
FusionAuth and GDPR
CertReports found no public GDPR evidence for FusionAuth as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 22 Sep 2025
- Expires or valid through
- 1 Sep 2027
- Scope
- FusionAuth collects and processes personal information in two distinct ways: through our website and marketing activities, and through our FusionAuth Product for customers who use our identity management services. Website and Marketing Data Collection When you visit our website, register for an account, place orders, subscribe to newsletters, or fill out forms, we collect information such as your name, email address, mailing address, phone number, and payment details. We also automatically collect browsing data through cookies and tracking technologies to understand how visitors use our website. We use this information to process your transactions, personalize your experience, provide customer support, send marketing communications, and maintain website security. Your data helps us deliver relevant content, improve our services, and administer promotions or surveys. FusionAuth Product Data Collection The FusionAuth Product collects information only in the exact manner that you specify through our APIs and web interfaces. You have complete control over what information is collected and stored, and you can delete any information permanently at any time. The FusionAuth Product uses cookies solely to manage sessions for web application interfaces and store identity data including JWTs and refresh tokens. These cookies are never shared with third parties, and FusionAuth employees never have access to cookies generated by our products. Payment Data Handling All payment transactions are processed through secure third-party gateway providers and are not stored or processed on our servers. This ensures your payment information receives additional security protection through specialized payment processors. How We Use Product Data FusionAuth does not process any information stored in the FusionAuth Product for business use unless you specifically instruct us to do so. Data stored in the product may be used internally only to provide you with support or enhancements, following industry best practices for security. Data Protection We protect all information through encrypted networks with restricted access and TLS v 1.2 or newer encryption for sensitive data. All transactions are processed securely through third-party payment gateways. While we work with advertising and analytics partners who may collect data through tracking technologies on our website, we do not sell, trade, or transfer any personally identifiable information to outside parties. You can control cookie preferences through your browser settings, and we regularly scan our systems for security vulnerabilities to keep your information safe.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | FusionAuth: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 a2dd7ee1f8 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is FusionAuth GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Identity and access category) whose GDPR row is verified or vendor-stated, ranked by similarity.