---
title: Data privacy with New Relic
source: https://docs.newrelic.com/docs/security/security-privacy/data-privacy/data-privacy-new-relic
---

New Relic takes your data privacy seriously. Our principles-based approach aims to go beyond the legal requirements for consent. We understand your concerns when you entrust us with your data, and we always strive to embrace your expectations and preferences.

This document provides links to detailed information about the privacy and security measures we take to protect you and your customers' data privacy. Our monitoring tools are data-agnostic; they don't require sensitive materials, and many of them don't require any personal data.

You are responsible for ensuring that your systems are appropriately set up and configured so that they don't send inappropriate personal data or sensitive materials to New Relic monitoring tools. For additional information about policies, credentials, audits, and other resources, see our [New Relic security website](https://newrelic.com/security).

> #### 💡 TIP
>
> New Relic includes the option of HIPAA-enabled accounts for customers meeting certain requirements. To learn more, see [HIPAA readiness at New Relic](https://docs.newrelic.com/docs/security/security-privacy/compliance/hipaa-readiness-new-relic).

## Personal data transfer (Data Privacy Framework and SCC) [#data-privacy-framework]

As of October 2023, the U.S. Department of Commerce has formally approved New Relic's certification under the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and the UK extension to the Data Privacy Framework.

The Data Privacy Framework replaces the Privacy Shield for data transfers to the U.S.  The Privacy Shield was invalidated in the [Schrems case](https://epic.org/privacy/intl/schrems/). The Schrems case reaffirmed the validity of Standard Contractual Clauses (SCC) as an appropriate legal mechanism to transfer personal data outside of the European Union.  Since then, New Relic has relied on the Standard Contractual Clauses as a mechanism to transfer personal data from the EU, Switzerland and the UK (the SCC were updated in 2021). You can find more information in [EU-U.S. Data Privacy Framework (DPF) & International Data Transfers](https://newrelic.com/blog/how-to-relic/eu-us-dpf-international-transfers).

If you want to send personal data from the EU, Switzerland, and/or the UK, we offer an appropriate data processing addendum (DPA) that makes reference to the Data Privacy Framework and/or the SCC, as applicable.  In the event that the Data Privacy Framework is invalidated, the SCC will automatically apply in order to ensure that there is a valid data transfer mechanism in place to govern the transfer of that data. For more information, consult our [Data Processing Addendum FAQ](https://newrelic.com/termsandconditions/dataprotectionFAQ), or see our online [Data Processing Addendum](https://newrelic.com/termsandconditions/dataprotection).

## Compliance with legal requirements [#legal]

We always strive to comply with all applicable laws as they take effect. This includes the European Union's [General Data Protection Regulation (GDPR)](https://newrelic.com/sites/default/files/2022-06/GDPR%20FAQ%20%28Updated%29-June%202022.pdf) and all relevant US State laws, such as the California Consumer Privacy Act (CCPA).

Our encryption at rest provides additional security while your data is at rest ([FIPS 140-2 compliant](https://csrc.nist.gov/publications/detail/fips/140/2/final)). In addition, we are authorized for Moderate Impact SaaS Services [(FedRAMP Authorized Moderate)](https://marketplace.fedramp.gov/#/product/new-relic?sort=productName&productNameSearch=new%20relic) for [accounts that meet specific criteria](https://docs.newrelic.com/docs/security/new-relic-security/compliance/data-encryption).

For privacy-related details about New Relic's contractual and regulatory commitments for services, see:

-   [Terms of Service](https://newrelic.com/termsandconditions/terms)
-   [Data Processing Addendum (DPA)](https://newrelic.com/termsandconditions/dataprotection)
-   [Services Privacy Notice](https://newrelic.com/termsandconditions/services-notices)

As per the terms of New Relic’s DPA, we may be able to provide additional information pertaining to New Relic’s privacy & security practices as follows:

**For paying New Relic customers:**

Upon review of such materials as described in Section 10.2 of the DPA, or as made available via the New Relic platform UI, if a paying New Relic customer identifies areas that have not been covered that it is lawfully permitted to audit under the DPA, then that customer may submit reasonable requests for information security and audit questionnaires that are necessary to confirm New Relic’s compliance with the DPA, provided that customer shall not exercise this right more than once per year.

**For free tier New Relic customers:**

Free tier New Relic customers may access the materials available at <https://trust.newrelic.com/>.

For more information about annual audits, see [Regulatory audits for New Relic services](https://docs.newrelic.com/docs/security/new-relic-security/compliance/regulatory-audits-new-relic-services).

If you have further questions, please contact your account team, or [privacy@newrelic.com.](mailto:privacy@newrelic.com.) Please note that we are unable to provide assistance to our customers with privacy questions via any third party platforms, including, e.g., any data privacy or data privacy compliance platforms. The only method by which we can provide assistance is as set out above.

Please note that New Relic may utilize a third party service provider to assist with note taking and/or transcription on calls with customers, and which may also incorporate AI functionality. During a call you may choose to share screen captures of your Customer Data (including any personal data, contained therein), or regulated or sensitive data, as well as yours or your colleagues’ own personal data.

By choosing to screen share, you grant full permission to New Relic and its third party service provider(s) for the processing and use of any Customer Data, personal data, regulated data, or sensitive data you choose to share or record. At the beginning of the call you will be informed via an on screen message that the call is being recorded, transcribed and/or using note taking functionality. If you choose to remain on the call, you will be deemed as having provided consent.

## Privacy by design and by default [#privacy-default]

New Relic follows "privacy by design" principles as part of our overarching security program. For example, when New Relic agents capture a webpage or referrer URL, all query parameters are stripped by default.

Here are examples of how we incorporate privacy considerations into our data and security practices.

**Personal data requests (GDPR, CCPA, etc.)**

New Relic strives to comply with all applicable laws as they take effect. This includes the European Union's GDPR and ePrivacy Directive and all applicable privacy laws, such as the California Consumer Privacy Act (CCPA) in the US. For more information about our process when responding to requests to access or delete personal data, see [New Relic personal data requests](https://docs.newrelic.com/docs/using-new-relic/new-relic-security/security/new-relic-personal-data-requests).

**Events and attributes**

You can query [events](https://docs.newrelic.com/docs/using-new-relic/welcome-new-relic/get-started/glossary#event) and [attributes](https://docs.newrelic.com/docs/using-new-relic/welcome-new-relic/get-started/glossary#attribute), as well as create charts and alert conditions about this data. For a complete list of all events and attributes tracked by New Relic agents, see our [data dictionary](/attribute-dictionary).

**Events and attributes example:**

If you use the [Infrastructure `ProcessSample` event's `commandLine` attribute](/attribute-dictionary/?event=ProcessSample&attribute=commandLine), by default we strip options and arguments from the full command line to prevent accidental leakage of sensitive information.

**Dropping data at ingest**

Dropping data gives you control over the data that you send to New Relic, including any personal data that you configured to be collected. By dropping specific events or attributes from events, you determine what data New Relic ultimately stores so that you can query, alert on, and analyze it. For more information, see [Drop data using NerdGraph](https://docs.newrelic.com/docs/accounts/accounts/data-management/drop-data-using-nerdgraph).

When our agents refer to data obfuscation, the agent actually removes the data before sending it to New Relic. The data cannot be recovered. For example, with APM queries, the `Record SQL?` value defaults to `obfuscated`. This strips the string literals and numeric sequences and then replaces them with the `?` character.

You can mask sensitive information in HTTP or HTTPS requests. For example, queries about distributed traces and transaction traces are obfuscated by default, in which case they cannot be recovered. For more information, see the documentation for specific New Relic services, including:

-   [APM transaction traces](https://docs.newrelic.com/docs/features/security-options-for-transaction-traces)
-   [Distributed tracing](https://docs.newrelic.com/docs/understand-dependencies/distributed-tracing/ui-data/additional-distributed-tracing-features-new-relic-one)

**Technical security controls**

We use a comprehensive set of technical controls to support general security needs as well as security for data we receive. For more information, see our documentation about [data security](https://docs.newrelic.com/docs/security/new-relic-security/data-privacy/security-controls-privacy), [data encryption](https://docs.newrelic.com/docs/security/new-relic-security/compliance/data-encryption), and [high-security mode for APM agents](https://docs.newrelic.com/docs/agents/manage-apm-agents/configuration/high-security-mode).

**Organizational security controls**

New Relic maintains a number of internal policies and procedures to guide employees in privacy-related subjects such as data classification and handling, data retention, handling of personal data, fulfilling personal data requests, incident response, etc. All employees must complete the security and privacy training upon hiring and renew this training annually.

## Account security [#account-security]

Our role-based account structure gives you direct control over who can access or change your account settings. For more information, see [Users and roles](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/introduction-managing-users). New Relic periodically audits and deactivates accounts for terminated employees that a customer may have provisioned for support.

**Retention of your data**

The New Relics platform gives you a single source of truth for all your operational data, empowering you to ask and answer any question in milliseconds. This platform stores different types of data for different periods of time. The **Data retention** page in our UI provides information on how long your data will be stored in the New Relic database (NRDB). For more information, see [Manage data retention](https://docs.newrelic.com/docs/telemetry-data-platform/get-data-new-relic/manage-data/manage-retention-stored-data).

**New Relic account emails**

By default, we communicate with you for a variety of purposes related to your status as New Relic subscribers. This includes product engagement, support, alert notifications, updates, billings, etc.

-   Individual users can unsubscribe from certain communications. General email preferences are managed through the account user interface. For more information, see [Account email settings](https://docs.newrelic.com/docs/accounts/accounts/account-maintenance/account-email-settings).
-   [Alert notification emails](//docs/apis/nerdgraph/examples/nerdgraph-api-notifications-channels/) are managed through the alerting UI.
-   New Relic customers should be vigilant of phishing attempts that target their employees. New Relic also makes available SAML, SSO, and SCIM provisioning, which is available here. Additionally, customers configured with SAML, SSO, and SCIM, are strongly encouraged to enable MFA.

**Account changes (NrAuditEvent)**

To view changes made to your account's users or to record configuration changes, query [`NrAuditEvent` events](https://docs.newrelic.com/docs/insights/use-insights-ui/manage-account-data/query-account-audit-logs-nrauditevent). To be notified about account changes, create [NRQL alert conditions](https://docs.newrelic.com/docs/alerts/new-relic-alerts/defining-conditions/create-alert-conditions-nrql-queries). For more about available `NrAuditEvent` attributes, see our [data dictionary](/attribute-dictionary/?event=NrAuditEvent).

## Audit New Relic user activity [#audit-user-activity]

New Relic collects user activity data when a user queries for data or makes configuration changes within an organization. You can query these events to address security-related concerns around user activity within your New Relic organization. Surfacing user activity information empowers security-sensitive customers to understand how members of their org access data in the New Relic platform.

You can surface user activity information with these events:

| Event name                                                  | Event description                                                                                        |
| ----------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
| [`NRAuditEvent`](/attribute-dictionary/?event=NrAuditEvent) | Records user activity when a user makes service configuration changes within your New Relic organization |
| [`NrdbQuery`](/attribute-dictionary/?event=NrdbQuery)       | Records user activity when a user queries data within the account                                        |

You can surface user activity data by going to **[one.newrelic.com](https://one.newrelic.com) > All Capabilities**, then working with two capabilities: **Metrics & Events** and **Query your data**. In general, you can use:

-   Metrics & Events for looking at broad, general trends
-   Query your data for answering specific, scoped questions with NRQL queries

**Surface event data in Metrics & Events**

To surface user activity information, go to **[one.newrelic.com](https://one.newrelic.com) > All Capabilities > Metrics & Events**, then search for either `NrAuditEvent` or `NrdbQuery` from the **Event type** column. For example:

![A screenshot that shows how to find events and attributes for user activity data](nr1FindUserActivityDatainMetricsandEvents "Find user activity data in Metrics & Events")

Go to **[one.newrelic.com](https://one.newrelic.com) > All Capabilities > Metrics & Events**: Search `NrAuditEvent` or `NrdbQuery` from the **Event type** column, then click **Dimensions** to view attributes.

You can select **Raw data** to view event attributes as key-value pairs. Attribute keys like ID, description, or timestamp are organized in the table's horizontal row while their values are listed out in the table's columns. Keep in mind that these attributes are subject to [data limits](https://docs.newrelic.com/docs/data-apis/manage-data/view-system-limits).

**Query event data with NRQL**

You can also use our **Query your data** tool to retrieve attributes and fields of interest. For example, take this example query:

````sql
FROM NrdbQuery SELECT user, query, productCapability, source.name where user = 'demonewrelic@gmail.com' limit max since 1 week ago until 1 day ago
```

<img
title="Query user activity data"
alt="A screenshot that shows how to query events to answer specific questions about user activity data"
src={nr1FindUserActivityDatainNrql}
/>

<figcaption>
Go to **[one.newrelic.com](https://one.newrelic.com) > All Capabilities > Query your data**: Build a query to answer specific questions about user activity.
</figcaption>

This query surfaces data from the `NrdbQuery` event but limits the data to:

 * These attributes: `SELECT user, query, productCapability, source.name`
 * A specific user: `where user = 'demonewrelic@gmail.com'`
 * With no set maximum number of results: `limit max`
 * Scoped to this time parameter: `since 1 week ago until 1 day ago`

This surfaces data about specific parameters rather than showing broad trends like in Metrics & Events. 

We recommend reviewing [How to query with NRQL](/docs/nrql/get-started/introduction-nrql-how-nrql-works) to learn more about using NRQL syntax to surface the information you need. 


````

## Security for products and services [#product-security]

We publish [security bulletins](https://docs.newrelic.com/docs/using-new-relic/new-relic-security/security/security-bulletins) with detailed information about vulnerabilities, remediation strategies, and applicable updates for affected software.

To receive notifications for future advisories, use either of these options:

-   Subscribe to our [security bulletins RSS feed](https://docs.newrelic.com/docs/using-new-relic/new-relic-security/security/security-bulletins).
-   Select the **Watching** option in our Support Forum's [Security notifications community channel](https://support.newrelic.com/s/hubtopic/Topic__c/Default?c__categories=%5B%7B%22icon%22%3A%22standard%3Adefault%22%2C%22id%22%3A%22a6c8W000000Eet5QAC%22%2C%22sObjectType%22%3A%22Category__c%22%2C%22title%22%3A%22Security%20Notifications%22%2C%22titleFormatted%22%3A%22Security%20Notifications%22%7D%5D) to receive email alerts.

The following summarizes how individual New Relic products and components ensure security, with links to additional details.

**Alerts**

By default, our alerting services do not record any personal data. In addition, they automatically set default permissions for individual account users and access levels within account structures. For more information, see our documentation about [alerts](https://docs.newrelic.com/docs/alerts-applied-intelligence/new-relic-alerts/get-started/introduction-applied-intelligence), as well as our [rules and limits for alerts](https://docs.newrelic.com/docs/alerts/new-relic-alerts/rules-limits-glossary/rules-limits-new-relic-alerts).

**APIs**

APIs simply are interfaces for data exchange automation. APIs have no knowledge of the content being transferred.

We require authorized users to provide their API keys to monitor subscription usage, manage account user permissions, query data, and perform other automated tasks. For more information, see [Introduction to New Relic APIs](https://docs.newrelic.com/docs/apis/get-started/intro-apis/introduction-new-relic-apis).

**APM**

APM agents monitor your applications' performance. By default, APM agents do not record any personal data. For more information, see our [APM security documentation](https://docs.newrelic.com/docs/apm/new-relic-apm/getting-started/apm-agent-data-security).

**Browser monitoring**

Our browser monitoring agent allows you to monitor the performance of their websites. For more information, see:

-   [Browser security documentation](https://docs.newrelic.com/docs/browser/new-relic-browser/performance-quality/security-new-relic-browser)
-   [Visitor's IP address](https://docs.newrelic.com/docs/browser/new-relic-browser/performance-quality/security-new-relic-browser#visitors-ip)
-   [New Relic cookies used by browser](https://docs.newrelic.com/docs/browser/new-relic-browser/page-load-timing-resources/new-relic-cookies-used-browser)
-   [Enabling or disabling cookie collection for session tracking](https://docs.newrelic.com/docs/browser/browser-monitoring/page-load-timing-resources/cookie-collection-session-tracking)

**Diagnostics**

The New Relic Diagnostics service inspects relevant system information and any other necessary information (such as logs and config files) to perform diagnostic checks that assess configuration and operability. By default, this data is not transmitted to New Relic.

You do have the option to upload this information to a support ticket over HTTPS. For more information, see the [Diagnostics security documentation](https://docs.newrelic.com/docs/using-new-relic/cross-product-functions/troubleshooting/new-relic-diagnostics#security).

**Infrastructure monitoring**

The Infrastructure agent allows you to monitor the performance of components in your ecosystem, such as servers, platforms, operating systems, databases, etc. Infrastructure may record the `userID` and `username` of users connecting to Infrastructure resources. For more information, see the [security documentation](https://docs.newrelic.com/docs/infrastructure/new-relic-infrastructure/getting-started/infrastructure-security) for infrastructure monitoring.

**Integrations and serverless monitoring**

Our integrations services allow you to retrieve and load data into the New Relic database from a [variety of sources](https://docs.newrelic.com/docs/integrations/new-relic-integrations/getting-started/introduction-infrastructure-integrations#integration-types), including:

-   Cloud-based integrations

-   On-host integrations in containerized environments, such as Kubernetes

-   On-host integrations built by New Relic

-   On-host integrations built by the open-source community

-   On-host integrations built by you

    Depending on the integration, different [types of data](https://docs.newrelic.com/docs/integrations/infrastructure-integrations/get-started/introduction-infrastructure-integrations#data-types) may be recorded so that you can monitor the integrations in New Relic.

    The integration services are data agnostic. They will have no knowledge of whether the imported data contains any personal information. For more information, see the documentation for the specific integration, including:

-   [Amazon Web Services (AWS)](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/aws-integrations-list)

-   [Google Cloud Platform (GCP)](https://docs.newrelic.com/docs/integrations/google-cloud-platform-integrations/gcp-integrations-list)

-   [Kubernetes](https://docs.newrelic.com/docs/integrations/kubernetes-integration/get-started/introduction-kubernetes-integration)

-   [Microsoft Azure](https://docs.newrelic.com/docs/infrastructure/microsoft-azure-integrations/get-started/introduction-azure-monitoring-integrations)

-   [On-host integrations](https://docs.newrelic.com/docs/integrations/host-integrations/host-integrations-list)

-   [Serverless function monitoring](https://docs.newrelic.com/docs/serverless-function-monitoring)

**Logs management**

Due to the nature of our logs management service, you have direct control over what data is reported to New Relic. To ensure data privacy and to limit the types of information New Relic receives, no customer data is captured except what you supply in your API calls or log forwarder configuration. All data for the logs service is then reported to New Relic over HTTPS.

The logs service automatically masks number patterns that appear to be for items such as credit cards or Social Security numbers. You can also manage obfuscation rules and expressions to hash or mask your log data. For more information, see our [obfuscation](https://docs.newrelic.com/docs/logs/ui-data/obfuscation-ui) and [Logs security](https://docs.newrelic.com/docs/logs/new-relic-logs/get-started/new-relic-logs-security) documentation.

**Mobile monitoring**

By default, our mobile monitoring service collects two pieces of personal data:

-   The IP address is used to derive high-level geographical data, and then is discarded.
-   A device ID is generated by New Relic and is used for billing purposes.

    For more information, see our [security documentation](https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile/get-started/security-mobile-apps) for mobile monitoring.

**Pixie auto-telemetry data**

Auto-telemetry with Pixie is New Relic's integration of Community Cloud for Pixie, a managed version of Pixie open source software. The data that Pixie collects is stored entirely within your Kubernetes cluster. This data does not persist outside of your environment, and it will never be stored by Community Cloud for Pixie. This means that your sensitive data remains within your environment and control. For example, you can:

-   Control who has access to your Pixie data.
-   Manage auto-update and two-way communication.

    For more information, see our [security documentation](https://docs.newrelic.com/docs/kubernetes-pixie/auto-telemetry-pixie/pixie-data-security-overview/) for auto-telemetry with Pixie data.

**Synthetic monitoring**

The synthetic monitoring service uses [monitors](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/getting-started/types-synthetics-monitors) distributed throughout [data centers around the world](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/administration/synthetics-public-minion-ips). It captures what is essentially performance data of simulated traffic. By default, it does not capture any personal data. For more information, see the [data privacy and security documentation](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/getting-started/security-new-relic-synthetics) for synthetic monitoring.

If you configure the synthetic service to monitor areas of websites that are located behind a login page, take care to create a non-personal login dedicated to this purpose. This will reduce the risk of unintended personal data exposure. For example, to securely store sensitive information, such as passwords, API keys, and user names, you can use [secured credentials for scripted browsers and API tests](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/using-monitors/secure-credentials-store-credentials-information-scripted-browsers).

The synthetic monitoring service also supports a variety of [authentication mechanisms](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/using-monitors/handle-sites-authentication). Depending on the type of monitor you choose, this includes Basic, Digest, NTLM, and NTLMv2.

You can also control which of your users can access your monitors and [private locations](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/private-locations/private-locations-overview-monitor-internal-sites-add-new-locations). For more information, see our documentation about [user role-based permissions](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/administration/user-roles-synthetics).
