controller with respect to Account Data").
  • Minor rewording in Subprocessors section: Changed "notifications of updates to the Subprocessors List" to "notifications of new Subprocessors". The objection clause now says "Customer may object to a new Subprocessor" instead of "the new Subprocessor".
  • Security and confidentiality scope narrowed: Previously covered "Customer Personal Data and Account Data"; now only "Customer Personal Data".
  • Updated definitions: "Customer Data" now includes data submitted "by or on behalf of Customer". "Customer Personal Data" is now "Personal Data contained within Customer Data" (was "Customer Data comprising Personal Data").
  • Effective date changed: From "February 28, 2023" to "January 3, 2024".
  • Minor text updates: "Master Subscription Agreement" changed to "Subscription Agreement"; "Datadog may make changes" changed to "Datadog may change"; and other small wording adjustments.
datadoghq.com/legal/data-processing-addendum

DPA · From before we started monitoring · 28 Feb 2023

The DPA has been significantly restructured and expanded, notably by adding a new 'Modifications' section (Section 13) that permits Datadog to unilaterally amend the DPA under certain conditions, removing the 'Counterparts' section, and incorporating detailed appendices (Appendix A on data transfer details and Appendix B on technical and organizational measures) that were previously only referenced as schedules. Several obligations have also been reworded: the breach notification timeline changed from 'within 48 hours' to 'without undue delay' (Section 7.1); the deletion process now refers to 'Customer Personal Data' instead of 'Customer Data' (Section 6); the audit section now requires mutual agreement on 'time, scope, and duration' rather than 'participants, schedule, scope, and methodology' (Section 8.2(c)); and the definition of 'Data Subject Request' is now explicitly defined (Section 14). The effective date is no longer listed; instead, the DPA is effective as of the Agreement's effective date.

datadoghq.com/legal/data-processing-addendum/2023-02-28

DPA · From before we started monitoring · 21 Jun 2022

This DPA was updated to broaden its scope from EEA-specific to global, expand transfer mechanisms to cover the UK and Switzerland, and revise procedures for subprocessors, data subject requests, breach notifications, and audits.

  • Effective date changed: from September 24, 2021 to June 21, 2022.
  • Scope broadened: the DPA now applies to Datadog's 'Processing of Personal Data in providing the Services' (instead of 'provision of access to the Services'), and the restriction to 'EEA' is removed (the DPA now references 'Applicable Laws' generally).
  • Customer responsibilities expanded: a new prohibition on submitting 'similarly sensitive Personal Data (defined in Data Protection Laws)' is added alongside special categories and criminal data.
  • Security measures now also cover Account Data: the provision that 'no such changes will reduce the overall level of protection' now applies to both Customer Personal Data and Account Data (previously only Customer Personal Data).
  • Subprocessor notifications and objections modified: the mechanism for notifying new subprocessors changes from email subscription to an update on the Subprocessors List; the objection period is extended from 14 to 15 days; the resolution period after an objection is shortened from 30 to 15 days; the right to use a new subprocessor while objections are pending is removed.
  • Data subject request handling: the DPA now requires Datadog to 'promptly notify Customer of the Data Subject Request' (previously only advised the data subject to contact Customer); assistance to Customer is now qualified as 'where required by Data Protection Laws' (previously unconditional).
  • Breach notification content and method: the DPA now specifies that the notification must describe the nature, categories, numbers, Datadog's measures, recommended Customer measures, and a point of contact; notification methods are limited to email to the signature-page address or under the Agreement (removing posting in the Services and subscription email); Customer's obligation to give advance copies of public notices is now subject to 'reasonable efforts' and an exception for legal requirements.
  • Audit rights restricted: Customer's audit right is now conditioned on being 'required by Data Protection Laws' and only if Datadog's compliance cannot be demonstrated by less burdensome means (e.g., audit reports); the previous exception for a breach-triggered audit is removed; reimbursement is now at 'reasonable' rates instead of 'then-current' rates; the prohibition on accessing hosting sites is removed.
  • Impact assessments and assistance narrowed: assistance is now provided only 'when required by Data Protection Laws' and 'only to the extent that Customer does not otherwise have access to the relevant information'.
  • Transfer mechanism section significantly expanded: the new version incorporates the SCCs and UK Transfer Addendum with specific module selections, governing law (Ireland), and detailed annex completions; it explicitly covers transfers from Switzerland and the UK.
  • New conflict clause added: Section 15 establishes an order of precedence: SCCs, then DPA, then Agreement.
  • Definitions revised and added: 'Data Protection Laws' and 'European Data Protection Laws' are newly defined; 'Personal Data Breach' is now defined specifically rather than by reference to the GDPR; 'Restricted Transfer', 'SCCs', 'UK Transfer Addendum' are added; several terms (e.g., 'AUP', 'Documentation', 'Order') are used in the body but no longer defined in the definitions section.
datadoghq.com/legal/data-processing-addendum/2022-06-21

Get notified when Datadoghq changes this

We check the document on a schedule and email a plain-language summary of what moved.

Start monitoring free