Privacy Center Hero Image

Committed to
Data privacy

At DigiCert, we value your privacy and protect your personal
data with industry-standard policies and best practices.

Our approach to privacy

As a leader in digital trust, our approach to privacy and protecting your personal data is built into how we design, deliver, and market our solutions, products, and services. To learn more, please see the information below on our data privacy practices.

Data privacy practices

Learn about our privacy practices as they relate to our various DigiCert brands, products, and services by reviewing one of the following:

For our customers who choose to use our Remote ID Verification process, please see our Remote Identity Verification section below.

Data Privacy Icon 1

Remote Identity Verification

Remote Identity Verification (RIV), also known as Identity Proofing, is a method to verify and authenticate the identity of a person through government identification, biometrics, facial recognition, or other means of identity validation. 

For our customers that choose to use our RIV process as part of validation related to the issuance of digital certificates, you may view our Remote ID Verification Privacy Notice that describes our privacy practices related to RIV.  As part of this process, we will obtain your consent prior to collecting your identity information and provide you an opportunity to withdraw your consent.

Data Privacy Icon 2

Privacy across borders

When DigiCert transfers personal data across country borders, we do so in compliance with applicable data protection laws and regulations. DigiCert has established appropriate cross-border safeguards, including intra-group standard contractual clauses and, for personal data transferred outside of the EU, UK, and Switzerland, certification under the EU-U.S. Data Privacy Framework (“DPF”), the UK Extension to the DPF, and the Swiss-U.S. DPF. For more information on DigiCert’s compliance with the DPF, please see our DigiCert Global Privacy Notice.

Third-party sub-processors

DigiCert works with third-party sub-processors, including vendors and service providers, that process personal data on our behalf.  DigiCert enters into data processing agreements that require our sub-processors to process personal data only for the purpose of providing you the services you have requested, and not for their own marketing or sales initiatives.  Our data processing agreements with our sub-processors incorporate cross-border safeguards, including the EU standard contractual clauses, that ensure cross-border transfers to sub-processors are compliant with the GDPR and similar data protection laws.

For a list of third-party sub-processors related to the following DigiCert brands, please see the links below:

VMC Blue Icon 2

DigiCert controller status

When DigiCert is acting as a Trusted Third-Party Public Certification Authority, it is acting as a data controller with respect to the personal data you share with us. For questions on why we should be designated as a controller when issuing public certificates, please see our Controller FAQ document.

DNS Blue Circle Icon

Internal processing and storage locations

Please see our list of locations where DigiCert stores and accesses your personal information for the purpose of internal processing. If you have questions regarding the available storage and internal processing locations, please contact our Support team at support@digicert.com.

Digital Trust to Combat Software Supply Chain Attacks

Technical and Organizational Measures (TOMs)

The security of your personal data is of the utmost importance to DigiCert. DigiCert has implemented and maintains internal technical and organizational measures (sometimes referred to as “TOMs”) in accordance with industry best practices and applicable data protection laws.

Data Privacy Icon 1

Your privacy rights

You have certain rights with respect to your personal data. This includes, among others, rights to access your personal data, request correction of inaccurate data, request deletion, restrict processing, object to processing, and data portability. If needed, you may submit a privacy request here.