
CleanDNS and GDPR
CertReports found no public GDPR evidence for CleanDNS as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 14 Dec 2023
- Expires or valid through
- 22 Jul 2027
- Scope
- CleanDNS is the provider of and anti-abuse service intended for DNS operators as well as other clients related to the field of Internet services such. as domain names, hosting services or law enforcement entities who work in this field. Our system ordinarily may process personal data in the provision of the core services. This data may ordinarily include, registrant data of reported domains, client data (subscriber data) relating to other online services for which we provide anti-abuse monitoring for, reporter information relating to reports of DNS abuse, business/client contacts (POCs and other business necessary details). Our system may also conclude certain commentary and details relating to the observed and evidenced use of domains that may be considered personal data. This data is held for the investigation and escalation of reported instances of abuse, with a view to remediation and disruption of such abuses. CleanDNS also has employees located within the EEA and UK, as such we will also process data relating to such employees, in the context of Human Resources actions. Disclosure of Data (as Controller) Where CleanDNS is acting as Controller, notwithstanding any legal or related obligations, we may disclose data in the context of carrying out the obligations of our various contracts: - In our role as employer to carry out any obligations, or provide any benefits as may be agreed under our contracts; - in the carrying out of any obligations with our contractors as per the terms of our contract agreements; or - Disclosure of CleanDNS Sinkhole data. As noted, CleanDNS does maintain a sinkhole infrastructure that collects data on web and DNS traffic relating to domains redirected to that sinkhole, as result of a connected assessed and actioned DNS Abuse (or other online harm as may be applicable). Although the vast majority of sinkhole data is considered to be non-PII, however, PII such as may be included in such webtraffic (e.g. IP addresses, cookie information) shall also be collected. For the avoidance of doubt, Sinkhole data (including PII were applicable) may disclosed to third parties (e.g. law enforcement, security researchers, academia, anti-abuse service providers or similar entities). This data shall however only be disclosed for the purpose of investigation, mitigation and disruption of online harms, or for other lawful purposes, consistent with applicable law. Disclosure of Data (as Processor) Where CleanDNS is acting as Processor, notwithstanding any legal or related obligations, we shall only disclose data as per the instructions of the Controller. General Disclosure We may also disclose Personal Information and/or non-personally-identifiable information if required to do so by law, or in the good faith belief that such action is necessary to comply with state and federal laws or respond to a court order, subpoena, or search warrant. CleanDNS reserves the right to disclose Personal Information and/or non-personally-identifiable information that CleanDNS believes, in good faith, is appropriate or necessary to take precautions against liability, to investigate and defend itself against any third-party claims or allegations, to assist government enforcement agencies, to protect the security or integrity of our Website, and to protect the rights, property, or personal safety of CleanDNS, our users or others.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | CleanDNS: Active: EU-US Certification, UK Extension Certification, SW-US Certification | Live pagesha256 9d97822a38 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is CleanDNS GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.