At CertCrowd, trust is not just a product feature, it is the foundation of our business. That is why we are excited to announce that CertCrowd is now fully aligned with the General Data Protection Regulation (GDPR), the world’s most stringent privacy and data protection framework.
For a global SaaS platform supporting organisations on their ISO and GRC journeys, GDPR compliance is not optional. It demonstrates that we protect personal data with the same level of rigour we ask our customers to uphold.
This achievement reflects months of focused work across legal, technical, and operational layers, and it now forms a core part of our governance, risk, and compliance ecosystem.
GDPR compliance ensures that when users entrust us with their information, we:
It is one of the strongest signals of privacy maturity a SaaS provider can demonstrate, especially for customers in Europe, the UK, and any organisation operating with globally distributed data.
Our compliance program covered all major GDPR pillars, and we have embedded these controls into the heart of our operations.
We rewrote and expanded our Privacy Policy to ensure it meets GDPR transparency requirements, including:
Our Privacy Policy now reflects exactly how CertCrowd uses and protects personal data, with no jargon, no hidden terms, and no ambiguity.
Every customer now benefits from a GDPR-aligned DPA that covers:
The DPA is available by default to all customers and is referenced throughout our terms.
To meet EU and UK requirements for non-essential cookies, we implemented:
This ensures users are in complete control over non-essential tracking technologies.
Because CertCrowd processes personal data of EU and UK residents without having an establishment in those regions, we appointed:
This ensures local supervisory authorities and individuals have direct contact points within the EU and UK jurisdictions.
We introduced a public Sub-processor Register that:
This transparency supports compliance for our customers’ own GDPR obligations.
We established a comprehensive ROPA to meet Article 30 requirements, documenting:
This forms a core part of our internal accountability framework.
All team members completed GDPR and privacy awareness training covering:
This ensures privacy is foundational, not optional.
Whether you are using CertCrowd to implement ISO 27001, manage audits, or streamline compliance:
In short, GDPR compliance is not just "done". It is embedded.
Achieving GDPR compliance is a major milestone, but not the endpoint.
We will continue to:
Because privacy and trust are not static; they are ongoing commitments.
This achievement reflects deep collaboration across engineering, legal, support, and security. To our customers and partners, thank you for trusting CertCrowd to safeguard what matters most.



