Databricks logo

Databricks

Unified data and AI platform (lakehouse) for analytics, data engineering, and machine learning.

✓ 16 of 32 frameworks
+ 1 partial
Security & General Standards
SOC 2 Type II

Annual SOC 2 Type II report available via account team per databricks.com/trust/compliance/soc

SOC 3

Public SOC 3 report downloadable from databricks.com/trust/compliance/soc

SOC 1 Type II

SOC 1 Type II report available via account team per compliance page

ISO 27001 (Information Security Management)

ISO 27001 certified across AWS/Azure/GCP multi-tenant regions per trust/compliance/iso-27001

ISO 27017 (Cloud Security)

Included in ISO certification scope per trust compliance pages; not broken out separately

ISO 27018 (Cloud Privacy)

Included in ISO certification scope per trust compliance pages; not broken out separately

ISO 27701 (Privacy Information Management)

Not documented on public trust pages

ISO 42001 (AI Management Systems)
?

Not documented on public trust pages

ISO 9001 (Quality Management)
?

Not documented on public trust pages

CSA STAR (Cloud Security Alliance)
?

Not documented on public trust pages

HITRUST CSF
~

HITRUST listed among standards supported by the compliance security profile on AWS

BSI C5 (German Cloud Security)

C5 listed among standards requiring the compliance security profile on AWS deployments

Privacy & Data Transfer
GDPR (EU)

GDPR support via Security Addendum and DPA; EU data residency documented

CCPA / CPRA (California)

Privacy documentation covers CCPA obligations but explicit CCPA certification not documented

UK GDPR
?

Not explicitly documented

LGPD (Brazil)
?

Not documented on public trust pages

PIPEDA (Canada)
?

Not documented on public trust pages

DPDP Act (India)
?

Not documented on public trust pages

PIPL (China)
?

Not documented on public trust pages

EU-US Data Privacy Framework

Not documented on public trust pages

Swiss-US Data Privacy Framework

Not documented on public trust pages

Global CBPR (APEC)
?

Not documented on public trust pages

Global PRP (APEC)
?

Not documented on public trust pages

Industry & Government
HIPAA (US Healthcare)

HIPAA supported via compliance security profile with BAA per docs.databricks.com HIPAA page

PCI DSS (Payment Card Industry)

PCI-DSS listed among standards supported by the compliance security profile

FedRAMP (US Federal)

FedRAMP Moderate authorized (AWS commercial regions); FedRAMP High supported via compliance security profile; Databricks on Azure Commercial listed on FedRAMP Marketplace

StateRAMP / TX-RAMP (US State)
?

Not documented on public trust pages

DORA (EU Finance)
?

Not documented on public trust pages

CJIS (US Law Enforcement)
?

Not documented on public trust pages

FINRA (US Broker-Dealers)
?

Not documented on public trust pages

IRAP (Australian Government)

IRAP listed among standards supported by the compliance security profile

Emerging & Strategic
NIST CSF (Cybersecurity Framework)
?

FedRAMP uses NIST 800-53 controls; explicit CSF alignment not documented

Data last verified: September 2026

Is this data outdated?

Spotted an error or a recent change in Databricks's posture? Submit a correction.

Submit a correction →

Work at Databricks?

Claim this profile to verify and enrich your compliance data.

Claim this profile →

Compare Databricks with:

← All Data & Analytics tools

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026