
DigiCert and GDPR
CertReports found no public GDPR evidence for DigiCert as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 28 Jun 2018
- Expires or valid through
- 24 Apr 2027
- Scope
- DigiCert uses personal information to provide ordered services and inform email subscribers about new products and services. DigiCert uses personal information to verify customers before providing them with certificate services. Verification information is obtained directly from the customer and from third party databases. Some of this information is embedded directly in an issued certificate. Embedded information is required for the certificate to function properly. Email subscribers may opt out of receiving future promotional communication from DigiCert at any time. DigiCert uses name, organization, email, phone number, address, and credit card information. DigiCert discloses credit card information to payment processors and banks. DigiCert also collects and processes personal data of employees of DigiCert-affiliated entities in the EEA and Switzerland, in order to streamline and manage personnel operations and to provide services for and oversight of DigiCert-affiliated employees in the EEA and Switzerland. Such personal data includes data necessary to maintain an employment relationship, which data are specifically listed in DigiCert's Employee Privacy Notice.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | DigiCert, Inc.: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 ebd97320c5 |
- Kind
- listing
- Scope
- Rapid Web Services collects names, email addresses, mailing addresses, phone numbers, credit card information, IP address, browser information and cookies for our site. Rapid Web Services uses this information to provide ordered services, including digital certificates and related products, as part of agreements with our partners, which are the Certificates Authorities that issue digital certificates, and the end user or reseller purchasing them. We use the data to market related products and services to customers, as well as to administer our reseller program.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Rapid Web Services, LLC: Inactive | Live pagesha256 b21df03098 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is DigiCert GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.