Skip to main content
SU

Substack

GDPR evidence

A place for independent writing.

substack.comE-commerceLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Substack and GDPR

CertReports found no public GDPR evidence for Substack as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
1 Nov 2024
Expires or valid through
11 Sep 2027
Scope
We process personal data in order to provide our customers and users an online platform for the publishing, hosting, and distribution of digital media, as well as associated social networking services. We act as a data processor for publishers who use as our platform, and as a controller for the data of users on our social media platform, processing the personal data of our users and customers, as well as the personal data of subscribers of publishers using our platform. We disclose the personal data we process to the various data processors and service providers we depend on to provide our platform, including payments, web hosting, customer service, and security service providers. Otherwise, personal information is disclosed as directed by our users or as required by law.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Substack Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 eb3f0c5470
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Substack GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the E-commerce category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No E-commerce vendor has GDPR evidence in the index yet.