Skip to content


Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?

Latest commit


Git stats


Failed to load latest commit information.
Latest commit message
Commit time

ComplianceRank (formerly GDPR Tracker)

ComplianceRank is a crowdsourced directory that makes it easier for companies and consumers to keep track of the data handling practices of their subcontractors and cloud services in real-time.

This repository holds all the services displayed in the directory. We strongly believe that data handling practices should be easily available to business & customers.

How to add a service?

You can add a service by following the contribution guidelines.


We use JSON Schema to validate the data and to maintain a high level of data quality. Please find the schema at the following location.

Field Type Format Required Options Description
id string * Unique id to identify the company
name string * Name of the company
description string * Description of the service
website string url * Website of the service
applicationUrl string url * Application of the service
categories array * Categories that the service belongs to
iconUrl string url * URL to the icon of the service (recommended size 400x400px). Must be HTTPS
countryHQ string ISO ALPHA-2 code * Country of HQ
gdprReadyStatus enum * unknown
GDPR readiness status of this service
privacyUrl string url Link to privacy policy
dsarUrl string url Data Subject Access Rights Form URL
dpaUrl string url Data Processing Agreement URL
subprocessorsUrl string url Subprocessors overview URL
dataCenters array Locations where data is hosted
hostingProviders array Hosting providers
contacts array Appointed DPOs or privacy officers per region, we only support 3 types DPO, Privacy Officer, Other
certifications enum - ISO 27001
- ISO 27002
- ISO 27017
- ISO 27018
- C5
- PCI DSS Level 1
- PCI DSS Level 3.1
- PCI DSS Level 3.2
- PCI DSS Level 4.0
- SOC 1
- SOC 2 Type I
- SOC 2 Type II
- SOC 3
- ISAE 3000
- EU-U.S. Privacy Shield
- Swiss-U.S. Privacy Shield
- OpenID
- TRUSTe Enterprise Privacy Certification
dataBreaches array Reported data breaches
articles array GDPR & privacy related articles
bugBountyProgramUrl string url Link to bug bounty program
statusUrl string url Link to status page
statusTwitter string Twitter account that communicates about service status & uptime
businessModel array - B2B
- B2C
- B2B2C
Business model
verified boolean Verified by company representative


  "id": "acme",
  "name": "Acme",
  "description": "CRM & Customer platform for SMBs",
  "categories": [
    "Customer Support"
  "iconUrl": "",
  "website": "",
  "applicationUrl": "",    
  "twitter": "acme",
  "countryHQ": "US",
  "gdprReadyStatus": "inProgress",
  "privacyUrl": "",
  "dsarUrl": "",
  "dpaUrl": "",
  "subprocessorsUrl": "",
  "dataCenters": [
  "hostingProviders": [
    "Digital Ocean"
  "contacts": [
      "type": "DPO",
      "name": "John Doe",
      "email": "",
      "region": "EU"
      "type": "DPO",
      "name": "Tim Doe",
      "email": "",
      "region": "US"
  "certifications": [
    "ISO 27001", 
  "dataBreaches": [
      "date": "10/12/2017",
      "url": ""
  "articles": [
      "date": "02/12/2018",
      "url": ""
  "bugBountyProgramUrl": "",
  "statusUrl": "",
  "statusTwitter": "beatswitchstatus",
  "securityUrl": "",
  "businessModel": ["B2C"]
  "verified": true


If you want your service to be removed from the tracker, send in a pull request with the reason stated.


MIT License. Please see the license file for more information.


Made in Belgium 🇧🇪 Europe 🇪🇺

The GDPR Tracker is created by Privacy Radius. Privacy Radius is a European provider of AI-powered data and privacy solutions to help companies create trusted environments to protect consumers' privacy and data rights.


We do our best to ensure that the data we provide is complete, accurate and useful. However, because we do not verify all the data, and because the processing required to make the data useful is complex, we cannot be liable for omissions or inaccuracies.