Skip to Content

The Institute of Internal Auditors (IIA) Privacy Policy

Table of Contents

  1. Sources of Personal Data
  2. Types of Personal Data We Collect
  3. How We May Use Personal Data
  4. How We Disclose Personal Data
  5. Cookies
  6. Data Security and Data Retention
  7. Children’s Privacy
  8. External Links
  9. Contact Information
  10. Supplemental U.S. States Privacy Disclosures
  11. Supplemental Information for EEA, Switzerland, India, and the UK

The Institute of Internal Auditors, together with its subsidiaries and affiliates (collectively, “IIA,” “Company,” “us,” “we,” or “our”) is committed to protecting the privacy of Personal Data (i.e., information reasonably related to a specific individual).  This Privacy Notice describes how we process Personal Data collected through our websites, social media accounts, mobile applications, and other online interactions and communications such as email (collectively, our “Digital Properties”); in-person events and purchases; research activities; and other online and offline interactions.

This Privacy Notice applies to information we collect about individual consumers, such as general website visitors (“Individuals”); information we collect about the personnel of our business partners, including vendors and business customers, in business-to-business interactions (“Business Contacts”); and information about individuals who apply for a job with us (“Applicants”).  However, this Privacy Notice does not apply to information about our current/former employees, contractors, and other individuals who interact with us for similar employment-related purposes.  This Privacy Notice also does not apply to data that we handle on behalf of and under the instructions of our business customers.

Whenever you interact with us on behalf of another individual or entity, such as if you refer a friend to us, you must obtain their consent (or have the legal authority without consent) to share their Personal Data with us.

Changes: We may update this Privacy Notice from time to time.  Any updated Privacy Notice will be effective when posted.  We will post the last updated date of our policy notice at the top of this document. Please check this Privacy Notice periodically for updates.

1. Sources of Personal Data

We collect Personal Data about you from the following sources:

  1. Directly from you.  We may collect Personal Data you provide to us directly, such as when you visit our websites; contact us through our Digital Properties; interact with us in person; register for an event; create an account and are issued an IIA Global Account Number (“GAN”); apply for a certification; request information or contact member services; interact with us during the registration or payment process; create a post or response on social media; answer a poll or survey; sign up for offers or newsletters; place or customize orders; participate in research activities; submit a job application to us (including on a dedicated online talent management platform); participate in job interviews or job application tests or surveys; or otherwise communicate with us.
  2. Data collected automatically and through Cookies.  We may automatically collect information or inferences about you, such as through cookies, pixels, tags, scripts, and similar technologies (collectively, “Cookies”), when you interact with our Digital Properties.  This may include information about how you use and interact with our Digital Properties, information about your device, and internet usage information.  For more information about Cookies, please see our Cookies Policy.
  3. From third parties.  We may collect Personal Data from third parties, such as service and content providers; our affiliated companies and subsidiaries; your employer if they enroll you for IIA membership, events, or certifications; your university or college if they enroll you in an IIA certification program; your chapter or assigned institute if you attend an event hosted by the chapter/institute; business partners; data brokers; social media companies; companies or individuals who refer you to us an Applicant (including staffing or recruiting firms); in connection with background checks, where permitted by law; or other parties who interact with us.
  4. From publicly available sources. We may collect Personal Data about you from publicly available sources, such as public profiles and websites.

We may combine information that we receive from the various sources described in this Privacy Notice, including third party sources, and use or disclose the combined information for the purposes identified below.

2. Types of Personal Data We Collect

We may collect the following types of Personal Data about you.  Except as otherwise specified, we may collect this Personal Data from Individuals, Business Contacts, and Applicants.

  1. Identifiers, such as your name, email address, physical mailing address, telephone number (work, home, and cell), business contact information, and device identifiers (e.g., cookie IDs and IP address).
  2. Records about you, such as signatures; physical characteristics or a description of you; primary language spoken; social media information; the content, timing and method of communications you have with us, such as online chats, calls, text messages, and emails; payment and financial account information; information you share with or upload to our Digital Properties, such as reviews and comments; information you provide in polls and surveys; salary and wage information; background check information (about Applicants) where permitted by law; information from employment eligibility checks and disciplinary records (about Applicants); information collected from job interviews or job application tests (about Applicants).
  3. Demographic information, such as age (including birthdates) and gender.
  4. Commercial information, such as information related to your transactions; publications, courseware, and other products or services purchased, obtained, or considered; membership and subscription information; or other purchasing or consuming histories or tendencies.
  5. Internet or other electronic network activity information, such as your browsing history, search history, preference information (including marketing and purchasing preferences), device and online identifiers, account settings (including any default preferences), and other information regarding your interactions with and use of the Digital Properties.  For more information about Cookies, please see our Cookies Policy.
  6. Non-precise geolocation data, such as your location as derived from your IP address.
  7. Audio, electronic, visual, or other sensory information, such as photographs and audio/video recordings, including voicemails, recorded calls, and footage collected by security cameras in public areas of Company facilities if you visit our premises.
  8. Professional or employment-related information, such as current and past job title and positions held; job code; company name; work mailing address and email address; professional licenses, credentials, or affiliations; speaker biographies; job preferences (about Applicants); documentation required under immigration and employment laws (about Applicants); and other professional and resume information.
  9. Education information.
  10. Inferences drawn from any of the information we collect about your preferences or behavior, including to assess the level of interest in our products and services based on frequency of visits and contact and determine your preferred frequency for receiving offers.
  11. Sensitive Personal Data, including the following:
    1. Social Security number, driver’s license number, or passport number.
    2. Account log-in information.
    3. Racial or ethnic origin.
    4. Citizenship, citizenship status, or immigration status.
    5. Information about criminal convictions and offenses.

3. How We Use Personal Data

We may use Personal Data for the following purposes:

  1. To provide you or your company products and services (for Individuals and Business Contacts), such as making our Digital Properties and other products and services (such as certifications, courses, conferences and events, webinars, and publications) available to you; registering, verifying, maintaining, and servicing your account with us; providing member service; providing and delivering you the goods and services you request, including through use of artificial intelligence tools; providing customer service; processing or fulfilling orders and transactions (including processing payments); verifying customer information and eligibility for certain programs or benefits; communicating with you (including soliciting feedback or responding to requests, complaints, and inquiries); hosting informational webinars; and providing similar services or otherwise facilitating your relationship with us.
  2. To provide public-facing research content (for Individuals and Business Contacts), such as reports, webinars, infographics, presentations, podcasts, and board briefings, including through use of artificial intelligence tools.
  3. In connection with your job application (for Applicants), such as assessing your application, interview, and test results to determine your qualifications for employment and suitability for the position for which you have applied or other open positions; communicating with you concerning job openings (including with our affiliates) or your application; conducting pre-employment verification and screening; conducting background checks, where permitted by law; and dealing with any inquiry, challenge, or request for feedback received in relation to our recruitment and hiring decisions.
  4. For our internal business purposes, such as day-to-day operation of our business; maintaining internal business records, such as accounting, document management and similar activities, including through use of artificial intelligence tools; administering and supporting volunteer-led programs and governance activities (including, for example, the Nomination Committee and mentor programs), where volunteers may receive and use limited Personal Data in order to perform their roles; capturing and forming conclusions based on data provided during public comment periods as new and revised standards and guidance are introduced; improving our recruitment process; enforcing our policies and rules; management reporting; auditing; and IT security and administration.
  5. For our internal research and product improvement purposes, such as verifying or maintaining the quality or safety of our products or services; improving our products or services; designing new products and services; developing and improving algorithms, artificial intelligence or machine learning tools and models; conducting surveys to obtain information about professional practices and member preferences; evaluating engagement with and the effectiveness of our advertising or marketing efforts; and debugging and repairing errors with our systems, networks, and equipment.
  6. For legal, safety or security reasons, such as complying with legal, reporting, and similar requirements; investigating and responding to claims against us, our personnel, and our customers; auditing our compliance with law; for the establishment, exercise or defense of legal claims, including through use of artificial intelligence tools; protecting our customers’, and other third parties’ safety, property or rights; monitoring data integrity and managing the solutions used to process and protect data; detecting, preventing, and responding to security incidents and health and safety issues (including managing spread of communicable diseases); and monitoring and protecting against malicious, deceptive, fraudulent, or illegal activity.
  7. In connection with a corporate transaction, such as if we acquire assets of another business, or sell or transfer all or a portion of our business or assets including through a sale in connection with bankruptcy and other forms of corporate change.
  8. For marketing and targeted advertising, such as marketing our products or services (such as certifications, courses, conferences and events, webinars, and publications) or those of our affiliates, business partners, or other third parties.  For example, we may use Personal Data we collect to personalize advertising to you (including by developing product, brand, or services audiences and identifying you across devices/sites); to analyze interactions with our Digital Properties or us, including through use of artificial intelligence tools; or to send you newsletters, surveys, questionnaires, promotions, or information about events or webinars.  You can unsubscribe from our email marketing via the link in the email, by responding “STOP” to the text message, or by contacting us using the information in Section 9 (Contact Information) below.

We may use anonymized, de-identified, or aggregated information for any purpose permitted by law.

4. How We Disclose Personal Data

We may disclose Personal Data to third parties, including the categories of recipients described below:

  1. Affiliates and subsidiaries, including parent entities, corporate affiliates, subsidiaries, business units, and other companies that share common ownership.
  2. Chapters and Institutes. We may provide your personal information to your chapter or National Institute for confirmation of membership, certification, registration, or participation in IIA events and conferences.

Outside North America, your personal information is initially collected by your institute (which is a separate legal entity from IIA Global) and is entered into our customer relationship management platform located on an Azure Managed Service Provider in the United States.

  1. Service providers that work on our behalf to provide the products and services you request or support our relationship with you, such as IT providers, internet service providers, data and web hosting providers, software service providers, email marketing providers, payment processing companies, data analytics providers, and companies that provide business support services, financial administration, or event organization.
  2. Recruitment partners (for Applicants), such as travel agencies, recruitment firms, and background check vendors, where permitted by laws.
  3. Professional consultants, such as accountants, lawyers, financial advisors, and audit firms.
  4. Research partners, such as academics who perform research.
  5. Vendors necessary to complete transactions you request, such as shipping companies and logistics providers.
  6. Law enforcement, government agencies, and other recipients for legal, security, or safety purposes, such as when we share information to comply with law or legal requirements, to enforce or apply our Terms of Service and other agreements or policies; and to protect ours, our customers’, or third parties’ safety, property, or rights.
  7. Other entities in connection with a corporate transaction, such as if we acquire assets of another entity, or sell or transfer all or a portion of our business or assets including through a sale in connection with bankruptcy and other forms of corporate change.
  8. Business partners that may use Personal Data for their own purposes, such as:
  • Advertisers, ad platforms and networks, and social media platforms;
  • Third parties whose Cookies we use as described in our Cookie Policy
  • Commercial data partners to whom we make information available for their own marketing purposes; and
  • Partners who work with us on promotional opportunities, including co-branded products and services.

Where recipients use your Personal Data for their own purposes independently from us, we are not responsible for their privacy practices or personal data processing policies.  You should consult the privacy notices of those third-party services for details on their practices.

  1. The public, such as when you have an opportunity to make comments regarding us or our products that we may share with the public, including comments on our blog posts and reviews on our product pages.  Any Personal Data in comments, reviews, or other content that you share in public areas of our Digital Properties may be read, collected, or used by other users or the public.
  2. Entities to which you have consented to the disclosure.
  3. Third-Party Training Providers and Redirects. In certain circumstances, we may offer or facilitate access to training programs, certifications, or other services that are provided by third-party partners (“Training Providers”). When you enroll in, access, or are directed to such offerings, you may be redirected from our Digital Properties to a third party’s website, platform, or environment.

As part of this process, we may share certain Personal Data with the applicable Training Provider to enable your participation in the requested service. The categories of Personal Data shared may include identifiers (such as your name and contact information), account or membership details, and information necessary to register you for or provide the relevant training, certification, or related services.

We share this Personal Data for purposes such as facilitating your access to the Training Provider’s services, administering enrollment, supporting service delivery, and maintaining our business relationship with the Training Provider. Depending on the context, this processing may be based on our performance of a contract with you, our legitimate interests in providing and improving our services, or your consent, where required by applicable law.

Once your Personal Data is shared with a Training Provider and you are redirected to their platform, that Training Provider may collect, use, and disclose your Personal Data independently for its own purposes, subject to its own privacy notice and practices. We do not control and are not responsible for the privacy practices of such Training Providers when they act as independent data controllers.

We encourage you to review the applicable Training Provider’s privacy notice before providing your Personal Data or engaging with their services. Where available, we will provide links to the Training Provider’s privacy notice at or prior to the point of redirection.

Retention and deletion of Personal Data shared with a Training Provider will be governed by that Training Provider’s policies and applicable agreements between the Training Provider and us, unless otherwise specified. We remain responsible for Personal Data we retain in our own systems in accordance with this Privacy Notice.

5. Cookies

Our Digital Properties and authorized third parties use Cookies to collect information about you, your device, and how you interact with our Digital Properties via Cookies.  Please see our Cookie Policy available at https://www.theiia.org/en/cookie-policy/ for further information.

6. Data Security and Data Retention

Although we maintain reasonable security safeguards, no security measures or communications over the Internet can be 100% secure, and we cannot guarantee the security of your information.

Your Personal Data will be retained as long as necessary to fulfill the purposes we have outlined above unless we are required to do otherwise by applicable law.  This includes retaining your Personal Data to provide you with the products or services you have requested and interact with you; for purposes consistent with the Applicant-related context of our interactions (for Applicants); maintain our business relationship with you; improve our business and job recruitment practices over time; ensure the ongoing legality, safety and security of our services and relationships; or otherwise in accordance with our internal retention procedures.  Subject to applicable law, we may retain Applicant Personal Data for a limited period after you have applied for a job for which you were not selected to allow you to reapply.  Once you have terminated your relationship with us, we may retain your Personal Data in our systems and records to ensure adequate fulfillment of surviving provisions in terminated contracts or for other legitimate business purposes, such as to enable easier future user onboarding, demonstrate our business practices and contractual obligations, or provide you with information about our products and services in case of interest.  If you would like to know more about the retention periods applicable to your Personal Data, you can contact us using the details provided in the Contact Information below.

7. Children’s Privacy

Our Digital Properties are intended for individuals 18 years of age and older.  The Digital Properties are not directed at, marketed to, nor intended for, children under 18 years of age.  Generally, we do not knowingly collect any information, including Personal Data, from children under 18 years of age. Our student program is for those registered in a college or university. Please contact Privacy@theiia.org regarding concerns regarding the potential collection of your child’s information.

8. External Links

Our Digital Properties may contain links to external sites or other online services that we do not control, including those embedded in third-party advertisements or sponsor information.  We are not responsible for the privacy practices or data collection policies of such third-party services.  You should consult the privacy notices of those third-party services for details on their practices.

9. Contact Information

If you have questions regarding this Privacy Notice, please contact us at: Privacy@theiia.org

10. Supplemental U.S. States Privacy Disclosures

A. Data Subject Rights

Depending on our relationship with you (i.e., whether you are an Individual, a Business Contact, or Applicant), and in which state you reside within the United States (such as Colorado, Oregon, or Delaware), you may have certain rights regarding Personal Data that you can exercise by emailing us at privacy@theiia.org:

  • Right to Access. You may have the right to confirm whether we process your Personal Data and request access to such Personal Data. You may also request the specific pieces of Personal Data we have collected about you.  Oregon and Minnesota residents may also request a specific list of third parties to whom we disclose your Personal Data.
  • Right to Delete. You may have the right to request that we delete Personal Data that we have collected about you.
  • Right to Correct. You may have the right to request that we correct inaccurate Personal Data that we maintain about you.
  • Right to Opt Out of Sale and Targeted Advertising. You may have the right to opt out of selling and targeted advertising (as such terms are defined under applicable laws).   You can exercise the Right to Opt Out of Sale and Targeted Advertising by both accessing our cookie preference center and disabling all Cookies except Strictly Necessary Cookies emailing us at privacy@theiia.org.

To the extent required by law, we will honor opt-out preference signals sent in a format commonly used and recognized by businesses, such as an HTTP header field or JavaScript object.  We will process opt-out preference signals at the browser level.

We will not discriminate against you for exercising your privacy rights.

Authentication: To process rights requests, we may need to obtain information to locate you in our records or authenticate your request, such as your name, mailing address, email address, phone number, and relationship to the IIA.

Authorized Agents: Authorized agents may exercise rights on your behalf by submitting a request via privacy@theiia.org. We may request information to authenticate the authority of an authorized agent to submit a request or to locate your information in our records.

Appeal: If we deny your rights request, you may have the right to appeal.  To submit an appeal, contact us at privacy@theiia.org. We will inform you in writing our response to your appeal.

Nevada residents: Individuals may contact us at privacy@theiia.org to inquire about your right to opt out of the sale of your Personal Data.

B. Additional Data Processing Disclosures

In addition to the disclosures above, this section provides supplemental information about how we process Personal Data. 

Disclosure of Personal Data

We may “sell” or use the following categories of Personal Data for targeted advertising, as such terms are described in applicable law: Identifiers (Section 2.A); Records about you ((Section 2.B); Demographic information (Section 2.C); Commercial information (Section 2.D); Internet or other electronic network activity information (Section 2.E); Geolocation data (Section 2.F); Professional or employment-related information (Section 2.H); and Inferences (Section 2.I).

California Shine the : If you are a California resident, you may opt out of sharing your Personal Data subject to California Civil Code §1798.83 (the “Shine the Light law”) with third parties for those third parties’ direct marketing purposes by following all of the instructions for opting out of disclosures that may be a “sale” or targeted advertising in Section 10.A (Data Subject Rights).  

11. Supplemental Information for the EEA, Switzerland, India, and the UK

The following terms supplement the above disclosures with respect to our processing of EEA, Swiss, UK, and Indian Personal Data, and only apply to the extent that applicable data protection laws apply to our processing of your Personal Data, including (where applicable) the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the Swiss Federal Data Protection Act, and India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).

To the extent applicable, in the event of any conflict or inconsistency between the other parts of the Privacy Notice and the terms of this Section 11, this Section 11 shall govern and prevail with regard to the processing of such Personal Data.

A. Data Controller

Unless otherwise specified, the IIA entity responsible for the processing of your Personal Data as the controller is the entity that has the primary relationship with you. This may be the IIA group entity whose Digital Property you are viewing or using, that provides services to and accepts payment from you, that markets or provides promotional materials to you, or the primary IIA group entity in the region where you interact with us.

If you purchase services from us, The Institute of Internal Auditors, INC., will generally be the controller of your Personal Data. Depending on the context of your interaction with us, the following IIA group entities may also (jointly – e.g., when they co-organize an event together) or instead (independently – e.g., when separately providing a training to you, maintaining a Digital Property you are visiting, or marketing to you) be the controller of your Personal Data:

  • IIA QUALITY SERVICES, LLC
  • SINO CERTIFICATIONS, LLC
  • INTERNAL AUDIT FOUNDATION, INC.

You can ask for further details and contact all controllers at 1035 Greenwood Blvd., Suite 401, Lake Mary, FL 32746 or using the contact details in Section 9 (Contact Information) above and we will send your query to the right group entity.

For individuals located in India, the applicable IIA entity acting as “Data Fiduciary” (as that term is defined under the DPDP Act) will generally be the entity that determines the purpose and means of processing your Personal Data, consistent with the descriptions above.

B. Legal Bases for Processing

We process the following categories of personal data for the following processing purposes enumerated in the table below. In India, we process Personal Data in accordance with the DPDP Act, which primarily relies on your consent or certain legitimate uses permitted by law (such as compliance with legal obligations, responding to emergencies, or performing functions related to employment or provision of services). Where required by law, we will obtain your consent before processing your Personal Data.

Processing purposes

Categories of personal data

Legal bases

To provide you with products and services (Section 3.A)

  • Identifiers (Section 2.A)
  • Records about you (Section 2.B)
  • Commercial information (Section 2.D)
  • Professional or employment-related information (Section 2.H)
  • Performance of a contract to which you are a party or to take steps at your request before entering into a contract.
  • Legitimate interests as set out in the How We Use Personal Data section above.
  • Your consent, when appropriate.

To provide public-facing research content, such as reports, webinars, infographics, presentations, podcasts, and board briefings (Section 3. B

  • Identifiers (Section 2.A)
  • Records about you (Section 2.B)
  • Commercial information (Section 2.D)
  • Professional or employment-related information (Section 2.H)
  • Performance of a contract to which you are a party or to take steps at your request before entering into a contract.
  • Legitimate interests as set out in the How We Use Personal Data section above.
  • Your consent, when appropriate.

In connection with your job application (Section 3.C)

  • Identifiers (Section 2.A)
  • Records about you (Section 2.B)
  • Demographic information (Section 2.C) 
  • Commercial information (Section 2.D)
  • Professional or employment-related information (Section 2.H)
  • Education information (Section 2.I) 
  • Inferences (Section 2.J) 
  • Sensitive Personal Data (Section 2.K) 
  • Performance of a contract to which you are a party or taking steps at your request before entering into a contract.
  • Our legitimate interests in hiring qualified employees.
  • Your consent, when appropriate.
  • Compliance with legal obligations, where applicable.
  • Performance of rights and obligations in the field of employment.

For our internal business purposes (Section 3.D)

  • Identifiers (Section 2.A)
  • Commercial information (Section 2.D)

 

  • Performance of a contract to which you are a party or to take steps at your request before entering into a contract.
  • Compliance with a legal or statutory obligation to which we are subject
  • Legitimate interests as set out in the How We Use Personal Data section above.
  • Your consent, when appropriate

For our internal research and product improvement purposes (Section 3.E)

  • Commercial information (Section 2.D)
  • Demographic information (Section 2.C)
  • Internet or other electronic network activity information (Section 2.E)
  • Inferences (Section 2.J)
  • Legitimate interests as set out in the How We Use Personal Data section above.
  • Your consent, when appropriate

For legal, safety or security reasons

(Section 3.F)

  • Identifiers (Section 2.A)
  • Records about you (Section 2.B)
  • Commercial information (Section 2.D)
  • Sensitive Personal Data (Section 2.K)
  • Performance of a contract to which you are a party or to take steps at your request before entering into a contract.
  • Compliance with a legal or statutory obligation to which we are subject
  • Legitimate interests as set out in the How We Use Personal Data section above.
  • Establishment, exercise or defense of legal claims
  • Protection of vital interests
  • Your consent, when appropriate

In connection with a corporate transaction (Section 3.G)

  • Commercial information (Section 2.D)
  • Legitimate interests as set out in the How We Use Personal Data section above.

For marketing and targeted advertising (Section 3.H)

  • Identifiers (Section 2.A)
  • Demographic information (Section 2.C)
  • Commercial information (Section 2.D)
  • Internet or other electronic network activity information (Section 2.E)
  • Non-precise geolocation data (Section 2.F)
  • Inferences (Section 2.J)
  • Legitimate interests as set out in the How We Use Personal Data section above.
  • Your consent, when appropriate

 

C. Your Data Protection Rights

Under the conditions set by applicable data protection laws, including the DPDP Act where applicable, you may exercise certain rights regarding your Personal Data.

  • Right to Access. You have the right to obtain confirmation from us whether we are processing your Personal Data and related information, as well as the right to obtain a copy of your Personal Data undergoing processing.
  • Right to Data Portability. You may receive your Personal Data that you have provided to us in a structured, commonly used, and machine-readable format.
  • Right to Rectification. You have the right to request rectification of inaccurate Personal Data and to have incomplete data completed.
  • Right to Objection. You have the right to object to the processing of your Personal Data in certain cases.
  • Right to Restrict Processing. You may request that we restrict the processing of your Personal Data in certain cases.
  • Right to Erasure. You may request that we erase your Personal Data in certain cases.
  • Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority in the country where you reside or where the conduct that is the subject of the complaint occurred.  You can also lodge a complaint with us using the information in Section 9 (Contact Information) if UK laws apply to you and you think we have infringed our UK data protection obligations when handling your Personal Data.
  • Right to Refuse or Withdraw Consent. In case we ask for your consent to process your Personal Data, you are free to refuse to give it.  If you have given your consent, you may withdraw it at any time without any adverse consequences.  The lawfulness of any processing of your Personal Data that occurred prior to the withdrawal of your consent will not be affected.
  • Right to Not Be Subject to Automated Decision-making. You have the right not to be subject to a decision based solely on automated processing and to be given more information about why any such decision was made.
  • Right to Access Information (India). You have the right to obtain information about the Personal Data we process about you, including the categories of data processed, the purposes of processing, and the identities of recipients with whom your data has been shared, subject to applicable law.
  • Right to Correction and Erasure (India). You have the right to request correction, completion, updating, or erasure of your Personal Data, subject to applicable legal requirements.
  • Right to Grievance Redressal (India). You have the right to have your grievances addressed by us within a reasonable time period. If your concerns are not resolved, you may escalate them in accordance with applicable law.
  • Right to Nominate (India). You have the right to nominate another individual who can exercise your rights on your behalf in the event of death or incapacity, as permitted under the DPDP Act.

You may exercise these rights by contacting us using the details in the Contact Information section above.

D. International Transfers of Personal Data

Due to the global nature of our operations, some of the recipients mentioned in the How We Disclose Personal Data section of this Privacy Notice may be located in countries outside the EEA, Switzerland, the UK, or India that do not provide an adequate level of data protection as defined by data protection laws in the EEA, Switzerland, the UK, and India.  Certain third countries have been officially recognized by the European Commission, Switzerland, and the UK Secretary of State as providing an adequate level of protection.  Transfers within our corporate group or to third parties located in third countries that have not received such recognition take place using an acceptable data transfer mechanism, such as the EU and/or UK Standard Contractual Clauses, Binding Corporate Rules, approved Codes of Conduct and Certifications, on the basis of permissible statutory derogations, or any other valid data transfer mechanism issued by the EEA, Swiss or UK authorities. For individuals located in India, cross-border transfers will be undertaken in accordance with the DPDP Act and any applicable government restrictions or requirements.

Please reach out to us using the contact information in the Contact Information section above if you want to receive further information about how we transfer Personal Data or, where available, a copy of the relevant data transfer mechanism.

E. Additional Information for Individuals in India

If you are located in India, the following additional terms apply to our processing of your Personal Data:

  • Consent-Based Processing. We will seek your consent where required under the DPDP Act before collecting or processing your Personal Data. You may withdraw your consent at any time, subject to legal or contractual restrictions.
  • Purpose Limitation. We will process your Personal Data only for the purposes described in this Privacy Notice or as otherwise permitted by applicable law.
  • Data Retention. We will retain your Personal Data only for as long as necessary to fulfill the purposes for which it was collected or as required under applicable law.
  • Grievance Officer. You may contact us using the details in Section 9 (Contact Information) to raise any concerns regarding the processing of your Personal Data. We will address such concerns in accordance with applicable law.
  • Cross-Border Transfers. Your Personal Data may be transferred outside India in accordance with applicable law. Where required, we will ensure that appropriate safeguards are in place.

EU/UK Representative

Where required under applicable data protection laws, including the European Union General Data Protection Regulation (“GDPR”) and the United Kingdom GDPR, The Institute of Internal Auditors has appointed representatives in the European Union and the United Kingdom.

European Union Representative

United Kingdom Representative

You may contact our EU or UK representative, as applicable, for matters related to the processing of your personal data or to exercise your rights under applicable data protection laws.

For the avoidance of doubt, these representatives are designated contact points for data protection inquiries. All requests received by the EU or UK representative will be forwarded to The Institute of Internal Auditors for response and handling.