Cisco Systems, Inc. and its U.S. based subsidiaries — Amorblox, Inc.; AppDynamics LLC; Broadsoft, Inc.; Cisco OpenDNS LLC; Cisco Systems Capital Corporation; Duo Security LLC; Fluidmesh Networks LLC; Isovalent LLC; Jasper Technologies LLC; Kenna Security, Inc.; Meraki, LLC; Socio Labs LLC; Splunk LLC; Thousand Eyes LLC; and Valix, Inc. — (collectively "Cisco-U.S.") has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regards to the processing of Personal Data received from the EU and EEA in reliance on the EU-U.S. DPF and from the U.K. (and Gibraltar) in reliance on the U.K. Extension to the EU-U.S. DPF. Cisco-U.S. has also certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. DPF Principles with regards to the processing of Personal Data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Privacy Statement and the EU-U.S. DPF Principles, the U.K. Extension to the EU-U.S. DPF Principles, and/or the Swiss-U.S. DPF Principles, the DPF Principles shall govern. For more information about the DPF program, and to view our certification, please visit the DPF Website.
Pursuant to the DPF Principles, Cisco-U.S. commits to the following:
Cisco-U.S. is responsible for the processing of Personal Data it receives under the DPF, and subsequently may transfer it to third parties acting as agents on its behalf. Cisco-U.S. complies with the DPF Principles for all onward transfers of Personal Data from the EU, EEA, U.K. (and Gibraltar), and Switzerland (for examples of such transfers, see Disclosing your Personal Data), including the onward transfer liability provisions. In certain situations, Cisco-U.S. may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Further, Cisco-U.S. is committed to protecting Personal Data received from EU and EEA member countries, Switzerland, and the U.K. (and Gibraltar) (see Collection and use of your Personal Data for examples of the Personal Data Cisco processes when you use our websites and Solutions and interact with us) in accordance with the DPF's applicable Principles and to help ensure Personal Data collected from individuals is accessible to them as part of their individual rights when Cisco is the Controller of the Personal Data (see Your privacy rights). Furthermore, Cisco acknowledges the right of EU, EEA, U.K. (and Gibraltar), and Swiss individuals to request access to their data while it is in the U.S. and to correct, amend, and supplement inaccurate or incomplete data. Said individuals also have the right to request erasure of Personal Data that has been handled in violation of the DPF Principles. Subject individuals interested in accessing their data should see Disclosing your Personal Data for information on how to contact us, or submit a Privacy Request online.
In compliance with the EU-U.S. DPF Principles, the U.K. Extension to the EU-U.S. DPF Principles, and/or the Swiss-U.S. DPF Principles, Cisco-U.S. commits to resolve complaints about your privacy and our collection or use of your Personal Data transferred to the U.S. pursuant to the DPF Principles. EU, EEA, U.K. (and Gibraltar), and Swiss individuals with DPF inquiries or complaints, or any questions or concerns regarding Cisco-U.S. processing or international transfer of their Personal Data should first contact Cisco-U.S. by submitting a Privacy Request online.
Cisco-U.S. has further committed to refer unresolved privacy complaints under the DPF Principles to a U.S.-based independent third-party dispute resolution mechanism, DPF Services, operated by JAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed by Cisco, please visit https://www.jamsadr.com/file-a-dpf-claim for more information and to file a complaint. This service is provided free of charge to you.
If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See https://www.dataprivacyframework.gov/s/article/G-Arbitration-Procedures-dpf?tabset-35584=2.
Cisco-U.S. is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission.
- Standard Contractual Clauses
When we transfer Personal Data out of the jurisdiction in which it was collected to countries that do not benefit from an adequacy decision, other transfer mechanism, or exemption, we may rely on Standard Contractual Clauses where applicable (ie, Brazil, EU and EEA, Kingdom of Saudi Arabia, the U.K., and Switzerland) with appropriate safeguards in place to protect Personal Data.
Complaint resolution
Cisco commits to resolve complaints and concerns about your privacy and our collection and use of your Personal Data. If you have concerns or complaints about your privacy and our collection and use of your Personal Data, please contact us via the Privacy Request Form.
For complaints or concerns about your privacy and our collection or use of your Personal Data transferred to the U.S. pursuant to the DPF Principles, please see Data Privacy Framework.
Alternatively, you can contact the data protection supervisory authority in your jurisdiction for assistance. (Note, Cisco's main establishment in the EU is in the Netherlands. As such, our EU lead authority is the Dutch Autoriteit Persoonsgegevens.)
Your California privacy rights
California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
For business purposes in the last 12 months, Cisco may have collected, used, and shared Personal Data about you as described in this Privacy Statement. Each category of data that may be used by Cisco or shared with third parties is categorically outlined in this Privacy Statement. Cisco does not sell Personal Data as the term “sell” is traditionally understood.
California residents (as well as those in jurisdictions with similar laws) have the right to ask Cisco not to “sell” or “share” certain Personal Data. For more information on how to make such a request, please see “Use of cookies and similar technologies” above or click the "Cookies / Do not sell or share my personal data" or “Cookies” link at the bottom of any page on this website. Please note that your choice is specific to the digital property you are visiting or website, the browser you are using, and to the device you are engaged with using. You will need to exercise your preferences specifically on each Cisco digital property that links to this Privacy Statement. California consumers have a right to: (1) request access, correction, and deletion of their Personal Data, (2) opt out of the sale or sharing of their Personal Data, and (3) not be discriminated against for exercising one of their California privacy rights. For more information on how to make a request to opt out of sharing certain Personal Data, please see “Use of cookies and similar technologies” above or click the “Cookies/Do not sell or share my personal data" or “Cookies” in the website footer. All individuals have the right to request access to and deletion of the information Cisco holds about them either online via the Cisco Privacy Request Form or by mail to Cisco Systems, Inc., Privacy Office, 170 West Tasman Dr., San Jose, CA 95134, USA.
In addition, California residents may also submit a request by calling direct 408-906-2726 or toll free 833-774-2726 (833-PRI-CSCO).
Cisco does not sell the Personal Data of California consumers.
Cisco does not discriminate against individuals for exercising their privacy rights.
View the Cisco CCPA Metrics Report.
California Shine the Light
Residents of the State of California, under California Civil Code § 1798.83, have the right to request from companies conducting business in California a list of all third parties to which the company has disclosed Personal Data during the preceding year for direct marketing purposes. Alternatively, the law provides that if the company has a privacy policy that gives either an opt out or opt in choice for use of your Personal Data by third parties (such as advertisers) for marketing purposes, the company may instead provide you with information on how to exercise your disclosure choice options.
Cisco has a comprehensive Privacy Statement and provides you with details on how you may either opt-out or opt-in to the use of your Personal Data by third parties for direct marketing purposes. Therefore, we are not required to maintain nor disclose a list of the third parties that received your Personal Data for marketing purposes during the preceding year.
Updates to this Cisco Privacy Statement
We may update this Privacy Statement from time to time. If we modify our Privacy Statement, we will post the revised version here with an updated revision date. If we make material changes to our Privacy Statement, we may also notify you by other means, such as by posting a notice on our websites or sending you a notification. By continuing to use our website after such revisions are in effect, you accept and agree to the revisions and to abide by them.
SMS policy
We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. (Business Texting available in US & Canada only)
The Cisco Privacy Statement was revised and is effective as of August 14, 2026
Previous version of the Privacy Statement
Summary version