Is Box GDPR compliant? What universities should check
Box is used by a number of universities and research groups as a central file platform, often because of its sharing model and its Box Zones data residency option. This page sets out what Box publicly documents about where content is stored, its contract and transfer tools, shared links, AI features and encryption keys, and what that means for research data.
Short answer
Box, Inc. is a US company that acts as processor for content customers upload. It offers a DPA with the EU and UK Standard Contractual Clauses, holds approved processor and controller Binding Corporate Rules for the EU and UK, and states that it complies with the EU-US Data Privacy Framework for business accounts. Box Zones lets an institution store content in a chosen region, including European options; for its newer and recently upgraded Zones Box says uploads, downloads and encryption keys are handled in that Zone, while Box says some other processing still takes place in the US. Box AI relies on US model providers, and Box says it does not train on customer content without explicit approval. For research data, the deciding factors are Zones configuration, shared link policy and whether customer-managed keys are needed.
What Box documents publicly
The table summarises Box's privacy notice, regional notice, GDPR page, subprocessor list, Zones documentation, AI pages and trust centre, read on 7 October 2026. It applies to Box business and enterprise accounts; individual accounts are outside the scope of this page.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and role | Documented Box, Inc. and its subsidiaries; the privacy notice (effective 5 October 2026) says Box acts as processor of personal information uploaded as customer content. A data protection officer is reachable at dpo@box.com. A named EU representative was not found in the notice (checked 7 October 2026). | Privacy notice [1] |
| Where data is stored and processed | Configuration-dependent Box says Zones spans ten regions, with Switzerland, Singapore and Israel added recently, and its support documentation refers to a France Zone and other EU Zones. For the new Zones and for France and Canada (from September 2026), Box says uploads and downloads go to Zone endpoints, files are encrypted and decrypted inside the Zone with keys managed there, and most previews and conversions stay in region. Box states that "other processing activities currently occur in the U.S." | Box Zones [2], Zones update [3], Zones overview [4] |
| Plan requirements for Zones | Plan-dependent Box's Multizones documentation lists more than 10 seats deployed and active Box Consulting and Premier Services packages as requirements. Box describes Zones as an add-on for Enterprise Plus and Enterprise Advanced, and says one price covers all Zones. | Multizones article [5], [3], [2] |
| Data processing agreement | Documented Box offers a standardised DPA with updated EU and UK SCCs, which customers request through a portal linked from its GDPR page. | GDPR page [6] |
| International transfers (BCRs, SCCs, DPF) | Documented Box holds EU and UK processor and controller BCRs, first approved in 2016, makes SCCs available to all customers, and says it complies with the EU-US DPF for data processed on behalf of organisations in business accounts (DPF status read from Box's privacy notice; the official DPF list API returned an error for every query on the check date). | Regional notice [7], [6], [1] |
| Subprocessors | Documented List updated 4 September 2026: Amazon Web Services, Google, IBM and Microsoft for infrastructure (US, or other regions if the customer selects them); TaskUs (Philippines) and Zendesk for support; OpenAI and Anthropic (US) for AI and machine learning; and a further AI entity listed as SpaceXAI LLC (US), effective 5 October 2026 unless the customer's agreement says otherwise. Customers can subscribe to change notifications. | Subprocessors [8] |
| AI features and training | Documented Box says neither Box nor its AI providers will train models on customer content without explicit authorisation, that providers delete queries and results once a response is returned, that AI respects existing permissions, and that customers can decide whether AI is applied to their content. | [1], Box AI principles [9], Box AI FAQ [10] |
| Shared links | Documented Links can be open to people with the link, people in the company, or collaborators only. Links can be set to expire, and changing an expiry date depends on the Box admin enabling it; disabled links are deleted and cannot be restored. | Shared links FAQ [11] |
| Customer-managed keys | Add-on Box KeySafe lets customers manage keys in AWS KMS with CloudHSM or Google Cloud HSM; Box says it can never see or access those keys. | KeySafe [12] |
| Security certifications | Documented Box lists ISO 27001, 27017, 27018 and 27701, SOC 1, SOC 2 Type II and SOC 3, Germany's C5 and France's HDS, among others. | Trust centre [13] |
Box deserves credit for two things that are not common among US storage vendors: approved processor BCRs, which give a transfer tool reviewed by European supervisory authorities rather than only standard clauses, and a data residency option in which file encryption keys stay in the chosen region. Both are relevant to the transfer analysis a university has to document.
What this means for a university
Validemic's analysis
Zones narrows, but does not remove, US processing. With an EU Zone, file content at rest stays in Europe, and for the Zones Box has upgraded it says keys stay there too, which is the main concern for most research data. Box is clear that other processing activities currently occur in the US [3], without listing them in that article. A transfer impact assessment should therefore cover metadata and AI use as well as files, and the DPA, BCRs and DPF statement together form the transfer basis.
Ownership decides the Zone. Box explains that content follows the owner of the folder, not the person who uploads it [5]. If a researcher stores files in a folder owned by a collaborator at another institution on a different Zone, those files live in that collaborator's Zone. For multi-site projects, agree who owns the project folders before data arrives.
Research data and links. Special category data under Article 9 GDPR [14] and pseudonymised datasets with key files should not be reachable by an open link. Restricting links to company or collaborator-only for sensitive folders, with expiry enabled, is the obvious control. External researchers then need Box accounts, which also gives you an access record.
AI on sensitive folders. When Box AI is used, relevant content goes to model providers [10]. The AI-specific entries on Box's subprocessor list (OpenAI, Anthropic and SpaceXAI LLC) are located in the US, and the infrastructure providers, which also list AI services, are in the US or other customer-selected regions [8]. Box's no-training and no-retention commitments are meaningful, but for interview transcripts or health data a university may still decide to keep AI off for those folders or enterprise-wide until it has assessed the use.
Keys. KeySafe [12] answers the same concern as Microsoft's Double Key Encryption: limiting what the vendor itself can access. It is an add-on, so it belongs in the procurement discussion rather than as an afterthought.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Box before approving it for research data
- Which Box entity signs our agreement and DPA, and which version of the SCCs and BCRs applies?
- Which Zone will hold our content, and which data categories (metadata, search index, audit logs, AI prompts) are processed outside it?
- Do our licences include the Consulting and Premier Services packages that Multizones requires?
- Can administrators disable Box AI per folder or group, and which model providers would process our content?
- How are we notified of new subprocessors, such as the AI provider added on 5 October 2026, and how do we object?
- Can we prevent open shared links enterprise-wide while allowing collaborator-only links for partners?
- Is KeySafe needed for our most sensitive projects, and what does it cost?
- Can we obtain the current SOC 2 Type II report and ISO certificates under NDA?
The EU AI Act angle
Box is a content platform, and Box AI features (summaries, questions over documents, metadata extraction) are general productivity functions rather than the education uses listed as high-risk in Annex III of the AI Act [15]. The obligation that applies today is AI literacy: Article 4, as amended by Regulation (EU) 2026/1744, requires deployers to take measures to support the AI literacy of staff using AI systems [16]. High-risk obligations for Annex III systems apply from 2 December 2027 [17].
Sources
- Box Privacy Notice (effective 5 October 2026), retrieved 7 October 2026
- Box Zones, retrieved 7 October 2026
- New Box Zones in Switzerland, Singapore and Israel with expanded in-region processing for France and Canada, Box Support, retrieved 7 October 2026
- Box Zones overview, Box Support, retrieved 7 October 2026
- Box Multizones, Box Support, retrieved 7 October 2026
- Box and the GDPR, retrieved 7 October 2026
- Box Regional Information, retrieved 7 October 2026
- Box Subprocessors (updated 4 September 2026), retrieved 7 October 2026
- Box AI Principles (effective 4 November 2025), retrieved 7 October 2026
- Box AI Frequently Asked Questions, Box Support, retrieved 7 October 2026
- Shared Links Frequently Asked Questions, Box Support, retrieved 7 October 2026
- Box KeySafe, retrieved 7 October 2026
- Box Trust Center, retrieved 7 October 2026
- Regulation (EU) 2016/679 (GDPR), Article 9, text read from the Publications Office copy, retrieved 7 October 2026
- AI Act Annex III, AI Act Service Desk, retrieved 7 October 2026
- AI Act Article 4: AI literacy, AI Act Service Desk (as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
- AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
About this page
We read Box's privacy notice, regional notice, GDPR page, subprocessor list, Zones pages and support articles, AI principles and AI model documentation, shared links FAQ, KeySafe page and trust centre, and the relevant EU legal texts on 7 October 2026. Statements about Box come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Box complies with the GDPR. If you spot an error or Box has updated a document, please contact us and we will correct it.
Frequently asked questions
Is Box GDPR compliant?
No tool is GDPR compliant on its own. Box states that it acts as processor for customer content, offers a DPA with the EU and UK SCCs, holds approved processor and controller Binding Corporate Rules and complies with the EU-US Data Privacy Framework for business accounts. Whether a university's use complies depends on its contract, Zones configuration, sharing settings and the data it stores.
Can Box store data in the EU?
Yes, through Box Zones. Box says Zones covers ten regions and lets administrators assign where content is stored. For its three new Zones and for France and Canada from September 2026, Box says file uploads, downloads, encryption with in-Zone keys and most previews happen in region, but Box states that other processing activities currently occur in the US. Box's Multizones documentation lists Box Consulting and Premier Services packages as requirements.
Does Box AI train on university files?
Box says it will not train AI models on customer content without explicit authorisation, and that its model providers delete queries and results once a response is returned. Box's subprocessor list includes OpenAI and Anthropic, both in the US, for AI and machine learning, and Box states that customers can decide whether AI is applied to their content.
Can Box links be opened by anyone?
Box shared links can be set to people with the link, people in your company, or invited collaborators only. Links can be given an expiry date, and Box says disabled links are deleted and cannot be restored.
Can a university hold its own encryption keys in Box?
Box KeySafe is an add-on that lets customers manage their own keys in AWS KMS with CloudHSM or Google Cloud HSM. Box says it can never see or access the customer's keys. Whether it is needed depends on the sensitivity of the data and the university's risk assessment.