
Check Point Software Technologies and GDPR
CertReports found no public GDPR evidence for Check Point Software Technologies as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 18 Jun 2024
- Scope
- Check Point US process the following types of personal data: customer’s data, visitor’s data, and HR data. Check Point US may engage third-party Sub-processors in connection with the provision of the Check Point products and services. The list of Sub-processors is available at Check Point’s website (currently at: www.checkpoint.com/sub-processors-list/). Check Point US process personal data for the following purposes: • for ongoing review and improvement of the information provided on Check Point Websites to ensure they are user friendly and to prevent any potential disruptions or cyberattacks; • to allow Check Point’s customers to use and access the functionality provided by the Check Point Products and the Check Point Services; • to assess application for Check Point Products and Check Point Services, where applicable; • to set up customers to use Check Point Products and Check Point Services; • to set up users to use the User Center; • to conduct analysis required to detect malicious data and understand how this may affect customers IT systems; • for statistical monitoring and analysis of current attacks on devices and systems and for the on-going adaptation of the solutions provided to secure devices and systems against current attacks; • to understand feedback on Check Point Products and Check Point Services and to help provide more information on the use of those products and services quickly and easily; • to communicate with Check Point’s customers in order to provide them with: (i) Check Point’s Services; (ii) information about Check Point and its Services; or (iii) offers and marketing information; • to send Check Point’s customers e-mail updates on the latest cyber security trends, news, upcoming events and other marketing or promotional materials; • for in-depth threat analysis; • to understand Check Point’s customers needs and interests; • for the management and administration of Check Point’s business; • for improvement of Check Point’s products and services. • to comply with and to assess compliance with applicable laws, rules and regulations, and internal policies and procedures; • for the administration and maintenance of databases storing Personal Data to market Check Point’s products and services; or • for back-up and data loss prevention. • to assess qualifications and suitability for employment of job applicants. • to facilitate employees onboarding, including administrative tasks such as payroll setup, benefits enrollment, and assigning access to internal systems and facilities. Additionally, HR data is used for ongoing employee’s management purposes, such as performance evaluations, training and more. • to comply with applicable employment laws and regulations. • to facilitate communications with both employees and job applicants. (iv) Attached is our revised privacy policy, based on your comments below.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Check Point Software Technologies, Inc.: Inactive | Live pagesha256 0ac907afb2 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Check Point Software Technologies GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.