Skip to main content
ALL4 logo

ALL4

GDPR evidence

all4inc.comCompliance and GRCLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

ALL4 and GDPR

CertReports found no public GDPR evidence for ALL4 as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
21 Mar 2025
Expires or valid through
16 Mar 2027
Scope
ALL4 processes personal data under the following lawful bases, aligned with both GDPR and DPF requirements: • Contractual Necessity: To fulfill contractual obligations with employees, contractors, and clients. • Legitimate Interest: Pursuing business interests (e.g., IT security, client relationship management) in ways that do not override individuals’ fundamental rights and freedoms. • Legal Obligation: Complying with applicable employment, tax, health and safety, and data protection laws. • Consent: Where individuals have given explicit permission, such as for marketing communications or the processing of sensitive personal data. Consent may be withdrawn at any time. • Pre-Contractual Steps: Processing necessary to evaluate job applicants prior to entering an employment contract. Personal Data Processed: • Contact and Identifying Information (name, address, phone, email, date of birth, gender, nationality, government-issued identifiers, emergency contacts) • Financial Data (bank account details, payroll records, tax information) • Employment Records (salary, benefits, job titles, performance reviews, training records) • Technical/Usage Data (IP address, login data, system usage logs) • Candidate/New Hire Data (resumes, background checks, right-to-work documents) • Website/Email Contacts (inquiries, marketing subscription preferences) Third Parties Receiving Data: • Enterprise IT providers (Microsoft 365, Box, Deltek ERP, Concur travel) • Security providers (Sophos XDR/MTR, DarkTrace, ProofPoint) • Marketing providers (Mailchimp for email marketing) • Insurance brokers (Brown & Brown, Highmark) • Government authorities (tax agencies, as legally required) • Professional advisers (legal counsel, auditors)
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026ALL4: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 e05dc1c445
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is ALL4 GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Compliance and GRC category) whose GDPR row is verified or vendor-stated, ranked by similarity.