1. Who we are
This website is operated by the ISC2 Chapter Portugal Chartering Founding Committee (referred to as “we”, “us”, or “the chapter”), a volunteer initiative working towards the official chartering of the ISC2 Portugal Chapter.
For all enquiries, including any request to exercise your data-protection rights under the GDPR, contact: info@isc2portugalchapter.pt.
Given the volunteer nature of the initiative and the limited scope of processing, we are not required to appoint a Data Protection Officer.
2. What personal data we process
- Email correspondence — your name, email address, message content, and any information you choose to include when you write to us.
- Membership applications — the data you fill into the membership application form (DOCX) you complete and email back to us, including name, contact details, ISC2 member ID where applicable, and professional information you provide.
3. Why we process it and legal basis (Art. 6 GDPR)
- Replying to enquiries — legitimate interest (Art. 6(1)(f)) and pre-contractual steps at your request (Art. 6(1)(b)).
- Membership applications — your consent (Art. 6(1)(a)) and processing necessary for the chartering and membership relationship (Art. 6(1)(b)).
4. Who we share it with
- Founding Committee volunteers handling your request.
- ISC2, Inc. (United States) for chartering and membership validation. International transfers are covered by ISC2’s own member-data framework, including Standard Contractual Clauses where applicable.
- No advertisers, no analytics vendors, no data brokers.
5. How long we keep it
- Enquiry emails: up to 24 months, then deleted.
- Membership application data: while membership is active, plus any minimum statutory retention period.
6. Your rights (Arts. 15–22 GDPR)
You have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw your consent at any time. To exercise any of these rights, email info@isc2portugalchapter.pt.
You may also lodge a complaint with the Portuguese supervisory authority, CNPD — Comissão Nacional de Proteção de Dados.
7. Security
We use TLS in transit, apply data minimisation, and do not publicly host any submitted form. Only Founding Committee volunteers handling your request have access to the data you send us.
8. No cookies, no tracking
This website does not use cookies, analytics, advertising pixels, or any other tracking technology. No consent banner is shown because none is required under the GDPR / ePrivacy rules.
9. Children
This service is not directed at people under 16. We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy as the chapter formalises. The “Last updated” date at the top reflects the most recent revision. See also our Legal Notice and Terms of Use.