Skip to main content
OneStream Software logo

OneStream Software

GDPR evidence

onestream.comFinance and accountingLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

OneStream Software and GDPR

CertReports found no public GDPR evidence for OneStream Software as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: SW-US Certification, EU-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
24 Mar 2017
Expires or valid through
20 Feb 2027
Scope
HR Data: OneStream Software LLC processes Personal Data of its affiliates’ employees for HR purposes, with OneStream Software acting as a controller. Personal data can be collected by OneStream as part of recruitment and on-boarding and on an ongoing basis as required to meet our responsibilities as an employer. Personal data can also be collected through use of third-party services, including without limitation, payroll, tax authorities, travel booking and expense claims. Examples include Personal contact details, salary, tax code, employment history and provision of employee benefits. Applicable Personal data may be shared with our suppliers, employment benefit providers and customers. It may also be disclosed in response to a lawful request by public authorities to meet national security or law enforcement requirements, in accordance with Applicable Data Protection Laws. Non HR Data: OneStream Software LLC makes available an enterprise finance software as a service (“Saas”) hosted by or on behalf of OneStream with the typical use case being the processing of non-public financial data. Personal Data of OneStream Software’s customers is processed for the purposes of delivering the SaaS service and meeting contractual obligations, with OneStream Software acting as a processor. OneStream Software processes some Personal Data of its customers for billing and compliance purposes, with OneStream Software acting as a controller. The customer determines the Data Subjects whose Personal Data will be processed. The following types of Data Subjects will be covered: • Persons who use the hosting services and software as a part of their work for Customer. • Persons who are the source of, or the responsible person associated with, data that Customer provides as part of its use of the software. The customer determines the categories of Personal Data that will be processed. The following categories of Personal Data will be covered: • Names and business contact details such as work email address, office address, telephone number and job title • Employee ID number or other account numbers It should be noted that for customers using the People Planning module, sensitive or special category personal data may also be processed such as personal data relating to employee benefits, tax and payroll information and ethnic background. Processing operations include, the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure and destruction for the duration of processing identified above. Customer Personal data is not disclosed to third parties. Please see our sub processors available here Sub-processors List.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026OneStream Software LLC: Active: SW-US Certification, EU-US Certification, UK Extension Certification
Live pagesha256 332a253b8e
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is OneStream Software GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Finance and accounting category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Finance and accounting vendor has GDPR evidence in the index yet.