Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
The VeriSign trust seal, now operated by DigiCert, is a third-party site seal and SSL trust badge embedded on websites to signal security to visitors. When loaded, it contacts external seal provider domains (seal.digicert.com, historically seal.verisign.com), transmitting the visitor's IP address and User-Agent to servers in the United States. While primarily a static visual badge with low tracking risk, it constitutes a transfer of personal data to a third country and must be documented in your privacy policy and cookie notice.
The VeriSign trust seal, historically known as the VeriSign Secured Seal and later as the Norton Secured Seal powered by Symantec, is a third-party site seal used to display a website's SSL/TLS certificate status and signal trustworthiness to visitors. The seal has undergone several ownership transitions: from VeriSign to Symantec, and then to DigiCert, which now operates the seal infrastructure under its own brand. Websites that display this seal embed a small script or image tag that loads content from external DigiCert or legacy VeriSign domains. The seal is common on e-commerce and financial websites seeking to reassure customers about site security.
When the trust seal loads on a page, the visitor's browser makes a request to the seal provider's servers (primarily seal.digicert.com for current DigiCert seals, and historically seal.verisign.com or trustseal.verisign.com). This request inherently transmits the visitor's IP address, User-Agent string, and HTTP referrer to DigiCert's infrastructure in the United States. The seal itself is largely cookieless for tracking purposes; its primary function is to render a dynamic badge confirming the certificate's validity. Some implementations may set a short-lived technical cookie to cache the seal state, but no behavioural profiling or cross-site tracking is performed.
Under the GDPR, the transmission of an IP address to a third-party server constitutes processing of personal data. The appropriate legal basis for loading a static trust seal is legitimate interest (Article 6(1)(f) GDPR), as the website operator has a genuine interest in demonstrating SSL certificate validity and the data transmitted is minimal and not used for tracking. Under the ePrivacy Directive, if the seal sets any cookies that are not strictly necessary for the communication, prior consent from the user is required. Because the seal is primarily cookieless and serves a security function, it typically qualifies for the legitimate interest basis, but the transfer to the US must be documented and adequately safeguarded.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
DigiCert is a US-based company, and loading the trust seal results in data being transferred to the United States, a third country under GDPR Chapter V. Website operators must ensure an appropriate transfer mechanism is in place: either reliance on the EU-US Data Privacy Framework (if DigiCert is certified), or Standard Contractual Clauses (SCCs). This transfer must be disclosed in the website's privacy policy, including the identity of the recipient (DigiCert, Inc.), the nature of data transferred (IP address, User-Agent), and the safeguard applied. Failure to document this transfer is a common compliance gap even for low-risk services.
To comply with GDPR and ePrivacy requirements when using the VeriSign/DigiCert trust seal, website operators should: (1) document the seal as a third-party service in their Records of Processing Activities (RoPA) under legitimate interest; (2) disclose the data transfer to DigiCert in the US within the privacy policy, referencing the applicable transfer mechanism; (3) list the seal domains (seal.digicert.com) in the cookie policy or privacy notice as a third-party resource; (4) verify via DigiCert's documentation whether the current seal implementation sets any cookies, and if so, categorise them appropriately; (5) consider self-hosting a static seal image as a privacy-preserving alternative that eliminates the third-party connection entirely.
Websites using VeriSign Trust Seal (DigiCert) must obtain user consent under GDPR regulations.
DPIA considerations
A full DPIA is unlikely to be required for a static trust seal. However, the transfer of IP addresses to US-based DigiCert servers should be assessed under the third-country transfer framework (SCCs or EU-US Data Privacy Framework). Document this transfer in your records of processing activities (RoPA). If the seal sets non-essential cookies, assess proportionality of consent collection.
Sample consent text
We embed the DigiCert/VeriSign site seal on this website to display our SSL certificate status. When this seal loads, your IP address and browser information are transmitted to DigiCert servers in the United States. This processing is based on our legitimate interest in demonstrating website security. No tracking cookies are set by this seal. For more information, see our Privacy Policy.
Third-party domains contacted
seal.digicert.comseal.verisign.comtrustseal.verisign.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Norton_sd | functional | Session | Technical cookie set by some DigiCert/VeriSign seal implementations to cache the seal verification state and avoid redundant checks on each page load. Not used for tracking or advertising. |
VeriSign Trust Seal (DigiCert) collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The VeriSign/DigiCert trust seal is largely cookieless. Its primary operation is loading a badge image from seal.digicert.com, which does not require cookies. Some legacy or dynamic seal implementations may set a short-lived technical cookie to cache the seal state or verify the certificate, but this is not used for advertising or behavioural tracking.
Consent is generally not required for a static trust seal loaded under legitimate interest. Because the seal serves a genuine security communication purpose and does not perform behavioural tracking, most Data Protection Authorities accept legitimate interest as the lawful basis. However, if the seal sets any non-essential cookies, ePrivacy rules require prior consent for those cookies.
The appropriate legal basis under GDPR is legitimate interest (Article 6(1)(f)). The website operator has a genuine interest in displaying SSL certificate validity to visitors, and that interest is not outweighed by visitor rights given the minimal data involved. A brief Legitimate Interest Assessment (LIA) should be documented to support this basis.
Yes. DigiCert is a US-based company and loading the seal transmits the visitor's IP address and User-Agent to DigiCert servers in the US. This is a third-country transfer under GDPR Chapter V. The transfer should be covered by the EU-US Data Privacy Framework (if DigiCert is certified) or Standard Contractual Clauses, and must be disclosed in your privacy policy.
A full DPIA is not typically required for a static trust seal, as it poses low risk to individuals: no profiling, no behavioural tracking, and minimal data (IP address only) is transmitted. However, the US data transfer should be assessed as part of your transfer impact assessment. Document the processing in your Records of Processing Activities.
To implement the seal compliantly: document it in your Records of Processing Activities under legitimate interest; disclose the DigiCert US data transfer in your privacy policy with the applicable safeguard (SCCs or EU-US DPF); list seal.digicert.com in your cookie/privacy notice as a third-party resource; conduct a brief Legitimate Interest Assessment; and consider self-hosting a static seal image if you want to eliminate the third-party data flow entirely.
Privacy-friendly alternatives include: (1) self-hosting a static seal image downloaded from DigiCert, which eliminates the third-party network request; (2) using a text-based or CSS-only trust indicator that does not load external resources; (3) displaying the padlock icon in the browser address bar, which is built-in and requires no third-party service. Any alternative that avoids external requests fully removes the data transfer concern.
In your cookie policy or privacy notice, add an entry under a "Security" or "Third-party services" section: name the service as DigiCert Site Seal (formerly VeriSign), describe it as a trust seal that contacts seal.digicert.com to verify your SSL certificate, state that the visitor IP address is transmitted to DigiCert in the US, specify the legal basis as legitimate interest, and note that no tracking cookies are set. Update this notice whenever the seal provider or domains change.