Tracer and GDPR
CertReports found no public GDPR evidence for Tracer as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 13 Mar 2019
- Expires or valid through
- 10 Jun 2027
- Scope
- Tracer provides enterprise online brand protection services as well as corporate registrar services. In connection with both services, Tracer collects certain identifying and contact information from its corporate customers’ designated employee contacts, all of which information is protected under GDPR-appropriate technological and operational safeguards and not shared with any outside third parties except as stated below. In providing brand protection services, Tracer gathers data relating to the activities and identity of entity and individual bad actors who are suspected of infringing Tracer customers’ trademarked brands--or using such brands to commit fraud or other abuses--across global mobile app stores, marketplaces, social media sites, paid search, and websites. The personal data of individuals which Tracer collects primarily consists of names, IP addresses, and email addresses. No sensitive personal data is collected and the personal data which is collected is protected by GDPR-appropriate technological and operational safeguards and processed to protect the legitimate interests of Tracer customers to protect their intellectual property rights. The personal data collected in connection with the Tracer brand protection services is used to investigate and take actions against suspected brand abusers, including using such data to send infringement notices to such abusers, the platforms upon which they operate, and the registrars and registries of the domains under which the abuses are conducted. Each infringement notice contains GDPR-appropriate advisories of the use of such data with a link to Tracer’s Privacy Policy. The personal data is not shared with any third parties other than the affected Tracer customer for whom such personal data is collected. To the extent that the brand protection-related personal data is collected from global platforms and sites, Tracer relies on its DPF Program certification. In providing its corporate registrar services, Tracer is required by third-party global domain registries to provide personal data (names, email addresses, telephone numbers) for the customer’s designated employee contacts in order to register and maintain their domains in compliance with ICANN and registry requirements. No sensitive personal data is collected in connection with such services, the personal data which is collected is not shared with any other third parties, and such data is protected by GDPR-appropriate technological and operational safeguards. In addition, certain European and international ccTLD registries require DPF Program certification, or similar international certifications, as a requirement of becoming an accredited registrar with those registries. In early 2023, Tracer acquired a Portuguese subsidiary through which it employs a number of Portuguese residents, the personal data of which is shared with the Tracer's US headquarters for purposes of managing those employees.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Tracer: Active: EU-US Certification, UK Extension Certification, SW-US Certification | Live pagesha256 0663a23ab7 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Tracer GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Analytics category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Analytics vendor has GDPR evidence in the index yet.