Data Protection.
How PCI collects, uses and protects personal data — lawfully and transparently.
Overview
PCI handles personal data to deliver certification fairly. This policy explains the principles it follows: collecting only what is needed, using it for clear purposes, protecting it, and respecting individuals’ rights.
At a glance
Our data-protection principles
- Collect only the personal data needed for certification
- Use it only for clear, stated purposes
- Keep it secure and retain it no longer than necessary
- Respect individuals’ rights over their data
Security and retention
PCI applies this consistently and documents what it does, so the approach can be checked and improved. Final detail is published as the institute matures, and is governed by the related policies below.
Common questions
What data does PCI collect?
Information needed to assess eligibility, deliver exams, and issue and verify credentials.
How long is it kept?
Under the records-retention policy, only as long as necessary.
Is exam monitoring data protected?
Yes — used only for integrity and handled under this policy.
Why this matters
Clear policies matter because they are how fairness is made real. A certification body that treats everyone consistently — on eligibility, conduct, security, impartiality and appeals — is one whose decisions can be trusted, and whose credential therefore means the same thing for everyone who holds it. These pages set out those commitments plainly.
PCI states its position honestly, including where processes are still being established. The aim is not legal cover for its own sake but genuine, transparent governance — the substance that lets a credential, and the body behind it, earn and keep professional trust.
- Substance over marketing
- Fair, transparent process
- Honesty about our status
- Responsible, governed use of AI
Founding-stage document · Version 1.0 — effective date to be confirmed · Reviewed under PCI governance. PCI makes no claims of accreditation or recognition beyond what is true today.
Where your data enters and why
Data protection is easier to judge when you can see exactly where personal data enters the system. At PCI there are four main points, each with its own clear purpose:
Enrolment and account
Name and contact details to create your record, plus credentials you set yourself via a secure link — PCI never emails you a plain password.
Examination
Identity information to confirm the person examined is the person certified, alongside your results — see candidate identification for how verification works.
Certification and verification
Records that support your credential's status over time, so it can be confirmed to those you authorise.
Enquiries and support
Correspondence you send, kept so your question can be answered properly and follow-ups make sense.
The minimisation principle applies at every one of these points: if a field is not needed for the stated purpose, it is not collected.
Rights you can exercise
Individuals have rights over their personal data, and PCI's job is to make exercising them straightforward rather than adversarial:
- Access — ask what personal data PCI holds about you and receive a copy
- Correction — have inaccurate or outdated information put right
- Deletion — request erasure where retention rules and legitimate certification needs allow it
- Objection and restriction — challenge or limit particular uses of your data
- Portability — receive the personal data you provided in a structured, commonly used, machine-readable format, or have it transmitted to another controller where technically feasible (Article 20)
- Withdraw consent — where processing relies on your consent, including the proctoring and biometric processing described below, withdraw it at any time, without affecting processing already carried out
- Complain to a supervisory authority — lodge a complaint with your data-protection regulator, including the UK Information Commissioner's Office (ICO) or your EU lead supervisory authority (Article 13(2)(d))
Requests go through the contact page. They are acknowledged promptly, and identity is verified before any data is disclosed — a safeguard for you, since it prevents someone else obtaining your records by pretending to be you.
How data is protected and retired
Protection rests on limiting access as much as on technology: personal data is available on a need-to-know basis tied to a specific function, not to anyone with a PCI role. Data also has an end of life. Retention periods follow the published records retention schedule, and when a purpose is exhausted the data is deleted or anonymised rather than kept by default. One honest exception is worth naming: certification records are retained for longer than most data, because the ability to verify a credential years after award depends on the underlying record still existing. Keeping those records is part of what makes the credential worth holding.
Keep going
Your data, our purposes
We process personal data for defined purposes only: administering enrolment, examination and credentials; maintaining the registry; meeting legal duties; and communicating about your own status. We do not sell personal data, and marketing is separate and consent-based.
You may request access, correction, or deletion where law and legitimate records-keeping allow — certification bodies must retain some decision records to protect the meaning of every certificate, per the retention policy. Requests and questions: contact us.
Why we are allowed to process your data
For individuals protected by the UK GDPR, the EU GDPR or comparable laws, PCI relies on a specific lawful basis under Article 6 for each purpose:
- Delivering certification — administering enrolment, examinations, and issuing and verifying credentials: Article 6(1)(b) (performance of a contract with you), supported by Article 6(1)(f) (our legitimate interest in protecting the integrity and meaning of the credential).
- Identity verification and examination integrity, including remote proctoring: Article 6(1)(b) and Article 6(1)(f), and — for the special-category elements described below — your explicit consent under Article 9(2)(a).
- Legal and regulatory compliance, and establishing or defending legal claims: Article 6(1)(c) (legal obligation) and Article 6(1)(f).
- Newsletter and optional marketing: Article 6(1)(a) (consent), which you can withdraw at any time.
Proctoring, biometrics and identity documents
Verifying identity and supervising a remote examination involves sensitive personal information, so we set out exactly what is involved — your consent can only be informed if it is specific. Before your first recorded session we ask for your separate, explicit consent, and you may decline or withdraw it (which may mean choosing an alternative sitting arrangement where one is available).
What is captured. During a remotely proctored exam we may record webcam video, microphone audio, a scan of your room and your on-screen activity for the duration of the session. To confirm identity we capture an image of your government-issued photo ID and a photo of you at check-in, and process the facial-image comparison between them. Where that comparison produces biometric identifiers, and where an ID image reveals special categories of data, it is treated as special-category or sensitive personal information.
Lawful condition and notice. This processing is carried out only on the basis of your explicit consent (Article 9(2)(a) GDPR) and, where US biometric-privacy laws such as the Illinois Biometric Information Privacy Act (BIPA) apply, under a written release. We use it solely to verify identity and protect examination integrity; we do not sell it, and we disclose it only to the proctoring and identity processors listed below under a data-processing agreement.
Who can access it. Access is limited, on a need-to-know basis, to the proctoring vendor and authorised PCI integrity reviewers.
Retention. Proctoring recordings (webcam video, audio, room scan and screen capture) are retained for 12 months after the examination to allow integrity review and appeals, then permanently deleted. Government-issued ID images and check-in photos are retained only as long as needed to verify identity and resolve any review, and in any case deleted within 90 days of the examination. Any biometric identifiers derived for the identity comparison are deleted once verification is complete and no later than these periods.
Who we share data with
PCI does not sell personal data. To run certification we rely on a small number of service providers (processors), each engaged under a written data-processing agreement and permitted to use your data only on our instructions:
- Payment processing — a third-party payment processor (Stripe) to take application, examination and membership fees. PCI does not store full card numbers.
- Remote proctoring and identity verification — a proctoring vendor that captures and reviews the examination recordings and identity checks described above.
- Email delivery — an email service provider used to send account, examination and transactional messages, and, with consent, the newsletter.
- Hosting and secure storage — cloud hosting and storage providers that hold our systems, records and ID images.
We may also disclose data where required by law, or to establish, exercise or defend legal claims. The categories above are the recipients relevant to most candidates; the specific providers in use are confirmed on request through the contact page.
Transfers outside the UK and EEA, and your representatives
PCI is established in the United States and serves candidates worldwide, including in the United Kingdom and the European Union. This means personal data may be transferred to, and processed in, countries whose laws differ from your own. Where we transfer data from the UK or EEA to a country without an adequacy decision, we rely on appropriate safeguards under Chapter V of the GDPR — principally the European Commission's Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum (IDTA) — together with supplementary technical and organisational measures.
As a US-based organisation offering services to individuals in the EU and the UK, PCI maintains representatives under Article 27 of the EU GDPR and the UK GDPR. You may contact our EU and UK representatives, or request their details, through the contact page or at hello@projectcontrolsinstitute.org, and you may raise any transfer concern with them or with your supervisory authority.
California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you additional rights. PCI does not sell or share your personal information as those terms are defined, and we do not use sensitive personal information for any purpose beyond verifying identity and protecting examination integrity. You have the right to:
- Know and access the categories and specific pieces of personal information we collect, and request a copy.
- Delete personal information we hold, subject to the certification-record exceptions set out above.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information — though PCI does not sell or share it.
- Limit the use of sensitive personal information to what is necessary to provide the service.
- Not be discriminated against for exercising any of these rights.
To exercise any of these rights, use the contact page; we verify your identity before acting on a request.
How long we keep each kind of record
We keep personal data only as long as the purpose requires. The full schedule is published in the records-retention policy; the main periods are:
- Account and contact details — for the life of your account and up to 24 months after it is closed.
- Examination results and certification decisions — for the life of the credential and up to 10 years after it lapses, to support verification through the live public register.
- Proctoring recordings — 12 months after the examination.
- Government-issued ID images and check-in photos — deleted within 90 days of the examination.
- Appeals, complaints and disciplinary records — up to 6 years.
- Enquiries and support correspondence — up to 24 months.
- Newsletter and marketing consent — until you withdraw consent.