
Zuora and GDPR
CertReports found no public GDPR evidence for Zuora as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 20 Oct 2016
- Scope
- As a data controller, we collect personal data from individual contacts of corporate customers, prospective corporate customers, suppliers and other business partners (EEA Business Contacts). From our EEA Business Contacts, we collect the following types of personal data: name, job title, company affiliation and contact information. We also store and process personal data on behalf of our corporate customers. Our corporate customers use our software-as-a-service products to process personal data at their discretion, including data pertaining to their own subscribers, such as name, contact information, account information, and payment information. We share personal data of EEA residents with our subsidiaries, affiliates and contractors, who process personal data on behalf of Zuora. We also provide information to our channel partners, such as distributors and resellers, to fulfill product and information requests, and to provide customers and prospective customers with information about Zuora and its products and services. We also share EEA Data with other third parties for the purposes for which we receive the EEA Data (e.g., performance of contractual obligations and rights), and we may also disclose EEA Data where we are legally required to disclose (e.g., under statutes, contracts or otherwise) or where the disclosure is permitted by law or the Data Privacy Framework Principles and we have a legitimate business interest in such disclosure.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Zuora, Inc.: Inactive | Live pagesha256 1c60d83db2 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Zuora GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Finance and accounting category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Finance and accounting vendor has GDPR evidence in the index yet.