Purpose and scope
Data protection
This policy sets operational data-protection controls for Certiqual quality processes. The Privacy Notice explains legal bases, categories, retention and individual rights in full.
01
Purpose and minimisation
Before collection, Certiqual identifies the operational purpose, lawful basis, minimum fields, access roles and retention need. Evidence sampling avoids unnecessary personal data and uses redaction, pseudonymisation or aggregation where these preserve the audit question.
02
Accuracy, security and sharing
Records are kept accurate enough for their purpose, protected by role-based access and appropriate technical and organisational controls, and shared only with authorised recipients under a defined need and duty.
03
Rights and incidents
Requests for access, correction, erasure, restriction, objection or portability are routed through the Privacy Notice and handled according to applicable law. Suspected personal-data incidents are contained, assessed, documented and notified where required.
Mandatory controls
What the policy requires in operation
- Personal data is not collected merely because it might become useful.
- Special-category or high-risk data receives enhanced necessity and access checks.
- Processors are used only under appropriate instructions and safeguards.
- The Privacy Notice prevails for detailed legal information.
Public accountability
Status changes remain visible
Where this policy affects a public accreditation or Certi Mark, the live register reflects the current status, restrictions and material public history without disclosing protected evidence or personal data.
