The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
Docebo’s AI-powered LMS helps world-class organizations train employees, partners, and customers on a unified
For each regulation, how many of the requirements it places on your vendors Docebo’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
18 documents listed on Docebo’s trust centre
trust.docebo.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where Docebo store Customers' data?
“Customers are free to choose where their data will be stored based on the AWS location of their preference from the list of AWS Data Center made available by Docebo. All customer data will be stored and processed in that environment. Docebo's AWS data centers are available in: USA, Europe, Canada, Australia, and India. Some residual data may be processed outside the chosen ASW environment by Docebo's sub processor...”
Regions named: EU, US, Canada, Australia, Indiaas of 21 Sep 2026Source
Where data is hosted or processed
Docebo Data Centers Physical Security
“Docebo's Services relies on AWS data centers that are ISO 27001, PCI DSS Service Provider Level 1-, and SOC 2 compliant. AWS infrastructure services include backup power, HVAC systems, and fire suppression equipment to help protect servers and, ultimately, your data. AWS on-site security includes several features such as security guards, fencing, security feeds, intrusion detection technology, and other security m...”
as of 21 Sep 2026Source
International data transfers
How does Docebo protect customer data transferred outside of the EU or UK?
“To enable transfers of customer personal data to its sub-processors located outside the EU and UK, Docebo alternatively relies on: (i) Data Privacy Framework, (ii) EU and UK adequacy decisions, or (iii) alternative transfer mechanisms, including Standard Contractual Clauses. We have also prepared a robust transfer impact assessment (“TIA”) document to describe the legal, technical, and organizational measures adop...”
Regions named: EU, UKas of 21 Sep 2026Source
Encryption
Docebo Encryption Standards In transit and at Rest
“Encryption in Transit: All communications with Docebo Services and APIs are encrypted via industry-standard HTTPS/TLS (TLS 1.2 or higher). This ensures that all traffic between you and Docebo is secure during transit. Additionally, for email, our product leverages opportunistic TLS by default. Transport Layer Security (TLS) encrypts and delivers email securely, mitigating eavesdropping between mail servers where p...”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.