
The European Union (EU) has led the evolution of privacy regulation requirements through the General Data Protection Regulation (GDPR). When utilizing Esri products our company typically operates as the Processor of the information and our customers the Controller. We provide our privacy commitment as a Processor within our Data Processing Addendum as well as within our Product Privacy Statement Supplement.
These Esri resources are available below as well as privacy guidance concerning the usage of our products and services, such as handling location sharing privacy demands as well as addressing data sovereignty concerns. We also are monitoring evolving privacy regulations around the usage of Artificial Intelligence (AI) and incorporating appropriate privacy mechanisms for our offerings through our internal Advancing Trustworthy AI initiative.
Regional Hosting & EU Data Sovereignty
ArcGIS Online supports regional data hosting, which allows customers to select the hosting location for their organization's hosted geospatial data (features, tiles, data files, and web maps). Regional hosting is selected at purchase and cannot be changed after purchase.
Some organization information and certain services may operate outside the selected region (for example, certain organization information and location-based services are operated from the United States). For EU customers, Esri's ISO 27001:2022 certification applies to in-scope services in the EU regional hosting location.
See the Regional Hosting page for more information on in-region vs. out-of-region considerations, Esri's ISO 27001 certification, Esri's Certified Services, and common deployment options for stricter sovereignty and localization needs.
Resources
- Esri GDPR Commitment (Public Trust Center).
- ArcGIS Online DPA (Public Trust Center document).
- Esri Product Privacy Statement Supplement (Public).
- ArcGIS Location Sharing Best Practices (Public Trust Center document).
- ArcGIS Data Sovereignty (Public Trust Center slides).
- EU-U.S. Data Privacy Framework (DPF) (Public Trust Center).