Skip to main content
RiskIQ logo

RiskIQ

GDPR evidence

riskiq.comSecurityLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

RiskIQ and GDPR

CertReports found no public GDPR evidence for RiskIQ as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
21 Jun 2019
Scope
RiskIQ, Inc. (now a Microsoft company), seeks to redefine the global standard for digital cybersecurity risk management beyond the traditional perimeter of a firewall. We provide attack surface-based digital risk protection by illuminating risk associated with an organization’s digital presence in open, deep and dark web, mobile, and social digital channels to proactively protect the organization, its brands, people, and data by providing services consisting of cloud computing featuring software through a browser interface (primarily SaaS) made extensible by way of APIs, together with managed security or professional services. Through our sites, we also provide information related to our services. We collect different types of information that may contain personal information, including: • users first and last name, job title, address, email address, internet protocol address, phone or fax number, usernames and passwords, when a user register through our sites to access our Services or any security information used to authenticate access to our sites or Services, through direct interactions, such as by registering for our Services or by corresponding with us by post, phone, electronically or otherwise. • current and historical information about how users use our sites and Services, which may include technical information about users devices used to access our Services, individual usage details and clickstream data, and other browsing actions and patterns. • high volumes of data, such as passive DNS, APIs, hosts, domains, SSL certificates, internet protocol addresses, from publicly available sources and host it in RiskIQ’s platform to allow the users of the Services to meaningfully analyze and manage their attack surface. Personal information may be incidentally included in the information RiskIQ collects if such information is available from a publicly available source. The information RiskIQ collects to provide our Services is a reflection of the information publicly available from the original source and thus only as accurate as the original source material itself. RiskIQ does not take steps to assess the accuracy of publicly available information we provide via our sites and Services.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026RiskIQ, Inc.: Inactive
Live pagesha256 0f7a2060cc
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is RiskIQ GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.