legal
GDPR evidence across 21 vendors
GDPR has no certification in general use. What a buyer can verify is a data processing agreement, standard contractual clauses, an EU representative, data residency options, and an active Data Privacy Framework listing. CertReports records each of those as its own dated fact.
- Verified rows
- 0
- Vendor-stated
- 21
- Expired
- 0
- Last verified
- 17 Sep 2026
Vanta
Compliance and GRC
Vanta—the proven leader in automated compliance helping startups…
CrowdStrike
Security
Datadog
DevOps and observability
Drata
Compliance and GRC
Cyera
Security
GitLab
DevOps and observability
A complete DevOps platform delivered as a single application.
OpenAI
AI infrastructure
Okta
Identity and access
Twilio
Communications and CPaaS
Fortinet
Security
Diligent
Compliance and GRC
A-LIGN
Compliance and GRC
KnowBe4
Security
Axon
Government and public sector
Intercom
Customer support
Vercel
Cloud and hosting
checkout
Payments
Bird
Communications and CPaaS
The world’s largest omnichannel communications platform
Sim
AI infrastructure
The AI Workspace for Building and Managing AI Agents.
Otter.ai
Communications and CPaaS
clickup
Project management
Data Privacy Framework
The EU-US DPF list is an official registry with annual recertification and a usage end date per participant. The General Court dismissed the challenge to the adequacy decision on 3 September 2025 (T-553/23); an appeal is pending at the Court of Justice (C-703/25 P).
DPA and subprocessors
"[vendor] dpa" and "[vendor] subprocessors" are among the most searched vendor questions. CertReports links the DPA and captures the subprocessor list with logos and change history where it is public.