Student membership enrolment is now open Begin enrolment →
PCI AIProject Controls
Institute Global, Inc.
Global Standards & Certification Body for Project Professionals
Legal

Privacy.

A plain-language summary of how PCI handles your personal information.

Overview

This is PCI’s plain-language privacy summary: what we collect, why, and the control you have. The full detail sits in the data-protection policy, but the principle is simple — collect only what’s needed, use it fairly, and protect it.

At a glance

Collect
Only what’s needed
Use
Clear purposes
Protect
Kept secure
Retain
No longer than needed
Rights
Respected

In short

  • We collect personal data to deliver certification fairly
  • We use it only for clear, stated purposes
  • We keep it secure and no longer than necessary
  • We respect your rights over your data
In practice

Where the detail lives

PCI applies this consistently and documents what it does, so the approach can be checked and improved. Final detail is published as the institute matures.

Common questions

What data do you collect?

Information needed for eligibility, exams, and issuing and verifying credentials.

How long do you keep it?

Only as long as necessary; see records retention.

Where is the full policy?

Why this matters

Clear policies matter because they are how fairness is made real. A certification body that treats everyone consistently — on eligibility, conduct, security, impartiality and appeals — is one whose decisions can be trusted, and whose credential therefore means the same thing for everyone who holds it. These pages set out those commitments plainly.

PCI states its position honestly, including where processes are still being established. The aim is not legal cover for its own sake but genuine, transparent governance — the substance that lets a credential, and the body behind it, earn and keep professional trust.

  • Substance over marketing
  • Fair, transparent process
  • Honesty about our status
  • Responsible, governed use of AI
Using PCI policies

How to read this policy

Scope. Unless a section says otherwise, PCI policies apply to candidates, members, credential-holders and, where stated, to staff, volunteers and committee members. Where a specific policy and a general one overlap, the specific policy prevails.

Review. Policies carry a review cycle and are amended through the governance framework; the version published on this site is the version in force. Material changes are announced before they take effect.

Questions and concerns. If anything here is unclear, ask us — we would rather answer a question than process a dispute. Formal routes exist too: appeals, complaints and the ethics code.

Related. See all policies & documents for the complete set, including examination rules, certification policy and the candidate handbook.

Exercising your rights

How to ask, correct or remove

Rights are only real if the route to using them is clear. To see the information PCI holds about you, correct something inaccurate, or ask for deletion, use the contact page and say plainly what you need. Expect three things:

  • We verify that the request genuinely comes from you before acting on it — the same protection you would want against someone else asking about your data.
  • Requests are acknowledged promptly and handled within the published window.
  • Where we cannot fully comply — for example, certification records that must be retained to protect the integrity of issued credentials — we tell you exactly what is retained and why, rather than declining silently.
Where it is sensitive

Privacy in examinations and certification

The most sensitive processing PCI does happens around examinations: identity is verified before every sitting, and remote examinations involve proctoring. This processing exists for one reason — protecting the integrity of every candidate's result — and it is done to the minimum needed for that purpose. Candidates are told what will be collected before they sit, not after. What is gathered, how long it is kept and who may see it are governed by the full data protection policy, which is the controlling document whenever this summary and the detail could be read differently.

The document set

How the privacy documents fit together

This summary

The plain-language layer: what we collect, why, and the control you have — written to be read in minutes, not decoded with a glossary.

The full policy

The data protection policy carries the complete detail and takes precedence. If you need the exact position on any point, that is the document to cite.

Cookies and retention

Site cookies are covered separately in the cookie policy, and how long each category of record is kept is set by the records retention schedule.

When any of these documents changes in a way that matters — a new purpose for data, a change to retention, a new category collected — we flag the change rather than editing quietly. A privacy summary you have to re-read defensively every month is not a plain-language summary at all.

The legal basis

Our lawful basis, sensitive data and transfers — in short

In plain terms: we process your data to deliver certification under our agreement with you and our legitimate interest in a trustworthy credential, and we rely on your consent for the newsletter and for the sensitive parts of examinations. The full legal detail — the Article 6 basis for each purpose — is set out in the data-protection policy.

  • Proctoring and identity checks. Remote exams record webcam video, audio, a room scan and your screen, and identity checks capture an image of your government photo ID and a check-in photo. Because this is sensitive information, we ask for your separate, explicit consent before the first recording (Article 9(2)(a)), keep proctoring recordings for 12 months and delete ID images within 90 days.
  • International transfers. PCI is US-based and serves the UK and EU, so data may move across borders. Where it leaves the UK or EEA we use Standard Contractual Clauses and the UK IDTA as safeguards, and we maintain Article 27 representatives for the EU and the UK.
  • Your rights. You can access, correct, delete, port or restrict your data, withdraw consent, and complain to a supervisory authority such as the ICO — see the data-protection policy.

Stay in the loop

Occasional updates on the standard, exam windows and new chapters. No noise, unsubscribe anytime.