Accessibility StatementSkip to main content
SUPPORT
eero home
  • Our Products
  • Why eero
  • Shop on Amazon

Legal Page

Terms of Service
Privacy Notice
Limited Warranty
Safety & Compliance
eero Subscription Terms of Service
Return & refund policy
Sales tax information
Trademark usage & policy
Open Source Compliance
Authorized reseller policy
Additional State-Specific Privacy Disclosures
eero Dynamic DNS Service
eero for Business wifi notices
Disclaimers
eero Subscription Bundle Offer Terms
Technical Support Terms
Data protection terms
Network management statement

Legal

  • Country
  • País
  • Pays
  • Land
  • Nazione
  • 国
  • دولة

Data protection terms

eero Data Protection Terms

Last Updated: 9-14-2026 – v1.0

These Data Protection Terms (these "Terms") apply where eero LLC ("eero") has agreed with an entity ("you" or "your") to provide access to eero Products, eero Software, and related eero Services pursuant to an applicable agreement referencing these Terms (the "Agreement"). Capitalized terms not otherwise defined have the meanings given to them in the Agreement. eero may update these Terms from time to time at its sole discretion or as otherwise set forth in the Agreement, provided that no update will materially diminish the privacy or security of Personal Information. Your continued use of or access to eero Products, eero Software, and eero Services after modifications become effective constitutes acceptance of the modified Terms.

During the Term, through your Deployment and use of the Products and use of and access to the eero Software, you may have access to or receive eero Service Data. You also may share with eero certain data of your customers, including Independently Collected Personal Information, or in respect of your Internal Products use the Products to Process data. Accordingly, the Parties agree as follows.

Section 1   eero Obligations

eero will implement reasonable and appropriate measures designed to secure eero Service Data (including eero Personal Information), and Independently Collected Personal Information (if applicable), against accidental or unlawful loss, access or disclosure. Safeguards include physical, organizational, and technical measures appropriate to the sensitivity of the applicable data. eero will comply with Applicable Law and the eero Privacy Notice (available at www.eero.com/legal/privacy) with respect to: (a) any eero Personal Information that eero shares with you under the Agreement; and (b) any Independently Collected Personal Information that you share with eero under the Agreement.

Section 2   Your Obligations

2.1  Permitted Uses of eero Data

You will Process eero Data solely in support of the authorized purposes below and in accordance with your Deployment Type(s) (as defined in the Agreement), and only to the extent necessary to achieve such authorized purpose:

(a)  End-User Networks.  If your authorized Deployment Type includes End-User Networks, you will Process eero Service Data solely for the following purposes: (A) billing of and account administration in respect of End-Users; (B) troubleshooting and providing technical support to End-Users with issues concerning Deployed Products and your Connectivity and Managed Services, including incorporating eero Service Data into applications for your internal use via your Personnel to provide such support; and (C) providing End-Users with enhanced Connectivity and Managed Services.

(b) Enterprise Networks. If your authorized Deployment Type includes Enterprise Client Networks, you may Process eero Service Data (including any eero Personal Information) solely for the following purposes: (A) network administration and management on behalf of the applicable Enterprise Client; (B) providing managed wifi services to the Enterprise Client; (C) troubleshooting and technical support; (D) incorporating eero Service Data into internal Applications you develop, solely for the purpose of delivering managed network services to Enterprise Clients; and (E) such other purposes as expressly authorized in your Agreement.

(c)  Internal Networks.  If your authorized Deployment Type includes Internal Networks, you may Process eero Service Data solely for your own internal business purposes, including network administration, troubleshooting, performance monitoring, and internal operations.

(d)  General Restrictions on eero Data.  Unless expressly authorized in writing under the Agreement, you will not: (A) transfer, rent, barter, trade, sell, loan, lease, or otherwise distribute or make any eero Data available to any third party; (B) combine or store eero Data with any data or information of yours or any third party; or (C) Process eero Data for any purpose not expressly permitted under this Section 2.1. You will logically isolate eero Data from your and any third-party information.

2.2  Requests for eero Data

You will inform eero within forty-eight (48) hours of your receipt of a request for eero Service Data pursuant to legal process or other Applicable Law. You will comply with the eero Security Requirements in respect of your use of and access to eero Services and eero Service Data.

2.3  eero Personal Information

eero Personal Information will be governed by eero's applicable privacy policy (www.eero.com/legal/privacy). Without limiting your obligations under Section 2.1, you will Process any eero Personal Information solely for the authorized purposes set forth in Section 2.1 for the applicable Deployment Type. You will strictly comply with the requirements in the eero Policies relating to Disassociation or notifying eero regarding loss or theft of Products from your possession or control.

2.4  Independently Collected Personal Data

You are responsible for ensuring that any Independently Collected Personal Information has been collected and is shared with eero in compliance with Applicable Law, including any of your own applicable privacy policies, and that you have obtained all required consents, permissions, and legal bases under Applicable Law prior to sharing such data with eero. 

The following applies only if you (1) provide Connectivity and Management services to multi-dwelling residential units that are managed by a property manager and (2) access or use eero Software features designed for such Deployments (i.e., eero Communities or a successor feature). If you receive from a property manager, or intends to receive from a property manager, any Personal Data of tenants or residents in a multi-dwelling unit managed by such property manager, then you will execute an agreement with such property manager sufficient to establish an independent controller to independent controller transfer and relationship (or local equivalent, such as a “user-directed transfer”) prior to receiving any such Personal Data. If hardware Products in a multi-dwelling unit broadcast an IoT SSID, then you will educate and provide resources to inform a Network Manager, or the property manager if applicable, about appropriate use of the IoT SSID, including any applicable IoT SSID guidelines contained in the eero Network Installation Policy.

2.5  Data Transfers

You will inform eero in advance if you Process eero Personal Information outside of the Territory, or if you provide or transfer Independently Collected Personal Information to eero. You agree to enter into such agreements as reasonably required by eero concerning the Processing and/or transfer of Personal Information prior to commencing such Processing or transfer, including any supplemental terms specified in the Agreement applicable to your Territory.

2.6  Use of Products to Process Data

This Section 2.6 applies solely in respect of Internal Networks, and does not apply to End-User Networks. You are solely responsible for ensuring your use of Products complies with Applicable Law, including all data protection obligations in the Territory (such as obtaining consents, providing notices, and implementing appropriate security measures). You will not upload or transmit to eero any data subject to restrictions on cross-border processing or disclosure, or use Products in any manner that would subject eero to data localization requirements or other violations of Applicable Law.

Section 3   Mutual Obligations

Each Party will independently respond to data subject access requests or data deletion requests it receives from End-Users, Connected Users, or Personnel concerning eero Personal Information or Independently Collected Personal Data. Each Party will perform its obligations, and conduct its operations, in connection with the Agreement in compliance with its published privacy notice.

Section 4   Controller to Controller Terms

4.1  Controller to Controller Relationship

Unless the Parties agree otherwise in a signed writing, where Personal Information is shared between you and eero in connection with End-Users and Connected Users, such sharing is intended as an independent controller to independent controller transfer (or the local law equivalent) under Applicable Law. You will only provide eero with Personal Information subject to the applicable data subject's direction or affirmative consent.

4.2  Supplemental Terms — EEA, United Kingdom, and Switzerland

If the Territory under the Agreement includes any jurisdiction in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the Controller-to-Controller Terms set forth in Appendix A to these Terms will automatically apply and are incorporated into the Agreement by reference. You will take appropriate steps to protect and secure eero Personal Data from unauthorized disclosure and to ensure use of such data only for authorized purposes, including complying with the terms of Appendix A.

Appendix A

Controller-to-Controller Terms

This Appendix A ("C2CA" or "Controller-to-Controller Terms") forms part of these Data Protection Terms and applies automatically where required under Section 4.2. You ("Other Controller" or "You") and eero LLC ("eero") (each, a "Party", and together the "Parties") agree to supplement the Agreement to ensure that the sharing of Personal Data between the Parties is carried out in compliance with Data Protection Law.

1.  Definitions

In this C2CA:

"Affiliate" means in relation to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with that party from time to time.

"eero Security Standards" means the standards set out in Schedule 1 (Security Standards) to this Appendix A.

"C2CA" means this Appendix A, including its Schedules and any other document incorporated by reference.

"Controller" has the meaning given in the GDPR.

"Data Protection Law" means all applicable laws, rules, and regulations relating to privacy, data protection and data.

"Data Subject" has the meaning given in the GDPR.

"GDPR" means the EU General Data Protection Regulation 2016/679.

"Party" means a party to this C2CA.

"Personal Data" has the meaning given in the GDPR.

"Personal Data Breach" has the meaning given in the GDPR.

"Restricted Transfer" means the transfer of Personal Data of end users that is protected under the GDPR (i) from the United Kingdom (UK) to another country or (ii) from the European Economic Area (EEA) to another jurisdiction outside of the EEA and, in each case, such a transfer is not on the basis of an adequacy decision.

"Standard Contractual Clauses" means the standard contractual clauses deemed by the European Commission as providing sufficient safeguards to enable the lawful transfer of Personal Data from the European Union to another jurisdiction (as updated from time to time).

"UK Addendum" means the template International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (as updated from time to time).

"UK Data Protection Law" means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the United Kingdom of Great Britain and Northern Ireland, including the UK GDPR and the Data Protection Act 2018.

"UK GDPR" has the meaning given in section 3 of the Data Protection Act 2018.

2.  Scope of this C2CA

2.1  Application.  This C2CA applies to all Personal Data shared by one Party with the other Party under the Agreement where each Party acts as an independent Controller with respect to such Personal Data. In the event and to the extent of any conflict between the terms of the Agreement and this C2CA, the terms of this C2CA will prevail.

3.  Data Processing Commitments

3.1  Status of the Parties.  The Parties acknowledge and agree that each Party will act as separate and independent Controllers in the course of performing the Agreement.

3.2  Compliance with Applicable Law.  Each Party will comply with its obligations under Data Protection Law.

3.3  Use of Personal Data.  The Party receiving Personal Data from the other Party will:

(a)  only process such Personal Data for the specific purpose(s) set out in Annex I.B to Schedule 2 of this C2CA;

(b)  implement and maintain physical, technical and organisational measures to protect such Personal Data against any Personal Data Breach which are commensurate with the nature of the Personal Data, and comply with the eero Security Standards at Schedule 1 to this Appendix A; and

(c)  be responsible for: (i) providing notice to Data Subjects in respect of such Personal Data (where notice is required by Data Protection Law); and (ii) independently responding to the Data Subject requests it receives concerning the Personal Data it holds, in accordance with Data Protection Law.

3.4  Assistance.  Each Party will provide the other prompt assistance as such Party may reasonably request to meet its obligations under Data Protection Law.

3.5  International Transfers.  To the extent eero or Other Controller accesses any Personal Data of end users collected by the other Party under the Agreement and such access constitutes a Restricted Transfer, then such Restricted Transfer will be subject to the Standard Contractual Clauses, as applicable. Neither Party shall make a Restricted Transfer unless such transfer is subject to a lawful transfer mechanism.

3.6  Continued Compliance.  If requested by eero in order to comply with Data Protection Law, or required under Data Protection Law, Other Controller will enter into any additional terms necessary to enable eero to comply with Data Protection Law. Other Controller shall promptly inform eero if it is unable to comply with this C2CA for any reason.

4.  Risk Allocation

4.1  Indemnification.  Other Controller shall indemnify eero, eero's Affiliates and each of their respective employees, agents, officers and contractors ("eero Indemnified Parties") in respect of any losses, damages, fines, costs, or expenses (including legal expenses and disbursements) incurred by any eero Indemnified Party resulting from a breach of Other Controller's obligations under this C2CA. The foregoing indemnity will not be subject to any limitations or exclusions of liability (whether in the Agreement or otherwise).

4.2  Remediation.  The Parties agree that eero will be entitled to recover from Other Controller any losses, damages, fines, costs, or expenses (including legal expenses and disbursements) incurred by eero or any of its Affiliates resulting from a breach of Other Controller's obligations under this C2CA, and such amounts will be deemed direct losses not subject to any limitations or exclusions of liability (whether in the Agreement or otherwise).

5.  General

5.1  Third Party Rights.  No person may enforce any term of this C2CA other than eero or Other Controller.

5.2  Remedies.  The rights and remedies provided under this C2CA are in addition to, and not exclusive of, any rights or remedies provided by law or in the Agreement.

5.3  Survival.  Sections 2, 3, 4.1, and 4.2 of this C2CA will survive termination or expiration of the Agreement.

5.4  Term.  This C2CA shall continue in force until the termination or expiration of the Agreement.

5.5  Governing Law and Jurisdiction.  The governing law and jurisdiction provisions of the Agreement will apply to this C2CA.

Appendix A — Schedule 1

eero Security Standards

The Parties will maintain physical, administrative, and technical safeguards consistent with industry-accepted best practices to protect the confidentiality, integrity, and availability of the Personal Data subject to the Agreement, including the following safeguards:

1.  Firewall

The Parties will install and maintain a working network firewall or equivalent acceptable technology to protect Personal Data accessible via the Internet on their respective servers and will keep all such Personal Data protected by the firewall. The firewall or equivalent acceptable technology must provide ingress filtering, and have a default policy of blocking network traffic.

2.  Updates

The Parties will keep their respective systems and software up-to-date with the latest upgrades, updates, bug fixes, new versions and other modifications necessary to ensure security of the Personal Data within a reasonable time of release of such upgrades, bug fixes, versions or modifications.

3.  Anti-Virus

The Parties will at all times use appropriate anti-virus software and scanning technologies or equivalent acceptable technology, and regularly updated signature files, to ensure that operating systems, software and other systems hosting, storing, processing, or that have access to Personal Data, and are known to be susceptible or vulnerable to being infected by or further propagating viruses, spyware and malicious code, are and remain free from such viruses, spyware and malicious code. Each Party will mitigate threats from all viruses, spyware, and other malicious code that are or should reasonably have been detected by such Party.

4.  Testing

At least annually or after significant changes, the Parties will test their respective security systems and processes to ensure they meet the requirements of this Schedule 1.

5.  Access Controls

The Parties will comply with industry best practices to ensure appropriate access controls in relation to the access of Personal Data on their respective servers, including adhering to the security principles of "segregation of duties" and "least privilege" with respect to Personal Data.

6.  Remote Access

The Parties will ensure that any remote access to their servers holding Personal Data or their corporate or development workstation networks requires multi-factor authentication (e.g., requires at least two separate factors for identifying users).

7. "In Bulk" Access

The Parties' employees will only be permitted to have access to Personal Data "in bulk" if they have been approved to have such access in accordance with such Party's IT security procedures.

8.  Encryption

Each Party will encrypt Personal Data using industry best practices and in the following circumstances: (a) the processing of Personal Data on any mobile device or removable media that connects to or contains information from the Party's server; and (b) electronic transmissions of Personal Data by a Party outside of its network.

9.  Third Party Systems

If either Party's subcontractors or affiliates process Personal Data on behalf of that Party, such Party will: (a) either (i) ensure that each such subcontractor acts as a user under that Party's written data security program, or (ii) ensure that each such subcontractor's written data security program complies with this Schedule via sufficient diligence and oversight; and (b) be responsible for the acts and omissions of such subcontractors as if they were the acts or omissions of such Party.

10.  Data Retention

Subject to Applicable Law, the Parties will use Personal Data only in accordance with the terms of this C2CA. If either Party retains Personal Data following the expiration or termination of the Agreement in accordance with the Agreement's terms, such Party will continue to hold such Personal Data in accordance with this Schedule 1.

11.  Forensic Destruction

Before disposing in any manner of any hardware, software, or any other media that contains, or has at any time contained, Personal Data, the Parties will perform a complete forensic destruction of the hardware, software or other media so that none of the Personal Data can be recovered or retrieved in any form.

12.  Training

The Parties will provide periodic security training to their personnel on relevant threats and data protection obligations.

13.  Secure Configurations

The Parties will manage security configurations of their systems using industry best practices to protect Personal Data from exploitation.

14.  Audit Logs

The Parties will collect and manage audit logs of events to help detect, investigate, and recover from unauthorized activity that may affect Personal Data.

15.  Change Management

Changes to production systems are reviewed, tracked, and recorded and retained for a period required by Applicable Law.

16.  Incident Response

The Parties will maintain written incident response plans. The Parties will remedy each security event in a timely manner following their response plan and industry best practices. Each Party will notify the other within 48 hours of becoming aware of a security incident with material effect that relates to Personal Data.

17.  Formal Security Program

The Parties will implement a written information security program, including appropriate policies, procedures, and risk assessments that are reviewed at least annually. The program will apply to the Parties' employees, agents, subcontractors, and suppliers. The Parties will maintain a process to monitor and enforce program compliance and log program violations.

18.  Intrusion Detection and Prevention

The Parties will maintain intrusion detection and prevention services to protect the production environment.

19.  Account and Password Management

The Parties will implement account and password management policies to protect Personal Data, including, without limitation, ensuring all personnel use strong passwords, and encrypting passwords and other secrets in an industry-accepted form.

Appendix A — Schedule 2

Standard Contractual Clauses (Controller-to-Controller)

SECTION I

Clause 1 — Purpose and scope

(a)  The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country.

(b)  The Parties:

(i)  the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter 'entity/ies') transferring the personal data, as listed in Annex I.A (hereinafter each 'data exporter'), and

(ii)  the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each 'data importer')

have agreed to these standard contractual clauses (hereinafter: 'Clauses').

(c)  These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.

(d)  The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses.

Clause 2 — Effect and invariability of the Clauses

(a)  These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects.

(b)  These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.

Clause 3 — Third-party beneficiaries

(a)  Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions: (i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7; (ii) Clause 8.5(e) and Clause 8.9(b); (iii) Clause 12(a) and (d); (iv) Clause 13; (v) Clause 15.1(c), (d) and (e); (vi) Clause 16(e); (vii) Clause 18(a) and (b).

(b)  Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.

Clause 4 — Interpretation

(a)  Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.

(b)  These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.

(c)  These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679.

Clause 5 — Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

Clause 6 — Description of the transfer(s)

The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.

Clause 7 — Docking clause (Optional)

(a)  An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex I.A.

(b)  Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these Clauses and have the rights and obligations of a data exporter or data importer in accordance with its designation in Annex I.A.

(c)  The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to becoming a Party.

SECTION II — OBLIGATIONS OF THE PARTIES

Clause 8 — Data protection safeguards

The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses.

8.1  Purpose limitation

The data importer shall process the personal data only for the specific purpose(s) of the transfer, as set out in Annex I.B. It may only process the personal data for another purpose: (i) where it has obtained the data subject's prior consent; (ii) where necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings; or (iii) where necessary in order to protect the vital interests of the data subject or of another natural person.

8.2  Transparency

(a)  In order to enable data subjects to effectively exercise their rights pursuant to Clause 10, the data importer shall inform them, either directly or through the data exporter: (i) of its identity and contact details; (ii) of the categories of personal data processed; (iii) of the right to obtain a copy of these Clauses; (iv) where it intends to onward transfer the personal data to any third party/ies, of the recipient or categories of recipients (as appropriate with a view to providing meaningful information), the purpose of such onward transfer and the ground therefore pursuant to Clause 8.7.

(b)  Paragraph (a) shall not apply where the data subject already has the information, including when such information has already been provided by the data exporter, or providing the information proves impossible or would involve a disproportionate effort for the data importer. In the latter case, the data importer shall, to the extent possible, make the information publicly available.

(c)  On request, the Parties shall make a copy of these Clauses, including the Appendix as completed by them, available to the data subject free of charge. To the extent necessary to protect business secrets or other confidential information, including personal data, the Parties may redact part of the text of the Appendix prior to sharing a copy, but shall provide a meaningful summary where the data subject would otherwise not be able to understand its content or exercise his/her rights. On request, the Parties shall provide the data subject with the reasons for the redactions, to the extent possible without revealing the redacted information.

(d)  Paragraphs (a) to (c) are without prejudice to the obligations of the data exporter under Articles 13 and 14 of Regulation (EU) 2016/679.

8.3  Accuracy and data minimisation

(a)  Each Party shall ensure that the personal data is accurate and, where necessary, kept up to date. The data importer shall take every reasonable step to ensure that personal data that is inaccurate, having regard to the purpose(s) of processing, is erased or rectified without delay.

(b)  If one of the Parties becomes aware that the personal data it has transferred or received is inaccurate, or has become outdated, it shall inform the other Party without undue delay.

(c)  The data importer shall ensure that the personal data is adequate, relevant and limited to what is necessary in relation to the purpose(s) of processing.

8.4  Storage limitation

The data importer shall retain the personal data for no longer than necessary for the purpose(s) for which it is processed. It shall put in place appropriate technical or organisational measures to ensure compliance with this obligation, including erasure or anonymisation of the data and all back-ups at the end of the retention period.

8.5  Security of processing

(a)  The data importer and, during transmission, also the data exporter shall implement appropriate technical and organisational measures to ensure the security of the personal data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. In assessing the appropriate level of security, they shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subject. The Parties shall in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner.

(b)  The Parties have agreed on the technical and organisational measures set out in Annex II. The data importer shall carry out regular checks to ensure that these measures continue to provide an appropriate level of security.

(c)  The data importer shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

(d)  In the event of a personal data breach concerning personal data processed by the data importer under these Clauses, the data importer shall take appropriate measures to address the personal data breach, including measures to mitigate its possible adverse effects.

(e)  In case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the data importer shall without undue delay notify both the data exporter and the competent supervisory authority pursuant to Clause 13. Such notification shall contain: (i) a description of the nature of the breach (including, where possible, categories and approximate number of data subjects and personal data records concerned); (ii) its likely consequences; (iii) the measures taken or proposed to address the breach; and (iv) the details of a contact point from whom more information can be obtained.

(f)  In case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the data importer shall also notify without undue delay the data subjects concerned of the personal data breach and its nature, if necessary in cooperation with the data exporter, together with the information referred to in paragraph (e)(ii) to (iv), unless the data importer has implemented measures to significantly reduce the risk or notification would involve disproportionate efforts.

(g)  The data importer shall document all relevant facts relating to the personal data breach, including its effects and any remedial action taken, and keep a record thereof.

8.6  Sensitive data

Where the transfer involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person's sex life or sexual orientation, or data relating to criminal convictions or offences, the data importer shall apply specific restrictions and/or additional safeguards adapted to the specific nature of the data and the risks involved. This may include restricting the personnel permitted to access the personal data, additional security measures (such as pseudonymisation) and/or additional restrictions with respect to further disclosure.

8.7  Onward transfers

The data importer shall not disclose the personal data to a third party located outside the European Union unless the third party is or agrees to be bound by these Clauses under the appropriate Module. Otherwise, an onward transfer by the data importer may only take place if: (i) it is to a country benefitting from an adequacy decision pursuant to Article 45 of Regulation (EU) 2016/679 that covers the onward transfer; (ii) the third party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47; (iii) the third party enters into a binding instrument with the data importer ensuring the same level of data protection; (iv) it is necessary for the establishment, exercise or defence of legal claims; (v) it is necessary in order to protect the vital interests of the data subject or of another natural person; or (vi) the data importer has obtained the explicit consent of the data subject for an onward transfer in a specific situation, after having informed him/her of its purpose(s), the identity of the recipient and the possible risks of such transfer.

8.8  Processing under the authority of the data importer

The data importer shall ensure that any person acting under its authority, including a processor, processes the data only on its instructions.

8.9  Documentation and compliance

(a)  Each Party shall be able to demonstrate compliance with its obligations under these Clauses. In particular, the data importer shall keep appropriate documentation of the processing activities carried out under its responsibility.

(b)  The data importer shall make such documentation available to the competent supervisory authority on request.

Clause 9 — Not used

Clause 10 — Data subject rights

(a)  The data importer, where relevant with the assistance of the data exporter, shall deal with any enquiries and requests it receives from a data subject relating to the processing of his/her personal data and the exercise of his/her rights under these Clauses without undue delay and at the latest within one month of the receipt of the enquiry or request. The data importer shall take appropriate measures to facilitate such enquiries, requests and the exercise of data subject rights. Any information provided to the data subject shall be in an intelligible and easily accessible form, using clear and plain language.

(b)  In particular, upon request by the data subject the data importer shall, free of charge: (i) provide confirmation to the data subject as to whether personal data concerning him/her is being processed and, where this is the case, a copy of the data relating to him/her; (ii) rectify inaccurate or incomplete data concerning the data subject; (iii) erase personal data concerning the data subject if such data is being or has been processed in violation of any of these Clauses ensuring third-party beneficiary rights, or if the data subject withdraws the consent on which the processing is based.

(c)  Where the data importer processes the personal data for direct marketing purposes, it shall cease processing for such purposes if the data subject objects to it.

(d)  The data importer shall not make a decision based solely on the automated processing of the personal data transferred which would produce legal effects concerning the data subject or similarly significantly affect him/her, unless with the explicit consent of the data subject or if authorised to do so under the laws of the country of destination, provided that such laws lay down suitable measures to safeguard the data subject's rights and legitimate interests.

(e)  Where requests from a data subject are excessive, in particular because of their repetitive character, the data importer may either charge a reasonable fee taking into account the administrative costs of granting the request or refuse to act on the request.

(f)  The data importer may refuse a data subject's request if such refusal is allowed under the laws of the country of destination and is necessary and proportionate in a democratic society to protect one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679.

(g)  If the data importer intends to refuse a data subject's request, it shall inform the data subject of the reasons for the refusal and the possibility of lodging a complaint with the competent supervisory authority and/or seeking judicial redress.

Clause 11 — Redress

(a)  The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject.

(b)  In case of a dispute between a data subject and one of the Parties as regards compliance with these Clauses, that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties shall keep each other informed about such disputes and, where appropriate, cooperate in resolving them.

(c)  Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer shall accept the decision of the data subject to: (i) lodge a complaint with the supervisory authority in the Member State of his/her habitual residence or place of work, or the competent supervisory authority pursuant to Clause 13; or (ii) refer the dispute to the competent courts within the meaning of Clause 18.

(d)  The Parties accept that the data subject may be represented by a not-for-profit body, organisation or association under the conditions set out in Article 80(1) of Regulation (EU) 2016/679.

(e)  The data importer shall abide by a decision that is binding under the applicable EU or Member State law.

(f)  The data importer agrees that the choice made by the data subject will not prejudice his/her substantive and procedural rights to seek remedies in accordance with applicable laws.

Clause 12 — Liability

(a)  Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses.

(b)  Each Party shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages that the Party causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter under Regulation (EU) 2016/679.

(c)  Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties.

(d)  The Parties agree that if one Party is held liable under paragraph (c), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its/their responsibility for the damage.

(e)  The data importer may not invoke the conduct of a processor or sub-processor to avoid its own liability.

Clause 13 — Supervision

(a)  The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent supervisory authority.

(b)  The data importer agrees to submit itself to the jurisdiction of and cooperate with the competent supervisory authority in any procedures aimed at ensuring compliance with these Clauses. In particular, the data importer agrees to respond to enquiries, submit to audits and comply with the measures adopted by the supervisory authority, including remedial and compensatory measures. It shall provide the supervisory authority with written confirmation that the necessary actions have been taken.

SECTION III — LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES

Clause 14 — Local laws and practices affecting compliance with the Clauses

(a)  The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses.

(b)  The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular of the following elements: (i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; (ii) the laws and practices of the third country of destination relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards; (iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination.

(c)  The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses.

(d)  The Parties agree to document the assessment under paragraph (b) and make it available to the competent supervisory authority on request.

(e)  The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under paragraph (a), including following a change in the laws of the third country or a measure indicating an application of such laws in practice that is not in line with those requirements.

(f)  Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures to be adopted to address the situation. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses.

Clause 15 — Obligations of the data importer in case of access by public authorities

15.1  Notification

(a)  The data importer agrees to notify the data exporter and, where possible, the data subject promptly if it: (i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; or (ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination.

(b)  If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible.

(c)  Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received.

(d)  The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request.

(e)  Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.

15.2  Review of legality and data minimisation

(a)  The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested until required to do so under the applicable procedural rules.

(b)  The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible under the laws of the country of destination, make the documentation available to the data exporter. It shall also make it available to the competent supervisory authority on request.

(c)  The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.

SECTION IV — FINAL PROVISIONS

Clause 16 — Non-compliance with the Clauses and termination

(a)  The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason.

(b)  In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. This is without prejudice to Clause 14(f).

(c)  The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where: (i) the data exporter has suspended the transfer of personal data to the data importer pursuant to paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension; (ii) the data importer is in substantial or persistent breach of these Clauses; or (iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses.

(d)  Personal data that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall at the choice of the data exporter immediately be returned to the data exporter or deleted in its entirety. The same shall apply to any copies of the data. The data importer shall certify the deletion of the data to the data exporter.

(e)  Either Party may revoke its agreement to be bound by these Clauses where: (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred.

Clause 17 — Governing law

These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of Luxembourg.

Clause 18 — Choice of forum and jurisdiction

(a)  Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State.

(b)  The Parties agree that those shall be the courts of Luxembourg.

(c)  A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence.

(d)  The Parties agree to submit themselves to the jurisdiction of such courts.


Appendix A — Schedule 2: Appendix

Annex I — List of Parties, Description of Transfer, and Supervisory Authority

ANNEX I.A — List of Parties

Data exporter(s):  Other Controller (you), as identified in the Agreement.

Data importer(s):  eero LLC, PO Box, San Francisco, CA 94107, USA; legal@eero.com.

ANNEX I.B — Description of Transfer

Categories of data subjects whose personal data is transferred:  End-users or customers of eero products and services; customer support agents; internal employees; contractors; vendors; vendor employees.

Categories of personal data transferred:

eero may share Personal Data with Other Controller, the extent and categorization of which will be determined in eero's sole discretion, in order for Other Controller to engage in the services contemplated by the Agreement. Categories of Personal Data shared by eero may include, but are not limited to:

•  Customer contact and account details and associated customer support records.

•  Network and connected device information, including MAC addresses for eero devices and connected devices, IP addresses and network SSID, family profile names, device hostnames, firmware data, and the association of devices with a specific family profile.

Other Controller may share Personal Data with eero, the extent and categorization of which will be determined in Other Controller's sole discretion, in order for eero to engage in the services contemplated by the Agreement. Categories of Personal Data shared by Other Controller may include, but are not limited to:

•  Customer contact and account details and associated customer support records.

Sensitive data:  N/A. The Parties will not intentionally transfer or share special categories of Personal Data unless separately agreed in writing.

Frequency of transfer:  Personal Data will be transferred on a continuous basis in accordance with the terms of this C2CA and the Agreement.

Nature and purpose of processing:  Other Controller is collaborating with eero for the supply of eero products, software, and services to Other Controller and its connected users. Processing may be continuous for the duration of the Agreement.

Retention period:  The period for which Personal Data will be retained will be determined by each Party in accordance with its data privacy and data retention policies and Applicable Law.

ANNEX I.C — Competent Supervisory Authority

The Luxembourg National Commission for Data Protection (Commission Nationale pour la Protection des Données – CNPD), in accordance with Clause 13.

ANNEX II — Technical and Organisational Measures

The technical and organisational security measures applicable to each Party in its capacity as data importer are as set forth in Schedule 1 (eero Security Standards) to this Appendix A.

Appendix A — Schedule 3

UK International Data Transfer Addendum

UK INTERNATIONAL DATA TRANSFER ADDENDUM TO THE EU COMMISSION STANDARD CONTRACTUAL CLAUSES

This Addendum has been issued by the UK Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.

Part 1: Tables

Table 1: Parties

See Annex I.A of Schedule 2 to this Appendix A.

Table 2: Selected SCCs, Modules and Selected Clauses

Addendum EU SCCs:  The version of the Approved EU SCCs to which this Addendum is appended is the Module 1 (Controller to Controller) Standard Contractual Clauses set out in Schedule 2 to this Appendix A, including the Appendix Information set out therein.

Table 3: Appendix Information

"Appendix Information" means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

Annex I.A (List of Parties): See Annex I.A of Schedule 2.

Annex I.B (Description of Transfer): See Annex I.B of Schedule 2.

Annex II (Technical and organisational measures): See Schedule 1 (eero Security Standards).

Annex III (List of Sub-processors, Modules 2 and 3 only): Not applicable.

Table 4: Ending this Addendum when the Approved Addendum Changes

Which Parties may end this Addendum as set out in Section 19:  Either the Importer or the Exporter.

Part 2: Mandatory Clauses

The Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s.119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses, are incorporated by reference and apply to Restricted Transfers from the United Kingdom. In the event of any conflict between the Mandatory Clauses and this Table 1, the Mandatory Clauses shall prevail.


  • Our Products
  • Why eero
  • Shop on Amazon
  • Legal

Connect with us

eero X
*See eero.com/legal/warranty for details.
*See eero.com/legal/compliance for safety and compliance details.
eero products and services are subject to the disclaimers located at eero.com/legal/disclaimers
©2026 eero LLC, San Francisco, CA
eero Facebook
eero Instagram
eero Linkedin
eero Youtube
Download on the App Store
Get it on Google Play
Download on the App Store
Get it on Google Play