Skip to main content
A-LIGN logo

A-LIGN

GDPR evidence

a-lign.comCompliance and GRCLast verified 17 Sep 2026
GDPR mark, CertReports state Vendor-stated as of 17 Sep 2026Vendor-stated

A-LIGN and GDPR

A-LIGN states it holds a data processing agreement. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states GDPR on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
A-LIGN trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026GDPR
Live page Snapshotsha256 483add9552
VerifiedActive: EU-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
15 Jun 2020
Expires or valid through
6 Jul 2027
Scope
Personal data (such as names, date of birth, nationality, Social Security number or other national identification number; passport number; address, email, phone; health information; education and training‐related information; photographs and other personal information as required by law and company’s policies) is collected and processed about former, current and prospective A-LIGN personnel for the purposes of human resources administration and recruitment of employees. Personal data (such as a first and last name, phone number, email address, and other contact information) is also collected and processed regarding prospective and current clients and employees/agents of those clients for the purpose of rendering professional services to A-LIGN’s clients. Personal data may be processed in limited circumstances pertaining to the general public in order to respond to requests for information submitted via A-LIGN’s website. Should such a request be received from the general public, A-LIGN will use the personal data voluntarily provided via the website to reply providing the requested information or communication to the individual making the request. A-LIGN may share your Personal Data with our subsidiaries and affiliates. Furthermore, A-LIGN may, from time to time, disclose Personal Data about a user or an employee to other persons or entities that perform services on behalf of A-LIGN (“Service Providers”), in compliance with A-LIGN’s Privacy Policies. Unless A-LIGN informs a user or an employee otherwise, a service provider does not have any right to use the Personal Data A-LIGN provides to them beyond what is necessary to assist A-LIGN, or in response to a legal obligation including without limitation a subpoena, court order or A-LIGN believes that the law requires disclosure, or where the information is currently in the public domain. Upon lawful requests by public authorities, governmental agencies, law enforcement agencies, or other third parties in order to comply with any law, court order, legal request, or other legal process, including to meet national security or law enforcement requirements, A-LIGN may disclose Personal Data as required by law. A-LIGN does not and will not sell, share or rent Personal Data to anyone in exchange for monetary compensation. We may disclose Personal Data of users by allowing certain third parties (such as online advertising services, advertising networks and social networks) to collect Personal Data via automated technologies on A-LIGN websites for cross-context behavioral advertising purposes. A-LIGN may sell or share for cross-context behavioral advertising purposes the following categories of personal information about its users to online advertising services, advertising networks and social networks: identifiers, online activity and inferences as described in A-LIGN’s California Consumer Privacy Statement representing an Attachment to A-LIGN’s Privacy Policy. A-LIGN does not sell or share (for cross-context behavioral advertising purposes) personal information about employees and HR Covered Individuals. SMS consent and phone numbers will not be shared with third parties or affiliates for marketing purposes.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026A-LIGN Compliance and Security, Inc.: Active: EU-US Certification, UK Extension Certification
Live pagesha256 35a7e20da1
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is A-LIGN GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Compliance and GRC category) whose GDPR row is verified or vendor-stated, ranked by similarity.