generated: '2026-08-12' method: searched source: https://www.mozilla.org/en-US/anonym/privacy-policy/ note: >- Anonym publishes no certification report, trust center, or audit attestation. What it does publish is a detailed data-protection compliance disclosure inside the Anonym privacy policy on mozilla.org — named regimes, a transfer mechanism, a named EU representative, and a DPO mailbox. Only what is stated on that page is recorded here. Technical claims (confidential computing, TEE, differential privacy) are marketing statements on the product pages with no published attestation, and are recorded as claimed rather than conformant. standards: - id: gdpr conforms: true evidence: >- The Anonym privacy policy names the EU General Data Protection Regulation, enumerates data subject rights (access, rectification, erasure, restriction, portability, objection) and states legal bases for processing. source: https://www.mozilla.org/en-US/anonym/privacy-policy/ - id: uk-gdpr conforms: true evidence: UK GDPR named alongside EU GDPR and Swiss data protection legislation. source: https://www.mozilla.org/en-US/anonym/privacy-policy/ - id: swiss-fadp conforms: true evidence: Swiss data protection legislation named alongside GDPR and UK GDPR. source: https://www.mozilla.org/en-US/anonym/privacy-policy/ - id: ccpa conforms: true evidence: >- The California Consumer Privacy Act is named explicitly, with California-specific provisions for users under 18. source: https://www.mozilla.org/en-US/anonym/privacy-policy/ - id: eu-standard-contractual-clauses conforms: true evidence: >- International transfers outside the EEA, UK or Switzerland are covered by the European Commission-approved Standard Contractual Clauses. source: https://www.mozilla.org/en-US/anonym/privacy-policy/ - id: soc2 conforms: false evidence: No SOC 2 report, attestation, or trust center is published on any Anonym or Mozilla Anonym page probed. - id: iso27001 conforms: false evidence: No ISO 27001 certification is published on any Anonym page probed. - id: hipaa conforms: false evidence: Not applicable and not claimed — Anonym is advertising measurement, not a covered entity. - id: oauth2 conforms: unknown evidence: >- The customer portal signs in through Firebase Authentication / Google Identity Toolkit (identitytoolkit.googleapis.com, accounts.google.com, oauth2.googleapis.com in the portal CSP), but no Anonym API authorization server, scope reference, or OAuth documentation is public. Cannot be asserted either way from outside the login. - id: rfc9457 conforms: unknown evidence: No public API contract to evaluate — the backend is a gated gRPC service. contacts: data_protection_officer: dpo@anonymco.com privacy: privacy@anonymco.com eu_representative: IT Governance Europe Limited — eurep@itgovernance.eu certifications: []