Skip to main content
Drata logo

Drata

GDPR evidence

drata.comCompliance and GRCLast verified 17 Sep 2026
GDPR mark, CertReports state Vendor-stated as of 17 Sep 2026Vendor-stated

Drata and GDPR

Drata states it holds a data processing agreement. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states GDPR on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Drata trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026GDPR
Live page Snapshotsha256 cc367178b7
VerifiedActive: SW-US Certification, EU-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
5 May 2022
Expires or valid through
14 Apr 2027
Scope
[Non-HR Data] Drata provides a software-as-a-service platform that our enterprise customers use to manage the governance, risk and compliance aspects of their businesses. In providing this platform, Drata processes data our customers submit to our services or instructs us to process on their behalf. While Drata's customers decide what data to submit, it typically includes information about their governance, risk and compliance programs, and contact information and billing information. Drata uses certain third-party service providers (“sub-processors”) to assist us in providing our services to customers. These third parties may access, process, or store personal data in the course of providing their services. Drata maintains contracts with these third parties restricting their access, use and disclosure of personal data in compliance with our Data Privacy Framework obligations. In addition, Drata processes personal data about EEA, UK and Swiss website visitors and EEA, UK and Swiss business contacts to provide the services requested, conduct business related tasks and to communicate with these individuals. Drata may disclose personal data to Drata's other corporate entities, third party service providers, partners and other related entities. [HR Data] Drata processes personal data about EEA, UK and Swiss employees and job applicants to manage all aspects of the employment relationship in compliance with our Data Privacy Framework obligations. Drata may disclose personal data to Drata's other corporate entities, third party service providers and government entities. Drata’ Privacy Notice for Drata Employment Candidates is provided on Drata’s website and describes how Drata collects, uses, discloses, transfers, and stores personal data as part of our recruitment process.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Drata: Active: SW-US Certification, EU-US Certification, UK Extension Certification
Live pagesha256 b68827d007
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
24 May 2017
Scope
VoiceThread is an online service that allows users to share and discuss digital media. The basic service structure is similar to wiki platforms or blogging platforms. Users upload media that we store and then distribute and make available to whomever the user determines should have access to it. The audience for that media is then given an opportunity to make comments about the media asynchronously, and a conversation takes place over time. VoiceThread collects first name, last name, and email address. These items are used to provision user accounts and identify them when they create content. Users may opt to go by an alias rather than real first and last name. VoiceThread utilizes Amazon Web Services as a datacenter, but user information is not shared with any other third party.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026VoiceThread: Inactive
Live pagesha256 02e7063213
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Drata GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  2. 17 Sep 2026Subprocessor added: Description of ServicesDescription of Services appeared on the subprocessor list.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Compliance and GRC category) whose GDPR row is verified or vendor-stated, ranked by similarity.