Personal Data Processing Policy
Global Alliance Register is committed to protecting the privacy, confidentiality and security of personal data entrusted to us through our testing, inspection, certification, conformity assessment, verification, audit, technical assurance, consultancy, training and related professional activities.
This Personal Data Processing Policy explains how Global Alliance Register (“GAR”, “we”, “our” or “us”) collects, uses, stores, shares, transfers and protects personal data in connection with its international operations, professional services and digital platforms.
GAR seeks to process personal data lawfully, fairly, transparently and proportionately, taking account of applicable data-protection and privacy laws in the jurisdictions where we operate or deliver services.
Review how GAR handles personal data across its international TIC, professional-services and digital activities.
Scope & Application
This Policy applies to personal data processed by GAR in connection with its professional activities, business relationships, websites, digital services, events, recruitment, contracting, supplier management and regulatory or accreditation responsibilities.
It may apply to personal data relating to clients, applicants, certificate holders, employees of clients, suppliers, subcontractors, inspectors, auditors, consultants, candidates, website users, business contacts and other individuals interacting with GAR.
Roles & Responsibilities
Depending on the nature of the activity, GAR may act as an independent data controller, joint controller, data processor or service provider.
Controller
GAR determines the purposes and essential means of processing personal data for its own business, legal, certification, accreditation and governance activities.
Processor / Service Provider
GAR may process personal data on behalf of a Client where the Client determines the primary purposes and means of processing.
Independent TIC Body
Certain inspection, certification or conformity-assessment activities may require GAR or a Network Resource to determine independently what records must be retained.
Network Delivery
GAR may coordinate competent laboratories, inspection bodies, certification bodies, auditors and specialists subject to appropriate confidentiality and data-protection controls.
Personal Data We May Process
| Category | Examples |
|---|---|
| Identification Data | Name, title, signature, identification reference and professional credentials. |
| Contact Data | Email address, telephone number, postal address and business contact details. |
| Professional Data | Employer, role, department, qualifications, licences, competence and experience. |
| Service & Contract Data | Applications, quotations, orders, project records, correspondence and service history. |
| Certification & Audit Data | Audit evidence, competence records, findings, corrective actions and certification records. |
| Financial Data | Billing information, payment references, tax records and transaction information. |
| Technical & Operational Data | Site records, inspection notes, test records, photographs, technical documents and equipment information. |
| Digital Data | IP address, browser data, device data, website usage and security logs. |
| Communication Data | Emails, enquiries, complaints, requests and other communications with GAR. |
How We Obtain Personal Data
GAR may receive personal data directly from individuals or indirectly through organizations involved in a service, project, certification activity or commercial relationship.
Why GAR Processes Personal Data
Personal data may be processed where reasonably necessary for GAR to establish, manage and deliver professional services and maintain effective business and regulatory relationships.
Service Delivery
Managing testing, inspection, certification, audit, verification, consultancy, training and related services.
Certification Administration
Managing applications, audits, certification decisions, surveillance, reassessment and certificate records.
Client & Supplier Management
Managing contracts, quotations, orders, suppliers, subcontractors and commercial relationships.
Legal & Regulatory Compliance
Meeting obligations arising from law, accreditation, certification schemes and competent authorities.
Quality & Integrity
Managing competence, complaints, appeals, impartiality, security, risk and quality-control processes.
Business Communication
Responding to enquiries and providing appropriate corporate, technical and service information.
Legal Bases for Processing
The legal basis applicable to a particular processing activity depends on the jurisdiction, the relationship with the individual and the purpose for which the information is required.
Testing, Inspection, Certification & Audit Records
TIC activities may involve personal data contained in technical, operational, competence, audit or certification evidence.
Such records may need to be retained to demonstrate the integrity, traceability, competence and defensibility of GAR’s professional conclusions and certification decisions.
Access to technical and certification records is restricted according to professional need, confidentiality obligations and applicable accreditation or legal requirements.
↑ Back to Policy GuideSensitive & Special Categories of Personal Data
GAR generally seeks to avoid collecting sensitive or special-category personal data unless it is genuinely necessary for a legitimate and lawful purpose.
Where such data is processed, GAR applies additional safeguards appropriate to the sensitivity of the information and the applicable legal framework.
Examples may include health-and-safety information necessary for site access or emergency response, disability-related information reasonably required for accessibility, or other protected information that GAR is legally required or expressly authorized to process.
↑ Back to Policy GuideSharing Personal Data
GAR does not disclose personal data indiscriminately. Personal data may be shared where reasonably necessary for legitimate service, operational, legal or professional purposes.
GAR Personnel
Authorized personnel requiring access for legitimate business or professional purposes.
Network Resources
Laboratories, inspection bodies, certification bodies, auditors, consultants and technical specialists.
Service Providers
IT, hosting, communications, accounting, legal and other professional service providers.
Regulatory & Accreditation Bodies
Competent authorities, accreditation bodies, scheme owners and regulators where disclosure is required or appropriate.
GAR seeks to ensure that recipients receive only the information reasonably necessary for the purpose concerned and are subject to appropriate confidentiality or legal obligations.
↑ Back to Policy GuideInternational Transfers
GAR operates internationally and may need to transfer personal data between countries in order to coordinate services, laboratories, inspectors, auditors, certification resources, Clients and support functions.
Where applicable data-protection law imposes restrictions on international transfers, GAR seeks to use an appropriate transfer mechanism or other legally recognized safeguard.
Retention & Disposal
GAR retains personal data for no longer than reasonably necessary for the purposes for which it was collected, subject to applicable legal, regulatory, contractual, accreditation and certification requirements.
Retention periods may differ according to the nature of the information and the activity concerned.
Once information is no longer required, GAR seeks to delete, destroy, anonymize or otherwise render it inaccessible in an appropriate manner.
↑ Back to Policy GuideSecurity & Confidentiality Controls
GAR applies technical and organizational safeguards designed to protect personal data against unauthorized access, unlawful disclosure, alteration, accidental loss or inappropriate destruction.
Access Control
Restricting access according to role, authorization and legitimate need.
Technical Protection
Appropriate system security, authentication, monitoring and backup controls.
Confidentiality
Contractual and professional confidentiality obligations for relevant personnel and service providers.
No information system can be guaranteed completely secure. GAR therefore reviews its safeguards periodically and adapts them according to reasonably foreseeable risks and technological developments.
↑ Back to Policy GuideData Subject Rights
Depending on applicable law, individuals may have rights concerning the personal data GAR holds about them.
Website, Cookies & Digital Communications
GAR websites and digital services may process technical information necessary to operate, secure and improve online services.
This may include IP addresses, device information, browser information, security logs and website usage information.
Where GAR uses cookies or similar technologies that require consent under applicable law, appropriate consent-management mechanisms should be used.
Marketing or informational communications are managed according to applicable legal requirements, and recipients may normally opt out of non-essential marketing communications.
↑ Back to Policy GuideChildren & Minors
GAR’s professional services are primarily directed toward businesses, organizations and adult professionals rather than children.
GAR does not knowingly seek to collect personal data from children through its general corporate services unless there is a legitimate, lawful and appropriately safeguarded reason to do so.
Where information concerning minors is processed, GAR seeks to apply safeguards appropriate to the circumstances and applicable law.
↑ Back to Policy GuideAutomated Processing, Artificial Intelligence & Profiling
GAR may use digital tools, automation or artificial-intelligence-enabled technologies to support administrative, analytical, technical or operational activities.
Where automated processing has legal or similarly significant effects on individuals, GAR seeks to comply with applicable requirements concerning transparency, human oversight, fairness and challenge rights.
Complaints & Supervisory Authorities
Individuals who have concerns about GAR’s handling of personal data are encouraged to raise the matter with GAR so that it can be reviewed and, where appropriate, resolved.
Depending on applicable law, individuals may also have the right to make a complaint to an appropriate data-protection or privacy supervisory authority.
GAR seeks to cooperate appropriately with competent authorities and to address substantiated privacy concerns in accordance with applicable law.
↑ Back to Policy GuidePolicy Updates & Contact
Policy Updates
GAR may update this Policy periodically to reflect changes in legal, regulatory, accreditation, technological or operational requirements.
The revision date displayed at the beginning of this Policy indicates when the published version was most recently updated.
Global Alliance Register
Privacy-related questions, requests or concerns may be submitted to GAR through its official contact channels.
Where a request concerns a specific certification body, inspection body, laboratory or GAR Network Resource, the request may be referred to the organization legally responsible for the relevant processing activity.
Trust Requires Responsible Stewardship of Information
Global Alliance Register recognizes that personal data may form part of technical, commercial, certification and professional records entrusted to us through international TIC activities. We seek to process that information lawfully, transparently and securely while preserving the confidentiality, independence and professional integrity expected of a Testing, Inspection and Certification organization.