Skip to main content
RD

RR Donnelley RRD

GDPR evidence

rrd.comMarketingLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

RR Donnelley RRD and GDPR

CertReports found no public GDPR evidence for RR Donnelley RRD as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
3 Dec 2017
Expires or valid through
7 Jan 2027
Scope
RRD operates as a data processor for our business clients located in the US, EU and other geographic locations worldwide. RRD’s business clients remain the data controllers with respect to any of their Customer data that they provide to RRD for our provision of services. RRD therefore acts in accordance with the instructions of such clients regarding the collection, processing, storage, deletion and transfer of Customer data, as well as other matters such as the provision of access to and rectification of this Customer data. RRD may obtain in the US the following types of EU and Swiss Business Contact Information: name, address, invoice information including bank account information, and order information. RRD uses EU and Swiss Business Contact Information for the following purposes: managing client relationships, managing orders, tracking payments and ensuring payment, and otherwise maintaining the client relationship. In context of Human Resource Data, RRD Information regarding RRD's practices concerning EU and Swiss Employee Information is provided to affected EU and Swiss employees through other company policies and procedures. As a data processor, RRD may share an individual's personal data only at the instruction and direction of our clients, the data controller, to other data processors who are under control of RRD's client and not RRD's. As a data controller, RRD could (1) with an individual's consent, share an individual's personal data with third parties as gathered from RRD's digital properties (such as, but not limited to, rrd.com or save.com) or (2) in fulfillment of RRD's employee recruitment and employer role. As a data controller, RRD uses tracking technologies (aka "cookies") on its digital properties to measure and improve the performance of RRD-owned websites in order to personalize content and adverts, provide social media features, and analyze web traffic; which are identified in RRD's published "cookie policy" on https://www.rrd.com/cookie-policy. If an individual consents, RRD shares information about an individual's use of our websites with our social media, advertising, and analytics partners. If an individual does not consent to this use through the provided "pop-up", RRD only uses cookies that are strictly necessary for the website to function. After providing or declining consent, an individual can change the preferences at any time by clicking on the "cookies" settings button at the top of a website's cookie policy page. As a data controller, RRD may share prospective, existing, and retired employees' personal data with RRD's recruiters, background check providers, payroll providers, benefits management, beneficiary recipients, and governing taxing agencies.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026RR Donnelley (RRD): Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 3f27252397
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is RR Donnelley RRD GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Marketing category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Marketing vendor has GDPR evidence in the index yet.