
Docebo and GDPR
CertReports found no public GDPR evidence for Docebo as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 15 Nov 2016
- Expires or valid through
- 30 Dec 2026
- Scope
- Name, business email, phone number/skype information on the marketing site and name, email address, physical address on the Docebo Platform. Docebo requires, as minimum mandatory information (metadata) about USERS at least a username, in a format that the Docebo customers can decide. This is the only mandatory datapoint in order to manage a USER RECORD in Docebo. The reason why a password is not considered a mandatory datapoint that Docebo hosts, is that Docebo may act as service provider and allow clients to authenticate through 3rd party systems, which will have the passwordinformation, stored. Docebo will also allow customers to create additional data fields. Such data fields are called in Docebo "custom fields". Such custom fields can be anything surrounding users information. Docebo however has no control over such fields as we do not monitor, and hold ourselves harmless, from the data appointed in such "custom fields". Additionally, The disclosure of personal information takes place to allow processing of customer payment via the third party service provider wirecard . The content of the information disclosed is limited to that information required to process customer payments (i.e. name, billing address, cc number, exp. date etc.). The customer understands at all times that such information is passed for the processing of such transaction.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Docebo NA, Inc.: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 0d111f2168 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Docebo GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Education category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Education vendor has GDPR evidence in the index yet.