Security · 9 November 2023
Ubivox receives ISAE 3000 report
As part of our work on GDPR compliance, we can now present our ISAE 3000 report – an objective review carried out by an external auditor. It should give you peace of mind that there really is action behind our words.

At Ubivox, the GDPR has long been at the top of our list of priorities. It matters to us that your data is safe in our hands. Beyond the legal responsibility, you as a company or public authority also have a moral responsibility to look after the recipient’s data when you work with emails and newsletters.
And as part of our work on GDPR compliance, we can now present our ISAE 3000 report. It should give you peace of mind that there really is action behind our words.
The ISAE 3000 report is a seal of approval on our work with data security
An ISAE 3000 report is an objective review of the procedures and controls a company has implemented in order to comply with the GDPR. The review is carried out by an external auditor.
When you do business and interact with a company, an ISAE 3000 report can therefore give you peace of mind.
We have long been able to offer you a GDPR-compliant platform
When you use our platform, we make sure your data stays within European borders – and so is not sent to unsafe third countries. We have therefore long been able to offer a GDPR-compliant platform. The new report is simply an objective assessment confirming that we really do comply with what we say when it comes to the GDPR in our internal working processes.
Why you should still think twice before sending data to the USA
For a long time it has been a problem to use systems with data processing agreements in the USA, since it is an unsafe third country.
In July 2023, however, the EU and the USA entered into a new agreement in Danish intended to make it possible to use American data processors, provided they have certified themselves under the EU-U.S. Data Privacy Framework with the US Department of Commerce.
This agreement is being met with great scepticism, though, and there are therefore prospects of it being challenged and declared invalid, like the two previous agreements. You can read more about the agreement’s challenges and limitations on the Danish Data Protection Agency’s website in Danish.