- Search BSI
- Verify a Certificate
Privacy Notice - General users and clients
Privacy Notice – Committee Members (BSI Documents)
Privacy Notice – Job applicants
½ûÂþÌìÌà (ICO registration Z7888292) (“BSI”) takes your privacy very seriously. This Privacy Notice is intended to set out your rights and answer any queries you may have about your personal data. If you need more information, please contact: PrivacyTeam@bsigroup.com
If you have entered into a contract with one of our subsidiaries or group companies, the controller of your data will be the BSI company or companies stated in your contract (BSI Standards Limited (ICO registration ZA342039), BSI Assurance UK Limited (ICO registration ZA341951) and/or BSI Digital Trust (UK) Limited (ICO registration Z1767162)) and/or the BSI company to which you provide any additional consent. In all other circumstances, the controller of your data will be ½ûÂþÌìÌÃ.
Our personal data handling policy and procedures have been developed in line with the data protection laws that apply to us in the countries in which we offer our goods and services, in particular the EU General Data Protection Regulation ((EU) 2016/679) (the “EU GDPR”) and the UK General Data Protection Regulation which reflects the retained and amended provisions of the EU GDPR that are incorporated into UK law under the UK European Union (Withdrawal) Act 2018 as amended (the “UK GDPR”), as these laws establish the most expansive data protection obligations.
We collect and process personal data about you when you interact with us and our products and when you purchase goods and services from us. The personal data we process includes:
We process the personal data listed in paragraph 1 above for the following purposes:
We may also send you direct marketing in relation to BSI’s relevant products and services. Electronic direct marketing will only be sent where you have given your consent to receive it, or (where this is allowed) you have been given an opportunity to opt out. We will not send you direct marketing of third-party products or services although our own products or services may on occasion include cooperation with third parties. You will continue to be able to opt out of electronic direct marketing at any time by following the instructions in the relevant communication.
We may share your personal data with our subsidiaries to process it for the purposes of inter-group administration and to deliver products or services where elements of these are provided by BSI group companies other than those with which you have directly contracted.
We may also share your personal data with the below third parties:
Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws. Personal data may also be shared with third-party service providers who will process it on behalf of BSI for the purposes above. Such third parties include but are not limited to, providers of website hosting, maintenance, call centre operation and identity checking.
In the event that our business or any part of it is sold or integrated with another business, your details will be disclosed to our advisers and those of any prospective purchaser and will be passed to the new owners of the business.
We will not keep your personal data for any purpose longer than necessary to fulfil the original or a compatible purpose. In some instances, we are required to retain certain information by law or due to our role as the National Standards Body, and for as long as reasonably necessary to meet regulatory or accreditation requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions. Where this is the case, your personal data will only be processed for the relevant legitimate purpose and not used for marketing.
Where you are a customer, we will keep your personal data for the length of any contractual relationship you have with us and after that for a period of up to 3 years unless you are a customer purchasing Standards in which event we will keep your information for up to 5 years in line with the Standards lifecycle.
Where you are a prospective customer and you have expressly consented to us contacting you, we will only retain your personal data for this purpose (a) until you unsubscribe from our communications; or, if you have not unsubscribed, (b) while you interact with us and our content; or (c) for 2 years from when you last interacted with us or our content.
In the case of any contact you may have with our customer services team, we will retain your details for as long as is necessary to resolve your query and for two weeks after the query is closed.
We may retain your personal data for a time beyond the specified retention period, to allow for information to be reviewed and any deletion to take place. After it is no longer necessary for us to retain your personal data, we dispose of it securely according to our Document & Information Retention Policy.
The personal data that we collect from you may be transferred to, and stored outside, the United Kingdom or the European Economic Area (“EEA”). It may also be processed by staff operating outside the United Kingdom or EEA who work for us or for one of our suppliers, in which case the third country's data protection laws will have been approved as adequate by the European Commission, the UK’s Information Commissioner's Office, or other applicable safeguards will be in place. Further information may be obtained from our Privacy Team.
You have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data, clicking the unsubscribe button on any communication we have sent to you or by contacting us.
Where you have consented to us using your personal data, you can withdraw that consent at any time.
If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.
You also have the right, with some exceptions and qualifications, to ask us to provide a copy of any personal data we hold about you.
Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine-readable format.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved. In some circumstances you can ask us to erase your personal data (a) by withdrawing your consent for us to use it; (b) if it is no longer necessary for us to use your personal data; (c) if you object to the use of your personal data and we don't have a good reason to continue to use it; or (d) if we haven't handled your personal data in accordance with our obligations.
Should you have any queries regarding this Privacy Notice, about BSI's processing of your personal data or wish to exercise your rights you can contact BSI’s Privacy Team using this email address: PrivacyTeam@bsigroup.com.
If you are not happy with our response, if you are based:
in the United Kingdom, you can contact the Information Commissioner's Office ;
in the EEA, you can contact the Dutch Data Protection Authority, which is our lead supervisory authority in the European Union ;
anywhere else, you have the right to lodge your complaint with the relevant data protection regulator in the country where you are located.
½ûÂþÌìÌà (ICO registration Z7888292) (“BSI”) takes your privacy very seriously. This Privacy Notice is intended to set out your rights and answer any queries you may have about your personal data. If you need more information, please contact:
The controller of your data will be ½ûÂþÌìÌÃ. In addition to BSI, the International Organization for Standardization (the “ISO”) will also be a controller of your personal data to facilitate your use of our Committee Member communication and document distribution system (BSI Documents).
Our personal information handling policy and procedures have been developed in line with the data protection laws that apply to us in the countries in which we offer our goods and services, in particular the EU General Data Protection Regulation ((EU) 2016/679) (the “EU GDPR”) and the UK General Data Protection Regulation which reflects the retained and amended provisions of the EU GDPR that are incorporated into UK law under the UK European Union (Withdrawal) Act 2018 as amended (the “UK GDPR”), as these laws establish the most expansive data protection obligations.
ISO’s data protection policy that describes how it collects, uses, stores, and shares your data will be communicated to you when you register to use BSI Documents. If you do not agree with the ISO’s policies, you should not access or use BSI Documents. We are not responsible for the ISO’s policies or actions.
We collect and process personal data about you when (a) you and/or your nominating organization contacts us to add you as a member of a Committee; (b) you register with BSI Documents; and (c) you attend Committee meetings. The personal data we process includes:
We process the personal data listed in paragraph 1 above for the following purposes:
We may also send you direct marketing in relation to relevant products and services. Electronic direct marketing will only be sent where you have given your express consent to receive it, or (where this is allowed) you have been given an opportunity to opt out. You will continue to be able to opt out of electronic direct marketing at any time by following the instructions in the relevant communication.
As described above, as the host and systems provider of BSI Documents, your personal data is shared with the ISO to facilitate your use of BSI Documents and associated features and functions such as the ISO Global Directory.
We may share your personal data with our subsidiaries to process it for the purposes of inter-group administration and to deliver products or services where elements of these are provided by group companies other than those with which you have directly contracted.
We may also share your personal data with the below third parties:
Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws. Personal data may also be shared with third-party service providers and business partners who will process it on behalf of BSI for the purposes above. Such third parties include but are not limited to, providers of website hosting, maintenance, call centre operation and identity checking.
In the event that our business or any part of it is sold or integrated with another business, your details will be disclosed to our advisers and those of any prospective purchaser and will be passed to the new owners of the business.
We will not keep your personal information for any purpose for longer than is necessary and will only retain the personal information that is necessary in relation to the purpose. We are also required to retain certain information by law or if it is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.
Where you are a Committee Member, we will keep your personal data for the lifecycle of the Committee. Beyond that, we will retain your name (though not your other details) indefinitely for the purpose of evidencing the constitution of the Committee and the transparency of the Standards development process.
Where you are a Consumer & Public Interest Network Representative, we will retain your data for the period that you hold that function.
We will retain your data for a short time beyond the specified retention period, to allow for information to be reviewed and any deletion to take place. In some instances, laws may require BSI to hold certain information for specific periods other than those listed above.
The personal data that we collect from you may be transferred to and stored outside the United Kingdom or the European Economic Area (“EEA”). It may also be processed by staff operating outside the United Kingdom or the EEA who work for us or for one of our suppliers, in which case the third country's data protection laws will have been approved as adequate by the European Commission, the UK’s Information Commissioner’s Office or other applicable safeguards are in place. Further information may be obtained from our Privacy Team.
You have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data, clicking the unsubscribe button on any communication we have sent to you or by contacting us.
Where you have consented to us using your personal data, you can withdraw that consent at any time. If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it. You also have the right, with some exceptions, to ask us to provide a copy of any personal data we hold about you.
Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine-readable format.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved. In some circumstances you can ask us to erase your personal data (a) by withdrawing your consent for us to use it; (b) if it is no longer necessary for us to use your personal data; (c) if you object to the use of your personal data and we don't have a good reason to continue to use it; or (d) if we haven't handled your personal data in accordance with our obligations.
Should you have any queries regarding this Privacy Notice, about BSI's processing of your personal data or wish to exercise your rights you can contact BSI’s Privacy Team using this email address: PrivacyTeam@bsigroup.com.
If you are not happy with our response, if you are based:
in the United Kingdom, you can contact the Information Commissioner's Office ;
in the EEA, you can contact the Dutch Data Protection Authority, which is our lead supervisory authority in the European Union ;
anywhere else, you have the right to lodge your complaint with the relevant data protection regulator in the country where you are located.
½ûÂþÌìÌà (ICO registration Z7888292) (“BSI”) takes your privacy very seriously. This Privacy Notice is intended to set out your rights and answer any queries you may have about how BSI collects and uses your personal data. If you need more information, please contact: PrivacyTeam@bsigroup.com
Unless we inform you otherwise during the recruitment process, BSI will be your data controller and will be the company to which you provide your consent for the processing of your personal data.
Our personal information handling policy and procedures have been developed in line with the data protection laws that apply to us in the countries in which we offer our goods and services, in particular the EU General Data Protection Regulation ((EU) 2016/679) (the “EU GDPR”) and the UK General Data Protection Regulation which reflects the retained and amended provisions of the EU GDPR that are incorporated into UK law under the UK European Union (Withdrawal) Act 2018 as amended (the “UK GDPR”), as these laws establish the most expansive data protection obligations.
We collect and process personal data about you when you apply for a job with us.
The personal data we process includes:
We obtain this information directly from you, our personnel, through our systems and equipment, as well as from third parties such as recruitment agencies, background-checking companies or former employers. We may also obtain it from your public profiles available online.
We process the personal data listed in paragraph 1 above for the following purposes only in accordance with our legitimate interests:
We may share your personal data for the purposes of intra-group administration. We may also share your personal data with our professional advisors such as our auditors and external legal and financial advisors.
Personal data may be shared with government authorities and/or law enforcement officials if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws. Personal data may also be shared with third-party service providers who will process it on behalf of BSI for the purposes above. In the event that any part of our business is sold or integrated with another business, your details may be disclosed to our advisors and those of any prospective purchaser and would be passed to the new owners of the business.
We will not keep your personal information for longer than is necessary and will only retain the personal information that is necessary to fulfil the purpose. We are also required to retain certain information by law or if it is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.
We will keep the personal data connected to your job application (including any interview records) for 6 months from the date of their creation by BSI or receipt from you. If your application is successful and you become a member of staff we will provide you with a copy of the Staff Privacy Notice. The retention periods referred to therein will apply to your personal data during your employment.
The personal data that we collect from you may be transferred to, and stored outside the United Kingdom or the European Economic Area (“EEA”). It may also be processed by staff operating outside the United Kingdom or EEA who work for us or for one of our suppliers, in which case the other country's data protection laws will have been approved as adequate by the European Commission, the UK’s Information Commissioner's Office, or other applicable safeguards are in place. Further information may be obtained from our Privacy Team.
Where you have consented to us using your personal data, you can withdraw that consent at any time.
If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.
You also have the right, with some exceptions, to ask us to provide a copy of any personal data we hold about you.
Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine-readable format.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved. In some circumstances you can ask us to erase your personal data (a) by withdrawing your consent for us to use it; (b) if it is no longer necessary for us to use your personal data; (c) you object to the use of your personal data and we don't have a good reason to continue to use it; or (d) we haven't handled your personal data in accordance with our obligations.
Should you have any queries regarding this Privacy Notice, about BSI's processing of your personal data or wish to exercise your rights you can contact BSI’s Privacy Team using this email address: PrivacyTeam@bsigroup.com.
If you are not happy with our response, if you are based:
in the United Kingdom, you can contact the Information Commissioner's Office ;
in the EEA, you can contact the Dutch Data Protection Authority, which is our lead supervisory authority in the European Union ;
anywhere else, you have the right to lodge your complaint with the relevant data protection regulator in the country where you are located.
Issue Date: July 2020
Reach out and see how we can help guide you on your path to sustainable operational success.