Skip to main content
Cloudinary logo

Cloudinary

GDPR evidence

Cloudinary is a SaaS company providing cloud media management services for websites and apps

cloudinary.comMedia and contentLast verified 29 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Cloudinary and GDPR

CertReports found no public GDPR evidence for Cloudinary as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, UK Extension Certification, SW-US Certification
as of 29 Sep 2026 · confidence 100%
Kind
Listing
Issued or listed
15 Feb 2017
Expires or valid through
20 Jul 2027
Scope
Cloudinary processes personal data received in reliance on the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF for the purpose of providing its cloud-based media management and delivery services, customer support, account administration, security, and business operations. The categories of personal data processed may include, as applicable: • Customer account information (e.g., names, business email addresses, company name, account identifiers, billing contacts). • User account information (e.g., names, email addresses, usernames, authentication identifiers, user roles and preferences). • Technical and usage information (e.g., IP addresses, device and browser information, log data, audit records, API usage information, cookies and online identifiers). • Customer content and associated metadata uploaded to the Cloudinary platform, which may contain personal data depending on the customer's use of the service. • Customer support communications and related information. • Human Resources (HR) data relating to Cloudinary employees and job applicants, where applicable. Cloudinary processes this personal data for the following purposes: • Providing, operating, maintaining, and securing the Cloudinary platform and related services. • Authenticating users and managing customer accounts. • Processing and delivering customer media assets. • Providing customer support and responding to service requests. • Monitoring, maintaining, and improving the security, availability, and performance of the platform. • Complying with applicable legal, regulatory, and contractual obligations. • Managing employment and recruitment activities, where applicable. Cloudinary may disclose personal data to trusted third-party service providers and subprocessors that assist in delivering its services, including providers of cloud infrastructure, content delivery networks (CDNs), customer support, monitoring and logging, communications, analytics, payment processing, and other operational services. Such disclosures are made only where necessary to provide the services and are subject to appropriate contractual obligations, including data protection and confidentiality requirements. A current list of Cloudinary's subprocessors is maintained and available to customers through Cloudinary's Subprocessor List.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
29 Sep 2026Cloudinary Inc.: Active: EU-US Certification, UK Extension Certification, SW-US Certification
Live pagesha256 c9a7073dcc
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Cloudinary GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 29 Sep 2026First indexed by CertReports2 evidence rows across 2 frameworks entered the index.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Media and content category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Media and content vendor has GDPR evidence in the index yet.

All articles