
Highspot and GDPR
CertReports found no public GDPR evidence for Highspot as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 13 Jul 2017
- Scope
- Highspot provides a SaaS platform and mobile applications that allows users to store and share content (Highspot acting as a data processor). When Highspot is the data processor processing personal data on behalf of its customers, Highspot collects personal data and related analytics about users of its services and recipients of content shared through the services to provide the services to its customers, improve the services, and provide customer support. This personal information may be shared with subprocessors to help provide and improve the services. These subprocessors may only use personal information to provide services to or perform tasks on behalf of Highspot in compliance with an agreement between the subprocessor and Highspot. Highspot, acting as the data controller, also collects personal information and related analytics from its websites, events, and other non-user activities, as part of its sales, marketing, and general business operations. This information includes first and last name, business contact details, professional history, and employer. When Highspot is the data controller, the personal information may be shared with Highspot subsidiary companies and subprocessors that may only use the personal information to provide services to or perform tasks on behalf of Highspot in compliance with an agreement between the subprocessor and Highspot.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Highspot, Inc.: Inactive | Live pagesha256 e1c2594f9f |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Highspot GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Sales tools category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Sales tools vendor has GDPR evidence in the index yet.