Skip to main content

CEMR
Member and stakeholder Privacy Notice
Last updated: Brussels, 17 December 2018.

  1. About this Notice
    1.1 This Privacy Notice (“Notice”) explains how we (as defined below) collect, share and use
    any information that, alone or in combination with other information, relates to you
    (“Personal Data”) in your capacity as a member or stakeholder (or as our contact person at
    your organisation) (“you” and “your”) of The Council of European Municipalities and
    Regions (“CEMR”, “we” and “our”).
    1.2 This Notice also sets out the rights that you have in relation to the Personal Data that we
    process about you and how you can exercise them.
    1.3 CEMR treats compliance with its privacy obligations seriously. This is why we have
    developed this Notice, which describes the standards that CEMR applies to protect Personal
    Data.
    1.4 For the purposes of this Notice, the CEMR interacts with you if you are a member or a
    stakeholder (e.g. previous members, press members, journalists, data subjects working in
    institutions or organisations, visitors of our website) and acts as the data controller for your
    Personal Data. As a data controller, the CEMR is responsible for ensuring that the
    processing of Personal Data complies with applicable data protection law, and specifically
    with the General Data Protection Regulation.
    1.5 Please take the time to read this Notice carefully. If you have any questions or comments,
    please contact us via email at privacy@ccre-cemr.org
  2. What Personal Data does CEMR collect and why?
    2.1 The types of Personal Data that we may collect about you, and the reasons why we process
    it, include:
    Why we collect it Types of Personal Data Legal basis
    Member relationship
    management

 Identification data (name,
professional address,
professional telephone)
 Education and training data
(e.g. professional
qualification, experience,
professional organisations)
 Data relating to profession
(e.g. employment details,
employer, job title, career,
attendance).
Legitimate interest of
CEMR: to have an
updated information
about its members
Management of websites  Identification data (name,
address, telephone)
Legitimate interest of
CEMR: to have an up-to-
2
 Data on CV (physical data
and personal characteristics),
 Education and training data
(e.g. qualification,
experience, professional
organisations)
 Data on affiliations to
organizations, charities,
volunteering, etc.
 Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
 Data revealing political
opinions
date information about
its existing members on
its websites for
transparency reason
Communication with members  Identification data (name,
address, telephone);
 Data on CV (physical data
and personal characteristics);
 National IDs and identifiers;
 Data on CVs (leisure
activities, affiliation,
education and training, jobs)
Legitimate interest if
CEMR: to inform
members about CEMR’s
activities and news
Communication with competent
Belgian authorities
 Personal characteristics
 Physical data
 National IDs and identifiers
 Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
Compliance with legal
obligations
Management of reimbursement
requests of members for travels
and expenses
 Identification data (name,
professional address,
professional telephone)
 Financial characteristics
(account number, credit/debit
car details)
Legitimate interest of
CEMR: to ensure that
members are
compensated for their
involvement in the
CEMR’s activities
Stakeholders’ relationship
management
 Identification data (name,
address, telephone number)
 Education and training data
(e.g. professional
qualification, experience,
professional organisations);
 Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance)
Legitimate interest of
CEMR: to maintain an
updated information
about CEMR’s
stakeholders
Communication with
stakeholders about CEMR
activities
 Identification data (name,
professional address,
professional telephone)

 Education and training data
(e.g. professional
qualification, experience,
professional organisations)
 Data relating to profession
and job (e.g. employment
Legitimate interest of
CEMR: to inform
stakeholders who have
shown an interest in
CERM’s activities and
news.
3
details, employer, job title,
career, attendance).
 Data revealing political
opinions
Transfer to public authorities,
institutions and public agencies
for survey or study purposes or
for any purposes that are closely
related to our missions and
activities
 Identification data (name,
postal address, telephone)
Legitimate interest of
CEMR: to work closely
and collaborate with
public authorities,
institutions and public
agencies on matter
related to its missions
and activities.
Events’ organisations  Identification data (name,
professional address,
professional telephone)
 Financial characteristics
(account number, credit/debit
car details)
 National IDs and identifiers
 Education and training data
(e.g. professional
qualification, experience,
professional organisations)
 Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
 Data revealing political
opinions
Legitimate interest of
CEMR: to ensure
participation of members
and stakeholders in the
events organised by the
CEMR.
Project’s management involving
members’ personal data
 Identification data (name,
address, telephone number)
 National IDs and identifiers
 Data relating to profession
and job (e.g. employment
details, employer, job title,
career, attendance).
Contractual necessity
and legitimate interest of
CEMR: to manage
projects conducted by
CEMR
If we ask you to provide any other Personal Data not described above, then the Personal
Data we will ask you to provide, and the reasons why we ask you to provide it, will be made
clear to you at the point we collect that Personal Data.
2.2 We may also collect certain information automatically from your device. Specifically, the
information we collect automatically may include information like your IP address, device
type, unique device identification numbers, browser-type, broad geographic location (e.g.
country or city-level location) and other technical information. We may also collect
information about how your device has interacted with our Website, including the pages
accessed and links clicked.
Collecting this information enables us to better understand the visitors who come to our
Website, where they come from, and what content on our Website is of interest to them. We
use this information for our internal analytics purposes and to improve the quality and
relevance of our Website to our visitors.
4
Some of this information may be collected using cookies and similar tracking technology, as
explained further in our Cookie Notice which is available on http://bit.ly/cookienotice.
2.3 From time to time, we may receive Personal Data about you from third party sources
(including national associations, European institutions, but only where we have checked that
these third parties either have your consent or are otherwise legally permitted or required to
disclose your Personal Data to us.
The types of Personal Data we collect from third parties include your name, function, contact
and we use this Personal Data we receive from these third parties to maintain and improve
the accuracy of the records we hold about you or send you relevant information regarding
our events and news.
2.4 In general, we will use the Personal Data we collect from you only for the purposes
described in this Notice or for purposes that we explain to you at the time we collect your
Personal Data. However, we may also use your Personal Data for other purposes that are
not incompatible with the purposes we have disclosed to you (such as archiving purposes in
the public interest, scientific or historical research purposes, or statistical purposes) if and
where this is permitted by applicable data protection laws.

  1. Who does CEMR share your Personal Data with?
    3.1 We may disclose your Personal Data to the following categories of recipients:
    (a) To other members, stakeholders or partners for the purpose of informing them
    about our activities, events and to expand our network of members and
    stakeholders;
    (b) To visitors of our website who wish to learn more about our members and
    activities;
    (c) To the European Commission, public authorities, institutions and public
    agencies that carry out studies or surveys or work that that are closely related to
    our missions or activities;
    (d) to our third party vendors, services providers and partners who provide data
    processing services to us, or who otherwise process Personal Data for purposes
    that are described in this Notice or notified to you when we collect your Personal
    Data. This may include disclosures to third party vendors and other service
    providers we use in connection with the services they provide to us, including to
    support us in areas such as, IT platform management or support services,
    infrastructure and application services, newsletters, event planning, business travel
    service providers, event planning organisations;
    (e) to any competent law enforcement body, regulatory, government agency,
    court or other third party where we believe disclosure is necessary (i) as a matter
    of applicable law or regulation, (ii) to exercise, establish or defend our legal rights,
    or (iii) to protect your vital interests or those of any other person;
    (f) to our auditors, advisors, legal representatives and similar agents in
    connection with the advisory services they provide to us for legitimate business
    5
    (g) purposes and under contractual prohibition of using the Personal Data for any other
    purpose;
    (h) to any other person if you have provided your prior consent to the disclosure.
  2. How we protect your privacy
    4.1 We will process Personal Data in accordance with this Notice, as follows:
    (a) Fairness: We will process Personal Data fairly. This means that we are transparent
    about how we process Personal Data and that we will process it in accordance with
    applicable law.
    (b) Purpose limitation: We will process Personal Data for specified and lawful
    purposes, and will not process it in a manner that is incompatible with those
    purposes.
    (c) Proportionality: We will process Personal Data in a way that is proportionate to the
    purposes which the processing is intended to achieve.
    (d) Data accuracy: We take appropriate measures to ensure that the Personal Data
    that we hold is accurate, complete and, where necessary, kept up to date. However,
    it is also your responsibility to ensure that your Personal Data is kept as accurate,
    complete and current as possible by informing CEMR of any changes or errors. You
    should notify your local CEMR contact of any changes to the Personal Data that we
    hold about you (e.g. a change of address).
    (e) Data security: We use appropriate technical and organisational measures to
    protect the Personal Data that we collect and process about you. The measures we
    use are designed to provide a level of security appropriate to the risk of processing
    your Personal Data. [Specific measures we use include: trainings provided to our
    staff members, confidentiality clauses, measures against physical danger,
    authentication systems and back-up systems.
    (f) Data processors: We may engage third parties to process Personal Data for and
    on behalf of CEMR. We require such data processors to process Personal Data and
    act strictly on our instructions and to take appropriate steps to ensure that Personal
    Data remains protected.
    (g) International data transfers: Your Personal Data may be transferred to, and
    processed in, countries other than the country in which you are resident. These
    countries may have data protection laws that are different to the laws of your
    country (and, in some cases, may not be as protective).
    Specifically, our servers are located in Belgium and Luxembourg and third party
    service providers and partners operate mainly in Belgium and the European Union.
    A few of our partners that we work with for the purpose of project’s management
    operate outside the EU/EEA. This means that when we collect your Personal Data
    we may process it in any of these countries.
    However, we have taken appropriate safeguards to require that your Personal Data
    will remain protected in accordance with this Notice. These include implementing
    the European Commission’s Standard Contractual Clauses for transfers of Personal
    6
    Data which require CEMR and its Partners to protect Personal Data they process
    from the EEA in accordance with European Union data protection law.
    (h) Data Retention: We retain Personal Data we collect from you where we have an
    ongoing legitimate business need to do so (for example, to provide you with a
    service you have requested or to comply with applicable legal, tax or accounting
    requirements).
    When we have no ongoing legitimate business need to process your Personal Data,
    we will either delete or anonymise it or, if this is not possible (for example, because
    your Personal Data has been stored in backup archives), then we will securely store
    your Personal Data and isolate it from any further processing until deletion is
    possible.
  3. Your data protection rights
    5.1 You have the following data protection rights:
    (a) If you wish to access, correct, update or request deletion of your Personal Data,
    you can do so at any time by contacting us using the following contact details
    privacy@ccre-cemr.org
    (b) In addition, in certain circumstances, as stipulated in the applicable data protection
    legislation, you can object to processing of your Personal Data, ask us to restrict
    processing of your Personal Data or request portability of your Personal Data.
    Again, you can exercise these rights by contacting us using the following contact
    details privacy@ccre-cemr.org
    (c) If we have collected and process your Personal Data with your consent, then you
    can withdraw your consent at any time. Withdrawing your consent will not affect
    the lawfulness of any processing we conducted prior to your withdrawal, nor will it
    affect processing of your Personal Data conducted in reliance on lawful processing
    grounds other than consent.
    (d) You have the right to opt-out of marketing communications we send you at any
    time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in
    the marketing e-mails we send you. To opt-out of other forms of marketing (such as
    postal marketing or telemarketing), then please contact us using the contact details
    provided above.
    (e) If you have a complaint or concern about how we are processing your Personal
    Data then we will endeavour to address such concern(s). If you feel we have not
    sufficiently addressed your complaint or concern, you have the right to complain
    to a data protection authority about our collection and use of your Personal Data.
    For more information, please contact your local data protection authority. (Contact
    details for data protection authorities in the European Economic Area, Switzerland
    and certain non-European countries (including the US and Canada) are available
    here.)
    7
    5.2 We respond to all requests we receive from individuals wishing to exercise their data
    protection rights in accordance with applicable data protection laws.
  4. Updates to this Notice
    6.1 We may update this Notice from time to time in response to changing legal, technical or
    business developments. When we update our Notice, we will take appropriate measures to
    inform you, consistent with the significance of the changes we make. We will obtain your
    consent to any material Notice changes if and where this is required by applicable data
    protection laws.
    6.2 You can see when this Privacy Notice was last updated by checking the “last updated” date
    displayed at the top of this Notice.