EFMD PRIVACY POLICY

Introduction

The data controller responsible for processing your data is EFMD (n° B.C.E./K.B.O 0411.610.491, hereinafter referred to as the “Data Controller”, “we” or “us”), a non-profit organisation, rue Gachard 88 - box 3, 1050 Brussels, Belgium.

EFMD strives for transparency and trust in protecting your privacy, and we aim to clearly explain how we collect and process your information. This policy outlines how we collect and use different types of personal information, and the reasons for doing so.

This privacy statement is regularly reviewed. This version was updated in October 2025.


What kind of information do we collect and process?

Processing Activity Name Purpose(s) of Processing Categories of Data Subjects Categories of Personal Data Legal Basis Recipients
Event Registration Registration and participation in EFMD events; networking among attendees Event participants (academics, professionals, partners) Full name, title, institution, email, profile picture Consent (Art. 6.1.a) used for optional participation, networking features, or marketing communications; contract (Art. 6.1.b) used for core registration and participation management Other participants
Website Access & Analytics Monitor website usage, improve functionality, marketing analysis Website visitors IP address, browser type, operating system, consulted pages, search data Legitimate interest (Art. 6.1.f) Third-party web analytics provider
Cookie Management Websites (efmdglobal.org and globalfocusmagazine.com) functionality, user preference storage, and audience measurement Website users IP address, cookie identifiers, device data Consent (Art. 6.1.a) User’s browser and EFMD internal servers
Contact via Email / Inquiries Respond to inquiries, support and correspondence Any data subject contacting EFMD Name, email address, message content Legitimate interest (Art. 6.1.f) Internal staff only
Gravatar Integration on Comments Display user avatars in comment sections Website users submitting comments Email (hashed), IP address, browser agent Legitimate interest (Art. 6.1.f) used to display avatars where the user already uses Gravatar, and public visibility is expected; consent (Art. 6.1.a) used if Gravatar service is optional or triggered only upon user agreement Gravatar (Automattic Inc.)
Event Photography & Video Promotion and documentation of EFMD activities Event attendees Photographic/video images Consent (Art. 6.1.a) used when individuals are clearly identifiable and explicit consent is obtained; legitimate interest (Art. 6.1.f) used for general event documentation with prior notice and opt-out options Public (via website, social media, newsletters)
Publicly Sourced Images of Contributors Illustration of speaker/contributor profiles in publications and communication Speakers, authors, contributors Public profile photographs Legitimate interest (Art. 6.1.f) Public via EFMD materials
Accreditation Processes To evaluate and accredit educational institutions and programmes Institutional representatives, faculty members, administrative staff Names, contact information, professional qualifications, institutional data Contractual necessity (Art. 6.1.b) used for data needed to perform the accreditation contract with institutions; legitimate interest (Art. 6.1.f) used for internal assessments, reports, and panel discussions Accreditation committee members, external reviewers
International Projects Participation To manage and participate in international collaborative projects Project partners, participants, stakeholders Names, contact details, roles, project-related information Consent (Art. 6.1.a) used when individuals opt in to participate in surveys or non-contractual project parts; contractual necessity (Art. 6.1.b) used for managing project deliverables and partner roles Project consortium members, funding bodies
Special Interest Groups (SIGs) To facilitate focused discussions and knowledge sharing among members SIG members, facilitators Names, contact information, professional background, contributions Consent (Art. 6.1.a) used for optional contributions, publications or newsletters; legitimate interest (Art. 6.1.f) used for member participation, group coordination, and general communication SIG participants, EFMD staff
Global Focus Magazine Subscriptions To manage subscriptions and distribute the magazine to readers Subscribers, contributors Names, email addresses, subscription preferences Consent (Art. 6.1.a) used for marketing communications; legitimate interest (Art. 6.1.f) used for member participation and general communication Mailing service providers, Internal staff
EFMD Newsletter Subscriptions To manage subscriptions and distribute email campaigns Subscribers Names, email addresses, subscription preferences Consent (Art. 6.1.a) used for marketing communications; legitimate interest (Art. 6.1.f) used for member participation and general communication Mailing service providers, Internal staff
Societal Impact Initiatives To promote and assess initiatives aimed at creating positive societal impact Programme participants, beneficiaries, partners Names, contact information, participation details, feedback Consent (Art. 6.1.a) used when beneficiaries agree to be featured or provide feedback voluntarily; legitimate interest (Art. 6.1.f) used for analysis, reporting, or showcasing anonymised outcomes EFMD staff, partner organisations

 

If you would like more information on how we use cookies, we invite you to consult our cookie policy, available at the following addresses: https://www.efmdglobal.org/cookie-policy and https://globalfocusmagazine.com/cookie-policy/.


Your rights under GDPR

Right of access

If your data is processed by us, you have the right to obtain the following information:

  • Confirmation that your data will or will not be processed;
  • Purposes of processing;
  • Categories of personal data concerned;
  • The recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients established in third countries or international organisations. In this case, you have the right to be informed of the appropriate safeguards with regard to such transfers;
  • Where possible, the intended retention period for personal data or, where this is not possible, the criteria used to determine this period;
  • The existence of the right to request the rectification or erasure of personal data, or a restriction on the processing of personal data relating to the data subject, or the right to object to such processing;
  • The right to lodge a complaint with a supervisory authority;
  • Where personal data is not collected from you, any available information as to its source ;
  • The existence of automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR and, at least in such cases, useful information regarding the underlying logic, as well as the significance and intended consequences of such processing for the data subject.
  • A copy of the personal data being processed.

To exercise this right, please send an email to privacy@efmdglobal.org, indicating "GDPR - Right of access" as the subject, along with a copy of the front of your identity card.

Right to rectification

If you find that any of the personal data I process is inaccurate, you have the right to request that I rectify/complete it.

To exercise this right, please send us an email to privacy@efmdglobal.org, indicating "GDPR – right to rectification" as the subject of the email, together with a copy of the front of your identity card.

Right to erasure

You have the right to ask us to delete your personal data in the following cases:

  • Personal data is no longer required for the purposes for which it was collected or otherwise processed;
  • You object to the processing within the framework of your right to object (see, in the present charter, the point relating to the exercise of this right);
  • Your data is not processed in accordance with current legislation.
    Your personal data must be erased in order to comply with a legal obligation under Union law or the law of the Member State to which the data controller is subject.
  • To exercise this right, please send us an email to privacy@efmdglobal.org, indicating "GDPR – Right to erasure" as the subject of the email, together with a copy of the front of your identity card.

Right to restriction of processing

You have the right to obtain limitation of processing where any of the following apply:

  • You dispute the accuracy of your personal data (during the time it takes me to verify the accuracy of your personal data).
  • The treatment is contrary to current legislation.
  • We no longer require your personal data for processing; however, it is still necessary for the establishment, exercise, or defence of legal claims.
  • You have exercised your right to object (during the verification as to whether the legitimate reasons pursued by the data controller prevail over those of the data subject);
  • Where processing is restricted, your personal data will no longer be processed without your prior consent, except for storage, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important reasons of public interest of the Union or of a Member State.

We will keep you informed of any limitations, as well as any lifting of such limitations.

To exercise this right, please send us an email to privacy@efmdglobal.org, indicating "GDPR - Right to restriction of processing" as the subject of the email, together with a copy of the front of your identity card.

Right to object

You have the right to object at any time, for reasons relating to your particular situation, to the processing of your personal data based on our legitimate interests.

You do not have the right to prevent us from continuing to process your data:

  • If this is necessary for the performance of a contract concluded with you;
  • If required by law;
  • If the processing is necessary for the establishment, exercise or defence of legal claims.

To exercise this right, please send us an email to privacy@efmdglobal.org, indicating "GDPR – Right to object" as the subject of the email, together with a copy of the front of your identity card.

Right to data portability

You have the right to request the personal data we process in a structured, commonly used and machine-readable format.

We have the right to refuse this request for the processing of personal data necessary for the performance of a contract concluded with you.

To exercise this right, please send us an e-mail to privacy@efmdglobal.org, indicating "GDPR - Right to data portability" as the subject of the e-mail, together with a copy of the front of your identity card.


With Whom Do We Share Your Personal Data?

In the course of our activities, we may share your personal data. Of course, we do so in a way that ensures optimal protection of your personal data.

Sharing Your Personal Data with Service Providers, Processors, or Other Third Parties

In order to fulfil the data processing purposes described above, EFMD delegates certain processing tasks to third parties known as "processors". EFMD may also share your personal data with service providers and/or commercial and contractual partners who may be involved in these data processing operations (see sections above), and may therefore have access to your data.

Processor / Service Provider or Other Third Party Purpose Location
Email service providers Management and delivery of communications United States
Database management solution providers Secure storage and management of user data EU
Online payment solution providers Processing of online transactions United States
Infrastructure and system/application maintenance providers Technical support and system management EU
Hosting service providers Website and application hosting EU
Survey platform providers Collection and analysis of user feedback United States

 

Sharing with Public Authorities

We may also disclose your personal data to public authorities in response to lawful requests, including those related to national security or law enforcement (e.g., social security authorities, tax administrations, etc.).

In accordance with our legal obligations, particularly with regard to the prevention and detection of criminal offences, we may disclose your personal data:

  • upon request from a judicial or police authority, legal officer, or administrative authority;
  • in good faith, where such disclosure is required to comply with applicable laws or regulations;
  • to protect or defend our rights or those of other users of our services.

In the Context of a Transaction

In the context of a transaction such as a merger, acquisition, consolidation, or asset sale, we may share your personal data with the involved buyers or sellers.


Categories of processors of your personal data

Data Transfers within the European Economic Area (EEA)

For the purpose of certain processing operations, some personal data may be transferred within the European Economic Area (see section 4).

Within the EEA, personal data benefits from the same level of protection, as all EEA countries are subject to the GDPR or equivalent data protection rules.

Data Transfers Outside the European Economic Area

For the purpose of certain processing operations, some personal data may be transferred outside the European Economic Area (see section 4).

We transfer your personal data and/or grant access to it to processors, service providers, or third parties located in countries outside the EEA only where:

  • The country in question benefits from an adequacy decision by the European Commission, ensuring an adequate level of protection; or
  • Appropriate safeguards have been implemented in accordance with the GDPR, such as:
    • The use of Standard Contractual Clauses (SCCs) adopted by the European Commission for the transfer of personal data to processors established in third countries.
    • The adoption of Binding Corporate Rules (BCRs) approved by a competent supervisory authority; or
    • The adherence to an approved code of conduct is combined with enforceable and binding commitments by the recipient.

Any transfer of personal data to a country outside the EEA shall immediately cease if the adequacy decision or any equivalent safeguard relied upon for the transfer is invalidated or no longer fulfilled.


Would you like to contact us about this Privacy Policy and/or lodge a complaint with a data protection authority?

If you have any questions or suggestions regarding this Privacy Policy, please do not hesitate to contact us via our contact form, by email at privacy@efmdglobal.org, or by post at:

rue Gachard 88 - box 3
1050 Brussels
Belgium

We would be pleased to hear from you and will respond as promptly as possible.

Do You Believe That Your Personal Data Is Not Being Adequately Protected?

If you believe that EFMD is not processing your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian law, you have the right to lodge a complaint with:

  • The data protection authority of the EU Member State where you habitually reside, or
  • The data protection authority of the EU Member State where you work, or
  • The data protection authority of the EU Member State where the alleged GDPR violation occurred.

Lodging a Complaint with the Belgian Data Protection Authority (DPA)

  • By post:

Autorité de protection des données
Rue de la Presse, 35
1000 Brussels, Belgium

Lodging a Complaint with Another European Data Protection Authority

To submit a complaint to another national supervisory authority, please consult the list available here: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.