generated: '2026-08-05' method: searched source: >- Tory Burch's own published policy pages - https://www.toryburch.com/en-us/customer-services/privacy-policy/ and https://www.toryburch.com/en-gb/customer-services/privacy-policy/ (both HTTP 200, fetched 2026-08-05) scope: >- Tory Burch publishes no API, so none of the API or cross-cutting technical standards this artifact normally asserts against (OAuth 2.0, OIDC, RFC 9457 problem details, JSON:API, OData, SCIM, FHIR, FAPI, PSD2, idempotency keys, pagination conventions) are applicable - there is no contract for them to apply to. What the company is actually measured against is consumer-privacy and payment regulation for a direct-to-consumer luxury retailer. Those regimes are recorded below, each with the evidence actually found on Tory Burch's own pages. Absence of a published claim is recorded as absence, not as non-compliance. conformance: - id: ccpa name: California Consumer Privacy Act / CPRA conforms: true evidence: >- The US privacy policy names the California Consumer Privacy Act explicitly (6 mentions of "CCPA") and operationalises it: the site carries a "Do Not Sell" / privacy-choices control (9 occurrences in the served markup) and the policy sets out consumer rights of access, deletion and opt-out. Verified at https://www.toryburch.com/en-us/customer-services/privacy-policy/ (HTTP 200, 2026-08-05). - id: california-shine-the-light name: California "Shine the Light" law (Cal. Civ. Code s. 1798.83) conforms: true evidence: >- The US privacy policy carries a dedicated "Shine the Light" section (6 occurrences) with the statutory disclosure request process. Verified at https://www.toryburch.com/en-us/customer-services/privacy-policy/ (HTTP 200, 2026-08-05). - id: us-state-privacy-laws name: US state comprehensive privacy laws (VA CDPA, CO CPA, CT CTDPA, UT UCPA) conforms: true evidence: >- The US privacy policy names Virginia, Colorado, Connecticut and Utah residents and extends state-specific rights to them. Verified in the served markup at https://www.toryburch.com/en-us/customer-services/privacy-policy/ (HTTP 200, 2026-08-05). - id: uk-gdpr name: UK GDPR / Data Protection Act 2018 conforms: partial evidence: >- The UK privacy policy references the Information Commissioner (the UK supervisory authority) as the complaints route and cites standard contractual clauses as the international-transfer mechanism, which are UK GDPR instruments. However the policy text does not name "GDPR" or "UK GDPR" as such in the served markup, and no lawful-basis table or Article 30 record is published. Recorded as partial because the mechanisms are present but the express regime claim is not. Verified at https://www.toryburch.com/en-gb/customer-services/privacy-policy/ (HTTP 200, 2026-08-05). - id: eu-gdpr name: EU General Data Protection Regulation (2016/679) conforms: unknown evidence: >- Tory Burch sells into the EU through /en-eu/, /de-de/, /fr-fr/ and /it-it/ storefronts, so the GDPR plainly applies to it. The EU-locale privacy policy returns HTTP 200 but the served markup does not name the GDPR, does not identify a data controller entity or DPO, and does not publish an Article 13/14 notice in a form a machine can read. Recorded as unknown rather than false: this is a gap in what is published, not evidence of a gap in what is practised. - id: pci-dss name: PCI DSS conforms: unknown evidence: >- Tory Burch accepts card payments directly and documents card, Afterpay, PayPal and other payment options at https://www.toryburch.com/en-us/client-services/payment/payment-options/, which puts it in scope for PCI DSS as a merchant. No PCI DSS attestation, SAQ level or compliance statement is published anywhere on the public site, and no trust centre exists. In scope by operation, unevidenced by publication. - id: rfc-9116-security-txt name: RFC 9116 security.txt conforms: false evidence: >- https://www.toryburch.com/.well-known/security.txt returns HTTP 404 (HTML error page), as does the apex host. No security contact, disclosure policy or PGP key is published at the standard location. The only published contact of a comparable kind is privacy@toryburch.com, given in the privacy policy for privacy requests rather than for vulnerability reports. - id: coordinated-vulnerability-disclosure name: Coordinated vulnerability disclosure / bug bounty conforms: false evidence: >- Probed for a published disclosure policy and for HackerOne, Bugcrowd and Intigriti programmes; none found. No security/tory-burch-vulnerability-disclosure.yml is written because there was no verified hit to write. - id: dmarc-enforcement name: DMARC enforcement (RFC 7489) conforms: true evidence: >- toryburch.com publishes an SPF record and a DMARC record at policy p=reject - full enforcement, the strongest of the three DMARC policies. Probed 2026-08-05; see security/tory-burch-domain-security.yml. - id: hsts name: HTTP Strict Transport Security (RFC 6797) conforms: true evidence: >- www.toryburch.com serves Strict-Transport-Security with max-age=31536000 over TLS 1.3. Probed 2026-08-05; see security/tory-burch-domain-security.yml. - id: dnssec name: DNSSEC conforms: false evidence: >- No DNSKEY record is published for toryburch.com. No CAA record is published either. Probed 2026-08-05; see security/tory-burch-domain-security.yml. not_applicable: reason: >- No public API contract exists, so these have nothing to bind to. They are listed so a reader can see they were considered and correctly skipped rather than overlooked. standards: - oauth2 - oidc - mutual-tls - rfc9457-problem-details - json-api - odata - scim - fhir - fapi - psd2 - idempotency-keys - pagination-conventions - rfc8594-sunset-header x-evidence: fetched: '2026-08-05' method: >- curl GET of the published US and UK privacy policies with a desktop user-agent, then string search of the served markup for named regimes; DNS/TLS facts carried over from the probe run recorded in security/tory-burch-domain-security.yml caveat: >- The policy pages are Next.js client-rendered. Regime names were confirmed in the served HTML/RSC payload rather than in rendered text, so counts reflect the markup as delivered.