Skip to main content
Zscaler logo

Zscaler

GDPR evidence

zscaler.comSecurityLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Zscaler and GDPR

CertReports found no public GDPR evidence for Zscaler as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
23 Nov 2016
Expires or valid through
30 Jul 2027
Scope
Zscaler is a global cloud-based information security company. We process customer data to provide our security services, protecting clients from cyber threats and data leaks. In addition, Zscaler processes Human Resources (HR) personal data received from the European Union, United Kingdom, and Switzerland in reliance on the Data Privacy Framework (DPF) for the purposes of managing the employment relationship. To manage our employment relationship, we process several categories of HR personal data, including identifiers (e.g., name, address, government IDs), professional and employment-related information (e.g., work history, performance evaluations), and financial data (for payroll). This data is used for essential HR functions such as recruitment, onboarding, administering pay and benefits, conducting performance reviews, ensuring the security of our business assets, and complying with legal and regulatory obligations. For these purposes, Zscaler may disclose HR personal data to third parties. These include our corporate affiliates for global HR administration; service providers who assist with payroll, benefits, and IT systems; government and regulatory authorities as required by law; and other parties as directed by employees or as part of a corporate transaction. When providing services to our customers, Zscaler acts as a data processor, processing personal data on their behalf and under their instruction. Our services use limited personal data, such as IP addresses, URLs, and user IDs, to provide customers' authorized users with secure access to the internet and applications, and to guard against threats.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Zscaler: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 7d568134f8
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Zscaler GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.