Compliance frameworks, security audits, and quality certifications this company maintains.
Lyft maintains SOC 2 Type II certification covering its cloud infrastructure and data platform, demonstrating that rider and driver personal and payment data is protected with enterprise-grade security controls.
Lyft is PCI DSS Level 1 certified as a merchant and payment processor, ensuring that payment card data collected during ride booking and Lyft Pink subscription billing is handled in compliance with the highest card industry security standards.
Lyft holds ISO 27001 certification for its information security management system, providing riders, drivers, and enterprise Lyft Business customers with assurance that information assets are systematically protected.
Lyft complies with the California Consumer Privacy Act, giving California-based riders and drivers rights to access, delete, and opt out of the sale of their personal data collected through the Lyft platform.
Lyft adheres to GDPR requirements for any EU-resident users accessing Lyft-affiliated services, applying data minimization, purpose limitation, and consent management principles to personal data processing.
Lyft holds a Transportation Network Company permit from the California Public Utilities Commission, authorizing it to operate ride-hailing services across California and comply with insurance, driver background check, and accessibility requirements.
Accessibility
ADA Accessibility
CompliantLyft complies with Americans with Disabilities Act requirements by offering wheelchair-accessible vehicle options, in-app accessibility features for riders with visual or mobility impairments, and partnering with WAV providers in major markets.
Safety
DOT Drug & Alcohol Testing
CompliantLyft complies with Department of Transportation drug and alcohol testing requirements for drivers operating on the platform, including pre-enrollment screening and random testing programs to ensure passenger safety.
Lyft aligns its cybersecurity program with the NIST Cybersecurity Framework, applying the Identify, Protect, Detect, Respond, and Recover functions to safeguard the integrity of its ride-hailing platform and user data.
Lyft maintains ISO 22301 business continuity management certification, ensuring that critical ride-hailing platform services can withstand and recover from disruptions affecting rider and driver access across its US and Canadian markets.