
Drata and GDPR
Drata states it holds a data processing agreement. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- listing
- Issued or listed
- 5 May 2022
- Expires or valid through
- 14 Apr 2027
- Scope
- [Non-HR Data] Drata provides a software-as-a-service platform that our enterprise customers use to manage the governance, risk and compliance aspects of their businesses. In providing this platform, Drata processes data our customers submit to our services or instructs us to process on their behalf. While Drata's customers decide what data to submit, it typically includes information about their governance, risk and compliance programs, and contact information and billing information. Drata uses certain third-party service providers (“sub-processors”) to assist us in providing our services to customers. These third parties may access, process, or store personal data in the course of providing their services. Drata maintains contracts with these third parties restricting their access, use and disclosure of personal data in compliance with our Data Privacy Framework obligations. In addition, Drata processes personal data about EEA, UK and Swiss website visitors and EEA, UK and Swiss business contacts to provide the services requested, conduct business related tasks and to communicate with these individuals. Drata may disclose personal data to Drata's other corporate entities, third party service providers, partners and other related entities. [HR Data] Drata processes personal data about EEA, UK and Swiss employees and job applicants to manage all aspects of the employment relationship in compliance with our Data Privacy Framework obligations. Drata may disclose personal data to Drata's other corporate entities, third party service providers and government entities. Drata’ Privacy Notice for Drata Employment Candidates is provided on Drata’s website and describes how Drata collects, uses, discloses, transfers, and stores personal data as part of our recruitment process.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Drata: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 b68827d007 |
- Kind
- listing
- Issued or listed
- 24 May 2017
- Scope
- VoiceThread is an online service that allows users to share and discuss digital media. The basic service structure is similar to wiki platforms or blogging platforms. Users upload media that we store and then distribute and make available to whomever the user determines should have access to it. The audience for that media is then given an opportunity to make comments about the media asynchronously, and a conversation takes place over time. VoiceThread collects first name, last name, and email address. These items are used to provision user accounts and identify them when they create content. Users may opt to go by an alias rather than real first and last name. VoiceThread utilizes Amazon Web Services as a datacenter, but user information is not shared with any other third party.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | VoiceThread: Inactive | Live pagesha256 02e7063213 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Drata GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026Subprocessor added: Description of ServicesDescription of Services appeared on the subprocessor list.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Compliance and GRC category) whose GDPR row is verified or vendor-stated, ranked by similarity.
Vanta
Compliance and GRC
Vanta—the proven leader in automated compliance helping startups…
Diligent
Compliance and GRC
Sim
AI infrastructure
The AI Workspace for Building and Managing AI Agents.
A-LIGN
Compliance and GRC