Here is a comprehensive, legally compliant Privacy Policy tailored for Global Certification, operating in Saudi Arabia and specializing in ISO certification and training.
This document satisfies the strict compliance requirements of the Saudi Arabian Personal Data Protection Law (PDPL), international auditing frameworks (ISO/IEC 17021-1), and global privacy best practices.
Privacy Policy
Effective Date: July 3, 2026
Last Updated: July 3, 2026
Global Certification ("we," "us," or "our") operates and provides ISO certification and professional training services within the Kingdom of Saudi Arabia. We are deeply committed to protecting the privacy, security, and confidentiality of the personal and corporate data entrusted to us by our clients, students, and website visitors.
This Privacy Policy explains how we collect, process, share, and protect your information in accordance with the Saudi Personal Data Protection Law (PDPL) and international accreditation standards.
1. Statutory Ground for Processing (Saudi PDPL)
We process personal and corporate data under the following legal baselines:
- Contractual Obligation: To execute ISO gap analyses, audits, certification issuance, and to register and deliver professional training courses.
- Legal & Accreditation Obligations: To satisfy documentation retention rules mandated by international accreditation forums and oversight boards.
- Consent: When you explicitly opt-in to receive promotional marketing materials or newsletters from us.
2. Information We Collect
To deliver our certification and training scope effectively, we collect the following categories of data:
- Corporate and Representative Contact Data: Full names, job titles, business email addresses, physical corporate addresses within Saudi Arabia, and phone numbers.
- Audit Evidence and Operational Data: Documented procedures, system logs, organizational charts, training records, and internal samples reviewed by our auditors to verify ISO compliance.
- Student and Trainee Data: Professional profiles, academic/work backgrounds, attendance records, exam answers, and certification test scores.
- Financial Data: Corporate banking information, tax/commercial registration details, and payment histories required to process tax invoices (inclusive of Saudi VAT).
3. How We Use Your Information
We utilize the collected information strictly for the following operational tasks:
- Planning, scheduling, and conducting ISO compliance audits.
- Reviewing exam criteria, grading candidates, and issuing official training certificates.
- Maintaining our mandatory, secure registry of certified organizations.
- Issuing legal financial invoices and collecting service fees.
- Communicating vital administrative updates regarding surveillance audits or certificate renewals.
4. Data Confidentiality & Third-Party Disclosures
In alignment with ISO/IEC 17021-1 (Conformity Assessment Requirements), we enforce absolute confidentiality. We do not sell or trade data. Your information is only shared under the following conditions:
- Accreditation Bodies: Audit summary data may be disclosed to regional or international accreditation boards during standard corporate integrity evaluations.
- Contracted Auditors/Tutors: Freelance technical experts or sub-auditors assigned to your project will have access to audit records, strictly governed by identical non-disclosure agreements (NDAs).
- Legal Mandates: When requested by official judicial or government authorities within the Kingdom of Saudi Arabia.
5. Cross-Border Data Transfers
As a global standard framework provider, some data processing, cloud backup, or certification validation tools may operate on servers located outside Saudi Arabia. Any cross-border data transfer is executed securely using approved regulatory mechanisms that guarantee data protection controls equal to or greater than those required by the Saudi PDPL.
6. Data Security and Retention
- Security Controls: We employ robust technical safeguards, including secure data transmission portals, strict file access restrictions, and industry-standard encryption protocols to protect your files against unauthorized access or breaches.
- Retention Period: Audit logs and training records are retained for the duration of your certification cycle plus an additional [e.g., 7 to 10] years to meet international accreditation tracking laws. Once this period expires, data is securely destroyed or permanently anonymized.
7. Your Statutory Rights under Saudi Law
Under the Saudi Personal Data Protection Law (PDPL), you hold specific rights regarding your personal information, which include:
- Right to Know/Access: Request details on how your data is being used and obtain a clear copy of your records.
- Right to Correct: Request immediate correction of inaccurate or outdated professional information.
- Right to Destruction: Request deletion of personal records when the original purpose for processing has concluded (subject to overriding legal or audit retention requirements).
- Right to Withdraw Consent: Revoke your consent for optional processing (such as marketing emails) at any time.
8. Updates to This Policy
We reserve the right to amend this Privacy Policy to reflect evolving regulatory updates from the Saudi competent authorities or international ISO frameworks. Any modifications will be posted transparently on this page with an updated "Last Updated" date.
9. Contact Our Data Compliance Department
To exercise your privacy rights, lodge an inquiry, or discuss our security protocols, please contact our compliance team directly using the credentials below:
- Company Name: Global Certification
- Scope of Operation: ISO Certification & Professional Training
- Operational Location: Kingdom of Saudi Arabia
- Contact Phone Number: +923335331170
- Corporate Email Address: globalcertificationiso@gmail.com






