Outcome · Say it on your website
Coming soon

Say “GDPR compliant” and “DORA ready” in public — truthfully and safely

You can say on your website and in tenders that you are GDPR compliant or DORA ready, if it is true and verifiable; you cannot display a trust mark you were not granted, or claim a certification or an authority's approval you do not hold. Audomate already helps you prepare the evidence such a claim rests on. The verified mark — which will let you say “verified against these articles on this date” and link a public evidence page — is in preparation.

01

Advertising law covers compliance claims

Unfair commercial practices law (Annex I of the UCPD) — unauthorised trust marks and false claims of approval are unfair in all circumstances.

02

“Certified” is a specific word

Art. 42 GDPR certification is issued by accredited bodies under approved schemes. If you do not hold one, do not use the word.

03

Verifiable beats vague

“Verified by Audomate against Art. 28–30 DORA on 7 September 2026” is something anyone can check. “Fully compliant” is not.

04

Truth in a tender is contract law too

A compliance statement in a proposal becomes a representation in the contract. Make it one you can prove.

What you are allowed to say

WordingSafe?Why
“We apply the GDPR to all the personal data we process.”YesA statement about your own conduct; your privacy policy has to be consistent with it.
“Our GDPR documentation was verified by Audomate on [date] — see the verification page.”YesVerifiable, dated, scoped, evidenced.
“GDPR certified”NoIt implies an Art. 42 certification you most likely do not hold.
“Approved by the data protection authority / the financial supervisor”NoAuthorities do not approve vendors; this is a blacklisted claim.
“DORA-ready ICT vendor — Art. 28–30 vendor obligations verified [date]”YesThe right framing: DORA does not certify vendors; verification of the relevant obligations is what a bank wants to see.
“DORA compliant” (unqualified, no evidence)RiskyDORA applies to financial entities; an ICT vendor is only “compliant” as to its contractual obligations. Qualify it or link the evidence.

How the verified mark will make the claim defensible

The mark will be the claim and the evidence in one link. It will name the scope and the articles, show the date and the validity, and list what was checked. When the evidence goes stale the mark will be withdrawn and the page will say so — and that is exactly the property that will make it credible to the compliance officer on the other side.

Where to put it

  • The site footer, next to the privacy policy and terms of service.
  • The security or trust section of your proposal and SaaS documentation.
  • Tender responses: as an annex, with the verification link in the compliance section.
  • Vendor questionnaires: the first sentence of your answer, then the cited evidence.
  • Your Trust Center page (the Standard and Pro plans).

See the Free planThree months free; the mark joins the plan once it launches.

Questions we get most often

Not in itself, if it is true and you can demonstrate it. It becomes an unfair practice when it misleads — for example by implying certification or approval by an authority, or where your actual documentation would not support it.
Yes, because the mark will not claim to be a DORA certification. It will state that your vendor-side obligations under Art. 28–30 — clauses, register data, incident and exit arrangements — were verified on a given date. That is the scope a bank checks.
The badge will link to a page that shows “expired” — the mark corrects itself. Knowingly displaying an expired mark would be your misleading statement, not ours — which is why re-verification is automated and prompted.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Reach this outcome in four weeks

One regulation, your real documents, a cited gap list and remediation drafts — plus a verified mark if you pass.