
IBM and GDPR
CertReports found no public GDPR evidence for IBM as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 2 Dec 2016
- Expires or valid through
- 11 Nov 2026
- Scope
- The types of personal information that Data Privacy Framework-Certified Cloud Services collect varies based on the type and nature of each offering and is described in its offering documentation or as otherwise provided by IBM. IBM uses such personal information as needed to deliver the Cloud Service, along with additional purposes as described in the specific transaction documents. IBM uses processors and subprocessors (including personnel and resources) in locations worldwide to deliver Cloud Services, and accordingly, may disclose personal information to those third parties for the purpose of delivering the Cloud Services to clients. IBM discloses the types of personal information processed, the purposes for processing, and the types of third parties to which IBM discloses personal information on an offering-by-offering basis via the external-facing IBM Terms site (at: https://www.ibm.com/support/customer/csol/terms/). This site contains Data Processing and Protection Datasheets for IBM’s Cloud Services.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | International Business Machines Corporation (IBM): Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 5b33de9499 |
- Kind
- listing
- Scope
- Merge eClinical, a leading provider of eClinical software and services to pharmaceutical, biotechnology, medical device, research sites or institutions, and contract research organizations (CROs and AROs) offers adaptive, web-based tools that work together to coordinate data capture, logistics, patient interaction and trial management and resolution turning data into intelligence. Merge eClinical acts as a processor of data collected and stored in secure databases on behalf of its clients, who are the data controllers of the information. The information is key-coded and is generally not personally identifiable to Merge eClinical. Merge eClinical does not analyze information or otherwise use it in any way beyond client instruction. Merge eClinical will take reasonable steps to ensure that personal information entered onto its platforms retains its original relevance, accuracy, completeness, and currency. The Merge eClinical Compliance department will periodically review and conduct compliance audits of the relevant privacy practices to verify adherence. Merge eClinical management will remedy issues arising out of any failure to comply with this Policy.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Merge eClinical: Inactive | Live pagesha256 f3209490d9 |
- Kind
- listing
- Scope
- Red Hat collects personal data, including contact details, from website visitors. Red Hat may process this data to: identify and authenticate the visitor, fulfill a website visitor’s service requests; provide information about Red Hat products, services and events, or other marketing purposes as permissible under applicable law; provide support and customer service; monitor and analyze usage patterns on its websites; enhance the website experience; diagnose and resolve issues with and otherwise improve and protect the Red Hat products and services. Red Hat processes personal data of vendors, customers and other business partners to: manage existing and prospective relationships; perform accounting, billing and auditing; and, comply with applicable law, industry standards and Red Hat’s procedures and policies. In addition, Red Hat collects customer registration information, which may include name, company name, email address, phone number, title or department. Red Hat uses this personal data for customer relationship management, including to: communicate with its customers; help monitor and analyze usage patterns on, diagnose and resolve issues with, and otherwise improve and protect its services. When providing its products and services to customers, Red Hat generally acts as a data controller of personal data it obtains from website visitors, vendors, customers and other business partners, for its aforesaid legitimate business purposes. In certain instances involving Red Hat-branded cloud or hosted service offerings (Online Services), Red Hat may act as a data processor of its customers’ content and process end-users’ personal data on behalf and upon instructions of its customers. As part of these Online Services, customers are data controllers and decide which data to upload onto Red Hat servers. In that context, Red Hat processes and discloses personal data as specified in its agreements with customers. Red Hat may share personal data with the following types of third-parties: business partners and service providers, including distributors, resellers, payment processors, financial service providers and institutions, materials production and shipping companies, postal or government authorities, market intelligence and consulting service providers, and IT service providers. Red Hat may also share personal data with: Red Hat affiliates and subsidiaries, including to its parent company International Business Machines Corporation (IBM); an acquirer, successor or assignee in case of merger, acquisition, consolidation, divestiture, debt financing, sale of assets or similar transaction or in case of insolvency, bankruptcy, or receivership; police or public authorities (including to meet national security or law enforcement requirements) if necessary to comply with law or legal process, to protect and defend the rights or property of Red Hat, to protect someone’s safety, or to investigate any violation or potential violation of the law, Red Hat’s privacy policy, or a customer agreement.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Red Hat, Inc.: Inactive | Live pagesha256 9c7e0e57ae |
- Kind
- listing
- Issued or listed
- 4 Nov 2016
- Scope
- Merge Healthcare processes personal data for client technical support purposes in diagnosing and fixing issues relating to Merge's hardware or software solutions. The client initiates the data processing by requesting support services. Merge obtains PI directly from clients who request support services. When providing support services, Merge may also need to view or otherwise process clients' customers personal information and, if needed, does so with the clients' permission. Our clients are required to ensure that they have consent or other lawful authority to transfer Personal Information to Merge for processing. Any such information provided is solely for the purpose of providing troubleshooting, diagnostic, or other support services on the software products provided by Merge. While Merge does sometimes need to send information to third parties, those third parties have been subcontracted to provide after-hours and complaint handling services for the client. There is no data that is transferred to other third parties for other business purposes. As noted in IBM's posted privacy policy: "Where we reference that we use your personal information in relation to marketing, improvement or development of our products or services, for reasons of safety and security, or regulatory requirements other than in connection with your agreement or request, we do this on the basis of our or a third party’s legitimate interests, or with your consent. When we collect and use your personal information subject to the EU Privacy Legislation this may have consequences for Your Rights."
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Merge Healthcare Solutions Incorporated: Inactive | Live pagesha256 2e8f22e341 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is IBM GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the AI infrastructure category) whose GDPR row is verified or vendor-stated, ranked by similarity.