Grade A+ — Highly protective (score 100/100)
A US government health agency privacy policy with no commercial data sharing, encryption in transit, and advance notice of changes. No material risks found.
Strong privacy protections. No data sale. Government agency.
We do not use or share your information for commercial purposes and, except as described above, we do not exchange or otherwise disclose this information.
The CDC will not sell your data or use it for marketing or commercial gain.
encrypting the transfer of personal information over the internet via secure sockets protocols such as Transport Layer Security (TLS), Secure Sockets Layer (SSL) etc.
Your data is protected by industry-standard encryption when transmitted to CDC.
We will provide additional notice in advance (e.g., a disclaimer on our website or an email to subscribers) if material changes are being made.
The CDC promises to warn you before making significant changes to how it handles your data.
A geofence does not track your location or your phone number; it is solely used to detect devices that may enter a specific geographic area at a point in time so they can receive a CDC-sponsored message.
CDC geofencing health alerts do not collect your location or phone number.
A child's parent or guardian is required to provide consent before CDC collects, uses, or shares personal information from a child under age 13.
Strict COPPA compliance: parents must consent before any data is collected from children under 13.
We retain the information only for as long as necessary to respond to your question or request.
The CDC keeps your information only as long as needed, then destroys it under federal records rules.
we may in some cases share that information (or automatically generated information) with other government agencies in response to lawful law enforcement requests or to protect CDC.gov from security threats.
Data is only shared with law enforcement when the request is legally valid.
Last reviewed 2026-07-26 under rubric v3.5.