
Roku and GDPR
CertReports found no public GDPR evidence for Roku as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 23 May 2019
- Expires or valid through
- 29 Apr 2027
- Scope
- Roku is a provider of digital streaming services, consumer electronic products, advertising services and other related services. Information collected by Roku is used by Roku and others on Roku’s behalf for the following purposes: 1. Support, Maintenance and Fulfillment. We use your information to provide and maintain the Roku Services and to process and fulfill your requests or orders; 2. Improvement of Products and Services. We use your information to understand and analyze our user base and how you use the Roku Services, to improve and enhance the Roku Services (including building correlations for use in Roku's advertising services in order to better serve our advertisers), and to develop new products, services, features, and functionalities; 3. Personalization. We use your information to personalize your experience on the Roku Services, including suggesting and offering you relevant content and recommendations; 4. Advertising Services. We use your information to show you ads (including personalized ads) through the Roku Services, on Third-Party Channels, and on third-party websites, mobile apps, platforms, and devices. We use your information to measure and understand the reach, viewership and effectiveness of advertising and to provide advertising analytics and reporting. We also help advertisers and advertising partners reach the desired audience and understand, measure and improve their ad campaigns. We associate the browsers and devices (such as smartphones, tablets, streaming players, connected TVs and computers) used by the same individual or household for the purposes of advertising to that individual or household on different browsers or devices. This allows, for example, ads you see on your tablet to be based on activities you engaged in on your Roku TV. 5. Marketing and Promotions. We use your information for marketing purposes, including to send you alerts, notifications, emails and text messages about products, events, promotions and offers from Roku or its partners, and to measure and understand the effectiveness of our marketing; 6. Analytics and Performance. We use your information to measure performance and analyze key metrics relevant to our business; 7. Service Communication and Customer Care. We use your information to communicate with you, including sending you service information such as confirmations, invoices, notices, updates, security alerts, user surveys, and support and administrative messages; and to respond to your comments and questions and provide customer service; 8. Protect Roku, our Users, and Others. We use your information to enforce our terms and conditions or protect our business, partners or users, and to comply with our contractual and legal obligations; and 9. Security and Fraud Prevention. We use your information to protect, investigate and deter against fraudulent, unauthorized, infringing or illegal activity, including click fraud.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Roku, Inc.: Active: SW-US Certification, EU-US Certification, UK Extension Certification | Live pagesha256 ed778ceab6 |
- Kind
- listing
- Scope
- The transfer is made for the following purposes: • In relation to employees and former employees: human resources administration employee performance evaluation retention of employees’ core details administration of core records, expense reimbursement and background checks arising from the administration of the recruitment process carried out by DataXu • In relation to job applicants: administration of job applications • In relation to clients and customers/end-users of clients: provision of advertising campaign services to clients provision of analytics services and related reports, including metrics, to clients client administration and core records management client relationship management and marketing The personal data transferred concern the following categories of data: • In relation to employees and former employees: copies of resumés or CVs details of education and qualifications work experience name address social security number or other government issued identity number (e.g. National Insurance number or passport number) contact telephone number(s) e-mail address age gender date of birth details of compensation by the data exporter entity and, in some cases, former employers special work environment requirements references payroll data photographic and video imaging • In relation to job applicants: copies of resumés or CVs details of education and qualifications work experience name address contact telephone number(s) e-mail address age date of birth references photographic and video imaging • In relation to clients and customers/end-users of clients: name address contact telephone number(s) e-mail address device IDs IP addresses The personal data transferred may be disclosed only to the following recipients or categories of recipients: • In relation to personal data of employees, former employees and and job applicants: authorised personnel in the human resources and finance departments authorised personnel involved in the recruitment and interviewing of job applicants authorised management including, without limitation, members of the Board of Directors third party providers of various services including, without limitation, referencing and verification services, IT services, client relationship management services, payroll services, accounting and audit services, data analytics services and legal services third party providers of various employee benefits including, without limitation, health insurance and pension providers • In relation to personal data of clients and customers/end-users of clients: authorised personnel in the campaign management, engineering, finance, client development, marketing and legal departments authorised management including, without limitation, members of the data importer’s Board of Directors third party providers of various services including, without limitation, IT services, client relationship management services, accounting and audit services, data analytics services and legal services
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | DataXu, Inc.: Inactive | Live pagesha256 efe7cd96ea |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Roku GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Consumer apps category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Consumer apps vendor has GDPR evidence in the index yet.