
Deloitte and GDPR
CertReports found no public GDPR evidence for Deloitte as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 21 Nov 2016
- Expires or valid through
- 30 Oct 2026
- Scope
- We process personal information regarding current, former, and prospective partners, principals and employees in connection with the personnel relationship, such as the administration of that relationship. We process personal information regarding clients and their personnel and customers in connection with the client relationship, such as the delivery of professional services and the administration of the client relationship. We process personal information regarding third parties (such as service providers and contractors) and their personnel in connection with the management and administration of the business relationships with the third parties. We disclose personal information to third party service providers in connection with the operation of our business, including our provision of services to clients and our administration of our Personnel and business relationships.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Deloitte LLP: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 a940703509 |
- Kind
- listing
- Issued or listed
- 31 Oct 2016
- Scope
- DTTS provides services to other legal entities within the Deloitte network of member firms. These entities include Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee ('DTTL'), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. In the context of providing these services, DTTS may process personal information pertaining to employees, clients or other third parties associated with these Deloitte entities as a data processor. DTTS uses personal information regarding third parties (such as service providers and contractors) and their employees in connection with the management and administration of the business relationships with such third parties. DTTS may process personal information received from the EEA, the United Kingdom and Switzerland in the employment context. DTTS may disclose personal data to third party service providers in connection with the provision of the applicable service.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Deloitte Touche Tohmatsu Services, Inc: Inactive | Live pagesha256 6f3e609b22 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Deloitte GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Business services category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Business services vendor has GDPR evidence in the index yet.