Clerk
User management and authentication SDK.
Detected by domain patterns
clerk.comclerk.devclerk.accounts.devclerkstage.devEuropean alternatives
GDPR & Data Residency
Clerk is owned by a US company. Under GDPR Chapter V, transferring personal data to the US requires an appropriate safeguard (typically Standard Contractual Clauses or adequacy decisions. The 2020 Schrems II ruling invalidated Privacy Shield and increased scrutiny on US data transfers, requiring case-by-case Transfer Impact Assessments (TIAs).
If your website loads Clerkscripts or sends user data to their servers, your users' data may be processed in the United States. Review Clerk's DPA (Data Processing Agreement) and ensure it covers SCCs.
Clerk is self-certified under the EU–US Data Privacy Framework — a lawful GDPR transfer mechanism for EU→US transfers.
Verified against the official DPF participant list on 3 Aug 2026. This is a technical observation, not legal advice — certification status can change, so re-check before relying on it.
Tip: Consider replacing Clerk with one of the EU-based alternatives listed above to simplify GDPR compliance and remove cross-border transfer obligations.
Does your website use Clerk?
Run a free StackPatrol scan to see all third-party services on your front page.