CalAmp and GDPR
CertReports found no public GDPR evidence for CalAmp as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 12 Aug 2024
- Expires or valid through
- 6 Aug 2027
- Scope
- Types of Personal Data In the context of providing services to business customers, CalAmp collects and processes certain data. Categories of data CalAmp processes are the following: • Personal and identification data (name, date of birth, place of birth, nationality, tax code, VAT number); • Contact data (address, e-mail address, IP address and telephone number); • Data required for the management of administrative, accounting, tax and financial processes; • Data of a vehicle on which the services are provided for: • Characteristics of the vehicle (model, number plate and any similar data); • GPS position of the vehicle in real time; • Vehicle routes, km/miles, travel speed, stopping times; • Vehicle status in real time (fuel and/or battery level, in the case of electric or hybrid vehicles, opening or closing of windows, doors, boot and bonnet, operation of the audible alarm system and engine immobilisation, if any, vehicle movement without the Customer's recognition device, removal of the vehicle's battery connection and any other similar vehicle data). Collection Purposes The purposes for which we collect and use personal data include: • Theft management and recovery of stolen vehicles; • Telematics services (including but not limited to: continuous position tracking with the car running, alert message to the customer in the event of unauthorised movement, information on speed, acceleration, average km travelled, driving data, distance travelled and hard braking, collection of further statistical analysis on vehicle use and accessories); • Management of administrative, accounting, tax and financial processes; • Protection of contractual rights and defence/exercise of rights in court (including related prodromal activities); • Management of subscribers and renewal of subscriptions when they expire; • Service/maintenance management resulting from technical problems with the device; • Welcome call in LoJack activities and further data entry; • Participation in surveys and questionnaires; • Marketing activities, i.e. sending of informative and promotional newsletters. Disclosure of personal data CalAmp may share personal data with third party vendor or service providers, including payment processors, data hosting providers, analytics providers, that process the data on our behalf for the purposes set forth in this Statement. We may also offer training or other services to the employees and workers of our business customers. In such cases, we may share personal data relating to the use of our training and other services with the identified business customers for their business use. We may also share personal data with third parties such as professional advisors or banks and accountants, as permitted or required by law or in the interest of protecting or exercising our or others’ legal rights, e.g., without limitation, in connection with requests from law enforcement officials and in connection with court proceedings. We may share or transfer personal data in connection with a prospective or actual sale, merger, transfer or other reorganization of all or parts of our business. Finally, we may also share personal data where you have granted us permission.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | CalAmp: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 1987faf1e2 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is CalAmp GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the IoT and devices category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No IoT and devices vendor has GDPR evidence in the index yet.