Cerner and GDPR
CertReports found no public GDPR evidence for Cerner as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Scope
- Cerner, as a data controller, collects and processes personal data relating to its clients, vendors, partners and associates. Personal data collected from clients, vendors and partners and processed by Cerner is limited to what is necessary in the business relationship, e.g. name, contact details, payment records, contracts and business correspondence. Where Cerner, as a data controller, receives, holds, and processes personal data from employees of Cerner's wholly-owned European subsidiaries, which are transferred to Cerner Corporation in the U.S. for purposes of human resource administration the processing of such data is subject to Cerner's HR Privacy Policy. In addition, Cerner's goal is to provide its global clients, partners and associates with a personalized Internet experience and an Internet-based online information and communication service that delivers the information, resources and services that are most relevant and helpful to its users. In order to achieve these goals, Cerner collects and processes personal data from users during visits to its Web sites and, in particular, during a user's visits to cerner.com and/or ucern.com. As a consequence, Cerner may process personal data from clients, partners and associates also within the EEA while providing website services such as an Internet based communication platform for professionals to connect to each other. Cerner's collection and use of personal data varies based on the website services requested by the users and the users' choice of privacy options within the relevant website services For EEA users of Cerner's website, the principles set out in Cerner's Privacy Policy also apply: http://www.cerner.com/Privacy/. Second, as a "data processor" Cerner processes personal data for its clients who are data controllers. In this capacity, Cerner does not own or determine the purposes for which it processes the personal data. Cerner's clients, as a data controllers, collect the data and determine the purpose for which it is processed. Cerner receives and processes personal data for and at the instruction of its client, and in such circumstances Cerner has no direct relationship with the individuals to whom such personal data relates. As a data processor acting on behalf of a Cerner client who is the data controller, Cerner is required to perform its services in accordance with the Data Privacy Framework Principles and its contract with the client together with any data privacy protections incorporated therein. Cerner, however, is otherwise dependent upon its client, the data controller, to comply with applicable EEA data protection laws at the time that the personal data is originally collected or received by the client. As a manufacturer of clinical and management information systems, Cerner assists its clients worldwide in the implementation and support of Cerner solutions in their healthcare institution(s). Since Cerner provides implementation and support for different healthcare institutions, Cerner may receive, hold, and process personal data from clients within the EEA, including client employee name, work role, email, telephone number, work address, etc. and any patient data provided by clients for the purpose of troubleshooting specific computer system hardware and software problems and issues in accordance with business and/or service agreements. Cerner also provides managed services such as remote hosting, remote system monitoring, disaster recovery, data warehousing and application management services, in which it may act as the custodian of patient health information for certain clients. With these offerings, Cerner not only has access to provider-based personal health information, but also performs many of a provider's custodial duties as well.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Cerner Corporation: Inactive | Live pagesha256 0ea63eb613 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Cerner GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the EHR and practice management category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No EHR and practice management vendor has GDPR evidence in the index yet.