
PostHog
GDPR evidence
The single platform to analyze, test, observe, and deploy new features
PostHog and GDPR
CertReports found no public GDPR evidence for PostHog as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 8 May 2024
- Expires or valid through
- 10 Mar 2027
- Scope
- PostHog provides a B2B, all-in-one product analytics platform that helps customers understand and optimize how end-users interact with their products and features. Customers use PostHog to collect and analyze behavioral data from their websites and applications. In this context, PostHog acts as a data processor, while its customers act as data controllers under applicable data protection laws. PostHog’s customers—not PostHog—determine the types of data collected, submitted, and processed through the platform. To help deliver its services, PostHog may engage carefully selected third-party subprocessors, as outlined in its Data Processing Agreement. In addition, PostHog acts as a data controller when processing personal data from its customers and business contacts—for purposes such as managing accounts, providing support and improving internal operations. PostHog also processes human resources data for purposes including hiring, payroll, and benefits administration, and may disclose this data to third-party providers that support these functions.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | PostHog Inc: Active: EU-US Certification, UK Extension Certification, SW-US Certification | Live pagesha256 89dcb7f3cb |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is PostHog GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Developer tools category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Developer tools vendor has GDPR evidence in the index yet.