Skip to main content
Carta logo

Carta

GDPR evidence

Carta’s ERP for private capital combines software and services to deliver connected clarity and control across equity, fund and portfolio

carta.comFinance and accountingLast verified 29 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Carta and GDPR

CertReports found no public GDPR evidence for Carta as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: SW-US Certification, UK Extension Certification, EU-US Certification
as of 29 Sep 2026 · confidence 100%
Kind
Listing
Issued or listed
11 Jul 2018
Expires or valid through
7 Nov 2026
Scope
Carta, Inc. (eShares, Inc. DBA Carta, Inc.) and its global subsidiaries rely on the EU-U.S. Data Privacy Framework (DPF), the UK Extension, and the Swiss-U.S. DPF for the transfer of personal data from the European Union, United Kingdom, and Switzerland to the United States. Carta is subject to the authority and enforcement powers of the U.S. Federal Trade Commission. The certification covers both HR and non-HR personal data collected in the course of Carta’s business activities. Carta processes personal data relating to customers, clients, investors, employees, and website visitors. The information is collected from individuals, their employers or investment entities, service providers, and automatically through Carta’s online services. The data includes identifiers such as names, contact details, and government-issued IDs; financial and transaction information; professional and employment details; internet activity and geolocation data; demographic information; personal records; audio or visual content; and derived inferences used to improve user experience. Carta uses this information to operate and enhance its services, manage relationships, meet contractual and legal obligations, provide service updates, ensure security and fraud prevention, comply with regulatory requirements, and, where permitted, conduct marketing and targeted advertising with notice and opt-out options. Carta retains personal data only as long as necessary to meet these purposes or as required by law. Carta maintains administrative, technical, and organizational safeguards to protect personal data and to meet the DPF Principles of notice, choice, accountability for onward transfer, security, data integrity, access, and recourse. Carta shares personal data with service providers that support hosting, analytics, communications, and customer assistance; with business clients and their authorized representatives; with financial technology partners such as Plaid Technologies, Inc.; with advertising and social media companies such as Google and Meta; with affiliates, professional advisers, and parties to business transactions; and with public authorities when required by law. Carta requires all third parties processing personal data on its behalf to provide equivalent protection consistent with the DPF Principles. Individuals whose personal data are processed under the DPF may exercise their rights to access, correct, delete, or limit use of their information.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
29 Sep 2026Carta, Inc.: Active: SW-US Certification, UK Extension Certification, EU-US Certification
Live pagesha256 3a8417c7a4
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Carta GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 29 Sep 2026First indexed by CertReports1 evidence row across 1 framework entered the index.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Finance and accounting category) whose GDPR row is verified or vendor-stated, ranked by similarity.

All articles