TRUSTe LLC Independent GDPR Privacy Practices Compliance Validation Findings Summary
Expiration Date: April 22, 2026
Scope
TRUSTe LLC has reviewed Tuya's IoT Product Line, encompassing its IoT platform, Tuya Cloud, Tuya Mobile Apps (Tuya Smart App and Smart Life App), other OEM branded apps, and Tuya API/SDK. This review, conducted as of April 22, 2025, assessed Tuya against 44 GDPR Privacy Practices Management Validation Requirements. The validation aims to ensure that the processing of personal information by Tuya and its third-party processors complies with the EU General Data Protection Regulation (GDPR).
The entities reviewed include Tuya Inc., Tuya (HK) Limited., Tuya Smart, Inc., Tuya Global, Inc., Tuyasmart (India) Private Limited, Tuya GmbH, Tuya Japan Co., Ltd. (株式会社), Hangzhou Tuya Information Technology Co., Ltd, Zhejiang Tuya Smart Electronics Co.,Ltd., Guangdong Tuya Smart Information Technology Co.,Ltd., and Hangzhou Tuya Technology Co., Ltd.
Inherent Limitations
Practices-level measures may have inherent limitations and may not always operate effectively to meet validation requirements. Findings are subject to the risk of changes in privacy practices or the potential ineffectiveness or failure of implemented measures.
Findings
Based on the descriptions and supporting evidence of practices-level measures identified in Tuya's GDPR Validation Assessment, TRUSTe LLC's opinion is:
- The applicable practices-level measures were implemented as of April 22, 2025.
- The measures were suitably designed to provide reasonable assurance that the Validation Requirements would be met if the practices-level measures operated effectively as of April 22, 2025.
Restricted Use
This summary is for the intended use of Tuya as of April 22, 2025, and may be used by the Organizations until its expiration date of April 22, 2026. It is not intended for use or reliance by anyone other than the Organization and its permitted stakeholders.
1 TRUSTe LLC is an independent subsidiary of TrustArc Inc.
2 This summary is an abbreviated, unofficial version of the full Findings Letter and accompanying report, intended for display on the Organization's website. Modifications are not permitted and would render it invalid. Only the full Findings Letter and report represent the official determination of TRUSTe.