Veracode and GDPR
CertReports found no public GDPR evidence for Veracode as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 29 Sep 2016
- Expires or valid through
- 26 Jan 2027
- Scope
- We collect personal information about you through the Sites to communicate with you, to the extent permitted by applicable law, about our solutions, products, services, promotions, company, and other products or services we think may be of interest to you. In the absence of your express prior consent, we will only send you marketing emails to advertise for our own products or services that are similar to those you purchased from us. You can object (opt-out) to the receipt of such marketing emails at any time, without any costs arising (other than transmission costs), by following the unsubscribe link found at the bottom of each marketing email or by contacting us as described in the section entitled, ‘Contact Us’, below. In addition, if you submit your resume, we will contact you about potential employment opportunities. We may share your personal information with third parties that provide services on our behalf or with whom we have partnered to offer a particular product or service as described in the section entitled ‘How we share information with third parties’ below. We use technical information which does not identify individual users, to improve user experience and overall quality of our Sites, to analyze trends, to administer the site, to track users’ movements around the site and to gather demographic information about our user base as a whole. For example, each visitor to the Site is identified by an IP address during their visit and IP addresses are automatically captured by Site management software. Veracode uses this information to help improve the operation of the Site and may at some time use this information to help adjust the content of the Site to the general geographic location of the visitor and for reporting purposes. Because technical information does not personally identify you, we may also use and disclose technical information for any other purpose. To the extent permitted by applicable law, we may combine personal information with technical information. If we do so, we will treat all combined information as personal information as long as it is combined. The personal information we collect is deleted once it is no longer used for the purposes stated above and if no statutory retention obligations apply (in which case the data will be deleted after the applicable retention period expires).
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Veracode: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 6fbcc6655b |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Veracode GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.