Compliance frameworks, security audits, and quality certifications this company maintains.
Security & Compliance
SOC 2 Type II
CertifiedAnnual SOC 2 Type II audit covering Security and Availability for Duolingo platform infrastructure, learner data, and DET testing environment.
EU GDPR compliance covering learner data processing, right to erasure, data subject requests, and cookie consent across the Duolingo app and web platform for European users.
California Consumer Privacy Act compliance including opt-out of data sale, consumer rights portal, and advertising data disclosures for California-resident users.
Children Online Privacy Protection Act compliance as an education app with significant under-13 users, including restricted data collection, parental consent mechanisms, and COPPA-compliant advertising.
PCI DSS compliance for Duolingo Plus, Duolingo Max subscription payments, and Duolingo English Test fee processing.
Family Educational Rights and Privacy Act compliance for Duolingo for Schools, governing student education records and restricting disclosure of student data to third parties.
Web Content Accessibility Guidelines 2.1 Level AA compliance across Duolingo web and mobile interfaces, supporting learners with disabilities through screen reader support, captions, and accessible lesson formats.
Security & Compliance
ISO 27001
CertifiedInformation Security Management System certification covering Duolingo engineering, data handling, and DET testing environment security operations.
Privacy & Data
COPPA Safe Harbor (kidSAFE)
CertifiedkidSAFE COPPA Safe Harbor certification for Duolingo's child-facing products, providing additional compliance assurance for school and parent audiences.
Section 508 accessibility compliance for Duolingo for Schools and DET products used by US government-funded educational institutions.