aivalet.nu, a Swedish guide
🆕 New guide Winningtemp price 2026: how much it costs Read →

HomeProton Pass › GDPR

Is Proton Pass GDPR-safe?

Partly: read the fine print

Proton Pass is a vendor in a country with an EU adequacy decision, but we have not been able to confirm EU data storage as standard. Check where data is actually processed before you put personal data in the tool.

Facts that decide

Vendor jurisdiction EU-approved third country (Proton AG)
EU data storageNo
GDPR terms / DPAStated to be available, verify in your contract
CertificationsISO 27001, SOC 2
CategoryPasswords & security

Full review of Proton Pass →

How to use it more safely

  1. Sign a data processing agreement (DPA) if personal data is processed.
  2. Never enter national IDs or sensitive data, especially here where data leaves the EU.
  3. Check the vendor's sub-processors: AI features often forward data.
  4. Read our GDPR guide for small businesses for the full picture.

Common questions

Does Proton Pass store data inside the EU?

No, Proton Pass has no confirmed EU data storage: data is processed in a third country.

Is Proton Pass covered by the CLOUD Act?

No, Proton Pass is based in a country outside the EU that the European Commission has approved for data transfers (adequacy decision under GDPR Art. 45), and it is not covered by the CLOUD Act through its owner.

What is needed to use Proton Pass in a GDPR-safe way?

Sign a data processing agreement (DPA) if the tool processes personal data on your behalf, minimise the personal data you feed in, and check the vendor's sub-processors. See our DPA guide for the steps.

Our assessment is based on verified data about vendor, storage and certifications (2026). GDPR compliance also depends on how you use the tool. This is guidance, not legal advice. See How we review.