GIGYA and GDPR
CertReports found no public GDPR evidence for GIGYA as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 24 Oct 2016
- Scope
- Our Gigya Privacy Policy covers personal information, e.g. email address, name, company name and address, phone number, we collect and process from visitors to our website, who voluntarily provide such information to find out more information about our Customer Identity Management Services (Services), register to attend a seminar, submit a form for marketing materials or email newsletters. We disclose such information to third parties for use in performing internal business functions (e.g. data hosting, surveys, email marketing, email transmission). Our Gigya Client Privacy Policy covers personal information,( e.g. company contact information such as name, email address, phone number, address), we collect and process from our Clients (customers) when they register for a Gigya Console account, become a customer of Gigya for the Gigya Services, contact us for customer service or otherwise interact with us and use our Services. We also collect personal information from visitors (end users) to our Clients' websites through our Clients' use of our Services. The type of personal information collected on behalf of our Clients' depends upon the particular Services to which the Client subscribes and their preferences. We use the Clients' personal information to provide our Services to the Client, for customer service purposes, to improve our services, research and analytic services and where, when permitted by law, to market products and services to the Client. We maintain no rights to use the end user personal information we collect on behalf of our Clients through the Services, except to make the Services available. We may disclose personal information we collect directly from the Client , personal information of end users we collect on behalf of our Clients, to third parties for their use in performing internal business functions (e.g. data hosting, email transmission, maintenance and security) on Gigya's behalf.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | GIGYA, INC.: Inactive | Live pagesha256 24568e6447 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is GIGYA GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Identity and access category) whose GDPR row is verified or vendor-stated, ranked by similarity.