Privacy Notice

The IASME Consortium Privacy Notice

This notice explains how The IASME Consortium Limited uses personal information: what we hold, where it comes from, why we use it, who we share it with, how long we keep it, and your rights.

Who we are

The IASME Consortium Limited (“IASME”, “we”, “us”) is a company registered in England and Wales 07897132. We are the controller for the personal information described in this notice, except where we say otherwise.

We operate certification, accreditation, assurance, training, consulting and technology services. Some services are IASME services. Where another organisation owns a scheme or service, that organisation may be the controller and IASME may operate the scheme or service on its behalf. In some services, including UK Cyber Security Council professional registration, controller responsibilities are divided. IASME is the controller for IASME-owned schemes and services, except where we say otherwise.

We run or support the following services and schemes:

Services and schemes run or supported by IASME
Service Owner or associated organisation Description
CAA ASSURE Civil Aviation Authority Certification scheme; the Civil Aviation Authority is the controller and IASME operates the scheme on its behalf.
Cyber Essentials and Cyber Essentials Plus National Cyber Security Centre (NCSC) Certification schemes; NCSC is the controller and IASME operates the schemes on NCSC’s behalf.
NCSC Cyber Incident Exercising Assured Service Provider NCSC Accreditation and assurance of people and organisations; NCSC is the controller and IASME operates the service on NCSC’s behalf.
NCSC Cyber Incident Response Standard Level Service Provider NCSC Accreditation and assurance of people and organisations; NCSC is the controller and IASME operates the service on NCSC’s behalf.
NCSC Assured Cyber Advisors NCSC Accreditation and assurance service; NCSC is the controller and IASME operates the service on NCSC’s behalf.
Defence Cyber Certification (DCC) Ministry of Defence (MoD) Certification scheme; the Ministry of Defence is the controller and IASME operates the scheme on its behalf.
IASME Cyber Assurance (ICA) IASME Certification scheme. IASME is the operator and controller.
IASME Cyber Baseline IASME Certification scheme. IASME is the operator and controller.
IoT Cyber Baseline IASME Certification scheme. IASME is the operator and controller.
Maritime Cyber Baseline IASME Certification scheme. IASME is the operator and controller.
UK Cyber Security Council professional registration UK Cyber Security Council (UKCSC) IASME is the controller for assessment and onboarding. UKCSC is the controller for the Register, assessment advice and audit information, as described below.
Training and consulting IASME Courses and consulting services. IASME is the operator and controller.
Branded assessment portals and Pervade API access IASME / Certification Bodies Portal creation and API access. IASME is the operator and controller.
Supplier Assurance Tool, certificate search and jobs board IASME Technology and public-facing services. IASME is the operator and controller.

We also assure Certification Bodies, Assured Service Providers, Cyber Essentials assessors, Cyber Advisors, Enterprise Assessors and other people or organisations involved in the services above.

Where another organisation owns a scheme or service, that organisation may be the controller and IASME may operate the scheme or service on its behalf. In some services, controller responsibilities are divided. IASME is the controller for IASME-owned schemes and services. The relevant position is stated in the section for each service.

The short version

  • We use personal information mainly to run our certification schemes: to assess and certify organisations, assure individuals, issue and publish certificates, assure Cyber Essentials assessors, Cyber Advisors (Cyber Essentials) and Enterprise Assessors, and work with our Certification Bodies and Assured Service Providers. We also use it to provide training and the Supplier Assurance Tool, answer your questions and, where you agree or the law allows, conduct research on the schemes and tell you about our services.
  • Most of it comes from you or the organisation you work for. Some comes from Certification Bodies, Assured Service Providers, public registers such as Companies House, and Dun & Bradstreet.
  • We share it with the Certification Body that assesses your organisation, Assured Service Providers that provide you with a service, the government for schemes it owns, service providers who work for us, and the others described below. We do not sell it.
  • Most of it is held in the UK. Where it is not, it is protected as described under Transfers outside the UK.
  • You can ask to see, correct or delete your information, or object to how we use it. You do not need an account with us to do this.

Contact us

Email: [email protected] — please mark your message for the attention of our Data Protection Manager.

Post: Data Protection Manager, The IASME Consortium Limited, Wyche Innovation Centre, Walwyn Road, Upper Colwall, Malvern, Worcestershire, WR13 6PL

Telephone: 03300 882 752

How we use your information

Each section below describes one situation in which we hold your information. It sets out what we hold, where it comes from, why we use it and the lawful basis we rely on. What each lawful basis means for your rights is explained under Your rights.

If your organisation applies for certification

This includes Cyber Essentials, Cyber Essentials Plus, CAA ASSURE, Defence Cyber Certification, IASME Cyber Assurance, IASME Cyber Baseline, IoT Cyber Baseline, Maritime Cyber Baseline and any other certification scheme operated by IASME.

Cyber Essentials and Cyber Essentials Plus

NCSC is the controller for the personal information processed to run Cyber Essentials and Cyber Essentials Plus. IASME operates the schemes on NCSC’s behalf and follows NCSC’s instructions. NCSC’s privacy information is available at www.gchq.gov.uk/section/about-this-website/privacy.

IASME also operates other services for NCSC, including Cyber Advisor services, the NCSC Cyber Incident Exercising Assured Service Provider service and the NCSC Cyber Incident Response Standard Level Service Provider service. NCSC is the controller for these services and IASME operates them on NCSC’s behalf.

CAA ASSURE and Defence Cyber Certification

We operate CAA ASSURE on behalf of the Civil Aviation Authority and Defence Cyber Certification on behalf of the Ministry of Defence. The Civil Aviation Authority is the controller for CAA ASSURE and the Ministry of Defence is the controller for Defence Cyber Certification. IASME operates each scheme on behalf of its owner. We use personal information to assess and certify organisations, administer the schemes, communicate with applicants and Certification Bodies, and share relevant information with the scheme owner.

What we hold

  • the names, job titles and contact details of people who apply, and of an organisation’s other contacts with us;
  • the organisation’s name, address and registration number;
  • answers to the assessment and evidence provided;
  • where relevant, technical audit results;
  • the outcome of the assessment and the certificate; and
  • payment and invoice records.

Where it comes from

From you, when you apply through the relevant assessment portal; from the Certification Body and assessor who carry out the assessment; from the scheme owner or commissioning body; from Companies House, the Charity Commission and other public registers; from Dun & Bradstreet; and from our own certification records.

Why we use it

  • to assess and certify your organisation and issue its certificate;
  • to publish certificate details so that others can confirm certification;
  • to administer the scheme, including overseeing Certification Bodies and assessors;
  • to report to or work with the relevant scheme owner or commissioning body;
  • to invoice for our services; and
  • to keep one accurate record of your organisation across our systems.

Lawful basis

For IASME-owned schemes, IASME determines the lawful basis set out below. Where another organisation owns the scheme, that organisation is the controller and determines the lawful basis; IASME processes the information on its behalf and in accordance with its instructions. IASME may separately act as controller for its own invoicing, security, support, legal claims and statutory business records where IASME determines those purposes.

  • Contract, where you apply as a sole trader or otherwise in your own name.
  • Legitimate interests, where you apply on behalf of an organisation. Our legitimate interest is administering certification and maintaining the integrity of the relevant scheme.
  • Legal obligation, for invoice and payment records, where applicable.

Publication: if your organisation is certified, we may publish its name, level of certification and, where relevant, the scope of the assessment on our certificate search or the relevant scheme register. For a sole trader, this may include your name. Details of assured people or organisations may also be published where the relevant scheme provides for this.

If you are an assessor, Cyber Advisor, Enterprise Assessor or other assured person

What we hold: your name, contact details, the Certification Body you work for, your qualifications and certification as an assessor, the results of any audit or investigation associated with you or your work, and your name on the certificates you issue.

Where it comes from: from you and from your Certification Body.

Why we use it: to certify and register assessors, maintain assurance standards and record who assessed each certificate.

Lawful basis:

  • Contract, where we certify you in your own right.
  • Legitimate interests, otherwise. Our legitimate interest is maintaining the integrity of our schemes.

If your organisation is, or applies to become, a Certification Body, Assured Service Provider or other assured organisation

What we hold:

  • the names and contact details of directors, manager-owners and persons of significant control;
  • the address and identifying details of the organisation and its key personnel;
  • company information from Companies House and other publicly available sources;
  • compliance and reputational information found through searches of publicly available sources (open-source intelligence). Where publicly reported, this can include information about criminal convictions or offences involving the organisation or its key personnel; and
  • once you are a Certification Body or Assessor, the contact details of the people we work with, and records of your performance and compliance.

Where it comes from: from the applicant, Companies House and publicly available sources. We do not ask applicants to provide all of this information directly.

Why we use it: to check that applicants are suitable organisations with a good compliance record; verify that they meet the warranties in the Certification Body Agreement; assess whether they pose a reputational risk to our schemes; and manage our relationship with partners.

Lawful basis: legitimate interests. Our legitimate interest is making sure we work only with suitable organisations and protecting the integrity of our schemes. Where this includes information about criminal convictions or offences, we process it only where Article 10 of the UK GDPR and an applicable condition in the Data Protection Act 2018 permit us to do so.

If you apply for UK Cyber Security Council professional registration

IASME is licensed by the UK Cyber Security Council (“UKCSC”) to assess applications for professional registration.

We may use your name and contact details, application information, qualifications, supporting documents and evidence, records of discussions and assessments, assessment decisions, and records of reviews, appeals or complaints.

IASME is the controller for the personal information necessary to:

  • assess your application against the relevant UKCSC Standard; and
  • onboard you to IASME’s professional-registration service.

Where you apply in your own name and are personally party to the registration arrangement, we rely on contract. The processing is necessary to consider your application and, if successful, provide the registration service.

Where an organisation arranges your application and you are not personally party to the agreement, we rely on legitimate interests. Our legitimate interest is assessing and administering professional-registration applications submitted for people working with that organisation.

We share relevant personal information with UKCSC. UKCSC is the controller for:

  • information about successful applicants used to maintain the UKCSC Register;
  • information UKCSC requires to advise IASME about an assessment; and
  • information collected in connection with UKCSC audits.

UKCSC determines its lawful basis for those activities. Its privacy notice explains how it uses your information, what information appears on its Register, how long it keeps it and how you can exercise your rights: UKCSC website privacy policy.

IASME and UKCSC are each responsible for requests relating to the personal information for which they are controller. If you contact us about information controlled by UKCSC, we will tell you how to direct your request to UKCSC or, where appropriate, pass it to UKCSC.

If you take our training or assessment

What we hold: your name, contact details, the courses or assessments you take, your progress, your test and assessment results, and the outcome of any certificate or assurance decision.

Where it comes from: from you and from your use of our training platform.

Why we use it: to provide the training and keep a record of it.

Lawful basis:

  • Contract, where you buy the training yourself.
  • Legitimate interests, where your organisation arranges it. Our legitimate interest is providing training to the organisation you act for.

If you tell us about a disability, health condition or dietary requirement

What we hold: information about a disability, health condition, allergy or access need, and dietary requirements, such as halal or kosher, that may indicate a religious belief. This is special category information, which the law gives extra protection.

Where it comes from: from you, or from the person who books training or an event on your behalf.

Why we use it: only to make the adjustments or arrangements you have asked for, for example to training, an assessment or an exam, or to meet dietary needs at an event.

Lawful basis: your explicit consent. You do not have to give us this information. Where we rely on your explicit consent, you can withdraw it at any time. We will stop using the information for that purpose and delete it unless we have another lawful reason to keep it. We may then be unable to continue the requested arrangement.

Who sees it: only the people who need it to make the arrangement, such as the trainer, venue or caterer for an event. Where we can, we pass on the requirement without your name.

If you use a branded assessment portal or the Pervade API

We create and operate branded assessment portals for Certification Bodies and provide API access to the Pervade assessment platform. Depending on the service, we may process information about applicants, assessors, Certification Body staff and other contacts, including account details, assessment data, records of actions and technical logs.

The Certification Body, scheme owner or another organisation may decide the purposes for which the information is used.

If you contact us

What we hold: your name and contact details, what you tell us, our correspondence with you, and any records we need to deal with a query, complaint or claim. That can include information from previous investigations and witness statements.

Where it comes from: from you and from anyone else involved in the matter.

Why we use it: to answer your query and deal with complaints and claims.

Lawful basis: legitimate interests. It is in the interest of both IASME and the person contacting us that all the relevant information is obtained so that the matter is dealt with properly. Where the query relates to a contract with you, we rely on contract.

If you visit our websites

What we hold: your IP address, and information about your device and browser.

Why we use it: to deliver our websites securely and protect them from attack. We use Cloudflare to do this.

Lawful basis: legitimate interests in keeping our websites secure. Where we use cookies that are not strictly necessary, we ask for your consent first. See our cookie policy.

What we hold: your name, contact details and account information; logs of API requests; IP addresses; and information about certificate or assurance searches. We use this to provide certificate and assurance information, monitor security and performance, and prevent misuse. The lawful basis is legitimate interests, unless the relevant scheme owner determines another basis.

If you use, or are added to, the Supplier Assurance Tool

The Supplier Assurance Tool lets organisations check the certification of their suppliers and invite them to join.

If you register, we hold your name, email address and job title; your organisation’s details and certification status; your sign-in details; records of what you do in the tool; your IP address; whether you have agreed to receive marketing; and, if your organisation buys vouchers, payment details. Card details are held by Stripe. If you cannot find your organisation when registering, you can look up your address; that lookup is provided by Google, which receives the address you enter and your IP address directly from your browser.

Lawful basis: contract, where your organisation is a sole trader and you accept our Terms of Use in your own name; otherwise, legitimate interests, our interest being to provide the service to the organisation you act for. We rely on legal obligation for payment records. You need to give your name and email address to create an account.

If another organisation adds yours as a supplier, we hold your organisation’s name, registered address, registration number and certification status, which we obtain from Companies House, the Charity Commission, Dun & Bradstreet and our own certification records. The organisation that added yours can see these details. It must be an organisation you already work with, or one considering you in a procurement.

We keep invitation details only for as long as necessary to issue and manage the invitation, provide support and deal with any related complaint or claim.

If that organisation invites you to join, we also hold the name and email address it gives us for the invitation. We hold no contact details for a supplier that has not been invited and has not registered. If your organisation is a sole trader, its name and address may identify you.

Lawful basis: legitimate interests. Our legitimate interest, and that of the organisation that added yours, is understanding the cyber security of supply chains. It also supports NCSC’s objective of extending the take-up of Cyber Essentials.

You can ask us to correct or remove this information, or object to its use, without creating an account.

If you use our consulting services

We may hold your name, contact details, organisation details, project correspondence, meeting records, information you provide to us, project documents, deliverables, invoices and records of our work.

We receive this information from you, the organisation you work for, other people involved in the engagement and our own records.

We use it to:

  • provide and manage the consulting service;
  • communicate with you and the organisation you represent;
  • plan and deliver projects;
  • maintain accurate client and project records;
  • manage quality, security and service continuity;
  • deal with questions, complaints and claims;
  • establish, exercise or defend legal claims; and
  • improve our consulting services.

Where you engage us in your own name and are a party to the consulting agreement, we rely on contract. Where you act for an organisation and are not personally a party to the agreement, we rely on legitimate interests.

Our legitimate interests are providing and managing the consulting service requested by the organisation, maintaining the client relationship, communicating with people involved in the work, protecting the security and integrity of our services, maintaining appropriate business records, and establishing, exercising or defending legal claims. We limit the information we use to what is relevant to the engagement and do not use consulting records for unrelated marketing.

We may share relevant information with our staff, professional advisers, technology and hosting providers, subcontractors or project partners involved in the engagement, the organisation that engaged us, and others where this is necessary to provide the service or where the law requires it.

We keep consulting records for as long as necessary to provide and manage the service, maintain appropriate business records, meet legal or regulatory requirements and deal with complaints or claims.

If a consulting engagement involves special-category information or information about criminal convictions or offences, we will only use it where the relevant additional legal condition applies.

If you use our jobs board

We may hold your name, contact details, account details, job-search or vacancy information, CV or profile information, applications, messages and other information you choose to provide through the jobs board. We may also hold technical information such as your IP address, browser details, login records and records of how you use the service.

We receive this information from you, from the employer or recruiter connected with a vacancy, and from your use of the jobs board.

We use it to:

  • operate and administer the jobs board;
  • create and manage user accounts;
  • publish vacancies and profiles according to the settings chosen by the user;
  • help applicants, employers and recruiters connect;
  • send job alerts or other service messages;
  • process applications and related communications;
  • maintain the security and integrity of the service;
  • prevent misuse, fraud and unauthorised access;
  • provide support and deal with complaints; and
  • establish, exercise or defend legal claims.

Where you create an account or use the jobs board in your own name, we rely on contract to provide the service you have requested.

Where you act for an employer or recruitment organisation and are not personally a party to the relevant agreement, we rely on legitimate interests. Our legitimate interests are operating and securing the jobs board, managing the relationship with the employer or recruiter, communicating with people involved in a vacancy, maintaining accurate business records, preventing misuse and dealing with claims.

We keep account and profile information while it is needed to provide the service. We keep applications and related messages only for as long as necessary to operate the jobs board, complete the relevant recruitment process, provide support, meet legal requirements and deal with complaints or claims.

We may share your information with the employer or recruiter connected with a vacancy when you apply, respond to an opportunity or otherwise choose to make your information available. That employer or recruiter is a separate controller for its own recruitment decisions and for any information it keeps after receiving it. IASME does not decide whether you are offered a job.

We may also share relevant information with our staff, jobs-board hosting and technology providers, professional advisers, employers, recruiters and others where this is necessary to operate the service or where the law requires it.

We do not use your CV, profile or application information for marketing unless you have agreed to that use or another lawful basis applies.

Research, reporting and archiving

We use our customer records in accordance with the retention criteria described below, and anonymised copies of assessments, to understand how our schemes are used and improve them. We report to NCSC on aspects of all its schemes mentioned above. That reporting is aggregated and does not identify individuals or organisations.

Lawful basis: legitimate interests. Our legitimate interest is understanding and improving our schemes and services.

Marketing

Our mailing list. If you join our mailing list, we will email you news and information about our schemes and services. We rely on your consent, which you can withdraw at any time.

Supplier Assurance Tool users. If you register for the Supplier Assurance Tool and your organisation does not hold Cyber Essentials, we may email you about the scheme. Where your organisation is registered at Companies House, we rely on legitimate interests, our interest being to tell organisations that do not hold Cyber Essentials about it. Otherwise, for example if you are a sole trader, we do this only if you agreed when you registered. If you declined, we will not. We do not send marketing to organisations that have been added to the tool by another organisation, unless someone from that organisation has registered.

Email tracking. Our marketing emails can record whether they were opened and which links were clicked. We only do this where you have agreed to it.

We do not use the certification records held in BlockMark to contact you for marketing. We use our customer records to contact you only if there is an issue with your certification.

You can object to marketing at any time. Use the unsubscribe link in any marketing email, or contact us. We will stop, whatever lawful basis we were relying on.

We use personal information where the law requires it, for example to keep financial records, meet tax and accounting requirements, respond to a lawful request, or comply with a legal or regulatory obligation. The applicable lawful basis is legal obligation where the relevant legal requirement applies.

Who we share your information with

Service providers

These organisations provide services used by IASME. Most act as processors and may use personal information only on the relevant controller’s instructions. Some also act as independent controllers for particular purposes; where this applies, we explain it below.

Service providers used by IASME
Provider What it does for us Where your information is held
Pervade Software Ltd Assessment portal UK
BlockMark Technologies Ltd Issues our certificates UK
Microsoft Email, documents and SharePoint UK. Some information may be accessed from the US and elsewhere for support and security.
Atlassian (Jira) Our query and ticketing system UK
QuickBooks (Intuit) Accounting and invoicing USA
Moodle Our online training platform UK
Brevo Sends our marketing and bulk emails European Economic Area (France)
Amazon Web Services Hosts some of our systems UK (London), with backup copies in Ireland
eUKhost Hosts some of our systems UK
Cloudflare Security for our websites Worldwide, at the location nearest to you
Stripe Payments for the Supplier Assurance Tool Ireland, with transfers to the US
Langdock An AI tool we use to draft and improve written content, which may include names European Economic Area (Germany)
Backup providers Keep copies of our systems for resilience. We do not name them, for security reasons. UK

Other organisations we share information with

  • NCSC, as controller, for Cyber Essentials, Cyber Essentials Plus and the other NCSC services described above. IASME operates those services on NCSC’s behalf.
  • The Ministry of Defence, as controller, for Defence Cyber Certification and other DCC information. IASME operates DCC on the Ministry of Defence’s behalf.
  • The Civil Aviation Authority, as controller, for CAA ASSURE. IASME operates CAA ASSURE on its behalf.
  • The UK Cyber Security Council, as controller for information used to maintain the UKCSC Register, advise IASME about assessments and conduct audits, as described above.
  • Government departments and public bodies that commission or oversee services.
  • Certification Bodies, assessors, Cyber Advisors, Assured Service Providers and other organisations involved in delivering or overseeing a relevant scheme.
  • The public, where we publish certificate, accreditation or assurance details on a certificate search or public register.
  • Dun & Bradstreet, a UK business information provider, which we use to find and confirm organisations’ registered details. We send it the name of the organisation being searched for, which for a sole trader may be the person’s own name, and it returns the organisation’s registered details. It may not use the information we send it for its own purposes, and it is contractually limited to using it in the UK and Ireland.
  • Organisations using the Supplier Assurance Tool, which can see the supplier details made available to them by the tool.
  • Google Ireland Limited, which provides the SAT address lookup and uses the information it receives under its own privacy policy.
  • Stripe, which uses some payment information for its own purposes, such as fraud prevention, under its own privacy policy.
  • Our professional advisers, such as auditors and legal advisers, where they need the information.
  • Phenna and other group service providers, where required for group reporting, finance, payroll or other services.
  • An organisation that takes over management of one of our schemes, where this is permitted and necessary.
  • Anyone else we are legally required to share information with.

Transfers outside the UK

Most of your information is held in the UK. Where one of our providers holds or accesses it outside the UK, the law requires that it stays protected to UK standards. We rely on one of the following safeguards.

Adequacy. The UK Government has decided that some destinations protect personal information to an adequate standard. These include the European Economic Area, and US organisations certified under the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”).

Transfer contracts. Where adequacy does not apply, the provider must sign the UK’s International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Both are approved by the UK and legally require the recipient to protect your information to UK standards.

International transfers and safeguards
Provider Destination Safeguard
Microsoft 365 The US and other countries, for support and security The UK–US data bridge, and the UK Addendum to the EU Standard Contractual Clauses in Microsoft’s data protection terms
Atlassian The US and other countries, for support and security The UK–US data bridge, and the UK Addendum to the EU Standard Contractual Clauses in Atlassian’s data protection terms
QuickBooks (Intuit) The US The UK–US data bridge, and the UK Addendum to the EU Standard Contractual Clauses in Intuit’s data protection terms
Brevo France Adequacy
Amazon Web Services Ireland, for backup copies Adequacy
Cloudflare Worldwide The UK–US data bridge, and the UK Addendum to the EU Standard Contractual Clauses in Cloudflare’s data protection terms
Stripe Ireland; the US Adequacy for Ireland. For the US, the UK Addendum to the EU Standard Contractual Clauses in Stripe’s data protection terms, and the UK–US data bridge
Langdock Germany Adequacy

Two services involve organisations outside the UK but are not transfers made by us. The address lookup in the Supplier Assurance Tool is provided by Google Ireland Limited, which your browser contacts directly; Google is responsible for any onward transfer it makes. Dun & Bradstreet is a UK company and is contractually limited to the UK and Ireland.

You can ask us for a copy of the safeguard that applies to any provider.

How long we keep your information

We keep personal information only for as long as we need it for the purpose for which we collected it. The period depends on the type of information, why we use it, the relationship involved, any legal or regulatory requirements, the possibility of a legal claim, and the requirements of the relevant scheme or service.

Where we rely on a scheme owner or commissioning organisation, such as NCSC, the Ministry of Defence, the Civil Aviation Authority or UKCSC, its retention requirements may also apply.

Deleted information may remain in backups until those backups expire in the normal course. We do not restore deleted information into active use.

You can contact us using the details above if you would like more information about how long we keep a particular type of information.

Your rights

You have the right to:

  • access your personal information, and ask where we got it and who we share it with;
  • correct information you think is inaccurate, and complete information you think is incomplete;
  • erase your information;
  • restrict how we use your information;
  • object to how we use your information;
  • data portability: have the information you gave us transferred to you or to another organisation; and
  • withdraw consent, where we rely on it.

If your request concerns a scheme owned by NCSC, the Ministry of Defence, the Civil Aviation Authority, UKCSC or another organisation, we will handle it under the relevant arrangement and help ensure it reaches the appropriate controller. IASME will handle requests relating to IASME-owned schemes and services and the UKCSC activities for which IASME is controller.

We may extend the response period by up to two further months where a request is complex or we have received several requests. If we do, we will tell you within the first month and explain why.

Some rights depend on the lawful basis we rely on:

Rights that do not apply to particular lawful bases
Lawful basis Rights that do not apply
Contract The right to object
Legal obligation The rights to erasure, to object and to data portability
Legitimate interests The right to data portability
Consent The right to object. You can withdraw your consent instead.

Some rights are also subject to exemptions, which means we may not always be able to do everything you ask. If so, we will tell you why.

You do not need an account with us to make a request, including if your organisation has been added to the Supplier Assurance Tool by one of your customers. Contact us using the details above. We will respond without undue delay, and in any event within one month. We may need to confirm your identity first.

For more about your rights, see the ICO’s guide to individual rights.

Automated decisions

We do not make decisions about you based solely on automated processing that have a legal or similarly significant effect on you.

Cookies

How we use cookies and similar technologies on our websites is explained in our cookie notice.

Changes to this notice

We update this notice when our use of personal information changes. The date below shows when it was last updated.

How to complain

If you have a concern about how we use your personal information, please contact us first using the details above.

If you are not satisfied with our response, you can complain to the Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint