Skip to main content
Braze logo

Braze

GDPR evidence

braze.comMarketingLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Braze and GDPR

CertReports found no public GDPR evidence for Braze as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
24 Oct 2018
Scope
Braze, Inc (hereinafter ‘Braze’) is a ‘Software as a Service’ U.S. company, headquartered in New York, with global operations. Braze is a life-cycle engagement platform for companies around the world ("Customers"), supporting stronger relationships between brands and their clients (“End Users”). This is done primarily by leveraging first party data to personalize and automate lifecycle marketing campaigns through first party channels, such as email, mobile and web push notifications, and in-app/in-browser messaging. In practical terms, this means that Braze’s Customers collect information from their End Users, which Braze then processes on behalf of its Customers within its platform. Braze’s Customers are able to customize their messages to such End Users of the Customer’s application, including marketing messages, that such End Users may find useful. Braze acts as both a “Data Controller”, where it determines the purposes and means of the processing of personal information collected by Braze for its own business use of such information, and as a “Data Processor” where personal information of Braze’s Customers’ End Users is processed within the Braze Services on behalf of such Customers. In offering the Braze Services to Customers, and its broader business operations (such as recruitment, employee management, procurement and marketing), Braze collects and processes personal data from a variety of types of data subjects. This includes the following: (1) Human Resources data from Braze’s EU, UK and Swiss employees. This data may be disclosed to various third parties including company service providers, employee service providers, law enforcement, corporate transaction participants, professional advisors, Customers, prospects and partners. (2) Data from EU, UK and Swiss data subjects, including job candidates, (email address, name, etc.) collected from website, events, and/or through other activities from Braze’s prospects, customers and vendors. This data may be disclosed to various third parties including company service providers, government authorities and law enforcement, corporate transaction participants, professionals advisors, Braze affiliates, partners, vendors and shared communities. (3) All data and information (including all personal data contained therein) submitted to or collected by the Braze Services, processed by Braze in connection with its provision of the Braze Services to its customers. This personal data is shared with the Braze sub-processors that can be found at braze.com/subprocessors.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Braze, Inc.: Inactive
Live pagesha256 58810c7a77
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Braze GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Marketing category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Marketing vendor has GDPR evidence in the index yet.