Skip to content
Search Login
United States
Canada
European Union
United Kingdom
Germany
Select language
  • There are no suggestions because the search field is empty.
Cancel
KnowBe4
  • Product + Pricing
    PLATFORM
    KnowBe4 HRM+
    PRODUCTS
    Security Awareness Training
    Cloud Email Security
    PhishER Plus
    SecurityCoach
    Compliance Plus
    AI Defense Agents
    Pricing
    Security Awareness Training
    PhishER Plus
    SecurityCoach
    AI Defense Agents
    Defend™
    Prevent™
    Resources
    Why Choose KnowBe4
    Customer Video Testimonials
    Customer Success
    Integrations
    KnowBe4 ModStore homepage with option to sort modules by Content Type, Topic, or by searching. The user has selected the
    See the World's Largest Security Awareness Training Library
    Get access
  • Free Tools
    PHISHING
    Phishing Security Test
    Phish Alert Button
    Security Awareness Training
    Automated Security Awareness Program
    SecurityCoach Preview
    Training Preview
    Compliance training
    Compliance Training Library
    Password Security
    Weak Password Test
    Email Security
    Domain Spoof Test
    Email Exposure Check Pro
    Domain Doppelgänger
    Malware
    RanSim
    BreachSim
    All Free Tools
    Human firewall made of joined human figures, with some highlighted in orange to show vulnerability.
    Find out what percentage of your employees are Phish-prone with your free Phishing Security Test
    Phish Your Users
  • Resources
    Learn
    Blog
    Industry Reviews
    Phishing Analysis Center
    Security Culture Analysis Center
    The Inside Man Series
    Glossary
    FAQs
    Product Resources
    Free Resource Kits
    Webinar Library
    eBooks and Whitepapers
    Product Collateral
    Case Studies
    Customer Reviews
    Training Library
    All Resources
    Security topics
    Security Awareness Training
    Security Culture
    Social Engineering
    Phishing
    Spear Phishing
    CEO Fraud
    Ransomware
    Multi-Factor Authentication
    Global Compliance and Regulations
    PIB-Report-cover
    2025 Phishing By Industry Benchmark Report

    Understand which industries and company sizes are most at risk
    Read The Report
  • Partners
    Partner Programs
    Overview
    Channel Partners
    Technology Alliances
    Risk & Insurance
    Partner Tools
    Partner Portal
    Find a Partner
    KnowBe4 Partner types including Certified, Premier, MSP, Authorized, and Technology Alliance Partners.
    Partner with us to empower your customers’ cybersecurity through knowledge, awareness, coaching, and mitigation
    Become a Partner
  • About Us
    Company
    Company Background
    Careers
    Company Merchandise
    CONNECT
    Contact Us
    Press Resources
    Global Events
    Support
    Sustainability
     
    X
    Facebook
    LinkedIn
    YouTube
    Knowsters chatting amiably, KnowBe4 CEO Stu Sjouwerman smiling while holding a trophy, and a silhouette representing the bad actors KnowBe4 helps to defend against.
    A fun and welcoming workplace for you and more secure world for everyone
    Join KnowBe4
  • Product + Pricing
    PLATFORM
    KnowBe4 HRM+
    PRODUCTS
    Security Awareness Training
    Cloud Email Security
    PhishER Plus
    SecurityCoach
    Compliance Plus
    AI Defense Agents
    Pricing
    Security Awareness Training
    PhishER Plus
    SecurityCoach
    AI Defense Agents
    Defend™
    Prevent™
    Resources
    Why Choose KnowBe4
    Customer Video Testimonials
    Customer Success
    Integrations
    KnowBe4 ModStore homepage with option to sort modules by Content Type, Topic, or by searching. The user has selected the
    See the World's Largest Security Awareness Training Library
    Get access
  • Free Tools
    PHISHING
    Phishing Security Test
    Phish Alert Button
    Security Awareness Training
    Automated Security Awareness Program
    SecurityCoach Preview
    Training Preview
    Compliance training
    Compliance Training Library
    Password Security
    Weak Password Test
    Email Security
    Domain Spoof Test
    Email Exposure Check Pro
    Domain Doppelgänger
    Malware
    RanSim
    BreachSim
    All Free Tools
    Human firewall made of joined human figures, with some highlighted in orange to show vulnerability.
    Find out what percentage of your employees are Phish-prone with your free Phishing Security Test
    Phish Your Users
  • Resources
    Learn
    Blog
    Industry Reviews
    Phishing Analysis Center
    Security Culture Analysis Center
    The Inside Man Series
    Glossary
    FAQs
    Product Resources
    Free Resource Kits
    Webinar Library
    eBooks and Whitepapers
    Product Collateral
    Case Studies
    Customer Reviews
    Training Library
    All Resources
    Security topics
    Security Awareness Training
    Security Culture
    Social Engineering
    Phishing
    Spear Phishing
    CEO Fraud
    Ransomware
    Multi-Factor Authentication
    Global Compliance and Regulations
    PIB-Report-cover
    2025 Phishing By Industry Benchmark Report

    Understand which industries and company sizes are most at risk
    Read The Report
  • Partners
    Partner Programs
    Overview
    Channel Partners
    Technology Alliances
    Risk & Insurance
    Partner Tools
    Partner Portal
    Find a Partner
    KnowBe4 Partner types including Certified, Premier, MSP, Authorized, and Technology Alliance Partners.
    Partner with us to empower your customers’ cybersecurity through knowledge, awareness, coaching, and mitigation
    Become a Partner
  • About Us
    Company
    Company Background
    Careers
    Company Merchandise
    CONNECT
    Contact Us
    Press Resources
    Global Events
    Support
    Sustainability
     
    X
    Facebook
    LinkedIn
    YouTube
    Knowsters chatting amiably, KnowBe4 CEO Stu Sjouwerman smiling while holding a trophy, and a silhouette representing the bad actors KnowBe4 helps to defend against.
    A fun and welcoming workplace for you and more secure world for everyone
    Join KnowBe4
  • login Login
    United States
    Canada
    European Union
    United Kingdom
    Germany
  • Request a quote
Get Started Now

KSAT, KCM GRC, PhishER, and SecurityCoach DPIA

Last Reviewed: October 2024
Customers
  • Customer Terms of Service
  • Product Privacy Notice
  • CPRA Addendum
  • Global Data Processing Addendum
  • KSAT, KCM GRC, PhishER, and SecurityCoach DPIA
  • Security
  • System Status
  • Maintenance Windows
  • Documentation Page
  • Federal
  • Code of Ethical Business Conduct
  • KnowBe4 Global Privacy Compliance
  • Transparency Report
  • Data Transfer Impact Assessment
  • ICO UK SCC Addendum
  • Free Downloadable Software Tools EULA
  • KnowBe4 Mobile App License Agreement - iOS
  • KnowBe4 Mobile App License Agreement - Android
Partners
  • Partner Portal
  • Partner Portal Terms of Use
  • Website Privacy Notice
  • Partner Code of Conduct
  • Anti-Corruption Policy
  • MSP Standards of Engagement
  • Reseller Agreement
  • Managed Service Provider Agreement
Website Visitors
  • Website Terms of Use
  • Website Privacy Notice
  • Cookie Notice
  • Job Applicant Privacy Notice
  • Virtual Patent Marking Notice
  • Accessibility
Legal Compliance
  • Whistleblower Hotline
  • Economic Sanctions & Export Control Compliance
  • Code of Ethical Business Conduct

1. SCOPE

This KnowBe4 Data Privacy Impact Assessment (“DPIA”) is only applicable to the extent KnowBe4, Inc. and/or its affiliates (“KnowBe4”) is a processor of personal data for its various product and service offerings, including KSAT, KCM GRC, PhishER, and SecurityCoach. The purpose of this DPIA is to provide information about KnowBe4’s personal data processing practices and to allow customers to complete their own data protection impact assessments on KnowBe4’s products and services. This DPIA only covers KnowBe4’s applicable services pursuant to the Services Agreement.

Description of KnowBe4 services.

KnowBe4 is a B2B SaaS (Software-as-a-Service) company that provides its Customers a variety of services. The services that will be included in this document are:

  • KSAT Console - a simulated phishing and security awareness and compliance training platform
  • KCM GRC Tool - a tool designed to help manage company governance, risk, compliance and audits
  • PhishER - a Security, Orchestration, Automation and Response (SOAR) platform for managing the high volume of potentially malicious email messages reported by your users.
  • SecurityCoach - a product that enables real-time security coaching of your users in response to risky security behavior based on the rules in your existing security software stack.

Describe the data that will be stored, used, collected or otherwise processed during the use of KnowBe4 services.

KSAT Console

Data Collected Directly From Customer

Name, Email address, Telephone Number, Title, Security, Strictly Necessary Cookie Information, IP addresses, Web browser Information, Third Party Integration Data

Generated Information

Phishing Campaign Results and Metrics, Security Awareness Training Results, Risk Score, Training and Coaching Information

KCM GRC Tool

Data Collected

Email address, browser information, strictly necessary cookie information, and information customers upload into the console (audit reports, compliance reports etc.)

PhishER

Data Collected

Email information submitted by customer

SecurityCoach

Data Collected Directly From Customer

Third party integration data

Generated Information

Training and coaching information

Does KnowBe4 collect special categories of data (including criminal convictions, health information)?

No, KnowBe4 does not request nor does it provide appropriate fields for submitting special categories of data for any of its tools. Any special categories of data that may be received would be incidental and can be deleted upon request.

Where are the locations of KnowBe4’s servers?

KnowBe4 operates instances located within the US, EU, UK, Canada, and Germany instances. Customers may choose where data is stored during the course of the services. However, KnowBe4 leverages subprocessors in the United States and generally personal data will always be processed in the United States.

Does KnowBe4’s processing of personal data include automated decision making which can produce legal effects concerning data subjects?

No.

Do you provide notice to data subjects about the processing of their personal data?

KnowBe4 acts as a processor for its customers so it does not initiate direct contact with data subjects, unless specifically instructed too. KnowBe4 adheres to the terms of our data processing agreements and data protection notices found here when processing personal data. Data stored in KnowBe4’s products and services are provided by customers and it is the responsibility of our customers to make their users aware of how their data is being processed.

2. ACCESS TO PERSONAL DATA

How is access to personal data handled?

KnowBe4 provides products and services that leverage RBAC (Role Based Access Control). Customer administrators are able to set users roles and permission to limit access. KnowBe4’s employees and other personnel are only allowed access on a restricted basis. Access is only allowed to fulfill KnowBe4’s contractual obligations, legal obligations or legitimate business interests, such as meeting SLA’s or upon a customer’s written permission.

How do you ensure the security of KnowBe4 products?

KnowBe4 has security policies, procedures and controls to ensure the security of its products and services. These controls may be found by reviewing KnowBe4’s SOC 2 Type 2, which you may request by emailing your KnowBe4 point of contact after executing a non-disclosure agreement. You may also review KnowBe4’s public facing SOC 3 report found here.

How does KnowBe4 handle customer data subject access requests (DSAR’s)?

KnowBe4’s procedure for handling end user DSAR’s for customers is to forward the request on to the console or service administrator and provide assistance as requested.

3. INFORMATION FLOWS

International Data Transfer.

You may also execute a Data Processing Addendum with standard contractual clauses (SCC’s) with KnowBe4 by following the instructions found here.

Please describe KnowBe4’s product data flows.

KSAT, KCM GRC, PhishER, and SecurityCoach are both built in the cloud leveraging Amazon AWS.

KSAT Data Flow Description: Customer administrators are able to upload end user information into the console. Personal data is also generated when users complete security modules or are subject to phishing campaigns. This data is then stored in KnowBe4’s cloud storage (Amazon AWS).

KCM GRC Data Flow Description: Customers create a user account with their business email address. KCM users then upload information into the KCM console. This information is then stored in KnowBe4’s cloud storage (Amazon AWS).

PhishER Data Flow Description: Customers enable PhishER and Customer’s users report suspicious emails to be sent to Customer’s PhishER inbox. This information is then stored in KnowBe4’s cloud storage (Amazon AWS).

SecurityCoach Data Flow Description: Customers first enable third party integrations and enable within Customer’s KSAT console. Risky activity is monitored on user devices and processed if data matches Customer detection rules and training is assigned based on the implemented rules. This information is then stored within KnowBe4’s cloud storage (Amazon AWS).

What sub-processors does KnowBe4 leverage in order to provide services?

KnowBe4 leverages sub-processors that process Personal Data in order to provide services to customers. You may request a list of sub-processors by emailing your KnowBe4 point of contact. Data Processing Agreements, including the most up to date Standard Contractual Clauses at time of signing of the Services Agreement, have been executed with all sub-processors in order to ensure the protection of Personal Data.

4. DATA SECURITY & PRIVACY BY DESIGN (PbD)

Where can I find KnowBe4’s security documentation?

KnowBe4 takes security seriously and takes appropriate measures in order to protect personal data. For more information about our security practices, you may visit our Security Page found here. Additionally, our CAIQ is available here. You may also request a copy of our SOC 2 Type 2 from your KnowBe4 point of contact after executing a non-disclosure agreement. Our public facing SOC 3 report can be found here.

How does KnowBe4 incorporate privacy by design into its products?

KnowBe4 conducts data privacy impact assessments and takes into account its data protection obligations when creating new products and services.

Are KnowBe4 employees and agents bound by confidentiality agreements?

KnowBe4 employees and other personnel who may have access to personal data are required to sign confidentiality agreements..

Do KnowBe4 employees receive privacy and security awareness training?

Yes, KnowBe4 employees receive periodic privacy and security awareness training. 

Does KnowBe4 maintain a record of processing activities?

Yes, KnowBe4 maintains a record of processing activities.

5. DATA RETENTION

How long does KnowBe4 store Personal Data for?

KnowBe4 retains customer personal data in accordance with its customer contracts (i.e. service agreements and data processing agreements) as well as in accordance with other legal obligations.

6. HAS KNOWBE4 APPOINTED A DATA PROTECTION OFFICER?

You may contact KnowBe4’s Data Protection Officer by emailing privacymanager@knowbe4.com. 

7. WHO CAN I REACH OUT TO IF I HAVE MORE QUESTIONS?

You can either contact your KnowBe4 point of contact or send an email to privacymanager@knowbe4.com.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.

Want to learn more? Let us show you how easy it is.

Request More Info
  • Products
    • Security Awareness Training
    • Cloud Email Security
    • PhishER Plus
    • SecurityCoach
    • Compliance Plus
    • AI Defense Agents
  • Free Tools
  • Resources
  • Partners
  • About Us
  • Contact Sales
    • Sales@KnowBe4.com
  • Contact Support
    • Support@KnowBe4.com
  • CyberheistNews
    • Subscribe
  • Legal
  • Privacy Policy
  • Terms of Use
  • Security Statement
X Facebook LinkedIn YouTube
KnowBe4
© 2025 KnowBe4, Inc. All rights reserved.