Who we are
The Institute for European Intelligence and Security is a non-profit professional body for covert human intelligence. This is our website.
Sending information
When visitors interact with this site or contact us using a form, certain data is collected in order for the site to function. For example, the visitor’s IP address and browser user agent string is used to help spam detection.
Our website automatically gathers some impersonal information from your computer such as your general location, when and what you viewed. This is collected to provide some insight into our visitors (e.g what pages to people like to visit most, from what countries and when?) so we can improve our site and services. None of the data our site gathers is specific enough to identify an individual.
In addition to that data collected by automated parts of the site, we deliberately collect data to deliver Institute services. For example, contact details, security, medical, financial and other personal information. We do not sign you up to third-party services or provide them with your personal data without your consent.
However, any information you choose to upload to the site must be passed over a public network. We do everything we can to secure and encrypt transmissions, but the internet and telecommunications networks are not secure spaces. So please be aware of the inherent vulnerabilities of the internet and your computer and think before you send!
Media
If you send images to us, you should avoid uploading images with embedded location data (EXIF GPS) included. This location data can be extracted from images to reveal where they were taken.
Cookies
Cookies are very small text files that are stored on your computer when you visit some websites. We use cookies to help identify your computer so we can tailor your user experience and track changes you have made to parts of our sites (e.g. e-learning entries, messages and other interactive elements). Our public website statistics program also uses cookies so we can tell what pages you find most interesting so we can improve the performance of our site.
You can prevent your browser storing cookies on your computer, but this may stop our website from functioning properly if you block functional cookies. Our cookies are designed to provide you with the best user experience. We don’t pass on cookie information to advertisers or government agencies using that data to track our visitors.
Embedded content from other websites
Pages on this site may include embedded content (e.g. videos, images, articles, news feeds, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
We do our best to reduce and restrict such content unless we are sure of the integrity of the source. For example, our pages have drawn upon NATO, UN and EUIBA news feeds in the past. So those sites could record the IP addresses and other browser data of visitors to our site as if they had visited theirs.
However, we cannot control the activity of all users of our site and ask users to be mindful when browsing.
How we categorise your data
Complies with data protection law and follows good data protection practices to protect the rights of individuals. We store and process data in a transparent way and aim to protect ourselves from the risks of data breach. As a result data relating to identifiable individuals is categorised as:
- Classified information: Information which may be harmful to national or international security if disclosed. For example, the identities and alias’ of covert operatives or channels on which they communicate.
- Sensitive information: Information which may be harmful to the data subject if inappropriately disclosed such as medical conditions, political or religions opinions, criminal convictions (inc. alleged offences), lifestyle profiles, financial stability, opinions/analysis etc.
- Personal information: Information that is privately held or permanently linked to an individual such as full names, education, training, home postal addresses, personal e-mail addresses, home telephone numbers, etc.
- Non-personal information: Information that is publicly available or not permanently linked to an individual such as work addresses, office telephone numbers/extensions, professional e-mail addresses, etc.
Our rules for processing your data
Information provided to the Institute shall be treated in full accordance with the EU regulations and standards. As such personal data will be subject to general data protection guidelines, including the following:
- Only those with a need to know should be able to access personal data.
- Personal information should be formally requested and access authorised.
- Access will not be granted to personal data until data protection training has been received.
- Personal data must be kept secure.
- Computers should be locked when unattended.
- Strong passwords must be used, regularly changed and never shared.
- Anyone possessing personal data is obligated to protect against unauthorised disclosure.
- Personal data should be regularly reviewed and updated. If it is out of date or no longer required it should be safely disposed of in a manner that would prevent recovery.
- Whenever possible personal data should be stored using pseudonymisation or anonymisation.
- If unsure about any aspect of data protection request assistance from the data controller.
- Personal data shall only be collected for a specific and lawful purpose.
- Any personal data shall be processed fairly and lawfully, ensuring collection is adequate, relevant and not excessive.
- There is a duty to ensure personal data is accurate and kept up to date.
- Personal data shall not be transferred outside of the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection.
- Personal data shall not be held longer than is necessary.
- Personal data must be protected proportionally and processed in accordance with the rights of data subjects.
- All data should be stored securely in a compartmentalised fashion so as to prevent inadvertent unauthorised disclosure.
- Physical files should not be left unattended but locked in a drawer or filing cabinet when not in use.
- Physical files should be shredded when no longer required.
- Electronic files should be protected from unauthorised access, accidental deletion and malicious hacking attempts.
- If electronic files are stored on removable media, these should be locked away securely when not in use.
- Electronic files should only be stored on designated drives and servers and not uploaded to cloud services.
- Servers containing personal data should not be co-located in general office space.
- Electronic data should be backed up incrementally and backups should be tested annually.
- Electronic data should never be saved directly to mobile devices.
- All servers and computers containing personal data should be protected by approved security software.
- Personal data should be securely communicated, encrypted before being transferred electronically and accessed centrally.
- Personal data should never be saved to private computers.
- Personal data must only be held in as many places as is necessary. Unnecessary duplicates must not be created.
- Every opportunity should be taken to verify and validate data.
- The Institute must, where possible, enable others to update their own information and that data should be updated as inaccuracies are discovered.
For legal and security reasons the Institute is required hold some sensitive data on data subjects (e.g. in order to satisfy legal obligations to conduct security checks on delegates). Sensitive information is subject to rigorous security standards and may only be used in the interests of public safety and security. The use of such information for ancillary support (e.g. routine administration, public relations, advertising and other marketing activities) is strictly prohibited.
When processing this sensitive data, the Institute and its personnel are typically subject to national security, law-enforcement, research/analysis or third-party exemptions.
How we use your data
Personal information is typically processed by the Institute to facilitate, protect and promote the:
- Interests of international security.
- Prevention of public disorder, international crime and terrorism.
- Maintenance of judicial authority and the rule of law.
- Protection of the fundamental rights and freedoms others.
Personal and non-personal information may be processed in the legitimate interests of the Institute when those interests are not overridden by the interests of the fundamental rights and freedoms of the data subject. However, it is strictly prohibited for sensitive information to be processed for ancillary support purposes (e.g. routine administration, public relations, advertising and other marketing activities).
By voluntarily submitting personal data to the Institute the data subject explicitly grants the Institute permission to process it for the purpose for which it was originally supplied and to retain it for as long as may be required to fulfil that purpose and satisfy any legal obligations relating to it. But the Institute will never make decisions that may affect an individual based solely upon the automated analysis of personal data.
How long we retain your data
Some personal information will be held indefinitely. For example, we need to hold data on qualifications in order to provide academic references and verify qualifications. Whereas data on financial transactions wer are required to hold for seven years.
We will not store data longer than is necessary and you may be ask us to delete or correct your data. However, this may have unforseen consequences we need to discuss with you before we comply with your instructions.
Some data we are not permitted to destroy for reasons on national law or international security. There are special rules for the handling of classified information, including its retention and destruction. Also, we may not be able to delete some information if it has an significant impact on our work or others.
However, in the vast majority of cases we can work with you to either remove all the data you want. In cases where that isn’t possible, we will set up systems and processes where the data we are required to retain will be purged at the earliest possible opportunity.
What rights you have over your data
All individuals who are the subject of personal data held by the Institute are entitled to:
- Ask what information the Institute holds about them and why.
- Ask how to gain access to it.
- Be informed how to keep it up to date.
- Be informed how the Institute is meeting its data protection obligations.
Requests for information should be made via this site to the data controller. The data controller can supply standard request forms but individuals do not have to use these.
Once a request for personal data is made by a data subject the data controller must provide the relevant data within 1 month.
Prior to releasing subject information individuals may be required to pay an administrative fee proportional to the expenses incurred in processing the request. The identity of an individual making a request must always be verified prior to the release of any personal information.
In limited circumstances, a subject may make a request to prevent processing if it causes damage or distress. To do so a request must state what the objection is, how processing is unwarranted and reasons why handling is causing damage or distress.
The Inspectorate is the next line of appeal available for dispute resolution above the Institute. In limited circumstances complaints may also be lodged with the relevant national data protection or supervisory authorities. To find out where your relevant authority is located please contact the data controller who will aim to address your query within 14 days.
Who data is shared with
The Institute takes security and secrecy very seriously so that confidence in our security and discretion is maintained. However, processing data often requires sharing parts of it with a variety of open and closed sources.
Government agencies, private individuals and organisations may all be consulted in order to fufil the purpose for which your data was originally supplied.
What happens in a data breach
The Institute complies with the relevant parts of European data protection regulation, common security policies and ISO27001 information security standards. But data breaches can still occur. Any such data breach likely to result in risks to the rights and freedoms of individuals will be reported to the relevant authority within 72 hours of the data controller becoming aware of it.
Furthermore, the Institute will immediately initiate an investigation and take all remediary action necessary to secure systems and processes. This will include making data subjects aware of any compromised information.
If you are aware of any vulnerability in our site that threatens your privacy or security, please contact us and we will action it as a priority.
Other related policies
Risk assessment and mitigation is required whenever specific risks to the rights and freedoms of data subjects are identified. Recurring high risk functions have been identified in legal disclosure, security vetting and unsolicited communication. All risks have been mitigated or reduced through the application of security procedures. Further details are available upon request.
Additional EU security regulations surround the use of sensitive, privileged and classified material and form the basis of the Institutes standard operating procedure for the protection of that material.
Additional policies regarding the terms and conditions of sale and use of services provided by the Institute are provided in the Institutes general terms and conditions.
How to contact us
Everyone who works for or with the Institute has some responsibility for ensuring data is collected, stored and handled properly. However, some roles have key areas of responsibility:
- The central committee is ultimately responsible for ensuring that the Institute meets its legal obligations.
- The data controller is responsible for communicating key information to the central committee, policy, procedure, training, advice, formal requests, contracts, agreements, statements, security compliance and audit.
The Chair of the Institute is a designated data controller for the purposes of this policy and relating legislation. However, any key representative of the Institute may be reached via the contact page on this site.
| Policy reference: | IEIS/0202/180524/1 |
| Policy owner: | Head of Counterintelligence & Security |
| Authorised date: | 14 May 2018 |
| Operational date: | 25 May 2018 |
| Review schedule: | Annual |