The short answer
HighLevel says it complies with the GDPR as a data processor. Its Data Processing Addendum covers the EU and UK GDPR, uses standard contractual clauses for transfers to the US and promises breach notice within 72 hours, and HighLevel is certified under the EU-U.S. Data Privacy Framework. It also says plainly that using its product alone does not make you GDPR compliant. That part is yours.
Controller and processor: who does what
HighLevel's GDPR help article puts its customer in the controller role and HighLevel in the processor role. You decide what personal data goes into the platform, why, and on what legal basis, and you answer to your contacts for it. HighLevel stores and manages that data on your instructions and says it will not use it for its own purposes. The ICO describes a controller as the party that determines the purposes and means of processing and must be able to demonstrate compliance, which is why an agency cannot hand its GDPR duties to the software it uses.
What HighLevel's paperwork covers
The Data Processing Addendum, last updated July 2026, is incorporated into HighLevel's Terms of Service, so it applies to every customer, and where the two conflict the addendum wins. HighLevel's GDPR article says the standard contractual clauses are how customers can lawfully send personal data to it in the US. The main commitments, as written in HighLevel's own documents, are listed below; read the full addendum before relying on any of them for a client.
- EU 2021 standard contractual clauses, plus the UK Transfer Addendum for UK data
- Notice of a personal data breach without undue delay and within 72 hours
- A published sub-processor list, with a sign-up for change notices
- Certification under the EU-U.S. Data Privacy Framework
- Product infrastructure in the United States, with no customer-set retention periods
Tools for meeting your own duties
HighLevel's consent guide is labeled information, not legal advice, and describes tools rather than a finished setup. Forms, surveys, calendars, order forms and the chat widget can show consent checkboxes and link your privacy policy, and a form consent tick is stored on the contact record. You can record a legal basis for each contact with a custom field and matching tags, set by automation when a form is submitted. Current and former customers can ask HighLevel in writing to delete data. Writing your privacy notice and choosing your legal bases stay with you and, ideally, a data protection professional.
More answers in HighLevel questions. For costs, see GoHighLevel pricing or run the cost calculator.