Merge API and GDPR
CertReports found no public GDPR evidence for Merge API as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 27 Dec 2023
- Expires or valid through
- 10 Dec 2026
- Scope
- Nature of the processing Merge offers a Unified API which provides integration services between joint systems that a controller chooses and made available by processor or subprocessor as the case may be. Purpose(s) of the data transfer and further processing: Merge provides its proprietary, Software-as-a-Service solution for integrating HR, payroll, recruiting, and accounting platforms to Customers (Party that purchases a Subscription to the Service) and End Customers (The Customer’s customer that enables integration between the Service and Partner’s platform in order for Merge to Process the End Customer’s Personal Data for the benefit of the Customer). The purpose of the processing is for the processor/subprocessor to provide these specific services to a controller (or on their behalf). Categories of data subjects whose personal data is transferred: Customer and its end users (e.g., account holders, job applicants, end-customers, prospective customers, employees, contractors, suppliers and end-users of the data exporter and the data exporter’s customers, vendors and partners). Categories of personal data transferred: Categories of personal data chosen by a controller and issued to processor or subprocessor as the case may be, via the Service (e.g., ATS, HRIS and Accounting related personal data): such as name, address, email, phone number, authentication information, work history, transactional and account information, pay rate and tax information, health plan information, gender, marital status, veteran status.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Merge API, Inc: Active: EU-US Certification, UK Extension Certification, SW-US Certification | Live pagesha256 a547337113 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Merge API GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Developer tools category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Developer tools vendor has GDPR evidence in the index yet.