
Medallia and GDPR
CertReports found no public GDPR evidence for Medallia as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 27 Jul 2017
- Expires or valid through
- 3 Mar 2027
- Scope
- Medallia processes personal data in two main capacities: as a data controller for our business contacts and as a data processor on behalf of the clients of our SaaS platforms. 1. Data Processed as a Data Controller (Covered Business Contacts) Medallia acts as a data controller when it collects and processes personal data from representatives of our clients, potential clients, vendors, service providers, professional advisors, and business partners. This data typically includes an individual’s name, job title, company affiliation, and contact information. The purposes for collecting and using this data are for legitimate business functions, including: ● Providing information about our products and services. ● Managing client accounts and relationships. ● Onboarding and interacting with vendors and service providers. ● Communicating with business partners and professional advisors. ● Providing customer support and technical assistance. ● Billing and financial management. ● Marketing and event management, with appropriate consent where required and an ability to opt out. 2. Data Processed as a Data Processor (Covered Customer Data) Medallia acts as a data processor when processing personal data on behalf of clients utilizing the Medallia Experience Cloud platform. In this role, our clients determine the types of personal data to be processed, which may pertain to their own customers and employees. Medallia processes this “Covered Customer Data” strictly in accordance with the instructions of its clients and for the sole purpose of providing the Medallia Experience Cloud platform and services as specified in our agreements with them. 3. Disclosure and Accountability for Onward Transfer Medallia may disclose personal data to the following types of third parties, in compliance with the Data Privacy Framework Principles. We do not sell or rent personal data to third parties for their own marketing purposes. ● Service Providers: We may transfer personal data to third-party service providers who perform services on our behalf, such as: ○ Hosting providers ○ Customer support platforms ○ Marketing service providers ○ Channel partners, such as distributors and resellers ● As Required by Law: Medallia may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. These third parties are contractually bound to process personal data only for the limited and specified purposes for which they were engaged and to provide a level of privacy protection consistent with the Data Privacy Framework Principles. Medallia remains liable if our agents process personal data in a manner inconsistent with these Principles.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Medallia, Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 5dd60f5612 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Medallia GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Customer support category) whose GDPR row is verified or vendor-stated, ranked by similarity.