
TrustArc and GDPR
CertReports found no public GDPR evidence for TrustArc as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 21 Oct 2016
- Expires or valid through
- 3 Nov 2026
- Scope
- TrustArc processes the personal information of customers and business partners (e.g., name, email address, company name, phone number, job function, job title, country, and any provided comments) in order to provide requested information about our solutions or partnership opportunities; to offer customer support for using the TrustArc privacy technology platform and other purchased services; to participate in our assurance programs and solutions; to engage with our consulting services; to enter negotiations and contractual relationships; to send sales-related and marketing communications, including for upcoming TrustArc webinars, events and related services that may be of interest; and to process market research and survey submissions. We also process data on individuals who engage with us in such activities as webinars, podcast, customer portal, and other such engagements such as name, email address, and company information. TrustArc also processes personal information that we collect either directly, through forms or data entry fields on our website, or through passive collection by cookies and other data collection technologies (e.g., analytics relating to services and features being used and which parts of the website are visited). TrustArc processes personal information (e.g., IP address, tracking preferences) when users express interest or manage their preferences through the technology solutions we provide on our websites and online properties. We collect personal information from consumers who submit complaints through TRUSTe’s Dispute Resolution form (e.g., email address, type of complaint and issue description), in order to investigate and resolve the consumer’s non-frivolous privacy-related complaint, question or concern. TrustArc also processes personal information of employees, contractors, job applicants and former employees (e.g., benefits, nationality, residency status, email address, office or other workplace location including remote work arrangements, work phone number, mobile phone number, photographs, passport, visas, marital status, beneficiaries and /or dependents and their associated data related to benefits such as date of birth or relationship status, emergency contact details, financial account information, social security number or other government-issued identification number), as appropriate and in accordance with applicable laws. We may share personal information with the following type of third parties - Hosting provider: Amazon Web Services - Email Service Provider: Mailgun Technologies Inc - Cloud Services support: Microsoft Inc. - Marketing Services: Marketo - Customer service, sales, and support: Salesforce - TrustArc affiliates to provide requested services - Advertising and Analytics services: Google Inc., ZoomInfo
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | TrustArc Inc: Active: EU-US Certification, UK Extension Certification, SW-US Certification | Live pagesha256 61237bb6af |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is TrustArc GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Compliance and GRC category) whose GDPR row is verified or vendor-stated, ranked by similarity.