Record confirmed by a person on 29 September 2026. 1 recorded change, listed below.
GoodData contracts through GoodData Corporation, registered in United States. Transfers of personal data out of the EEA are covered by EU-US Data Privacy Framework (DPF). Its trust center is published at https://www.gooddata.ai/security/. Its customer data processing agreement, also called a data processing addendum, is published by GoodData itself; the link is below. Its sub-processor list is published by GoodData itself; the link is below. A person last went through this record on 29 September 2026.
A US certification scheme covered by an EU adequacy decision. Transfers to a certified US organisation need no further mechanism for the certified scope.
A ready row. Replace the purpose with what your client actually uses GoodData for.
| Subprocessor | Legal entity | Country | Purpose | Transfer | DPA |
|---|---|---|---|---|---|
| GoodData | GoodData Corporation | US | Analytics | DPF | https://legal.gooddata.com/ |
Changes we noticed on GoodData's own pages and a person confirmed. The vendor does not publish this, and neither does anyone else.
29 September 2026
We recorded changes to the transfer mechanism, the UK transfer mechanism.
Worked out from the registry and what we have written: the country this vendor contracts from, the guides that answer the question this page raises, and the rest of the registry.
Six of them. All analytics in the registry · others that transfer the same way.