D&B has had its privacy and information security management systems independently audited against ISO 27701 and ISO 27001 standards in applicable markets, providing third-party assurance of its data governance controls.
This analysis describes what Dun & Bradstreet's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
ISO 27701 certification is a recognized international benchmark for privacy information management, providing external validation that D&B's privacy controls meet a defined standard, though certification scope varies by market.
Interpretive note: Certification scope is market-specific and not universally applied across all D&B legal entities or geographies; the specific list is available only on a linked external page not reproduced in this document.
The updated privacy policy removed explicit language describing how users can manage cookie preferences and enable chat functionality. Previously, the policy stated that users could click 'Manage Choices' to enable or disable specific cookies including 'Chat' cookies. The revised version no longer includes these detailed preference options in the displayed policy language. The terms now indicate that chat functionality requires accepting 'Chat Cookies,' but the granular control mechanisms previously described have been removed from the public policy disclosure.
View change record →The updated privacy statement removes extensive disclosures about Dun & Bradstreet's data processing practices, ethical commitments, certifications, and individual rights procedures. Previously, the policy described the company's core values, ethical principles, ISO certifications, cross-border privacy frameworks, data broker registrations in multiple states, and how individuals could exercise rights. The revised statement now provides minimal substantive guidance. Under the updated terms, users will find substantially less information about how their data is processed, what protections apply, and how to contact the company regarding their rights.
View change record →These certifications provide independent assurance that D&B's data management practices in certified markets meet internationally recognized privacy and security standards, which is relevant for business customers assessing D&B as a data supplier. The certification scope is market-specific and not universal across all D&B operations.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
to object to profiling activities based on our own legitimate interests
"Our program has been designed and audited for compliance with ISO 27701, Privacy Information Management Systems (PIMS). In markets in which we are certified as compliant with ISO 27001, Information Security Management Systems (ISMS), we also hold an ISO 27701 certification (PIMS). These certifications are designated on the global ISO certifications page, where applicable.Excerpt from Dun & Bradstreet's D&B Privacy Policy
REGULATORY LANDSCAPE: ISO 27701 is recognized by regulators including the EU data protection authorities as a relevant standard for demonstrating GDPR compliance, and may be cited as evidence of appropriate technical and organizational measures under …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
ISO 27701 certification is a recognized international benchmark for privacy information management, providing external validation that D&B's privacy controls meet a defined standard, though certification scope varies by market.
These certifications provide independent assurance that D&B's data management practices in certified markets meet internationally recognized privacy and security standards, which is relevant for business customers assessing D&B as a data supplier. The certification scope is market-specific and not universal across all D&B operations.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Dun & Bradstreet.