Skip to main content
TR

Tracer

GDPR evidence

tracer.aiAnalyticsLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Tracer and GDPR

CertReports found no public GDPR evidence for Tracer as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, UK Extension Certification, SW-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
13 Mar 2019
Expires or valid through
10 Jun 2027
Scope
Tracer provides enterprise online brand protection services as well as corporate registrar services. In connection with both services, Tracer collects certain identifying and contact information from its corporate customers’ designated employee contacts, all of which information is protected under GDPR-appropriate technological and operational safeguards and not shared with any outside third parties except as stated below. In providing brand protection services, Tracer gathers data relating to the activities and identity of entity and individual bad actors who are suspected of infringing Tracer customers’ trademarked brands--or using such brands to commit fraud or other abuses--across global mobile app stores, marketplaces, social media sites, paid search, and websites. The personal data of individuals which Tracer collects primarily consists of names, IP addresses, and email addresses. No sensitive personal data is collected and the personal data which is collected is protected by GDPR-appropriate technological and operational safeguards and processed to protect the legitimate interests of Tracer customers to protect their intellectual property rights. The personal data collected in connection with the Tracer brand protection services is used to investigate and take actions against suspected brand abusers, including using such data to send infringement notices to such abusers, the platforms upon which they operate, and the registrars and registries of the domains under which the abuses are conducted. Each infringement notice contains GDPR-appropriate advisories of the use of such data with a link to Tracer’s Privacy Policy. The personal data is not shared with any third parties other than the affected Tracer customer for whom such personal data is collected. To the extent that the brand protection-related personal data is collected from global platforms and sites, Tracer relies on its DPF Program certification. In providing its corporate registrar services, Tracer is required by third-party global domain registries to provide personal data (names, email addresses, telephone numbers) for the customer’s designated employee contacts in order to register and maintain their domains in compliance with ICANN and registry requirements. No sensitive personal data is collected in connection with such services, the personal data which is collected is not shared with any other third parties, and such data is protected by GDPR-appropriate technological and operational safeguards. In addition, certain European and international ccTLD registries require DPF Program certification, or similar international certifications, as a requirement of becoming an accredited registrar with those registries. In early 2023, Tracer acquired a Portuguese subsidiary through which it employs a number of Portuguese residents, the personal data of which is shared with the Tracer's US headquarters for purposes of managing those employees.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Tracer: Active: EU-US Certification, UK Extension Certification, SW-US Certification
Live pagesha256 0663a23ab7
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Tracer GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Analytics category) whose GDPR row is verified or vendor-stated, ranked by similarity.

No Analytics vendor has GDPR evidence in the index yet.