Databricks
Unified data and AI platform (lakehouse) for analytics, data engineering, and machine learning.
| Security & General Standards | |
|---|---|
| SOC 2 Type II | ✓ Annual SOC 2 Type II report available via account team per databricks.com/trust/compliance/soc |
| SOC 3 | ✓ Public SOC 3 report downloadable from databricks.com/trust/compliance/soc |
| SOC 1 Type II | ✓ SOC 1 Type II report available via account team per compliance page |
| ISO 27001 (Information Security Management) | ✓ ISO 27001 certified across AWS/Azure/GCP multi-tenant regions per trust/compliance/iso-27001 |
| ISO 27017 (Cloud Security) | ✓ Included in ISO certification scope per trust compliance pages; not broken out separately |
| ISO 27018 (Cloud Privacy) | ✓ Included in ISO certification scope per trust compliance pages; not broken out separately |
| ISO 27701 (Privacy Information Management) | ✓ Not documented on public trust pages |
| ISO 42001 (AI Management Systems) | ? Not documented on public trust pages |
| ISO 9001 (Quality Management) | ? Not documented on public trust pages |
| CSA STAR (Cloud Security Alliance) | ? Not documented on public trust pages |
| HITRUST CSF | ~ HITRUST listed among standards supported by the compliance security profile on AWS |
| BSI C5 (German Cloud Security) | ✓ C5 listed among standards requiring the compliance security profile on AWS deployments |
| Privacy & Data Transfer | |
| GDPR (EU) | ✓ GDPR support via Security Addendum and DPA; EU data residency documented |
| CCPA / CPRA (California) | ✓ Privacy documentation covers CCPA obligations but explicit CCPA certification not documented |
| UK GDPR | ? Not explicitly documented |
| LGPD (Brazil) | ? Not documented on public trust pages |
| PIPEDA (Canada) | ? Not documented on public trust pages |
| DPDP Act (India) | ? Not documented on public trust pages |
| PIPL (China) | ? Not documented on public trust pages |
| EU-US Data Privacy Framework | ✓ Not documented on public trust pages |
| Swiss-US Data Privacy Framework | ✓ Not documented on public trust pages |
| Global CBPR (APEC) | ? Not documented on public trust pages |
| Global PRP (APEC) | ? Not documented on public trust pages |
| Industry & Government | |
| HIPAA (US Healthcare) | ✓ HIPAA supported via compliance security profile with BAA per docs.databricks.com HIPAA page |
| PCI DSS (Payment Card Industry) | ✓ PCI-DSS listed among standards supported by the compliance security profile |
| FedRAMP (US Federal) | ✓ FedRAMP Moderate authorized (AWS commercial regions); FedRAMP High supported via compliance security profile; Databricks on Azure Commercial listed on FedRAMP Marketplace |
| StateRAMP / TX-RAMP (US State) | ? Not documented on public trust pages |
| DORA (EU Finance) | ? Not documented on public trust pages |
| CJIS (US Law Enforcement) | ? Not documented on public trust pages |
| FINRA (US Broker-Dealers) | ? Not documented on public trust pages |
| IRAP (Australian Government) | ✓ IRAP listed among standards supported by the compliance security profile |
| Emerging & Strategic | |
| NIST CSF (Cybersecurity Framework) | ? FedRAMP uses NIST 800-53 controls; explicit CSF alignment not documented |
Data last verified: September 2026
Is this data outdated?
Spotted an error or a recent change in Databricks's posture? Submit a correction.
Submit a correction →Work at Databricks?
Claim this profile to verify and enrich your compliance data.
Claim this profile →