
Abacus Data Systems and GDPR
CertReports found no public GDPR evidence for Abacus Data Systems as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 8 May 2018
- Scope
- As it relates specifically to Human Resources related information, Abacus Data Systems, Inc. and its subsidiaries (collectively “Abacus”) may collect personal data related to prospective, current and former employees. As it relates to prospective, current and former employees, Abacus only holds personal data which is directly relevant to the employee relationship. The following are examples of data which may be collected held and processed by Abacus: (1) Information contained in resumes; (2) information disclosed as part of background checks; (3) Identification information including, but not limited to, names and contact details; (2) Equal opportunities monitoring information including age, gender, race, nationality and religion; (4) Special Category Information including details of sick leave, medical conditions, disabilities and prescribed medication; (5) Employment records including, but not limited to, interview notes, curricula vitae, application forms, assessments, performance reviews and similar documents; (6) Details of salaries including increases, bonuses, commission, overtime, benefits and expenses; (7) Records of disciplinary matters including reports and warnings, both formal and informal; and (8) Details of grievances including documentary evidence, notes from interviews, procedures followed and outcomes. Abacus Data Systems, Inc. and its subsidiaries (collectively “Abacus”) collect personal data related to prospective, current and former customers, vendors, partners, resellers and website visitors for the purposes of providing relevant Abacus products or services. Abacus uses personal data in connection with products and services primarily for: (1) enabling and providing the requested product or service; (2) customer service activities, including processing orders, providing technical support, and customizing and improving Abacus products and offerings; (3) sales and marketing activities and customer relationship management; and (4) internal business processes and management, crime/fraud detection and prevention, security, and compliance with governmental, legislative, and regulatory requirements. Information we collect includes name, email address, billing information, phone number, and IP address and statistics concerning activities on our websites, mobile apps and products. We may share such data with third parties who provide us with billing, marketing, and account management tools. In addition, as a service provider (data processor) to its clients (data controllers), Abacus may be in possession of client data that contains information defined as personal data. In performing these services, Abacus does not process, store, or handle personal data in any other manner other than that directed by the primary data controller. Accordingly, Abacus does not share, uniquely identify, or in any way use personal data for any commercial purpose other than that defined by the controller. In some cases, in accordance with our client agreements, we may disclose Personal Data with a subcontractor contracted to provide services on our behalf, in order to provide service to our clients.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Abacus Data Systems, Inc.: Inactive | Live pagesha256 6c2492ec69 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Abacus Data Systems GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Legal tech category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Legal tech vendor has GDPR evidence in the index yet.