Is Cursor GDPR compliant?
YesAnysphere · Coding
Yes. Anysphere offers a Data Processing Agreement (DPA) for Cursor, the baseline GDPR control when a vendor processes personal data on your behalf.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Data Processing Agreement
- Confirmed
- Anysphere publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
- EU data residency
- Not verified
- No EU-residency option was confirmed in the sources reviewed for this profile.
- Default data training
- Opt-out required
- For free/Pro individual users Privacy Mode is opt-in (off by default), and with it off Cursor states it 'may use and store codebase data, prompts, editor actions, code snippets, and other code data and actions to improve our AI features and train our models.'
- Business-tier training
- No by default
- Privacy Mode is enforced/on by default for Team and Enterprise plans, so code is not used for training by Cursor or its model-provider subprocessors.
Practical risk: On the free/Pro tier Privacy Mode is opt-in and OFF by default, so an at-work user who does not enable it has their code, prompts and editor actions stored and used to train Cursor's models.
How to make a decision
Check the precise account tier, written contract and intended data before approving Cursor. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Cursor
Is Cursor HIPAA compliant?Is Cursor SOC 2 compliant?Is Cursor ISO 27001 certified?Does Cursor train on your data?
See the full Cursor risk profile, with every data-handling fact and its source, or browse all rated AI tools.