Confidentiality Policy.
How PCI protects sensitive candidate, examination and project information.
Overview
PCI handles information that matters — candidate data, examination content, and information shared in confidence. This policy ensures it is accessed only on a need-to-know basis, stored securely, and never misused.
At a glance
What is protected
- Candidate personal and eligibility information
- Examination items, item banks and scoring keys
- Investigation, appeals and complaints records
- Information shared in confidence by partners or employers
Handling and obligations
PCI applies this consistently and documents what it does, so the approach can be checked and improved. Final detail is published as the institute matures, and is governed by the related policies below.
Common questions
Who can access confidential information?
Only authorised people, on a need-to-know basis.
How is personal data treated?
Under the data-protection policy.
What if confidentiality is breached?
It is handled under the investigation procedure.
Why this matters
Clear policies matter because they are how fairness is made real. A certification body that treats everyone consistently — on eligibility, conduct, security, impartiality and appeals — is one whose decisions can be trusted, and whose credential therefore means the same thing for everyone who holds it. These pages set out those commitments plainly.
PCI states its position honestly, including where processes are still being established. The aim is not legal cover for its own sake but genuine, transparent governance — the substance that lets a credential, and the body behind it, earn and keep professional trust.
- Substance over marketing
- Fair, transparent process
- Honesty about our status
- Responsible, governed use of AI
Founding-stage document · Version 1.0 — effective date to be confirmed · Reviewed under PCI governance. PCI makes no claims of accreditation or recognition beyond what is true today.
How to read this policy
Scope. Unless a section says otherwise, PCI policies apply to candidates, members, credential-holders and, where stated, to staff, volunteers and committee members. Where a specific policy and a general one overlap, the specific policy prevails.
Review. Policies carry a review cycle and are amended through the governance framework; the version published on this site is the version in force. Material changes are announced before they take effect.
Questions and concerns. If anything here is unclear, ask us — we would rather answer a question than process a dispute. Formal routes exist too: appeals, complaints and the ethics code.
Related. See all policies & documents for the complete set, including examination rules, certification policy and the candidate handbook.
How need-to-know works in practice
Need-to-know is a discipline, not a slogan. Access follows role and task — never seniority, and never curiosity.
Access follows the task
A person handling your application sees your application. They do not thereby see exam content, appeal files or anyone else's records.
Everyone is bound
Staff, committee members, examiners and subject-matter experts all accept confidentiality obligations before touching sensitive material — obligations that survive their departure.
Exam content sits highest
Items, item banks and scoring keys are the most tightly held material PCI has, because a single leak devalues every honest result.
What you can expect of PCI
If you apply, sit an examination, appeal or raise a complaint, these commitments apply to you:
- Your application and results are seen only by those processing them;
- Your results are not shared with an employer or sponsor without your consent;
- Appeal, complaint and investigation records are restricted to the people the process genuinely requires;
- Information you share in confidence is used for the purpose you shared it, and personal data is handled under the data protection policy.
The honest limits of confidentiality
Confidentiality is strong but not absolute, and it is fairer to say so plainly. Information may be disclosed with your consent, where the law requires it, or where there is an imminent risk to safety. Aggregate statistics — such as examination statistics PCI has committed to publish once there is a meaningful cohort — are only ever released in forms that cannot identify an individual. Records are kept no longer than their purpose requires, under the records retention policy. And a suspected breach of confidentiality is itself treated seriously: it is examined under the investigation procedure, and affected people are informed where appropriate.