ZeroEyes and GDPR
CertReports found no public GDPR evidence for ZeroEyes as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 15 Jun 2026
- Expires or valid through
- 15 Jun 2027
- Scope
- ZeroEyes processes security camera data to deliver its AI-enabled firearm detection service and related customer support, including analyzing images from customer security camera video feeds to detect visible firearms, forwarding suspected firearm images to its operations center for human verification, and, when a threat is verified, sending those alerts (with situational details) to authorized customer personnel and, as applicable, to law enforcement / emergency response recipients. The analytic is trained to detect the form factor of a firearm, and bladed weapon, it does not look for personally identifiable information or any other human characteristic, simply the object. In connection with these services, it may process customer/organization account and user data (for example, names, addresses, email addresses, and telephone numbers provided for account creation, billing, support, and communications), technical and usage data (for example, IP address, browser and device details), and mobile application data where used (which may include device identifiers and, for location-based services, geolocation data and push-notification permissions). For the firearm/knife detection workflow specifically, it may process and retain detection-related images (including true positives and false positives) and, if permitted by the customer, limited installation/testing video; retention timeframes can be specified by the customer and this data is described as transmitted/stored in encrypted form. ZeroEyes' analytic is for weapons detection, and does not store biometric identifiers, noting that a person’s face would only be recorded/retained in the instance of an active assailant incident. It discloses personal data to (i) customer organizations and their authorized users to operate the service and receive alerts, (ii) law enforcement/emergency responders where warranted for threat response and as required by law.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | ZeroEyes, Inc.: Active: EU-US Certification, UK Extension Certification | Live pagesha256 9b542c3cf9 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is ZeroEyes GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.