Stripe
GDPR evidence
Economic infrastructure for the internet.
Stripe and GDPR
CertReports found no public GDPR evidence for Stripe as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 11 May 2026
- Expires or valid through
- 11 May 2027
- Scope
- Stripe processes personal data relating to its Business Users, End Users, End customers, Representatives and Visitors as defined in its Privacy Policy. Stripe processes personal data which includes personal identifiers, transaction data, financial data, merchant data, analytics data, device and usage data. Data is processed by Stripe to facilitate payment processing; manage online payments and transaction authentication; identity verification; fraud prevention and security purposes; improve and develop Stripe products and services; communicate with users; advertise and promote our services and comply with legal obligations. Stripe shares data with Business Users as required to provide its services; Stripe Affiliates; service providers and processors; financial partners; advertising partners; professional service providers; parties to a corporate transaction as part of a merger, financing, acquisition, bankruptcy, dissolution or a transfer, divestiture or sale of all or a portion of Stripe business or assets; and governmental regulators, law enforcement and others in connection with audits, investigations or other legal and regulatory purposes. Stripe processes HR related data which includes personal details, financial information, work related data, system application and premises access data, online activity information, geolocation, video and audio recordings; recruitment data, remuneration and benefits data, performance management, training and leave data. Stripe processes HR data to administer the terms of the employment contract; conduct performance reviews; for assessments and training; comply with applicable employment and other laws; defend against legal claims and disputes; manage health and safety in the workplace; manage Stripe operating systems; operate and maintain security of Stripe systems; issue equity; and to manage employee absences and leave. HR data is shared with Stripe Affiliates; service providers and processors; insurance pension and health providers; professional service firms; parties to a corporate transaction as part of a merger, financing, acquisition, bankruptcy, dissolution or a transfer, divestiture or sale of all or a portion of Stripe business or assets; and governmental regulators, law enforcement, court officials and others in connection with audits, investigations, or other legal and regulatory purposes.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Stripe, LLC: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 24bb558c88 |
- Kind
- listing
- Scope
- Stripe processes personal data relating to its Business Users, End Users, End customers, Representatives and Visitors as defined in its Privacy Policy. Stripe processes personal data which includes personal identifiers, transaction data, financial data, merchant data, analytics data, device and usage data. Data is processed by Stripe to facilitate payment processing; manage online payments and transaction authentication; identity verification; fraud prevention and security purposes; improve and develop Stripe products and services; communicate with users; advertise and promote our services and comply with legal obligations. Stripe shares data with Business Users as required to provide its services; Stripe Affiliates; service providers and processors; financial partners; advertising partners; professional service providers; parties to a corporate transaction as part of a merger, financing, acquisition, bankruptcy, dissolution or a transfer, divestiture or sale of all or a portion of Stripe business or assets; and governmental regulators, law enforcement and others in connection with audits, investigations or other legal and regulatory purposes. Stripe processes HR related data which includes personal details, financial information, work related data, system application and premises access data, online activity information, geolocation, video and audio recordings; recruitment data, remuneration and benefits data, performance management, training and leave data. Stripe processes HR data to administer the terms of the employment contract; conduct performance reviews; for assessments and training; comply with applicable employment and other laws; defend against legal claims and disputes; manage health and safety in the workplace; manage Stripe operating systems; operate and maintain security of Stripe systems; issue equity; and to manage employee absences and leave. HR data is shared with Stripe Affiliates; service providers and processors; insurance pension and health providers; professional service firms; parties to a corporate transaction as part of a merger, financing, acquisition, bankruptcy, dissolution or a transfer, divestiture or sale of all or a portion of Stripe business or assets; and governmental regulators, law enforcement, court officials and others in connection with audits, investigations, or other legal and regulatory purposes.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Stripe, Inc.: Inactive | Live pagesha256 d5115d3fb5 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Stripe GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Payments category) whose GDPR row is verified or vendor-stated, ranked by similarity.