Last updated: 24 August 2026
The UK Cybersecurity Standards Council ("UKCSC", "we", "us") is committed to protecting your personal data. This policy explains how we collect, use, and safeguard information when you visit our website or interact with our services.
The UKCSC is an independent private standards body registered in England and Wales. We are the data controller for personal data collected through this website. We are not affiliated with any UK government department.
We process data to respond to enquiries, provide membership and certification services, maintain assessment integrity, issue and verify certificates, prevent abuse, secure the platform, meet legal and accounting obligations, and send opted-in communications. The usual lawful bases are contract, legitimate interests, legal obligation, and consent where consent is required. We do not sell personal data.
Optional AI and people-search features may use approved external processors. Do not submit sensitive personal data that is not necessary for the requested service. Where processing involves an international transfer, appropriate contractual or legally recognised safeguards are applied.
Under UK GDPR, you have the right to access, correct, or erase your personal data. Please contact the UKCSC Data Protection Contact at council@ukcybersec.com first so we can investigate and resolve your concern promptly. You may also contact the Information Commissioner’s Office if you remain dissatisfied.
Contact enquiries are retained for 24 months. Account and certification records are retained for the duration of the relationship plus 6 years where required for legal, accounting, fraud-prevention, or certification-verification purposes. Uploaded evidence and AI job inputs are retained only for the relevant application, review, dispute, and audit period, then securely deleted or anonymised. Security logs are retained for up to 12 months unless a longer period is required for an investigation.
For any data protection queries: council@ukcybersec.com