Skip to main content
RE

Remitly

GDPR evidence

remitly.comLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Remitly and GDPR

CertReports found no public GDPR evidence for Remitly as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
18 Dec 2025
Expires or valid through
18 Dec 2026
Scope
Remitly provides digital only cross-border remittance service accessible via a proprietary mobile application or the web. While the journey of Remitly began in digital cross-border remittances, the Remitly Group continues to evolve and invest in its technology platform to be able to deepen relationships with its customers and address their financial services needs, many of which are not met by legacy institutions. Remitly Inc. (RINC), registered under the entity number of 5051455, is a wholly owned subsidiary of Remitly Global Inc., registered under the entity number of 7085413, (the “Remitly Group”), a publicly listed company on the NASDAQ exchange. The Remitly Group also includes European and UK-based entities: Remitly Europe Ltd. ("REL"), a private company limited by shares incorporated in Ireland with company registration number 629909 and registered address at Ground Floor, 1 Albert Quay, Ballintemple, Cork, T12 X8N6, Ireland. REL is authorised and regulated by the Central Bank of Ireland under reference number C186163. Remitly UK Ltd. ("RUK"), a private limited company incorporated in England and Wales with company registration number 09896841 and registered address at 90 Whitfield Street London W1T 4EZ, United Kingdom. RUK is authorised and regulated by the Financial Conduct Authority (FCA) as an Authorised Payment Institution under reference number 728639 since 30th April 2018. Remitly Poland SP. Z O.O., a private limited company incorporated in Poland with company registration number 0772554, and registered address at Ks. I. Skorupki 5, 00-546 Warsaw, Poland. Consistent with Remitly Group’s strategic approach to leverage centralised capabilities across customer-facing entities and benefit from economies of scale, the Group incorporates outsourcing as a key component of its operational model. RINC provide the following outsourced core services to the European and UK affiliates: Product Development Customer Operations Human Resources Finance Facilities Compliance (Monitoring and Testing) Marketing IT Information Security Legal Services Each of these services are outsourced under structured Intercompany Agreements (ICAs). As a U.S.-based entity within a global remittance and cross-border payments organization, RINC are proposing to process personal data received from European and RUK in reliance on the EU-US Data Privacy Framework (DPF) and the UK Extension to the EU-U.S. DPF, the Swiss-U.S. Data Privacy Framework. Through the provision of these outsourced services, RINC processes personal data from European and UK data subjects. The personal data processed may include the following categories: Customer Data: Name, contact details, transaction data, communication history, IP addresses. AML/KYC Data: Identity data (passports, utility bills etc), sanctions screening data, source of funds data. Employee and Contractor Data (HR Data): Name, Date of Birth (DOB), address, Government issued ID and visa information, employee ID, bank details, job performance data, health data relating to medical leave. Job Applicant Data (HR Data): CVs/resumes, background check information, interview data, results of assessments. Vendor and Business Partner Data: Business contact details. RINC may disclose data to third parties in accordance with applicable privacy and security requirements/regulation. These third parties include: Service Providers: Such as cloud hosting providers, HR systems, communications platforms, and professional advisors. Remitly Group Entities: Data may be shared between entities within the Remitly Group as part of data operations. Government Authorities or Regulators: When legally required to comply with applicable law, regulation, or lawful requests.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Remitly Inc: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 9f490aff51
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Remitly GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.

No same-category vendor has GDPR evidence in the index yet.