Setting Up Calendly in a GDPR/DSG-Compliant Way

6 min readLast updated By Marc Grob

Introduction

Calendly has long been the default scheduling tool in many Swiss SMEs, consulting firms and sales teams. A few clicks, a slick public URL, and clients or prospects can book time in your calendar. As simple as this is technically, it becomes demanding from a data-protection perspective: Calendly LLC is a US company headquartered in Atlanta that processes personal data (name, email, IP address, optional phone number, custom questions, meeting topics) and passes it on to various sub-processors.

This article shows:

  • which data flows actually happen during a Calendly booking;
  • which contractual foundations (DPA, SCC, EU-US DPF) must be in place;
  • which settings you should configure in the Calendly admin to keep the tool DSG- and GDPR-compliant;
  • how Calendly's embed and cookie behaviour should be handled;
  • which mandatory information must appear in your privacy policy;
  • and which alternatives are realistic for Swiss organisations.

Legal anchors: Federal Act on Data Protection (DSG, Art. 6, 8, 9, 16, 19, 22), GDPR (Art. 6, 13, 28, 44 et seq.), Calendly Data Processing Addendum, EU-US Data Privacy Framework (2023), Swiss-US Data Privacy Framework (15 September 2024), FDPIC cookie guidance (2023).

Data flows during a Calendly booking

When a visitor opens your Calendly URL and books a slot, the booking moves through several stations:

  1. Browser → Calendly server (US/EU): already loading the booking page transmits the IP address, user agent, referrer and set cookies to Calendly. Calendly runs data centres in the US (primary region AWS us-east-1) and, since 2023, an EU region for Enterprise customers.
  2. Booking form: name, email and any custom fields are captured. Caution: custom fields are often abused to ask for sensitive data ("describe your concern" → may contain health, financial or mandate details).
  3. Calendar sync: Calendly writes the event back into your connected calendar (Google Workspace, Microsoft 365, iCloud). It holds OAuth tokens with write rights.
  4. Confirmation emails / SMS: sending happens via SendGrid (email) and Twilio (SMS, optional). Both are US sub-processors.
  5. Webhook / Zapier integration: when active, booking data is forwarded to your CRM (HubSpot, Salesforce, Pipedrive) or to automation tools.

This chain produces at least three disclosures relevant to data-protection law: to Calendly as processor, to sub-processors (SendGrid, Twilio, AWS) and, through integrations, to additional processors of your own.

Contractual foundations, DPA, SCC and DPF

For lawful use under Art. 9 DSG and Art. 28 GDPR, you need a data processing agreement. Calendly provides a standard Data Processing Addendum, which you can accept electronically in the Calendly admin (under Account → Legal). The DPA incorporates the EU Standard Contractual Clauses (Module 2: controller-processor) and, since 2023, the Swiss Addendum for DSG compliance.

Calendly self-certified under the EU-US Data Privacy Framework in mid-2023; since 15 September 2024, the Swiss-US DPF also applies after the Swiss Federal Council recognised it as adequate. For data transfers from Switzerland to the US, this materially reduces the transfer burden, but you must periodically verify Calendly's DPF certification (public DPF list at dataprivacyframework.gov).

If you rely on the DPF, document this explicitly in the record of processing activities (Art. 12 DSG / Art. 30 GDPR). If the DPF were to fall (a Schrems III scenario), the SCCs remain as a fallback mechanism, a TIA is then additionally advisable.

Practical tip: Calendly customers on the Enterprise tier can activate EU data residency, moving primary processing to Irish AWS data centres. This is the most robust configuration for Swiss customers with GDPR exposure.

Configuring Calendly, the ten most important settings

Most data-protection issues do not arise in the tool itself but in its configuration. We recommend a minimum baseline:

  1. Activate EU region (Enterprise tier) for Swiss and EU customers.
  2. Keep custom fields minimal: only name and email are mandatory. Avoid free-text fields where sensitive data can land.
  3. Privacy notice in the booking form: activate the Privacy Notice field with a link to your privacy policy, it shows in the booking footer.
  4. Do not pre-tick marketing opt-in: if you include a newsletter opt-in in the booking form, it must be opt-in active, never preselected.
  5. SCIM / SSO: activate on the Enterprise tier for centralised user management and clean account deactivation on staff exit.
  6. Enable audit log (Enterprise tier) for traceability of admin and booking events.
  7. Configure retention: by default Calendly keeps booking data indefinitely. Set a retention policy (e.g. 24 months after the last appointment).
  8. Couple embedded code with consent: the Calendly inline embed loads scripts from calendly.com, it may only fire after cookie consent, otherwise it breaches the EU ePrivacy regime and the FDPIC cookie guidance.
  9. Document webhook recipients: every webhook reaches a further recipient, that recipient must appear in the record of processing activities and in the privacy policy.
  10. Minimise calendar data access: Calendly needs write access but can be reduced to free/busy-only if needed, preventing Calendly from seeing the content of other events.

Embed, cookies and ePrivacy

Calendly offers three embed forms: pop-up widget, pop-up text and inline embed. All three load third-party scripts from calendly.com and assets.calendly.com. Cookies that are strictly necessary for functionality come with this, plus potentially analytics cookies depending on the configuration.

The consequence under EU law (Art. 5(3) ePrivacy Directive in the relevant national implementations) and the FDPIC's 2023 cookie guidance:

  • Strictly necessary cookies (booking function) are permissible without consent.
  • Analytics or marketing cookies (e.g. if you also embed Google Analytics, Facebook Pixel or LinkedIn Insight Tag on the booking page) require prior consent.
  • The Calendly embed may only load after consent when it appears alongside tracking scripts. In practice a consent loader in your cookie banner helps: Calendly scripts are loaded only after the visitor clicks "accept".

A leaner alternative: instead of an inline embed, just use a button linking to calendly.com/your-handle, that moves cookie setting onto the Calendly domain and avoids cross-site tracking on your own site.

Mandatory information in the privacy policy

If you use Calendly, your privacy policy must at minimum contain the following points (Art. 19 DSG / Art. 13 GDPR):

  • Provider details: "We use the scheduling service Calendly, operated by Calendly LLC, 271 17th Street NW, Suite 1000, Atlanta, GA 30363, USA."
  • Purpose: appointment coordination, confirmation emails, reminders.
  • Categories of data: name, email, optional phone number, IP address, booking metadata, content of custom fields.
  • Legal basis: DSG: contract performance / legitimate interest; GDPR: Art. 6(1)(b) or (f).
  • Recipients: Calendly (US/EU), sub-processors (AWS, SendGrid, Twilio, integrated CRM systems where applicable).
  • Cross-border transfer: US, legal basis Swiss-US DPF and EU-US DPF, supplemented by EU SCCs and the Swiss Addendum.
  • Retention period: reference to your retention policy (e.g. 24 months).
  • Data-subject rights: note on access, rectification, deletion rights and the right to lodge a complaint with the FDPIC / EU supervisory authority.

Additionally: if you use custom fields that could elicit sensitive personal data, you need explicit consent (Art. 6(7) DSG / Art. 9 GDPR), ideally directly in the booking form.

Alternatives for Swiss organisations

For organisations with high confidentiality requirements or a general CH-/EU-only strategy, alternatives with European data residency exist:

  • Cal.com (open source / EU-hosted): self-hostable or as EU cloud offering, fully DPA-ready.
  • Microsoft Bookings: already included in your M365 licence, runs within the same tenant, no additional third party.
  • YouCanBookMe (UK): with EU/UK hosting.
  • SuperSaaS (NL): Dutch provider with EU data residency.
  • TerminApp / Termin.ch: Swiss providers, some with CH hosting depending on the plan.

Which provider fits depends on how tightly you need calendar sync (Google/Microsoft), payment processing (Stripe), CRM integration and branding controls. If you already run Microsoft 365, Microsoft Bookings is often the most compliance-frugal choice, no additional processor relationship, no additional cross-border disclosure.

How SIDD supports you

SIDD regularly assesses third-party tools like Calendly, Cal.com, Microsoft Bookings or SuperSaaS for DSG and GDPR compliance. For Calendly we provide:

  • tool assessment with a clear recommendation (continue with Calendly, activate EU region or switch to an alternative);
  • drafting or update of your privacy policy;
  • configuration review of your Calendly tenant;
  • cookie banner audit and consent mechanics;
  • mandates as external data-protection advisor for ongoing support;
  • GDPR DPO function for companies with EU exposure (GDPR DPO mandates);
  • EU representation under Art. 27 GDPR (EU representative);
  • privacy workshops for sales and marketing teams (privacy workshop).

Write to us via the contact form or request a quote via the quote form. We deliver a Calendly quick-check within two working days.

Need help putting this into practice? SIDD operates the matching service.
See service →

Setting Up Calendly in a GDPR/DSG-Compliant Way

INSIGHT

Data Protection
24 May 2026
Marc Grob
Using Calendly in line with data protection law: data flows of a booking, DPA and third-country transfers, key settings, cookies and alternatives.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.