
KnowBe4 and GDPR
KnowBe4 states it holds a data processing agreement. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- listing
- Issued or listed
- 23 May 2018
- Scope
- Non-HR Data: Personal data is collected for the purposes of business to business direct marketing and for delivering our services to our customers. KnowBe4 provides security awareness training, simulated phishing, email security, and data protection services to its customers. We may use a limited number of third-party subprocessors in providing our services. We maintain contracts with each subprocessor to ensure any data they process on our behalf is protected in line with our Data Privacy Framework obligations. For HR Data: We collect personal data relevant to the relationship with our employees, contractors, and temporary staff. This information is used to operate and maintain an effective employer/employee relationship, including: performance management, individual rights, third-party employment searches, internal policy compliance and investigations, business programmes (e.g. partnership, third party events), business activities, and references. Limited third-party subprocessors may be used to provide services relevant to the support of the HR function, with appropriate contractual protections in place.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | KnowBe4: Inactive | Live pagesha256 5fda0b6200 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is KnowBe4 GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.