Information governance

Data Protection and Privacy Notice

The rules governing personal data across the ICEQC website, application centre, certification activities and official registers.

Secure review of digital information in an education setting

1. Controller, identity and contact details

The International Council for Education Quality Certification (ICEQC) is the controller of the personal data described in this Notice unless a service-specific notice identifies another controller. ICEQC is a Swiss association (Verein), registered under Swiss UID CHE-196.137.617, with its registered office at Quai de l’Ile 13, 1204 Geneva, Switzerland.

Questions, objections and requests concerning personal data may be sent to contact@iceqc.org or delivered by post to the registered office. The registered office is not a public service counter and should not be used to submit certification evidence. Security vulnerabilities must be reported to security@iceqc.org without including confidential evidence or unnecessary personal data in the initial message.

2. Scope of this Notice

This Notice applies to the official public website at iceqc.org; account and application services at portal.iceqc.org; enquiries and institutional correspondence; eligibility and due-diligence reviews; certification applications, evidence and conformity verification; technical review and certification decisions; surveillance, renewal, scope changes and enforcement; the Public Certificate Register and Standards Register; consultations, complaints, appeals and integrity reports; agreements, quotations, invoices, payments and refunds; and the administration and security of those activities.

A notice displayed at the point where information is collected may provide additional details for that activity. An applicant agreement, certification agreement, complaint or appeal procedure, consultation notice or other controlled instrument may impose further record and confidentiality requirements. Those instruments apply together with this Notice. Where their provisions address a particular processing activity more specifically, the specific provisions govern that activity to the extent permitted by law.

This Notice concerns personal data relating to identifiable natural persons. Information relating solely to a legal entity may nevertheless be protected by confidentiality, contract, intellectual-property or other law and is handled under the applicable ICEQC controls.

3. Applicable data-protection framework

ICEQC processes personal data principally under the Swiss Federal Act on Data Protection (FADP) and the Ordinance to the Federal Act on Data Protection. It applies the principles of lawfulness, good faith, transparency, proportionality, purpose limitation, data minimisation, accuracy, storage limitation and appropriate security.

Other mandatory data-protection rules may apply to a defined activity because of the location of a data subject, the nature of the service or the territorial reach of those rules. This may include the EU General Data Protection Regulation or the United Kingdom data-protection regime where its statutory conditions are met. A reference in this Notice to a right or lawful ground that exists under one regime does not extend that regime to processing that falls outside its legal scope.

ICEQC does not treat use of a public webpage as consent to unrelated processing. Consent is requested separately where consent is the appropriate or required ground, and refusal or withdrawal is respected subject to processing that remains necessary or lawful on another ground.

4. How personal data is obtained

Directly from the individual

Information is obtained when a person creates or uses an account, acts for an applicant or certificate holder, submits a form or evidence, pays an invoice, participates in an interview or consultation, requests assistance, or communicates with ICEQC.

From an organisation or authorised representative

An applicant, certificate holder, employer, contractor or other organisation may provide information about its officers, personnel, representatives, learners, clients or other affected persons where that information is relevant and lawfully disclosed.

From verification and public sources

ICEQC may obtain information from official registers, competent authorities, institutional websites, published policies, professional references and other sources reasonably required to verify identity, authority, scope, evidence, claims or continuing conformity.

From systems and service providers

Security, authentication, delivery, storage, email and payment systems generate technical, transaction and event records needed to operate the service, protect accounts and reconcile actions.

5. Website, device and security data

When a person requests a page or uses an online service, ICEQC and its infrastructure providers may process the Internet Protocol address, date and time, requested resource, referring address where supplied, request and response status, browser and device characteristics, language, approximate country derived from network information, security signals, challenge results and diagnostic events. These records support page delivery, abuse prevention, access control, incident investigation, service integrity and aggregated operational reporting.

The public website does not currently use advertising cookies, social-media tracking pixels or an active audience-measurement service. A first-party local-storage record remembers the website privacy notice and category state for 180 days. Cloudflare may place short-lived, strictly necessary security cookies when a security or bot-management control is triggered. The Cookie and Similar Technologies Policy provides the current inventory and control information.

6. Account and authentication data

Account administration may involve a person’s name, email address, position, organisation, account identifier, password verifier, email-verification status, authentication and recovery events, session and anti-forgery information, acceptance records, access status and related security logs. Passwords are not intended to be stored in readable form.

This information is used to create and secure the account, verify the email address, authenticate the user, recover access, bind authorised actions to the correct organisation, prevent misuse and preserve an accountable history of material account events. ICEQC may restrict or suspend an account where this is reasonably necessary to protect a person, an organisation, the certification process or the service.

7. Applicant, organisation and representative data

Eligibility and intake records may include the applicant’s legal and trading names, jurisdiction and registration identifier, address, website, product line, proposed certification object and scope, operating countries, relevant relationships, and the names, positions, business contact details and authority declarations of representatives. Due-diligence records may include conflicts, legal or regulatory matters, sanctions or integrity checks, and the sources and conclusions used to resolve them.

ICEQC uses this information to identify the legal applicant, confirm that the representative is authorised, determine whether the proposed object and scope are eligible, identify conflicts and material risks, prepare the applicable agreement and certification plan, and maintain a reliable link between the organisation and its official records.

8. Certification evidence and assessment records

Certification files may contain applications, declarations, policies, procedures, contracts, system records, datasets, screenshots, files, interviews, demonstrations, sampling records, findings, corrective actions, technical reviews, committee records, decisions, surveillance information and correspondence. Depending on the certification object, source material may incidentally contain information about personnel, learners, children, customers, complainants or other individuals.

Applicants must redact, pseudonymise or aggregate personal data wherever identity is not required to establish conformity. Special-category or otherwise sensitive data, information about children, health information, government identifiers, financial account information and credentials must not be uploaded merely because they appear in a source record. They may be provided only where the applicable requirement makes the information necessary, the applicant is authorised to disclose it, and ICEQC has identified an appropriate controlled route.

Where the relevant fact can be verified by controlled viewing without ICEQC retaining the underlying personal data, ICEQC may record what was viewed, the method used to establish authenticity and the fact confirmed. The resulting verification record forms part of the certification file even where the source evidence remains under the applicant’s control.

9. Enquiries, consultations, complaints, appeals and reports

ICEQC processes names, contact details, organisational relationships, submissions, supporting material, correspondence, procedural status, conflict checks, findings and outcomes where a person makes an enquiry, responds to a consultation, requests a correction, reports suspected misuse, raises a complaint or pursues an appeal. Anonymous or confidential treatment is considered where the relevant procedure permits it, but complete anonymity cannot be guaranteed if fair determination, safeguarding, legal process or an effective response requires identification or disclosure.

Complaint and appeal information is separated from the original decision function to the extent required by the applicable procedure. Access is limited to persons whose role requires the information. A person must not submit allegations, personal data or confidential documents that are irrelevant, excessive, unlawfully obtained or knowingly false.

10. Agreements, fees, invoices, payments and refunds

Commercial and accountability records may include quotations, fee-schedule references, agreement acceptances, purchase and tax information, invoice numbers, amounts, currency, due dates, payment status, payment method, external transaction references, reconciliation and refund records, and communications about those records. ICEQC uses them to form and administer agreements, collect and reconcile fees, issue payment confirmations, prevent duplicate or unauthorised transactions, process an approved refund, maintain accounts and meet audit, tax and legal obligations.

If online card payment is available and selected, ICEQC creates a Stripe-hosted Checkout session. The payer supplies card and billing information directly to Stripe. ICEQC receives and records the provider session or transaction reference, amount, currency, status and related event information needed to reconcile the invoice. ICEQC does not intend to receive or store the full card number or card security code in its application database.

11. Public registers and official disclosures

The Public Certificate Register is an official transparency and verification record. For a certificate, it may publish the certified legal holder, certification object and scope, applicable documents and editions, certificate identifier, relevant dates, current status, material scope changes and status history. It is not intended to publish private contact details or underlying assessment evidence.

Information required to maintain the integrity of a public certification claim may remain publicly available after suspension, withdrawal, expiry, correction or scope reduction, with the historical status clearly identified. Removal of an account or change of representative does not erase a necessary public or audit record. A substantiated correction request will be assessed against the integrity of the official record and the rights of affected persons.

ICEQC may also publish consultation responses or attributable comments where the collection notice states that publication will occur or the contributor has authorised it. Confidential submissions are not made public merely because they concern a public consultation.

12. Purposes of processing

  • Provide, administer, maintain and secure the public website, application centre, accounts, communications and requested services.
  • Verify identity, representative authority, eligibility, independence, scope, evidence and conformity against the applicable ICEQC requirements.
  • Plan and conduct assessments; issue, maintain, change, suspend, withdraw or renew certification; and preserve complete decision and review records.
  • Operate the Standards Register and Public Certificate Register and protect the accuracy of official documents, certificates, marks and public claims.
  • Administer consultations, complaints, appeals, correction requests, integrity reports, security reports and related procedural safeguards.
  • Prepare and administer quotations, agreements, invoices, payments, refunds, accounting and audit records.
  • Detect, prevent and investigate fraud, impersonation, conflicts, misuse, security threats and conduct capable of undermining the reliability of ICEQC services.
  • Establish, exercise or defend legal claims; meet legal, regulatory, tax, accounting and recordkeeping duties; and respond to lawful demands from competent authorities.
  • Evaluate and improve the reliability, accessibility, security and administration of services using proportionate operational information.

13. Legal grounds and justification

Under Swiss law, ICEQC processes personal data in accordance with the statutory processing principles and relies, where a justification is required, on consent, an overriding private or public interest, a contractual relationship or law. ICEQC’s overriding private interests include providing requested certification and verification services, maintaining reliable official records, securing systems, preventing misuse and protecting the integrity of decisions, provided those interests are pursued proportionately and do not unlawfully override the affected person’s interests.

Where the GDPR or a comparable regime applies to a particular activity, processing may be necessary to take requested pre-contract steps or perform a contract, comply with a legal obligation, protect vital interests, perform a task in the public interest where legally assigned, or pursue legitimate interests after the required balancing. Consent is used where the law requires it or the activity is genuinely optional. The applicable ground depends on the purpose and context; a person may request the ground relevant to their information.

If information is required by law, contract, an ICEQC application requirement or a necessary security control, ICEQC will identify that requirement at or before collection where it is not already evident. Failure to provide necessary information may prevent account creation, verification, payment, assessment or a reasoned decision. It does not by itself authorise an adverse conclusion beyond the applicable process and evidence rules.

14. Sensitive data and information about children

ICEQC services are directed principally to organisations and their authorised adult representatives. The public website is not designed to solicit applications or payment instructions directly from children. ICEQC may nevertheless review education evidence relating to children or other vulnerable persons where that material is lawfully provided for certification, complaint, safeguarding or verification purposes.

Sensitive data is subject to heightened minimisation, access and transfer controls. An applicant remains responsible for selecting lawful evidence, informing affected persons where required, obtaining any necessary authority, and using redaction or controlled viewing. ICEQC may reject, quarantine, return or securely delete material that is unnecessary, manifestly excessive, unlawfully disclosed or unsafe to retain, without treating the rejected material as evidence of conformity.

15. Human review and automated processing

ICEQC does not grant, refuse, suspend or withdraw certification solely through automated processing. Systems may validate required fields, calculate dates or amounts, detect inconsistent records, route work, apply access controls or flag matters for review. Such functions support, but do not replace, the authorised assessment, technical review or decision required by the applicable procedure.

If ICEQC introduces automated individual decision-making that produces a legal effect or similarly significant effect for a person, it will provide the information and review opportunity required by applicable law. Statistical, security and administrative automation that does not make such a decision remains subject to proportionality, accuracy and oversight controls.

16. Internal access, confidentiality and decision independence

Access is granted by role and limited to the information required for assigned duties. Depending on the matter, recipients may include authorised administrative personnel, assessors, technical reviewers, decision-makers, committee members, complaint or appeal authorities, finance personnel and security personnel. They are subject to applicable confidentiality, conflict-of-interest, impartiality, access and recordkeeping requirements.

Confidentiality does not prevent a lawful disclosure required to conduct a fair procedure, obtain specialist or legal advice, investigate misconduct, protect a person or system, enforce an agreement or comply with a competent authority. Where feasible and lawful, disclosure is limited to the information and recipients necessary for that purpose.

17. Principal service providers and other recipients

Cloudflare

Cloudflare provides website delivery, network and application security, bot and challenge controls, serverless application infrastructure, database and object-storage services, and transactional email routing used by ICEQC. Technical, account, application, evidence and communication data may be processed through those services according to function.

Stripe

Stripe provides hosted Checkout and payment processing when online card payment is offered and selected. Stripe processes payer, billing, device, fraud-prevention and transaction data under its applicable terms and privacy notice; ICEQC receives the transaction information necessary to administer the invoice.

Professional and assessment functions

Authorised assessors, reviewers, committee participants, interpreters, accessibility support providers, auditors and professional advisers may receive the information necessary for their assigned function and are bound by applicable duties.

Authorities and legal recipients

Information may be disclosed to courts, regulators, law-enforcement bodies, tax or other competent authorities, insurers, advisers or affected parties where disclosure is required or authorised by law, necessary for legal claims or protection, or otherwise lawfully justified.

Organisational parties

An applicant or certificate holder may receive account, application, payment and decision information concerning its authorised representatives and activities. ICEQC verifies authority and limits disclosure where individual rights, confidentiality or procedural independence require it.

18. International disclosure and processing locations

ICEQC is established in Switzerland and operates services for an international user base. Its principal technology and payment providers operate infrastructure, support functions and subprocessors in several countries. Depending on routing, service configuration, support and the transaction, data may be processed in Switzerland, the European Economic Area, the United Kingdom, the United States and other countries identified in the relevant provider’s current subprocessor or privacy documentation.

Before disclosing personal data from Switzerland to a country or international body that is not recognised as providing an adequate level of protection, ICEQC applies a permitted safeguard or statutory exception. Safeguards may include recognised standard contractual clauses adapted for Swiss law, contractual and technical supplementary measures, or another mechanism recognised by the FADP. ICEQC assesses whether the recipient can comply with the safeguard and limits the data and access according to purpose and risk.

Where another applicable regime imposes additional transfer requirements, ICEQC applies those requirements to the affected transfer. Information about the country and applicable safeguard for a person’s data is available through the access process, subject to lawful limits and protection of security and third-party rights.

19. Retention and disposal

ICEQC assigns retention by record purpose, certification lifecycle, contractual status, sensitivity, public-register function, limitation period, legal obligation and evidential value. A record is not retained merely because storage is technically available. A legal hold, active complaint, appeal, investigation, enforcement matter, debt or claim may suspend ordinary disposal for the relevant material.

Certification records

Unless a longer period is required by an applicable scheme, agreement or lawful obligation, the complete certification record is retained for the current certification cycle and the immediately preceding cycle and, in all cases, for not less than seven years after the final activity to which the record relates.

Complaints, appeals, integrity and enforcement

These records are retained for not less than seven years after closure and longer where necessary to support an active restriction, a legal matter or an accurate historical public status.

Financial and accounting records

Books, accounting records and supporting documents are retained for the period required by Swiss law, generally ten years from the end of the relevant financial year, and longer where a lawful hold applies.

Public-register records

Current and historical certificate status information may be retained for as long as necessary to authenticate certificates, prevent misleading claims and preserve the integrity of the official record.

Accounts, enquiries and technical records

These are retained for the period needed to provide and secure the service, manage the relationship, resolve the matter and meet applicable limitation, evidence or legal requirements. Short-lived authentication, challenge and session records expire according to their security function.

Website privacy choice

The first-party local-storage record is treated as expired after 180 days or when the policy version changes. A visitor can delete it earlier through browser controls.

20. Security and integrity measures

ICEQC uses technical and organisational measures proportionate to the nature, scope, context and risk of processing. Measures include controlled identity and access management, separation of public, applicant and administrative functions, encryption in transit, secure credential handling, anti-forgery and abuse controls, restricted evidence channels, role-based permissions, event and decision logging, continuity and recovery arrangements, provider due diligence and procedures for security events.

No Internet transmission, provider or storage system can be guaranteed to eliminate every risk. Users must protect credentials, verify the iceqc.org or portal.iceqc.org domain before signing in or paying, avoid sending evidence by ordinary email, close sessions on shared devices and report suspected compromise promptly. ICEQC will never ask a user to disclose a password or full card security code by email.

ICEQC takes proportionate steps to keep identity, contact, application, payment, register and decision information accurate and complete for the purpose for which it is used. Authorised users can correct certain account or application information through the applicable process. A material amendment to evidence or a decision record is dated and attributable; it does not silently replace the information on which an earlier decision was made.

A proposed processing activity that is likely to create a high risk for a person’s personality or fundamental rights is assessed before implementation as required by applicable law. The assessment considers necessity, proportionality, data flows, affected persons, foreseeable harm, provider and transfer risk, safeguards and residual risk. Consultation with the competent authority is undertaken where the statutory conditions require it.

21. Personal-data breaches

ICEQC assesses suspected loss, destruction, alteration, unauthorised disclosure of or access to personal data under its incident process. Where a breach is likely to result in a high risk to a person’s personality or fundamental rights, ICEQC reports it to the Swiss Federal Data Protection and Information Commissioner as soon as required by Article 24 FADP. Affected persons are informed where this is necessary for their protection, required by the Commissioner or required by another applicable law.

A notice may be delayed, limited or omitted only where law permits, including where immediate disclosure would prejudice an investigation or security measure or another overriding interest applies. ICEQC records the assessment, material facts and remedial action whether or not external notification is legally required.

22. Rights of individuals

Subject to the law governing the relevant processing, a person may request confirmation of whether ICEQC processes personal data about them and access to that data and the prescribed supplementary information. A person may also request correction of inaccurate data, deletion or destruction of data processed unlawfully or no longer justified, cessation of or objection to particular processing, restriction where available, release or transfer of data in a commonly used electronic format where the statutory conditions are met, and withdrawal of consent for future processing.

Rights are not absolute. ICEQC may refuse, restrict or defer a request where a formal law or overriding interest permits, including the rights of another person, protected confidential material, the integrity and independence of an assessment or appeal, legal privilege, prevention of fraud, system security, a legal obligation, an active claim or a manifestly unfounded or abusive request. ICEQC does not use a limitation more broadly than necessary and gives the reason where required by law.

Correction or deletion of a personal data item does not require ICEQC to alter a substantiated conformity finding, decision or historical event. Where the accuracy of a contested item cannot be established, ICEQC may mark the item as disputed if the applicable law so provides while preserving the decision record.

23. How to exercise a right

A request should be sent to contact@iceqc.org with the subject ‘Data protection request’ or by post to the registered office. It should identify the person, the relevant account, organisation, application, certificate or communication, and the right being exercised. Do not send a full identity document in the initial email. ICEQC may request proportionate proof of identity or authority and will use it only to verify the request.

Under the FADP, access information is in principle provided free of charge within 30 days. If it cannot be provided within that period, ICEQC will state when it will be provided. A fee may be requested only where permitted by law, including where responding requires disproportionate effort; the requester will be informed in advance. Time limits and fee rules under another applicable regime apply where they govern the request.

ICEQC may need to consult an applicant, certificate holder, provider or other person before deciding a request that concerns their rights or confidential information. That consultation does not transfer responsibility for ICEQC’s decision on the request.

24. Complaints and supervisory authorities

A person who believes that ICEQC has handled personal data improperly may submit a written privacy complaint to contact@iceqc.org. The complaint should identify the processing in question, the reason for concern and the remedy sought. ICEQC will assign the matter outside the directly challenged function where necessary for a fair review and may ask for information needed to investigate.

A person may contact the Swiss Federal Data Protection and Information Commissioner or another supervisory authority competent for the processing. Contacting ICEQC first may allow prompt correction but is not a condition of approaching a competent authority or court. The availability and form of a remedy are determined by applicable law.

25. Data supplied by an applicant about other persons

An applicant or certificate holder commonly acts as the immediate source of personal data contained in governance records, staffing evidence, interview lists, complaints information and samples selected for assessment. The organisation remains responsible for determining that it may lawfully disclose that information to ICEQC, for giving an affected person any notice required by law and for respecting duties owed under employment, education, safeguarding, professional-secrecy and confidentiality rules. Acceptance of a file by the application centre is not confirmation that the disclosure was lawful or necessary.

Before submission, the organisation must identify the requirement being evidenced and remove names, signatures, contact details, identifiers and narrative detail that do not contribute to that requirement. Where a sample must remain person-specific, the organisation should use a coded reference and retain the key unless ICEQC expressly requires identity for verification. ICEQC may ask the organisation to explain the source, authority, notice, redaction and protective measures applicable to a submission and may require replacement evidence where those matters are not adequately established.

If an individual contacts ICEQC about information supplied by an organisation, ICEQC will determine its own obligations as controller for the copy and assessment record it holds. It may consult the supplying organisation where necessary to verify facts or protect its rights, but the organisation cannot direct ICEQC to disregard a valid data-subject request. Conversely, ICEQC will not disclose the organisation’s confidential assessment material merely because it contains the requester’s name where a lawful restriction applies.

26. Personnel, assessor, expert and supplier records

ICEQC may process professional and administrative information concerning employees, independent assessors, technical experts, committee participants, interpreters, contractors, suppliers and prospective appointees. Depending on the role, this may include identity and contact information, curriculum vitae, qualifications, experience, languages, availability, fee and banking details, tax and invoicing information, references, screening results, training and competence records, assigned work, performance and quality records, declarations of confidentiality and impartiality, actual or potential conflicts, recusals, complaints and correspondence.

The purposes are to evaluate competence and suitability, make and administer appointments, allocate work, protect impartiality, arrange access and accessibility support, pay properly rendered invoices, monitor performance, investigate concerns and demonstrate that certification functions were carried out by authorised and competent persons. A conflict declaration may necessarily identify an applicant, former employer, financial interest or professional relationship; access is confined to those who need the information to determine and manage the conflict.

Unsuccessful expressions of interest and superseded appointment records are not kept indefinitely. Retention is determined by the recruitment or appointment purpose, applicable limitation periods, accounting duties and the need to demonstrate competence and impartiality for work actually performed. Information that forms part of a completed assessment, decision or appeal record is retained with that controlled record even after the individual’s appointment ends.

27. Communications, events, research and public consultation

When ICEQC administers a standards consultation, briefing, meeting, webinar, research activity or sector engagement, it may process registration details, organisational affiliation, accessibility and dietary requirements, attendance, contributions, questions, correspondence, recordings where notified, and publication preferences. The collection notice for the activity will state whether names or submissions are intended for publication, whether a recording will be made and any material terms that differ from this general Notice.

A contribution is not attributed publicly merely because it was made during a consultation. ICEQC distinguishes between a published organisational response, a comment submitted for analysis without attribution and a confidential submission. Where consultation results are reported, ICEQC may aggregate or paraphrase contributions to explain the evidence considered. Confidential treatment cannot be promised where disclosure is required by law, necessary for procedural fairness or incompatible with the contributor’s chosen public submission method.

Research outputs are prepared from information that is aggregated, de-identified or otherwise lawfully usable for the stated purpose. De-identification is assessed in context and is not treated as effective merely because direct identifiers were removed. ICEQC does not publish a small cell, quotation or combination of characteristics where it reasonably permits an individual to be re-identified without an adequate justification and protective measure.

28. Direct communications and communication preferences

ICEQC sends messages necessary to administer an enquiry, account, application, agreement, invoice, assessment, certificate, surveillance activity, complaint, appeal, consultation registration or security event. Those communications are part of the requested or existing relationship and may contain deadlines, evidence requests, status information or protective instructions. A recipient cannot opt out of a necessary service or legal communication while retaining the affected service, but may ask that an obsolete address be corrected or an unauthorised contact be removed after authority is reviewed.

Newsletters, event announcements and other optional sector communications are sent only on a lawful basis and include the withdrawal mechanism required by applicable law. Withdrawing from optional communications does not suppress operational messages. ICEQC records the preference, address, source and time needed to honour a subscription or objection and may retain a minimal suppression record so that an address that opted out is not inadvertently re-added.

Recipients must not send credentials, full payment-card data, unrestricted learner records or confidential certification evidence in reply to a general communication. ICEQC may redirect the exchange to an authorised channel and remove unnecessary attachments from ordinary correspondence where operationally and legally practicable.

29. Joint activities and allocation of controller responsibility

A joint project with an authority, standards body, research partner or other organisation does not automatically make every participant a joint controller. ICEQC determines the role of each party from the purposes, decision-making authority, instructions and actual data flows. Where two parties jointly determine purposes and essential means, they will allocate their respective responsibilities in a transparent arrangement as required by applicable law, including responsibility for notices, rights requests, security and breach coordination.

Where ICEQC processes personal data solely on documented instructions for another controller, the governing instrument defines the subject matter, duration, nature, purpose, data types, affected persons and required safeguards. ICEQC will not describe itself as a processor where it independently determines a certification, complaint, register, security or legal purpose. The same organisation may have different roles for different processing operations.

A person may request the essence of an applicable joint-controller allocation or identify the party from which a right may most effectively be exercised. An internal allocation does not deprive the person of a right against a controller that applicable law makes responsible.

30. Processor selection, instructions and subprocessing

Before entrusting personal data to a processor, ICEQC considers the service purpose, categories and volume of data, access model, security and continuity measures, processing locations, subprocessor governance, deletion and return capability, assistance with rights and incidents, and evidence of relevant assurance. The contract restricts processing to documented purposes and instructions, requires confidentiality and appropriate security, regulates subprocessing and international transfers, and provides for information or assurance needed to supervise compliance.

ICEQC does not require a provider to disclose security information in a manner that would weaken the service or expose another customer’s confidential material. Assurance may therefore consist of contractual commitments, independent reports, certifications, technical documentation, incident records and targeted enquiries proportionate to risk. A material deficiency is subject to remediation, restriction, alternative safeguards or replacement according to severity and feasibility.

Provider and subprocessor lists change as services, infrastructure and support arrangements develop. The principal providers relevant to current public, portal and payment functions are identified in this Notice. More specific information may be provided for a request where disclosure is lawful and does not compromise security or third-party rights. A provider change that materially alters risk or requires a new choice is assessed before the changed processing begins.

31. International-transfer assessment and supplementary safeguards

For a restricted international disclosure, ICEQC identifies the exporter, recipient, roles, data, purposes, systems, onward transfers and countries in which access may occur. It then determines whether an adequacy decision applies or whether a recognised contractual safeguard, binding rule, statutory exception or other permitted mechanism is required. A contractual document is not treated as sufficient in isolation where the circumstances indicate that supplementary technical or organisational measures are necessary.

The assessment may consider encryption and key control, pseudonymisation, data minimisation, role and location restrictions, challenge and transparency practices, government-access law, practical access experience, onward-transfer controls and the ability to suspend or terminate the transfer. Exceptions intended for occasional and necessary transfers are not used to legitimise systematic processing that should be protected by an enduring mechanism.

A copy or meaningful description of the safeguard relevant to a person’s data may be requested through contact@iceqc.org. ICEQC may redact commercial terms, security details and information concerning other persons, but will not withhold the information necessary to understand the nature of the safeguard where disclosure is required by law.

32. Accuracy, provenance and contested information

ICEQC takes reasonable steps to ensure that personal data used for a material administrative or certification purpose is accurate, complete and sufficiently current for that purpose. The reliability expected of a contact address is different from the reliability required of an identity, authority, conflict or disciplinary fact. Verification is therefore proportionate to consequence and may include confirmation with the source, an official register, contemporaneous evidence or the affected person.

Assessment and decision records distinguish, where material, between information asserted by an applicant, information obtained from another source, professional evaluation and a formally established fact. A later correction does not erase the fact that particular information was presented and considered at an earlier date. ICEQC preserves an attributable amendment trail where silent replacement would compromise auditability, procedural fairness or the historical accuracy of the file.

Where information is contested and cannot promptly be resolved, ICEQC may restrict reliance, record the competing position, seek corroboration or defer the affected determination. A dispute marker is not an acceptance that the information is false and must not be used as a substitute for completing an investigation that the applicable procedure requires.

33. Privacy by design, default settings and change control

New forms, workflows, registers, integrations and evidence routes are designed to collect the minimum personal data reasonably required for their defined functions. Default visibility is limited to the audience necessary for the service; publication, optional measurement and external sharing are not enabled merely because a platform supports them. Field definitions, access roles, retention events, export functions and administrative logs are considered before release rather than added only after a complaint.

A material change is reviewed for purpose compatibility, lawful basis or justification, transparency, affected persons, data volume and sensitivity, automated effects, access, transfers, providers, security, retention, deletion and the means by which rights can be exercised. Testing uses synthetic or appropriately protected data wherever practicable. Production personal data is not copied into an unrestricted development environment for convenience.

Where Swiss law requires a data-protection impact assessment because planned processing is likely to present a high risk, ICEQC documents the proposed processing, necessity, proportionality, risks and measures. Residual high risk is handled in accordance with the required consultation process. Completion of an assessment does not by itself authorise processing that would otherwise be unlawful.

34. Requests involving legal privilege, confidentiality and other persons

An access, portability, correction or deletion request may encompass a record containing information about several people, confidential institutional evidence, deliberative assessment material or legal advice. ICEQC considers whether information can be separated, redacted, summarised or provided through a controlled inspection without unjustifiably impairing the requester’s right. It does not apply a blanket refusal merely because a document also concerns an organisation or another person.

ICEQC may withhold or limit material where disclosure would reveal another person’s personal data without justification, breach protected professional secrecy, prejudice a live fraud or security investigation, undermine an assessment or appeal that requires confidential deliberation, or disclose legally privileged advice. Any restriction is applied to the affected information and purpose, not automatically to the entire file, and a reason is given where required and lawful.

A requester is not entitled through a privacy request to obtain an applicant’s complete certification file, the identity of a confidential source in every circumstance, or intellectual property belonging to another person. Separate complaint, appeal, disclosure or evidential procedures may provide a more appropriate route and may carry different tests.

35. Erasure, restriction and integrity of official records

When a valid erasure or destruction ground applies, ICEQC deletes or irreversibly de-identifies the affected personal data from active systems and instructs relevant processors as required. Erasure may be refused or deferred to the extent retention remains necessary for a legal obligation, legal claims, protected archiving, fraud prevention, certificate authentication, public-register integrity, procedural fairness or another overriding lawful purpose. The retained information is limited and access restricted to that continuing purpose.

Restriction may be used while accuracy, objection, lawfulness or the appropriate remedy is being determined. Restricted data remains protected and is not used for the disputed operational purpose except where law permits, including with consent, for legal claims or to protect another person. ICEQC informs the requester before lifting a restriction where applicable law requires that notice.

A public certificate history is not a personal profile. Nevertheless, if a register entry identifies a sole trader, named representative or other natural person, ICEQC considers the person’s rights together with the need to prevent false reliance on a certificate. A correction normally preserves the former status and date while making the accurate current position conspicuous.

36. Accountability, records and independent review

ICEQC maintains records appropriate to the processing for which it is responsible, which may include purposes, data categories, affected persons, recipients, transfers, retention, security measures, consent or preference evidence, processor arrangements, rights requests, breaches and impact assessments. The level of detail reflects the activity and legal requirement. An internal record is evidence of governance, not a substitute for complying with the underlying obligation.

Material privacy decisions are assigned to an authorised function and escalated where they involve high risk, a conflict, a contested disclosure, a significant incident or an interpretation capable of affecting multiple persons. Legal, security and operational advice may be obtained, while responsibility for the controller decision remains with ICEQC. A person who made or materially participated in a challenged operational decision will not be the sole reviewer of the resulting privacy complaint where separation is reasonably required for fairness.

ICEQC periodically reviews access, provider assurance, retention events, public disclosures and recurring request or incident themes. Findings are documented and prioritised according to risk. Audit and review material is itself protected because unrestricted disclosure could reveal personal data, confidential assessment methods or security controls.

37. Changes, language and document control

ICEQC reviews this Notice when processing activities, providers, systems, certification procedures or legal requirements materially change. A revised Notice states its effective date. A change that materially affects an existing choice or requires new consent will be brought to the affected person’s attention through an appropriate service notice or renewed control before the changed optional processing begins.

The English version is the authoritative version of this Notice. Translations are provided for access and must not reduce a mandatory right. If a translation differs from the English version, the English version governs to the extent permitted by applicable law.

A superseded notice may remain available where needed to establish the terms that applied to an earlier collection or event. The effective date identifies the operative public version; it does not imply that every record is governed only by the law or technology existing on that date. Material processing is assessed under the law applicable when it occurs.