Grade A- — Mostly protective (score 88/100)
Esri's privacy overview emphasizes customer data ownership, minimal collection, and GDPR/CCPA compliance. No major violations, though specific retention and export details are absent.
Privacy-forward policy. Customer data ownership. No violations found.
Customer Data is owned by the customer and is treated as confidential.
Esri explicitly states that the customer's data belongs to the customer and is handled as confidential information.
Customer may choose not to store personal information in ArcGIS Online.
Users have a meaningful choice about whether personal information is stored in Esri's cloud product at all.
Esri collects minimal personal information in order for customers to use ArcGIS Online.
Esri states that data collection is limited to what is needed to deliver the service — a data-minimization pledge.
Not storing credit card payment instrument number information within Esri systems.
Esri does not store raw credit card numbers on its systems, lowering the risk of payment data exposure.
Security and privacy assurance of FedRAMP third-party validation and mapping to ISO27k.
Esri's security posture has been independently audited under FedRAMP and aligned with the ISO 27000 family of standards.
Esri has obtained certification under the EU-US Data Privacy Framework (DPF) to facilitate and ensure the protection of data transfers between the EU and the US.
Esri is certified under the EU-US Data Privacy Framework, providing a recognized legal basis for trans-Atlantic personal data transfers.
Customers can choose to limit storage of personal information to their own infrastructure with a hybrid deployment model.
Organizations that need to keep sensitive data on-premises can use a hybrid model so personal information does not have to live in Esri's cloud.
Last reviewed 2026-07-28 under rubric v3.5.