Webflow users in the EU must be aware of how data protection and data transfer compliance works when using Webflow, particularly involving Webflow’s U.S.-based infrastructure and subcontractors like AWS and Fastly.
1. Webflow and Standard Contractual Clauses (SCCs)
- Webflow uses Standard Contractual Clauses (SCCs) to ensure GDPR-compliant data transfers from the EU to the U.S.
- These SCCs are included in Webflow’s Data Processing Addendum (DPA), available to enterprise and business-tier customers.
- SCCs are legally recognized under GDPR for cross-border data transfers, but their sufficiency depends on assessing the recipient country's legal environment (per Schrems II decision).
2. Subcontractors (AWS, Fastly) and GDPR Compliance
- Under GDPR, subprocessors like AWS and Fastly must also adhere to safeguards equivalent to those offered by SCCs.
- Webflow lists subprocessors transparently and contracts with them using flow-down clauses ensuring SCC-level compliance.
- EU-based users can assert rights indirectly, as Webflow, as the data processor, remains responsible for its subprocessors.
3. EU-specific Hosting or On-Premise Options
- As of now, Webflow does not offer:
- An on-premise version of its platform.
- A hosting option restricted to EU-based servers.
- An EU-based subsidiary that would change the data controller jurisdiction.
- Webflow currently relies on U.S.-centric infrastructure, notably AWS and Fastly with global distributions that include Europe, but data can transit through or be processed in the U.S.
4. Future Possibilities
- Webflow has acknowledged the importance of European privacy compliance and has discussed improvements in handling EU data transfers.
- However, no public roadmap or announcement exists (as of 2024) confirming EU-only hosting or an EU legal entity.
Summary
Webflow users in the EU rely on Standard Contractual Clauses for lawful data transfers, including use of AWS and Fastly as subprocessors. Although EU user rights extend contractually through Webflow to these subprocessors, Webflow does not currently offer EU-only hosting, on-premise deployment, or an EU-based subsidiary. GDPR-conscious users should review the DPA and consider whether SCCs provide sufficient safeguards for their compliance needs.