Source
Privacy policy — Vanta
Checked for Vanta on 16 Sep 2026
- Page
- https://www.vanta.com/legal/privacy
- Checked
- 16 Sep 2026, 03:47 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:fe45aed658403576883d59d4ef3a0136f4de1fd89deeabda0fab00db63c36af3
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Entity Report an error
“Vanta Inc. Attn: Data Privacy Officer 655 Montgomery Street San Francisco, CA 94111”
-
Effective date Report an error
“Effective date: February 25, 2026”
-
GDPR lead supervisory authority Report an error
“the Irish Data Protection Commissioner, which is Vanta’s lead supervisory authority in the European Union”
-
Data privacy framework certified Report an error
“Vanta has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
-
International transfer safeguards Report an error
“Vanta deploys appropriate safeguards for transfers of personal information between jurisdictions with differing data protection laws, such as the EU standard contractual clauses, and has self-certified under the E.U.-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and the UK Extension to the E.U.-U.S. Data Privacy Framework with respect to the personal information of individuals from the European Economic Area, Switzerland, and the UK.”
-
List reference Report an error
“Additional information about the subprocessors Vanta uses to support delivery of our Services is set forth in our list of Vanta Subprocessors.”
-
Affiliate locations URL Report an error
“Vanta’s affiliate locations can be found at trust.vanta.com/subprocessors.”
-
Retention policy Report an error
“Vanta may retain personal information for as long as necessary for the purposes described in this Privacy Policy.”
-
Age limit Report an error
“Vanta does not allow use of our Services and Websites by anyone younger than 16 years old.”
-
Sale or sharing of data Report an error
“Vanta has sold or shared information (such as identifiers and internet activity information via Cookies) to ad networks, analytics providers, and marketing providers to serve you relevant ads on our Websites and other websites you visit.”
-
CCPA minors data sale Report an error
“To our knowledge, we do not sell the Personal Data of minors under 16 years of age.”
-
Ftc jurisdiction Report an error
“The Federal Trade Commission (FTC) has jurisdiction over Vanta’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).”
-
Dpf arbitration cost Report an error
“The services of JAMS ADR are provided at no cost to you.”
-
Msa governs customer data Report an error
“This Privacy Policy does not apply when Vanta collects personal information as a processor on behalf of a customer of the Services, nor to any third-party applications, software, products, or services that integrate with the Services (“Third-Party Services”), though it may reference those activities for purposes of clarity.”
Scores citing this record
- Dp Ciso European sovereignty
- Dp Ciso European sovereignty
- The Drafted Generalist European sovereignty
- The Drafted Generalist European sovereignty
- The External DPO European sovereignty
- The External DPO European sovereignty
- The IT Integrator European sovereignty
- The IT Integrator European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The CISO European sovereignty
- The CISO European sovereignty
- The CISO European sovereignty
- The CISO European sovereignty
- The CISO European sovereignty
- The GRC Consultant European sovereignty
- The GRC Consultant European sovereignty
- The GRC Consultant European sovereignty
- The GRC Consultant European sovereignty
- The GRC Consultant European sovereignty
- The Evidence Integrator European sovereignty
- The Evidence Integrator European sovereignty
- The Evidence Integrator European sovereignty
- The Evidence Integrator European sovereignty
- The Evidence Integrator European sovereignty
- The Evidence Integrator European sovereignty
- The Drafted IT Officer European sovereignty
- The Drafted IT Officer European sovereignty
- The Drafted IT Officer European sovereignty
- The Drafted IT Officer European sovereignty
- The Drafted IT Officer European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The Skeptic European sovereignty