Casepoint and GDPR
CertReports found no public GDPR evidence for Casepoint as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 24 Feb 2017
- Expires or valid through
- 24 Oct 2026
- Scope
- The primary purpose of collecting, receiving, and/or processing data from the EU, UK, or Switzerland would be in relation to our role as an eDiscovery/eDisclosure technology solution provider where Casepoint will process client/customer data as a processor or sub-processor (as applicable) on behalf of a Client/Customer (whether the controller or itself a processor acting on behalf of a third party controller). Casepoint may collect the following categories of sensitive Personal Data including but not limited to: race, religion, social status medical history, criminal history and the fact that the person suffered damages by a crime. When we collect sensitive Personal Data, we will obtain your opt-in consent where the EU-U.S. DPF requires, including if we disclose your sensitive Personal Data to third parties, or before we use your sensitive Personal Data for a different purpose than we collected it for or than you later authorized. Certain exceptions to our obligation to obtain affirmative opt-in consent to process sensitive personal data are where the processing is: (i) in the vital interests of the individual or another person; (ii) necessary for the establishment of legal claims or defenses; (iii) required to provide medical care or diagnosis; (iv) carried out in the course of legitimate activities by certain foundations, associations, or other non-profit bodies; (v) necessary to carry out employment law-related obligations; (vi) related to data made public by the individual. We process personal data for the following purposes: to provide our services, including with respect to billing, identification, and authentication, to contact and communicate with our clients regarding our services, to profile prospective clients, and to build our mailing list for information distribution (subject to legal requirements including opt-out options). Data subjects whose personally identifiable information we process include consumers, clients including individuals, law firms, companies and other legal persons, suppliers, business partners, job applicants, independent contractors, and employees.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Casepoint: Active: UK Extension Certification, EU-US Certification, SW-US Certification | Live pagesha256 6d85786447 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Casepoint GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Compliance and GRC category) whose GDPR row is verified or vendor-stated, ranked by similarity.