Originally published in GoDaddy’s 2025 Global Stakeholder Impact Report
Cybersecurity & Data Privacy
As an operator of large internet infrastructure, cybersecurity and data privacy are top priorities.
We maintain enterprise-wide programs to protect our systems, safeguard customer and employee data, and address evolving cyber threats. We implement governance systems to support our cybersecurity and data protection processes. We regularly review and refine these efforts to further strengthen our defenses and keep pace with a constantly changing threat landscape.
Cybersecurity
Our management team is responsible for identifying, assessing, and managing GoDaddy’s cybersecurity risks on an ongoing basis. This includes establishing processes designed to help ensure that potential cybersecurity risk exposures are monitored, appropriate mitigation and remediation measures are implemented, and the company's cybersecurity programs are maintained.
Our Board oversees the company’s cybersecurity risk management program through its Audit and Risk Committee. The committee receives regular reports from GoDaddy’s Chief Information Security Officer (CISO), which are shared with the Board at least quarterly.
GoDaddy's CISO has primary responsibility for the company's programs for identifying, assessing, and managing the company's cybersecurity risks. The CISO regularly provides reports and updates to the CEO on significant matters relevant to the company's cybersecurity risk.
Our Information Security Team employs a variety of controls and initiatives to safeguard our systems and protect our customers.
- Proactive Monitoring: We regularly scan our environment for vulnerabilities, and research and monitor industry threats to proactively identify cybersecurity issues that could impact GoDaddy and our customers.
- Training & Internal Communications: Education is key to maintaining our high security standards. We deliver an annual data privacy and cybersecurity training program for all employees, along with regular updates on key initiatives and best practices through timely alerts.
- Security by Design: Our developers are encouraged to consider cybersecurity from the initial design phase of our products to completion. Teams within our Information Security organization collaborate to integrate security measures into new products and services. We design and implement risk-based processes and procedures to conduct security reviews on new or updated applications prior to launch.
- Incident Response: We have a dedicated incident response team that works with our business units and other internal and external subject matter experts to respond to potential cybersecurity incidents.
- Security Frameworks: Some parts of our business are required to align with specialized frameworks, such as the Payment Card Industry Data Security Standards (PCI-DSS) for handling payment card data. Where required by our customer or other agreements, we align our practices and controls with additional recognized standards such as International Organization for Standardization (ISO) 27001.
Data Privacy
Our Chief Privacy Officer manages our global privacy program, which includes, but is not limited to, conducting privacy impact assessments, providing training to employees, responding to data subject requests, and engaging with data protection authorities. We regularly review and enhance our privacy practices to reflect evolving regulatory requirements and stakeholder expectations, and we take a proactive approach to managing our data privacy obligations. Some of our efforts include:
- Core Data Privacy Practices: We empower our customers, employees, and individual data subjects to manage their privacy preferences and exercise their privacy rights. Our core privacy practices are set forth in our Global Privacy Notice and related privacy policies.
- Global Regulatory Frameworks: We apply a core set of common principles to how we handle personal data globally. We also consider local requirements and restrictions in the jurisdictions where we do business.
- International Data Transfers: GoDaddy certified its compliance with the E.U.-U.S. Data Privacy Framework, as well as the U.K. Extension to the E.U.-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework. Where these frameworks do not apply, we rely on Standard Contractual Clauses and other lawful mechanisms for cross-border data transfers where necessary.
- Data Processing Agreements: Where required by our agreements or applicable laws, we enter into data processing agreements that govern our rights and responsibilities for processing personal data.
- Service Providers: We use service providers to support our operations and provide services to our customers. When we share personal data with service providers or third parties, they are required to comply with our instructions, adhere to contractual restrictions for processing personal data securely, and comply with applicable laws.
- GDPR Independent Assessment: In 2025, TRUSTe independently assessed our compliance with the E.U. General Data Protection Regulation (GDPR). TRUSTe validated that GoDaddy continues to implement program-level measures aligned with TRUSTe’s GDPR Privacy Program Validation Requirements.
- Privacy by Design: Our Data Governance and Operations Team works with our business teams on day-to-day privacy matters, including earlystage product design, to embed privacy considerations throughout product development. The team also partners with our Legal, Information Technology, and other subject matter experts to support thorough data privacy impact assessments.
Learn more about GoDaddy’s 2025 Global Stakeholder Impact Report.
About this Report
The GoDaddy 2025 Global Stakeholder Impact Report details our progress toward our corporate sustainability goals, strategies, and initiatives in support of our overarching purpose and values. Unless otherwise noted, this report reflects our corporate sustainability performance across our global operations covering the fiscal year period from January 1 to December 31, 2025. To demonstrate our commitment to transparent communication regarding our sustainability progress, we routinely share updates through our website and our annual reporting. We welcome your questions, comments, and feedback on this report by contacting [email protected].
This report references the Global Reporting Initiative Standards, includes select Sustainability Accounting Standards Board metrics for the Internet Media and Services sector, and the Task Force on Climate Related Financial Disclosures. We also disclose our contributions and progress toward priority UN SDGs. For additional information on how we align with these frameworks and key indicators demonstrating our sustainability performance, please refer to the Frameworks & Metrics section.
About GoDaddy
GoDaddy, the world's largest domain name registrar, helps millions of entrepreneurs globally start, grow, and scale their businesses. People come to GoDaddy to name their idea, build a website and logo, sell their products and services and accept payments. GoDaddy Airo®, the company's AI-powered experience, makes growing a small business faster and easier by helping them to get their idea online in minutes, drive traffic and boost sales. GoDaddy's expert guides are available 24/7 to provide assistance. To learn more about the company, visit www.GoDaddy.com.