Skip to main content
Aura logo

Aura

GDPR evidence

aura.comSecurityLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Aura and GDPR

CertReports found no public GDPR evidence for Aura as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Scope
Aura provides AI-powered consumer digital security and protection services, including identity theft protection, credit and financial account monitoring, dark web monitoring, antivirus and device security, VPN, call, SMS and email fraud protection, and parental controls. Personal data processed in reliance on the DPF is customer, prospective customer, and website and app visitor data. Categories include: identifiers and contact data, including name, username, email address, telephone number, postal address, date of birth; government identifiers, including Social Security numbers (for identity protection products); billing and payment data; identity verification data; account and login credentials; communications, support and survey records; user-uploaded images and files; email content and metadata where email protection is enabled, excluding attachments; marketing, promotion and preference data, including demographic data such as age and gender; usage, device, diagnostic and approximate IP-derived location data; GPS-derived precise geo-location, child and family member account data where parental controls are used; and data received from third parties, including referrals, security and threat intelligence, business customer submissions, and publicly available records such as court records, home and auto title records, and dark web scan results. Aura processes this personal data to: (1) provide, maintain, troubleshoot and support the services, including AI and machine learning based monitoring, detection, analytics and insights that are integral to service delivery; (2) perform billing, payment processing and account administration; (3) communicate with users and prospective users about the services, updates and support requests; (4) promote, operate and improve the services, including administering co-branded offers and promotions, enabling interactive features, analyzing usage and engagement, and conducting threat, fraud and spam research; (5) carry out measurement, research and analytics, including development of new services; (6) advertise and market its services, including targeted advertising through cookies; (7) aggregate or de-identify data for research, product development, regulatory compliance and other legitimate business purposes; (8) prevent fraud, abuse, security incidents, and harm or liability to Aura and its users; and (9) comply with applicable law and legal process, enforce legal rights, and resolve disputes. Outputs generated by Aura's AI features are informational alerts and insights provided to the individual. Aura does not use them to determine eligibility for credit, insurance, housing, employment, healthcare or other services, and does not make automated decisions producing legal or similarly significant effects. Aura may disclose personal data covered by the DPF to the following types of third parties: cloud hosting and infrastructure providers; payment processors; identity verification, credit bureau and monitoring data providers; customer support and sales platforms; analytics providers; marketing and advertising providers; AI and machine learning service providers supporting Aura's AI features; corporate affiliates; co-branding and promotional partners; third-party account providers where an individual links an external account; other users with whom an individual chooses to share data, such as on family plans; administrators of business customer accounts; selected cybersecurity industry members receiving de-identified threat intelligence; professional advisers and parties to a corporate transaction; and law enforcement, regulators and other public authorities where legally required. This self-certification does not cover human resources data.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Aura: Inactive
Live pagesha256 e81470a77e
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Aura GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.