Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

Cursor

Cursor (Anysphere)

By deploymentEU: LimitedPlan-dependentRetention by featureRegion by agreement

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out Cursor safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Pro USD20, Pro+ USD60 and Ultra USD200 monthly; Teams Standard USD40/user and Premium USD120/user; Enterprise custom

Enterprise Features

Enforced Privacy Mode, model and repository controls, DPA, US residency, requested EU plus Iceland inference-only coverage, and CMEK for Cloud Agent data

Last Updated

September 10, 2026

Reviewed: 10 September 2026 - prepared by WAIMAKERS B.V.


1 Purpose

Deployment-specific review. Cursor can be used in a GDPR-governed development environment only after the organisation maps the features, models and data involved. Privacy Mode addresses training and ordinary model-provider retention, but it does not keep every feature local, remove all safety-retention exceptions, or establish an EU-resident service.


2 Comparison of Cursor Tiers (EU focus)

The figures below are from Cursor's current pricing help and pricing page.

Plan Privacy control Contract route Public price at review date
Hobby User can enable Privacy Mode Privacy Policy; Cursor says the DPA does not apply to individual plans Free
Pro / Pro+ / Ultra User-controlled Privacy Mode Same individual-plan position $20 / $60 / $200 per month
Teams Team-wide Privacy Mode and SAML/OIDC SSO DPA and subprocessor coverage for Teams customers $40/user/month Standard; $120/user/month Premium
Enterprise Privacy enforcement plus model, repository, MCP and agent controls; CMEK for stored Cloud Agent data Enterprise agreement and DPA Custom

Usage allowances and on-demand model charges are separate from subscription prices and change more often than the plan names. Check the billing dashboard before purchase.


3 Is Cursor GDPR-Compliant?

Data use and retention

  • ✅ With Privacy Mode enabled, Cursor says Customer Data is not used for training by Cursor and model providers operate under zero-data-retention arrangements.
  • ⚠️ That guarantee has documented exceptions. Non-ZDR models require approval, providers may retain data that triggers abuse classifiers for investigation, and requests made with a customer's own API key follow that provider's policy rather than Cursor's ZDR agreement.
  • ✅ Privacy Mode is enabled by default for team members and can be enforced by an administrator. It remains a user setting on individual plans.
  • ⚠️ Cursor sends prompts and code context to model and inference providers. Its security page says code data reaches Cursor servers for AI features.
  • ⚠️ Codebase indexing uploads plaintext chunks to calculate embeddings. Cursor says plaintext is deleted after processing and embeddings plus metadata are retained. Users can disable indexing and should use .cursorignore as an additional exclusion control, not as a legal guarantee.
  • ⚠️ Cloud Agents are a distinct flow: they temporarily store encrypted repository copies while an agent runs and delete them after completion. Self-Hosted Machines keep tool execution on the customer's machine, while the agent loop remains in Cursor's cloud.
  • ⚠️ The DPA provides deletion or return within 30 days of written direction after service termination, unless law requires retention. That is different from zero retention during ordinary use.

Location and security

The previous “all processing and storage is US-only” statement was too broad. Cursor's Enterprise documentation offers US-only residency and, on request, EU plus Iceland inference-only coverage. Broader EU processing and storage residency was still under development at the review date. Confirm the locations of every enabled feature and subprocessor in writing.

Cursor's security page, updated 25 August 2026, states AES-256 encryption at rest, TLS 1.2+ in transit, a SOC 2 Type II attestation and AIUC-1, ISO/IEC 27001:2022 and ISO/IEC 42001:2023 certifications. These measures and Privacy Mode support a risk assessment; they do not decide lawful basis, purpose limitation, data minimisation, international-transfer compliance or whether source code contains personal data.


4 EU Rollout Checklist (Practical)

  1. Use Teams or Enterprise for organisational workloads so Privacy Mode can be enforced.
  2. Execute the DPA, inspect the current subprocessor list and document transfer mechanisms and supplementary measures.
  3. Restrict non-ZDR models, own-key routes, Cloud Agents, MCP servers and plugins according to the data classification.
  4. Exclude secrets, personal data and regulated repositories from prompts and indexing; verify exclusions technically.
  5. Decide whether Cloud Agents may hold temporary repository copies. Use Self-Hosted Machines only after documenting the remaining cloud agent loop.
  6. Request written scope for any EU plus Iceland inference arrangement; do not describe it as full EU residency.
  7. Complete a DPIA where the planned processing is likely to create high risk. Cursor's DPA says customers should not provide special-category data.

5 Notes & Caveats

Open procurement questions

  • Which exact models are ZDR, which have safety-retention exceptions, and can administrators block them?
  • Which features are included in the requested residency programme and where are processing, storage, backups and support access located?
  • What is the deletion evidence for indexing data, Cloud Agents, logs and backups?
  • Does CMEK cover only Cloud Agent data or other stored Customer Data in the purchased configuration?
  • Which current SOC 2 scope and penetration-test evidence covers the selected product surfaces?

6 References

  • Cursor privacy and data help
  • Cursor data use and Privacy Mode
  • Cursor security and infrastructure
  • Cursor Enterprise privacy, retention and residency
  • Cursor DPA
  • Cursor pricing
  • Cursor pricing help
  • GDPR, official text

7 Disclaimer

This page is a practical procurement and data-risk overview, not legal advice. Suitability depends on the signed agreement, enabled product surfaces, model allowlist, data classes and the customer's GDPR assessment.

Compare related tools

Mistral AIWispr Flow

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy