
Klaviyo and GDPR
CertReports found no public GDPR evidence for Klaviyo as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 28 May 2018
- Scope
- Klaviyo processes Customer's data, Customer's end consumer data, and web visitor data from the EU, UK, and Switzerland. Additionally, Klaviyo has business operations in the UK and the EU which also employs individuals, and processes their personal data. Klaviyo is a SaaS platform that provides marketing automation to its customers to leverage their email, web, and mobile communications. This data is transferred to the US in order to provide the Services as well as to run its business operations. Customer's End Consumer Data Klaviyo Customers must upload the Personal Data of their end consumers who are targets of the Customer's marketing activity. The data points are determined by the Customers. Klaviyo acts as a Processor for this data and shall only process it in accordance with the written instructions of the Customer. All of this data is stored in the United States. Furthermore, Klaviyo uses sub-processors in order to provide the Services to its Customers and in turn for those Customer's end consumers. A list of these sub-processors is available in its Data Processing Agreement. To the extent the sub-processor is also a member of the EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF, such transfer is subject to the DPF. To the extent that the end consumers are residents or are otherwise subject to the Privacy Laws of the UK, EU, or Switzerland, their Personal Data is transferred in reliance on EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF. Customer's Data In order to provide the Klaviyo services to its platform, Customers must provide the Personal Data of their authorized users of the Klaviyo platform. Klaviyo automatically collects user data based on the Customer's and their authorized user's use of the platform, which includes Personal Data. To the extent that Customers or its users are residents or or otherwise subject to the subject to the Privacy Laws of the UK, EU, or Switzerland, they are subject to the EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF. Website Visitors Klaviyo collects data, including Personal Data, upon appropriate notice and consent, of visitors to its websites in accordance with its Privacy Notice. Klaviyo also processes data that is voluntarily provided by end users when interacting with the Klaviyo website. For example, when a user provides information in order to receive a newsletter, or information provided in order to receive more information from Klaviyo. To the extent that Customers or its users are residents or or otherwise subject to the subject to the Privacy Laws of the UK, EU, or Switzerland, they are subject to the EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF. HR Data Klaviyo has business operations in the UK and EU and, as part of these operations, has employees in both. In the ordinary course of business, Klaviyo processes the Personal Data of its employees, consultants, interns, and job applicants, and such data is transferred to the US. This is subject to Klaviyo's Global Employee Data Privacy Notice or the Klaviyo Job Applicant Privacy Notice, respectively. To the extent that employees or job applicants are UK or Irish residents, they would be subject to the to the EU-U.S. DPF or the UK Extension to the EU-U.S. DPF, respectively.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Klaviyo: Inactive | Live pagesha256 21dc3d0daf |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Klaviyo GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Email marketing category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Email marketing vendor has GDPR evidence in the index yet.