CDW and GDPR
CertReports found no public GDPR evidence for CDW as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 25 Oct 2017
- Expires or valid through
- 17 Jul 2027
- Scope
- The types of personal data processed include: • Names and titles of individuals associated with customer accounts; • Customer contact information such as postal addresses, e-mail addresses, and telephone numbers; • Billing and order information, including but not limited to customer ID numbers, order history, billing instructions, invoice information, bank and financial information (including credit card number); • Technical information relevant to information technology management, including but not limited to: user log data, Active Directory information, statistics of information systems administration, employee premises access logs, user IDs and passwords, help desk information, and customer satisfaction information; • Other information specific to the certain services provided by CDW to a particular customer, as specified in the contractual arrangements with such customer. • Social media information to interact with you on your social media accounts. • Information about employers to create user accounts. • Event information related to attending a CDW-related event. • Survey and contest information if you have taken one of our surveys or entered a contest. • Information relating to inquiries or other contacts you make with us. • Investment information related to CDW investors. • Log file data including your IP address, device operating system, application software, browser type, peripheral devices, language, user log and clickstream data, access times, Active Directory information and the websites you visited before/after ours. • Cookies and related technology data including your usage and activity on our online services. • Location data including your general geographic location based on your IP address or more precise location when accessing the website through a mobile device. CDW collects personal data only as necessary to provide its UK and EU customers with its technology products and services and manage its business. CDW processes personal data consistent with these purposes. CDW’s entities in the United States will not use personal data received under the Data Privacy Framework to directly market to individuals in the UK and/or EU. CDW will obtain consent before using any personal data received under the Data Privacy Framework for purposes different than those stated above. CDW may disclose personal data to third parties: • When CDW uses those third parties to provide the services requested by CDW’s corporate customer; • If CDW or any of its Data Privacy Framework-certified affiliates or substantially all of their assets are acquired by a third party; • When CDW has a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our Terms of Use or terms and conditions of supply and other agreements; or to protect the rights, property, or safety of CDW, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction. • CDW manages any third-party recipients of personal data from the UK and EU to ensure they provide protections consistent with the Data Privacy Framework Principles. Under the Data Privacy Framework, CDW remains responsible for how these third parties handle personal data CDW has received and transferred under the protection of the Data Privacy Framework. In addition, CDW is required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | CDW: Active: UK Extension Certification, EU-US Certification | Live pagesha256 fcc91b9881 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is CDW GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the IT management category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No IT management vendor has GDPR evidence in the index yet.