NAVEX Global and GDPR
CertReports found no public GDPR evidence for NAVEX Global as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 5 Dec 2016
- Scope
- NAVEX processes personal data received in reliance on the three Frameworks for the following purposes: To process HR employee personal data provided to NAVEX about its UK & EU affiliates. The purpose is to process such employee personal data as necessary to perform NAVEX's business functions in our role as an employer, including administrative and managerial tasks in connection with employment and the provision of services to employees. The type of data is HR data. NAVEX does disclose HR data to outside third parties. Our affiliate group will have access to the personal data, which include NAVEX Global, Inc., NAVEX Global UK Limited, NAVEX Deutschland GmbH, GCS Compliance Services Europe Unlimited Company, WhistleB Whistleblowing Centre AB, NAVEX India Private Limited, and NAVEX Japan LLC. Our service providers/data processors, provide data processing services on our behalf. Any personal data processed by NAVEX’s data processors is strictly in accordance with that relationship and such providers are not authorized to process personal data except as necessary to perform the services. To process HR candidate personal data provided to NAVEX about its UK & EU affiliates, with respect to their applicants. The purpose is to process such candidate personal data as necessary to perform NAVEX's business functions in our role as a potential employer, including administrative and managerial tasks in connection with the application process and the provision of services to applicants. The type of data is HR data. NAVEX does disclose HR data to outside third parties. Our affiliate group will have access to the personal data (as listed above). Our service providers/data processors, provide data processing services on our behalf. Any personal data processed by NAVEX’s data processors is strictly in accordance with that relationship and such providers are not authorized to process personal data except as necessary to perform the services. To process B2B visitor personal data in relation to our website, and to process B2B customer personal data in relation to prospects and data controller processing activities to provision services to existing customers, for example, when NAVEX maintains the customer relationship by processing personal data necessary to manage the account (e.g., operational communications, contracting information, and administrator communications). The purposes include, but are not limited to, marketing NAVEX’s products and services, responding to support requests, personalizing the experience with the website, and to manage professional relationships with our business customers. The type of data is non-HR data. NAVEX does disclose visitor or customer personal data to outside third parties. Our affiliate group will have access to the personal data (as listed above). Our service providers/data processors, provide data processing services on our behalf. Any personal data processed by NAVEX’s data processors is strictly in accordance with that provider relationship and such providers are not authorized to process personal data except as necessary to perform the services. To process personal data provided to NAVEX on behalf of its customers at their instruction in the course of delivering NAVEX’s products and services, in NAVEX’s role as a service provider/data processor. The purpose is to process such customer personal data as necessary to deliver the contracted services NAVEX provides to its business customers. The type of data is non-HR data. NAVEX does disclose customer personal data to outside third parties. Our affiliate group will have access to the personal data (listed above). Our service providers/data processors provide data processing services on our behalf. Any personal data processed by NAVEX’s data processors is strictly in accordance with that relationship and such providers are not authorized to process personal data except as necessary to perform the services.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | NAVEX Global, Inc.: Inactive | Live pagesha256 c3ff100aab |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is NAVEX Global GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 18 Sep 2026First indexed by CertReports1 evidence row across 1 framework entered the index.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.