GoTo and GDPR
CertReports found no public GDPR evidence for GoTo as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 5 Dec 2016
- Expires or valid through
- 7 Apr 2027
- Scope
- When we act as a controller of personal data, we collect it for the purposes disclosed in our privacy notice. These purposes may vary by data subject type and include the following: to prepare to enter into, to enter into , and to perform contracts with data subjects; to operate our business; to conduct research on new products, services, and markets; to provide information that may be of interest to data subjects; for security, integrity, safety, and fraud prevention purposes; to comply with applicable law; to comply with legal and administrative requests; to protect our rights; to assess compliance with policies; and to assert and defend against legal claims. The type of data we collect and further process is also disclosed in our privacy notice, may vary by data subject type, and includes identifiers; commercial and financial information; professional or employment-related information; education history; protected characteristics, including sensitive personal data (where required and in compliance with applicable law); internet or other electronic network activity information; audio, electronic, visual or similar information; inference, preferences, and other information. We disclose personal data to third parties as disclosed in our privacy notice. These parties may vary by data subject and purpose, and include our affiliates; to third parties with notice or consent if required; to service providers, advisors, or consultants who provide services to us; to third parties in connection with corporate transactions such as mergers, divestitures, or financing or restructuring transactions; and to third parties as required by law or to pursue or defend legal claims. When we act as a processor of personal data, we collect information to provide, operate, improve, and support the GoTo services for customers and their users/attendees. The type of data processed varies by service and may include first name, last name, email address, authentication information, credit card or other billing information required for processing payments, and information generating arising from participation in the services. Personal data may also be processed as needed to provide communication, security, and diagnostics for service improvement. Personal data may be disclosed to trusted third parties which provide service to us or otherwise support the provision of the services to customers. We may also disclose personal data to third parties in connection with corporate transactions such as mergers, divestitures, or financing or restructuring transactions; and to third parties as required by law or to pursue or defend legal claims. HR Data: Personal data about employees and contractors (“HR data”) is collected and processed for various business purposes, in accordance with applicable law and regulations and with a lawful basis. These purposes are disclosed in our workforce privacy notice and include, but are not limited to, the following: to prepare to enter into, to enter into, and to perform contracts with data subjects; to operate our business and our workforce; to conduct research about experiences and attitudes about GoTo; for security, integrity, safety, and fraud prevention purposes; to comply with applicable law; and to comply with legal and administrative requests. The type of data we collect and further process is also disclosed in our workforce privacy notice and may vary by data subject type and jurisdiction. This data includes identifiers; commercial and financial information; professional or employment-related information; education history; protected characteristics, including sensitive personal data (where required and in compliance with applicable law); internet or other electronic network activity information; audio, electronic, visual or similar information; inference, preferences, and other information. We disclose personal data to third parties as disclosed in our privacy notice. These parties may vary by data subject and purpose.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | GoTo Group, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 b4794ae024 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is GoTo GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.