Information Collection Scope
Collects personal data and usage data from website and communications.
🌐 www.isc2.org
Describes collection of personal data including sensitive exam biometrics (palm vein pattern) but notes ISC2 does not store it; explains data sharing with third parties and security measures, though lacks detailed safeguards for all data types.
References GDPR, CCPA, and provides user rights (access, correction, deletion, opt-out) and a DPO contact; however, some rights are vaguely described and opt-out mechanisms rely on browser settings.
Provides user rights and opt-out options, but includes one-sided clauses (e.g., unilateral policy changes, broad data use for marketing) and limited recourse beyond contacting support or DPO.
Uses plain language in many sections but is lengthy and includes legal jargon; discloses data uses and third-party sharing, but risks and data retention periods are not fully clear.
- The policy allows ISC2 to change the privacy terms unilaterally, and continued use of the website is deemed acceptance of those changes, which may reduce user control over their data.
- It collects broad categories of personal information, including gender and date of birth, which may not be necessary for the services provided.
- The policy states that usage data like IP address and browsing behavior "generally" does not identify individuals, but does not guarantee this, and it may be linked with personal information without clear user consent.
- There is ambiguous language around the use of personal information for advertising and direct marketing, with no clear opt-in mechanism for such processing.
- The policy allows for the disclosure of personal information to third parties for marketing, but only requires consent "if you have consented," which could mean consent is assumed unless the user actively opts out.
- It mentions sharing information with affiliates and contractors who are bound by confidentiality, but does not specify how users can verify or limit these disclosures.
- The policy collects palm vein pattern biometric data through exam vendors, and while it says ISC2 does not store raw data, the vendor retains algorithmic data for five years, which may raise privacy risks.
- The transfer of personal data to the United States is stated without adequate explanation of safeguards for users from other jurisdictions, such as the EEA, UK, or Switzerland.
- The policy does not clearly define the legal basis for processing personal data for legitimate interests in many cases, leaving users uncertain about how their data is used.
- Users are given the right to opt out of marketing only after data collection, rather than requiring explicit consent before such use.
- The policy relies on cookies for behavioral tracking and targeted advertising, but only mentions consent as the legal basis for non-essential cookies in the EEA, UK, and Switzerland, not globally.
- The section on "Your Rights" does not clearly explain how users outside the EEA can exercise rights like access, correction, or deletion, and the process depends on email requests.
- The policy states that user contributions may remain on cached or archived pages even after deletion, which could lead to unintended data persistence.
- It is unclear how the policy handles data retention periods for most personal information, with the exception of biometric data retained for five years.
- The policy collects sensitive information like ethnicity and date of birth during exam registration, but does not specify why this is necessary or how it is protected.
- The use of social media cookies and sharing with social media platforms is mentioned, but users are not given clear control over this data sharing.
- The policy does not provide a straightforward mechanism for users to withdraw consent for processing, especially for data collected for multiple purposes.
- The "URL Links" section disclaims responsibility for third-party sites, but users may be misled into thinking those sites are covered by this policy.
- The notice for individuals in the EEA is separate, but the main body of the policy does not consistently apply those higher standards globally.
- The policy states that ISC2 may not accommodate requests to change information if it believes the change would violate a law or cause incorrectness, which could be used to deny legitimate requests.
Collects personal data and usage data from website and communications.
Uses data to provide services, personalize experience, and prevent fraud.
Shares data with contractors, affiliates, and marketing partners with consent.
Users can access, correct, or delete personal information upon request.
Transfers data to the US with adequate safeguards for EEA users.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free