Xerox and GDPR
CertReports found no public GDPR evidence for Xerox as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 16 Nov 2018
- Scope
- Our Privacy Shield commitment covers human resources information we collect in the context of the employment relationship as well as other personal information that we collect from customers and potential customers. We collect personal information from customers and potential customers through direct email and telephone calls. Additionally, customers and potential customers can register on our website to purchase or get quotes regarding our products and services or to receive additional information regarding the same. We may collect some or all of the following information from customers and potential customers located in the EU and Switzerland: name; email address; mailing address; billing address; telephone number; fax number. We use tokens for credit card information from our customers. We use the personal information we collect from our customers and potential customers located in the EU and Switzerland only for legitimate business purposes, including: (1) contract and billing administration, (2) product and service delivery, (3) communications regarding marketing and technical information concerning our products and services, (4) notifying our customers and potential customers regarding product launches and important events related to Xerox Corporation, and (5) fulfilling our business obligations to our customers. The personal information that we collect from our customers and potential customers in the EU and Switzerland is stored in a database that is accessible by certain employees that are located in the United States. We limit access to this information to only those employees who are necessary to carry out the above listed business purposes. We use human resources data we collect from our employees in the EU and Switerland only for the following business purposes: (1) the management and operations of our company, its functions and activities, (2) employee communications, including employee surveys, (3) maintaining a global directory, (4) carrying out obligations under employment contracts and employment, tax and benefits laws, and in connection with other working relationships or arrangements, (5) development and training programs, (6) recruiting and hiring job applicants, (7) assessing qualifications and performance, (8) performing background checks and verifying references, (9) managing employee performance, (10) determining employee compensation or payment, (11) managing the employee termination process, and (12) other general human resources purposes. The human resources data that we collect from our EU and Swiss employees is stored in a database that is accessible by certain employees that are located in the United States. We limit access to this information to only those employees who are necessary to carry out the above listed business purposes. Xerox does not sell personal information to third parties. In certain circumstances Xerox Corporation transfers personal information to our agents, resellers or third party service providers (such as accountants, attorneys, consultants, and other service providers). We will only transfer personal information to agents, resellers or third party service providers who need the information in order to provide services to or perform activities on behalf of Xerox Corporation, including in connection with the delivery of services or products, Xerox Corporation management, administration, or legal responsibilities. We only transfer personal information collected from individuals located in the EU and Switzerland to third parties in compliance with the Privacy Shield Framework Principals.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Xerox Corporation: Inactive | Live pagesha256 531c84a7a8 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Xerox GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the IT management category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No IT management vendor has GDPR evidence in the index yet.