Verily Health and GDPR
CertReports found no public GDPR evidence for Verily Health as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 20 Apr 2026
- Expires or valid through
- 20 Apr 2027
- Scope
- Verily may collect personal data received in reliance on the EU-US DPF and, as applicable, the UK Extension to the EU-US DPF, and/or the Swiss-US DPF to provide its services, including to operate, maintain, improve, and address questions relating to its services, and to meet its contractual obligations. This personal data may include: contact and demographic information (e.g. username, first and last names, phone numbers, and email addresses); information from third parties (e.g. if an individual is accessing our services through a third-party connection or log-in and Verily may collect user IDs associated with accounts); information from third party sources (e.g. public sources, social media platforms, and third party data providers and information services); automatic information about how an individual may use and/or interact with Verily services to help Verily provide and improve our services to individuals; and phone or device information (e.g. collection of data for personalization, analytics, and advertising). This type of personal data may be collected by Verily in its role as a controller, e.g. personal data that is collected directly from individuals who may visit Verily websites, or in its role as a processor, i.e. Verily may enter into contracts and/or agreements with customers, clients, or partners to provide services on their behalf. As a controller, Verily may also collect human resources (HR) data on its employees. The categories of data that Verily may collect in its role as an employer are: personal data (e.g. name, address, phone number, email, emergency contact details); employment details (e.g. job title, department, hire date, employment status); compensation; performance data (e.g. performance reviews); diversity and demographics (e.g. gender, ethnicity, veteran status); leave records; training and development; and work activity data (e.g. computer screen time, on-site, i.e. entrance and exit). Verily may share personal data with third parties, including service providers and third party advertising partners (i.e. entities that we may contract with to support our operations and to help us operate our technology and services); business and research partners, including study sponsors; professional service companies (i.e. attorneys, accountants, similar professionals); and/or other third parties (i.e. legal, security, and safety purposes).
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Verily Health Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 7926eca93d |
- Kind
- listing
- Issued or listed
- 2 Feb 2018
- Expires or valid through
- 12 Mar 2027
- Scope
- Verily may collect personal data received in reliance on the EU-US DPF and, as applicable, the UK Extension to the EU-US DPF, and/or the Swiss-US DPF to provide its services, including to operate, maintain, improve, and address questions relating to its services, and to meet its contractual obligations. This personal data may include: contact and demographic information (e.g. username, first and last names, phone numbers, and email addresses); information from third parties (e.g. if an individual is accessing our services through a third-party connection or log-in and Verily may collect user IDs associated with accounts); information from third party sources (e.g. public sources, social media platforms, and third party data providers and information services); automatic information about how an individual may use and/or interact with Verily services to help Verily provide and improve our services to individuals; and phone or device information (e.g. collection of data for personalization, analytics, and advertising). This type of personal data may be collected by Verily in its role as a controller, e.g. personal data that is collected directly from individuals who may visit Verily websites, or in its role as a processor, i.e. Verily may enter into contracts and/or agreements with customers, clients, or partners to provide services on their behalf. As a controller, Verily may also collect human resources (HR) data on its employees. The categories of data that Verily may collect in its role as an employer are: personal data (e.g. name, address, phone number, email, emergency contact details); employment details (e.g. job title, department, hire date, employment status); compensation; performance data (e.g. performance reviews); diversity and demographics (e.g. gender, ethnicity, veteran status); leave records; training and development; and work activity data (e.g. computer screen time, on-site, i.e. entrance and exit). Verily may share personal data with third parties, including service providers and third party advertising partners (i.e. entities that we may contract with to support our operations and to help us operate our technology and services); business and research partners, including study sponsors; professional service companies (i.e. attorneys, accountants, similar professionals); and/or other third parties (i.e. legal, security, and safety purposes).
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Verily Life Sciences, LLC: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 f5cf42fdbc |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Verily Health GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.