NordVPN
NordVPN is a Panama-based VPN provider.
Score
Citation
NordVPN may process your personal data (email address) for direct marketing purposes in the following cases: when we obtain your consent to such processing (the legal basis for processing, in this case, is your consent)
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Citation
You may request us to discontinue processing of your personal data, in which case your data will be processed only as much as it is necessary to effect the discontinuation of your use of the NordVPN Services (e.g., final settlement, or deleting all personal data based on your email address), or finalizing other NordVPN’s legal relationship with you (e.g. accounting, invoicing, processing refunds).
Due to technical reasons (such as backup copies of the databases) your personal data may be finally deleted only within 60 days or longer, if it is mandated by the statutory requirements.
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Citation
NordVPN uses third party data processors only for processing of payment data, emailing service and basic website and app analytics.
Score
Citation
Further, NordVPN have a strict no logs policy when it comes to seeing user activity online: NordVPN is based in Panama, which does not require data storage.
Score
Citation
In order to ensure security of the personal data, NordVPN employs various administrative, technical and physical security measures
Notes
The policy is very vague about this, but an independent audit was conducted: https://nordvpn.com/blog/nordvpn-audit/
Score
Citation
The date of the most current wording of the Privacy Policy is indicated at the top of the text
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Citation
This is not specified in the policy
Score
Citation
The amendment of the Privacy Policy may be communicated to you by sending an email and/or by publishing the updated Privacy Policy on the NordVPN website
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Notes
Nowhere in the policy are any third parties listed as data sources.
Score
Citation
If you choose to create a user account, you must provide the following basic information:
Email address. We ask for your email address as part of your registration. That ensures that we can communicate with you when we have any exciting announcements to make, service updates to advise or errors to report. Valid email address is also needed to retrieve a lost password and to make a VPN connection.
Payment data. In addition to the conventional payment methods, such as credit card, users can buy NordVPN service with cryptocurrency. Our payment processing partners process basic billing information for payment processing and refund requests.
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Citation
You can set up warnings for every time the Site places a cookie in your browser, or you can choose to disable all cookies. You can do both through your browser settings. Since each browser has a different procedure for managing cookies, look at your browser’s Help Menu to learn the correct way to do it.
Alternatively, you can disable all cookies by visiting the Network Advertising Initiative Opt Out page or by using the Google Analytics Opt Out Browser add-on. Please note that choosing to disable cookies may negatively affect some of the features that make your Site experience more efficient.
Score
Citation
If you choose to create a user account, you must provide the following basic information:
Email address. We ask for your email address as part of your registration. That ensures that we can communicate with you when we have any exciting announcements to make, service updates to advise or errors to report. Valid email address is also needed to retrieve a lost password and to make a VPN connection.
Payment data. In addition to the conventional payment methods, such as credit card, users can buy NordVPN service with cryptocurrency. Our payment processing partners process basic billing information for payment processing and refund requests.
Last Updated
December 7, 2020
Sources
Contributors