Privacy & Cookie Policy.
Effective date: July 2026 · Data controller: Global AI Standards Body (GAISB) · Privacy contact: privacy@gaisb.org
Manage your choices at any time: Cookie Settings · Do Not Sell or Share My Personal Information
This policy explains how GAISB collects, uses, and protects personal information across gaisb.org and the GAISB certification ecosystem, and how we meet the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
Who we are
GAISB is the vendor-neutral, practitioner-governed standards body for the AI profession. We define the GAISB Common Body of Knowledge, govern the GAISB certification programs, operate the certification examinations at exams.gaisb.org, and maintain the Public Verification Registry at registry.gaisb.org. Enrollment is delivered through Prompt Atlas, the official community of GAISB.
What we collect
- Candidates and certificants — name, email, country, enrollment and program records, exam registrations and results, capstone submissions (including video presentations where a program requires them), certification status, credential ID, and renewal/continuing-education records.
- Registry records (public) — for every issued credential: holder name, credential earned, credential ID, status (active, suspended, revoked), and validity dates. Publication in the registry is intrinsic to the credential — it is what makes it verifiable.
- Prospective candidates and site visitors — contact details you submit (inquiries, newsletter), and technical data (IP address, browser, pages viewed, cookie identifiers per your consent).
- Employers and verifiers — search queries against the public registry (not linked to verified identity).
- Commercial data — orders and payments are processed by our enrollment and payment partners (including Prompt Atlas as official enrollment partner); GAISB does not store full card numbers.
Why we use it, and our lawful bases (GDPR)
- Delivering programs, exams, and certification; issuing and maintaining credentials — performance of a contract (Art. 6(1)(b)).
- Publishing credential records to the Public Verification Registry — legitimate interests (Art. 6(1)(f)): enabling employers, regulators, and the public to verify professional credentials; and the certification agreement each certificant accepts.
- Exam integrity, proctoring, and misconduct investigations — legitimate interests and contract.
- Invoicing, tax, accounting — legal obligation (Art. 6(1)(c)).
- Newsletters, analytics and marketing cookies — consent (Art. 6(1)(a)), withdrawable at any time.
Cookies
We ask for consent before setting anything non-essential. Change your choice any time via Cookie Settings.
- Strictly necessary — site function, security, and recording your consent choice. Always active.
- Functional — preferences such as language or region. Opt-in.
- Analytics — aggregated usage statistics to improve the site. Opt-in.
- Marketing — campaign measurement and program communications. Opt-in; disabled by a “Do Not Sell or Share” opt-out or a Global Privacy Control signal.
This site loads typefaces from Google Fonts, which involves transmitting your IP address to Google when fonts load.
The Public Verification Registry
The registry exists so that anyone, anywhere can verify a GAISB credential without intermediaries. By completing certification, certificants agree to publication of their credential record (name, credential, ID, status, dates). Registry records are retained for the life of the credential, including suspension and revocation entries, because the integrity of the profession depends on a complete public record. Certificants may request removal of their record by writing to privacy@gaisb.org; removal ends public verifiability of the credential, and we will explain the consequences before acting. Disciplinary entries are governed by the Code of Professional Conduct and its due-process procedures.
Sharing — and what we don’t do
GAISB does not sell personal information and does not share it for cross-context behavioral advertising. We disclose personal information only to: service providers under contract (hosting, enrollment and payment via Prompt Atlas and payment processors, exam delivery and proctoring, e-signature, email); capstone reviewers bound by confidentiality (for programs with panel review); and authorities where required by law. Public registry data is, by design, public.
International transfers
We operate globally. Where personal data is transferred out of the EEA, UK, or Canada, we use appropriate safeguards, including Standard Contractual Clauses and equivalent processor commitments.
Retention
Enrollment, exam, and certification records: for the life of the credential plus applicable limitation periods (these records substantiate the credential itself). Capstone videos: for the review and appeal period, then deleted or anonymized. Financial records: per tax law. Marketing data: until you withdraw consent. Consent records: for as long as your choice is in force.
Your rights — GDPR (EU & UK)
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests; where processing rests on consent you may withdraw it at any time. Note that erasure of certification records ends the verifiability of your credential (see the Registry section). Write to privacy@gaisb.org; we respond within one month. You may lodge a complaint with your supervisory authority.
Your rights — CCPA/CPRA (California)
You have the right to know, delete, and correct your personal information; to opt out of sale or sharing (we do not sell — you may still record a formal opt-out via Do Not Sell or Share My Personal Information); to limit use of sensitive personal information (we use none beyond what the services require); and to non-discrimination for exercising any right. We honor the Global Privacy Control signal automatically. Submit requests to privacy@gaisb.org with “California Privacy Request” in the subject; authorized agents accepted with verification; response within 45 days (extendable once with notice).
Your rights — PIPEDA (Canada)
We follow PIPEDA’s ten fair information principles — accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Request access or correction, or withdraw consent (subject to legal and contractual limits), at privacy@gaisb.org. If unsatisfied, you may contact the Office of the Privacy Commissioner of Canada.
Security
Administrative, technical, and organizational safeguards appropriate to sensitivity: encryption in transit, access controls, least-privilege administration, exam-integrity firewalls (instructors cannot access or proctor examinations), and processor due diligence. Capstone videos are accessible only to the assigned review panel.
Children
Our services are directed to professionals. We do not knowingly collect personal information from anyone under 16; if you believe a minor has provided data, contact privacy@gaisb.org and we will delete it.
Changes & contact
Material changes will be posted here with a new effective date and, where required, renewed consent. Questions, requests, or complaints: privacy@gaisb.org.