
ALL4 and GDPR
CertReports found no public GDPR evidence for ALL4 as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 21 Mar 2025
- Expires or valid through
- 16 Mar 2027
- Scope
- ALL4 processes personal data under the following lawful bases, aligned with both GDPR and DPF requirements: • Contractual Necessity: To fulfill contractual obligations with employees, contractors, and clients. • Legitimate Interest: Pursuing business interests (e.g., IT security, client relationship management) in ways that do not override individuals’ fundamental rights and freedoms. • Legal Obligation: Complying with applicable employment, tax, health and safety, and data protection laws. • Consent: Where individuals have given explicit permission, such as for marketing communications or the processing of sensitive personal data. Consent may be withdrawn at any time. • Pre-Contractual Steps: Processing necessary to evaluate job applicants prior to entering an employment contract. Personal Data Processed: • Contact and Identifying Information (name, address, phone, email, date of birth, gender, nationality, government-issued identifiers, emergency contacts) • Financial Data (bank account details, payroll records, tax information) • Employment Records (salary, benefits, job titles, performance reviews, training records) • Technical/Usage Data (IP address, login data, system usage logs) • Candidate/New Hire Data (resumes, background checks, right-to-work documents) • Website/Email Contacts (inquiries, marketing subscription preferences) Third Parties Receiving Data: • Enterprise IT providers (Microsoft 365, Box, Deltek ERP, Concur travel) • Security providers (Sophos XDR/MTR, DarkTrace, ProofPoint) • Marketing providers (Mailchimp for email marketing) • Insurance brokers (Brown & Brown, Highmark) • Government authorities (tax agencies, as legally required) • Professional advisers (legal counsel, auditors)
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | ALL4: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 e05dc1c445 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is ALL4 GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Compliance and GRC category) whose GDPR row is verified or vendor-stated, ranked by similarity.