REDCap Cloud and GDPR
CertReports found no public GDPR evidence for REDCap Cloud as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 30 Jan 2019
- Expires or valid through
- 18 Aug 2027
- Scope
- nPhase provides an online platform and applications for our customers to operate aspects of their businesses, including the collection, processing and storage of clinical and operational data for the planning, conduct and optimization of clinical trials and other types of research. nPhase’s customers decide what data to submit to our platform or applications, which may include information about their authorized users, employees, and clinical trial patients. nPhase processes this data as instructed by our customers, and does not control or own its customer’s personal data. Our customer instructions may include processing or using personal data for purposes of providing or developing the nPhase platform, applications and services, preventing or addressing service or technical problems, responding to support issues, responding to our Customer’s instructions, or as may be required by law. nPhase only discloses personal data as instructed by our customers. In some cases, we may use third-party providers to assist us in providing or developing our platform or applications to our customers, such as to offer support to our customers and their authorized users and employees and to provide technical or operational support such as data hosting, transmission, and storage. These providers may access, process, or store personal data in the course of providing their services to nPhase . nPhase maintains contracts with these providers restricting their access, use and disclosure of personal data in compliance with our Privacy Shield obligations.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | REDCap Cloud: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 585ad195a4 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is REDCap Cloud GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.