Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
D&B provides a web-based portal where individuals can submit requests to access, correct, or delete their personal data held by D&B entities, covering both personal and professional data.
This analysis describes what Dun & Bradstreet's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The existence of a rights portal is the primary mechanism through which individuals can discover and control what data D&B holds about them, particularly relevant given D&B's data broker status and the likelihood that many individuals are unaware their data is held.
Interpretive note: The document does not specify response timelines, the scope of data covered across all three registered data broker entities, or the identity verification process, creating uncertainty about the practical effectiveness of the rights mechanism.
The updated privacy policy removed explicit language describing how users can manage cookie preferences and enable chat functionality. Previously, the policy stated that users could click 'Manage Choices' to enable or disable specific cookies including 'Chat' cookies. The revised version no longer includes these detailed preference options in the displayed policy language. The terms now indicate that chat functionality requires accepting 'Chat Cookies,' but the granular control mechanisms previously described have been removed from the public policy disclosure.
View change record →The updated privacy statement removes extensive disclosures about Dun & Bradstreet's data processing practices, ethical commitments, certifications, and individual rights procedures. Previously, the policy described the company's core values, ethical principles, ISO certifications, cross-border privacy frameworks, data broker registrations in multiple states, and how individuals could exercise rights. The revised statement now provides minimal substantive guidance. Under the updated terms, users will find substantially less information about how their data is processed, what protections apply, and how to contact the company regarding their rights.
View change record →Individuals can submit data access, correction, or deletion requests via D&B's TrustArc-hosted portal, which applies to both personal and professional data held by D&B. The practical scope of which rights are available may vary by jurisdiction, as GDPR, CCPA, and other frameworks confer different and not always identical rights.
How other platforms handle this
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
to request that your data be transferred to a third party (data portability)
Monitoring
Dun & Bradstreet has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We are committed to respecting the data and digital rights of individuals in both their personal and professional capacities as set forth in our Global Data Subject Rights Policy Statement. You may exercise your rights in connection with our data processing here.Excerpt from Dun & Bradstreet's D&B Privacy Policy
REGULATORY LANDSCAPE: The data subject rights framework engages GDPR Articles 15-22 (rights of access, rectification, erasure, restriction, portability, and objection), CCPA/CPRA rights to know, delete, and correct, and equivalent rights under the UK GDPR, Swiss FADP, and other applicable national laws. The TrustArc platform as the operational mechanism for rights fulfillment means D&B has engaged a third-party consent and rights management processor, which itself introduces a sub-processor relationship subject to data processing agreement requirements. GOVERNANCE EXPOSURE: Medium. The rights portal commitment is positive from a transparency standpoint, but the adequacy of response timelines, identity verification processes, and the scope of data covered (across all three registered data broker entities) is not detailed in this document. GDPR requires responses within 30 days; CCPA requires responses within 45 days with a possible 45-day extension. JURISDICTION FLAGS: EU and UK data subjects have the strongest enforceable rights framework, including the right to object to processing on legitimate interests grounds and the right to lodge complaints with supervisory authorities. California residents have CCPA/CPRA rights that may be more operationally straightforward to enforce. Rights available to individuals in jurisdictions without comprehensive privacy laws (e.g., most U.S. states outside California, Colorado, Virginia, Texas) depend on D&B's voluntary commitments under this statement. CONTRACT AND VENDOR IMPLICATIONS: Organizations that have provided D&B with employee or customer data through data licensing or API integrations should assess whether their vendor agreements with D&B address downstream data subject rights fulfillment obligations, including who is responsible for responding to deletion requests that flow through the organization's own privacy mechanisms. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that D&B's TrustArc sub-processor arrangement is covered under an appropriate data processing agreement and that D&B's response to rights requests includes data held by Eyeota and NetWise entities. Teams should also confirm whether the portal's geographic scope covers all jurisdictions in which their employees or customers may be located.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
The existence of a rights portal is the primary mechanism through which individuals can discover and control what data D&B holds about them, particularly relevant given D&B's data broker status and the likelihood that many individuals are unaware their data is held.
Individuals can submit data access, correction, or deletion requests via D&B's TrustArc-hosted portal, which applies to both personal and professional data held by D&B. The practical scope of which rights are available may vary by jurisdiction, as GDPR, CCPA, and other frameworks confer different and not always identical rights.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Dun & Bradstreet.