CEMR
Member and stakeholder Privacy Notice
Last updated: Brussels, 17 December 2018.
- About this Notice
1.1 This Privacy Notice (“Notice”) explains how we (as defined below) collect, share and use
any information that, alone or in combination with other information, relates to you
(“Personal Data”) in your capacity as a member or stakeholder (or as our contact person at
your organisation) (“you” and “your”) of The Council of European Municipalities and
Regions (“CEMR”, “we” and “our”).
1.2 This Notice also sets out the rights that you have in relation to the Personal Data that we
process about you and how you can exercise them.
1.3 CEMR treats compliance with its privacy obligations seriously. This is why we have
developed this Notice, which describes the standards that CEMR applies to protect Personal
Data.
1.4 For the purposes of this Notice, the CEMR interacts with you if you are a member or a
stakeholder (e.g. previous members, press members, journalists, data subjects working in
institutions or organisations, visitors of our website) and acts as the data controller for your
Personal Data. As a data controller, the CEMR is responsible for ensuring that the
processing of Personal Data complies with applicable data protection law, and specifically
with the General Data Protection Regulation.
1.5 Please take the time to read this Notice carefully. If you have any questions or comments,
please contact us via email at privacy@ccre-cemr.org - What Personal Data does CEMR collect and why?
2.1 The types of Personal Data that we may collect about you, and the reasons why we process
it, include:
Why we collect it Types of Personal Data Legal basis
Member relationship
management
Identification data (name,
professional address,
professional telephone)
Education and training data
(e.g. professional
qualification, experience,
professional organisations)
Data relating to profession
(e.g. employment details,
employer, job title, career,
attendance).
Legitimate interest of
CEMR: to have an
updated information
about its members
Management of websites Identification data (name,
address, telephone)
Legitimate interest of
CEMR: to have an up-to-
2
Data on CV (physical data
and personal characteristics),
Education and training data
(e.g. qualification,
experience, professional
organisations)
Data on affiliations to
organizations, charities,
volunteering, etc.
Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
Data revealing political
opinions
date information about
its existing members on
its websites for
transparency reason
Communication with members Identification data (name,
address, telephone);
Data on CV (physical data
and personal characteristics);
National IDs and identifiers;
Data on CVs (leisure
activities, affiliation,
education and training, jobs)
Legitimate interest if
CEMR: to inform
members about CEMR’s
activities and news
Communication with competent
Belgian authorities
Personal characteristics
Physical data
National IDs and identifiers
Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
Compliance with legal
obligations
Management of reimbursement
requests of members for travels
and expenses
Identification data (name,
professional address,
professional telephone)
Financial characteristics
(account number, credit/debit
car details)
Legitimate interest of
CEMR: to ensure that
members are
compensated for their
involvement in the
CEMR’s activities
Stakeholders’ relationship
management
Identification data (name,
address, telephone number)
Education and training data
(e.g. professional
qualification, experience,
professional organisations);
Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance)
Legitimate interest of
CEMR: to maintain an
updated information
about CEMR’s
stakeholders
Communication with
stakeholders about CEMR
activities
Identification data (name,
professional address,
professional telephone)
Education and training data
(e.g. professional
qualification, experience,
professional organisations)
Data relating to profession
and job (e.g. employment
Legitimate interest of
CEMR: to inform
stakeholders who have
shown an interest in
CERM’s activities and
news.
3
details, employer, job title,
career, attendance).
Data revealing political
opinions
Transfer to public authorities,
institutions and public agencies
for survey or study purposes or
for any purposes that are closely
related to our missions and
activities
Identification data (name,
postal address, telephone)
Legitimate interest of
CEMR: to work closely
and collaborate with
public authorities,
institutions and public
agencies on matter
related to its missions
and activities.
Events’ organisations Identification data (name,
professional address,
professional telephone)
Financial characteristics
(account number, credit/debit
car details)
National IDs and identifiers
Education and training data
(e.g. professional
qualification, experience,
professional organisations)
Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
Data revealing political
opinions
Legitimate interest of
CEMR: to ensure
participation of members
and stakeholders in the
events organised by the
CEMR.
Project’s management involving
members’ personal data
Identification data (name,
address, telephone number)
National IDs and identifiers
Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
Contractual necessity
and legitimate interest of
CEMR: to manage
projects conducted by
CEMR
If we ask you to provide any other Personal Data not described above, then the Personal
Data we will ask you to provide, and the reasons why we ask you to provide it, will be made
clear to you at the point we collect that Personal Data.
2.2 We may also collect certain information automatically from your device. Specifically, the
information we collect automatically may include information like your IP address, device
type, unique device identification numbers, browser-type, broad geographic location (e.g.
country or city-level location) and other technical information. We may also collect
information about how your device has interacted with our Website, including the pages
accessed and links clicked.
Collecting this information enables us to better understand the visitors who come to our
Website, where they come from, and what content on our Website is of interest to them. We
use this information for our internal analytics purposes and to improve the quality and
relevance of our Website to our visitors.
4
Some of this information may be collected using cookies and similar tracking technology, as
explained further in our Cookie Notice which is available on http://bit.ly/cookienotice.
2.3 From time to time, we may receive Personal Data about you from third party sources
(including national associations, European institutions, but only where we have checked that
these third parties either have your consent or are otherwise legally permitted or required to
disclose your Personal Data to us.
The types of Personal Data we collect from third parties include your name, function, contact
and we use this Personal Data we receive from these third parties to maintain and improve
the accuracy of the records we hold about you or send you relevant information regarding
our events and news.
2.4 In general, we will use the Personal Data we collect from you only for the purposes
described in this Notice or for purposes that we explain to you at the time we collect your
Personal Data. However, we may also use your Personal Data for other purposes that are
not incompatible with the purposes we have disclosed to you (such as archiving purposes in
the public interest, scientific or historical research purposes, or statistical purposes) if and
where this is permitted by applicable data protection laws.
- Who does CEMR share your Personal Data with?
3.1 We may disclose your Personal Data to the following categories of recipients:
(a) To other members, stakeholders or partners for the purpose of informing them
about our activities, events and to expand our network of members and
stakeholders;
(b) To visitors of our website who wish to learn more about our members and
activities;
(c) To the European Commission, public authorities, institutions and public
agencies that carry out studies or surveys or work that that are closely related to
our missions or activities;
(d) to our third party vendors, services providers and partners who provide data
processing services to us, or who otherwise process Personal Data for purposes
that are described in this Notice or notified to you when we collect your Personal
Data. This may include disclosures to third party vendors and other service
providers we use in connection with the services they provide to us, including to
support us in areas such as, IT platform management or support services,
infrastructure and application services, newsletters, event planning, business travel
service providers, event planning organisations;
(e) to any competent law enforcement body, regulatory, government agency,
court or other third party where we believe disclosure is necessary (i) as a matter
of applicable law or regulation, (ii) to exercise, establish or defend our legal rights,
or (iii) to protect your vital interests or those of any other person;
(f) to our auditors, advisors, legal representatives and similar agents in
connection with the advisory services they provide to us for legitimate business
5
(g) purposes and under contractual prohibition of using the Personal Data for any other
purpose;
(h) to any other person if you have provided your prior consent to the disclosure. - How we protect your privacy
4.1 We will process Personal Data in accordance with this Notice, as follows:
(a) Fairness: We will process Personal Data fairly. This means that we are transparent
about how we process Personal Data and that we will process it in accordance with
applicable law.
(b) Purpose limitation: We will process Personal Data for specified and lawful
purposes, and will not process it in a manner that is incompatible with those
purposes.
(c) Proportionality: We will process Personal Data in a way that is proportionate to the
purposes which the processing is intended to achieve.
(d) Data accuracy: We take appropriate measures to ensure that the Personal Data
that we hold is accurate, complete and, where necessary, kept up to date. However,
it is also your responsibility to ensure that your Personal Data is kept as accurate,
complete and current as possible by informing CEMR of any changes or errors. You
should notify your local CEMR contact of any changes to the Personal Data that we
hold about you (e.g. a change of address).
(e) Data security: We use appropriate technical and organisational measures to
protect the Personal Data that we collect and process about you. The measures we
use are designed to provide a level of security appropriate to the risk of processing
your Personal Data. [Specific measures we use include: trainings provided to our
staff members, confidentiality clauses, measures against physical danger,
authentication systems and back-up systems.
(f) Data processors: We may engage third parties to process Personal Data for and
on behalf of CEMR. We require such data processors to process Personal Data and
act strictly on our instructions and to take appropriate steps to ensure that Personal
Data remains protected.
(g) International data transfers: Your Personal Data may be transferred to, and
processed in, countries other than the country in which you are resident. These
countries may have data protection laws that are different to the laws of your
country (and, in some cases, may not be as protective).
Specifically, our servers are located in Belgium and Luxembourg and third party
service providers and partners operate mainly in Belgium and the European Union.
A few of our partners that we work with for the purpose of project’s management
operate outside the EU/EEA. This means that when we collect your Personal Data
we may process it in any of these countries.
However, we have taken appropriate safeguards to require that your Personal Data
will remain protected in accordance with this Notice. These include implementing
the European Commission’s Standard Contractual Clauses for transfers of Personal
6
Data which require CEMR and its Partners to protect Personal Data they process
from the EEA in accordance with European Union data protection law.
(h) Data Retention: We retain Personal Data we collect from you where we have an
ongoing legitimate business need to do so (for example, to provide you with a
service you have requested or to comply with applicable legal, tax or accounting
requirements).
When we have no ongoing legitimate business need to process your Personal Data,
we will either delete or anonymise it or, if this is not possible (for example, because
your Personal Data has been stored in backup archives), then we will securely store
your Personal Data and isolate it from any further processing until deletion is
possible. - Your data protection rights
5.1 You have the following data protection rights:
(a) If you wish to access, correct, update or request deletion of your Personal Data,
you can do so at any time by contacting us using the following contact details
privacy@ccre-cemr.org
(b) In addition, in certain circumstances, as stipulated in the applicable data protection
legislation, you can object to processing of your Personal Data, ask us to restrict
processing of your Personal Data or request portability of your Personal Data.
Again, you can exercise these rights by contacting us using the following contact
details privacy@ccre-cemr.org
(c) If we have collected and process your Personal Data with your consent, then you
can withdraw your consent at any time. Withdrawing your consent will not affect
the lawfulness of any processing we conducted prior to your withdrawal, nor will it
affect processing of your Personal Data conducted in reliance on lawful processing
grounds other than consent.
(d) You have the right to opt-out of marketing communications we send you at any
time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in
the marketing e-mails we send you. To opt-out of other forms of marketing (such as
postal marketing or telemarketing), then please contact us using the contact details
provided above.
(e) If you have a complaint or concern about how we are processing your Personal
Data then we will endeavour to address such concern(s). If you feel we have not
sufficiently addressed your complaint or concern, you have the right to complain
to a data protection authority about our collection and use of your Personal Data.
For more information, please contact your local data protection authority. (Contact
details for data protection authorities in the European Economic Area, Switzerland
and certain non-European countries (including the US and Canada) are available
here.)
7
5.2 We respond to all requests we receive from individuals wishing to exercise their data
protection rights in accordance with applicable data protection laws. - Updates to this Notice
6.1 We may update this Notice from time to time in response to changing legal, technical or
business developments. When we update our Notice, we will take appropriate measures to
inform you, consistent with the significance of the changes we make. We will obtain your
consent to any material Notice changes if and where this is required by applicable data
protection laws.
6.2 You can see when this Privacy Notice was last updated by checking the “last updated” date
displayed at the top of this Notice.