• Home
  • /
CSCE - Privacy policy

Privacy policy

This Privacy Notice explains how personal data is collected, used, shared and protected in connection with the website sanctionscertificate.eu and the Audit, Gap Report and Certification process offered by CSCE.

Certified Sanctions Compliance Entity (CSCE)

Effective date: 01.08.2026    |   Last updated: 11.08.2026


1. Introduction

Certified Sanctions Compliance Entity (« CSCE ») provides an independent Audit, Gap Report and Certification service that assesses whether a company’s sanctions compliance programme meets recognised EU and international standards.

We are accountable for how we handle personal data. We can demonstrate our compliance with data protection law on request, and we build privacy safeguards into our services and systems from the outset (privacy by design and by default).

This Notice applies to the personal data of visitors to our website, individuals who contact us, and Corporate Representatives involved in the Audit, Gap Report and Certification process described in Section 8.

2. Definitions

3. Who We Are

CSCE is operated by Rymarz, Zdort, Maruta, Wachta, Gasiński, Her i Wspólnicy, with its registered office at Prosta 18, 00-850 Warszawa, registered under number KRS 0000026546. You can contact us using the details set out in Section 17.

4. Scope of this Privacy Notice

This Notice applies to:

This Notice does not apply to third-party websites or services that we may link to, including social media platforms, which are governed by their own privacy notices.

5. Categories of Personal Data We Collect

We do not intentionally collect special category data (as defined in Article 9 GDPR) through the Website. We ask Clients not to include special category data in documents submitted for the Audit unless it is strictly necessary and relevant to the assessment.

6. Sources of Personal Data

We collect personal data:

Personal Data Received from Clients (Article 14 GDPR)

Where we receive personal data relating to Corporate Representatives from our Clients rather than directly from the individuals concerned, we process that data solely for the purposes described in this Notice. Such data typically consists of contact details (name, role, business email address, telephone number) and personal data appearing in documents and evidence submitted for the purposes of the Audit (see Section 5).

We expect our Clients, as the party best placed to do so, to ensure that the individuals concerned have been provided with all information required by applicable data protection law (including this Notice) before their personal data is disclosed to us, or to ensure that an applicable exemption applies.

Where it is not possible to provide this information directly to each individual, or doing so would involve a disproportionate effort – for example, because a large number of Corporate Representatives are named in documents submitted during an Audit – we rely on the exemption available under Article 14(5)(b) GDPR. In such cases, we make this Notice publicly available on the Website and take appropriate measures to protect the individuals’ rights, including by limiting our use of their data to the purposes described in this Notice.

7. Purposes and Legal Bases

The table below summarises why we process personal data and the legal basis we rely on. Retention periods are set out in Section 12.

Purpose

Legal basis

Responding to enquiries submitted through the contact form

Our legitimate interest in responding to enquiries addressed to us, including responding fully where information is provided on a voluntary basis (Art. 6(1)(f) GDPR). Where a specific enquiry amounts to a request to take steps, at your request, prior to entering into a contract, Art. 6(1)(b) GDPR applies instead

Providing the Audit, Gap Report and Certification services under the agreement concluded directly with the Client (e.g. where the Client is a sole trader)

Performance of a contract with the Client, or steps taken at the Client’s request prior to entering into a contract (Art. 6(1)(b) GDPR)

Providing the Audit, Gap Report and Certification services in relation to Corporate Representatives acting on behalf of a corporate Client

Our legitimate interest in performing the agreement concluded with our Client and in delivering the Certification service (Art. 6(1)(f) GDPR)

Compliance with legal obligations (e.g. accounting, tax, anti-money-laundering checks)

Compliance with a legal obligation (Art. 6(1)(c) GDPR)

Publication of Certification status, where applicable (see Section 8.5)

Consent (Art. 6(1)(a) GDPR), or our legitimate interest in maintaining a verifiable record of Certifications issued (Art. 6(1)(f) GDPR)

Website analytics (Google Analytics, Google Tag Manager)

Consent given through the cookie banner (Art. 6(1)(a) GDPR)

General correspondence not related to an existing contract

Our legitimate interest in responding to correspondence addressed to us (Art. 6(1)(f) GDPR)

Establishing, exercising or defending legal claims

Our legitimate interest in protecting our legal position (Art. 6(1)(f) GDPR)

 

8. The CSCE Certification Process

 

8.1 Overview

CSCE’s core service is a three-step process: an Audit of a company’s sanctions compliance controls, a Gap Report setting out prioritised findings and a remediation roadmap, and a Certification confirming the outcome of the assessment (Approved or Pending).

8.2 Audit

During the Audit, we process personal data of Corporate Representatives who act as contact points, provide information, or are named in documents and evidence submitted by the Client. This may include name, role, contact details, and personal data appearing incidentally in submitted materials.

8.3 Gap Report

The Gap Report is prepared on the basis of the Audit findings. It may reference the individuals responsible for specific controls or remediation actions within the Client organisation.

8.4 Certification

Following the Audit and, where applicable, remediation, we issue a certificate reflecting the Client’s compliance status (Approved or Pending).

8.5 Public Register

As part of the CSCE service, we may publish a public register of certified entities on the Website. The register is designed to allow third parties – such as counterparties, banks and regulators – to verify a Client’s Certification status (Approved or Pending) without contacting us directly. This register is one of the core features supporting the credibility of the CSCE Certification.

The register displays information about the certified entity itself. It is not designed to identify individual Corporate Representatives, and we do not include personal data of Corporate Representatives in the register.

The legal basis for maintaining the register is our legitimate interest in providing a transparent, verifiable record of Certifications issued, which is a core part of the value of the CSCE service (Art. 6(1)(f) GDPR); where a specific form of publication requires it, we instead rely on the Client’s consent (Art. 6(1)(a) GDPR). A Client may request removal of its entry from the register in accordance with the terms of its agreement with CSCE.

8.6 Communication with Clients

We use the contact details of Corporate Representatives to communicate about the progress and outcome of the Audit, Gap Report and Certification, and to respond to related queries.

8.7 Legal Claims

We may process personal data connected with the Certification relationship to establish, exercise or defend legal claims arising from or in connection with our services.

8.8 Confidentiality of Client Materials

Documents and evidence submitted during the Audit are treated as confidential business information. Access is limited to personnel involved in delivering the services and to authorised subcontractors bound by equivalent confidentiality obligations.

9. Cookies and Website Analytics

9.1 Cookie Notice

The Website uses cookies and similar technologies. Strictly necessary cookies are used without consent, as they are essential for the Website to function. All other categories require your consent, given through the cookie banner, and can be withdrawn at any time through the cookie settings link in the Website footer. We do not use advertising or behavioural profiling cookies.

9.2 Google Analytics 4

We use Google Analytics 4 to understand how visitors use the Website (e.g. page views, session duration, traffic sources), on an aggregated basis. IP anonymisation is enabled where supported by the tool. This processing takes place only with your consent.

9.3 Google Tag Manager

Google Tag Manager, where used, is a tag management system that loads Google Analytics and other approved scripts on the Website.

9.4 Contact Form

When you submit an enquiry through the contact form available on the Website, we process the personal data you provide, such as your name, business e-mail address and the content of your message, for the purpose of responding to your enquiry and communicating with you.

Providing the requested data is voluntary but necessary for us to respond to your enquiry.

9.5 LinkedIn

We maintain a LinkedIn company page. Any interaction with that page is also governed by LinkedIn’s own privacy policy. We do not control how LinkedIn processes personal data of visitors to our page.

9.6 Managing Your Cookie Preferences

You can change or withdraw your cookie consent at any time using the cookie settings link available in the Website footer, or by adjusting your browser settings.

10. Sharing Personal Data

 

We disclose personal data only to the extent necessary for the purposes described in this Notice, to the following categories of recipients, acting as our processors or, where relevant, as independent controllers:

We require our processors to protect personal data to a standard consistent with the GDPR. We may also disclose personal data to public authorities where required by law.

11. International Transfers

Personal data is primarily processed within the European Economic Area (EEA). Where personal data is transferred outside the EEA, this happens only on the basis of an appropriate transfer mechanism, and in accordance with the following approach.

11.1 Transfer assessment. Whenever personal data is transferred to a third country, we assess the legal basis for the transfer and, where required by law, implement appropriate supplementary technical and organisational measures to ensure a level of protection essentially equivalent to that guaranteed within the European Economic Area. This reflects the approach required following the Court of Justice’s Schrems II judgment.

11.2 Transfer mechanisms. Depending on the recipient, we rely on one or more of the following mechanisms:

You can request further information about the safeguards applicable to a specific transfer by contacting us using the details in Section 17.

12. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Notice, in accordance with the following schedule. The periods below reflect our proposed retention approach; please confirm them against CSCE’s operational and record-keeping practice before publication.

Category of data / purpose

Retention period

Contact form enquiries that do not lead to an engagement

For as long as necessary to respond to the enquiry and, where appropriate, for the period necessary to establish, exercise or defend legal claims in accordance with the applicable limitation periods under Polish law

Audit, Gap Report and Certification records (including personal data of Corporate Representatives)

For the duration of the Certificate’s validity, plus 6 years from the end of the engagement, reflecting the general limitation period for civil claims under Polish law

Accounting and tax records

5 years from the end of the calendar year in which the relevant tax obligation arose, in accordance with Polish tax law

Website analytics data (Google Analytics)

14 months, being the default Google Analytics retention setting, unless configured otherwise in our Google Analytics account

Records kept for the establishment, exercise or defence of legal claims

Until the relevant claims become time-barred (generally up to 6 years under Polish law, depending on the nature of the claim)

 

13. Security Measures

 

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including:

All personnel and contractors with access to personal data are subject to confidentiality obligations. We maintain a documented incident-response procedure, including notification of personal data breaches to the competent supervisory authority and affected individuals where required by law.

Privacy by design and by default. We take data protection into account when designing new features of the Website and the Audit, Gap Report and Certification process, and we configure our systems, by default, to collect and retain only the personal data necessary for the specific purpose in question.

14. Artificial Intelligence Statement

CSCE does not use artificial intelligence or automated means to make decisions producing legal effects concerning you, or similarly significantly affecting you, without meaningful human involvement. Any AI-assisted tools used internally to support the Audit are reviewed by a qualified sanctions compliance professional before any conclusion is reached or communicated to the Client.

15. Your Rights

Subject to the conditions set out in applicable data protection law, you have the right to:

To exercise any of these rights, please contact us using the details in Section 17. We may request additional information to verify your identity before responding to your request. We aim to respond within one month of receiving a verifiable request and will inform you if we need to extend this period.

16. International Business Customers and Corporate Representatives

Most of the individuals whose personal data we process in connection with the Audit, Gap Report and Certification process are Corporate Representatives acting in a professional capacity on behalf of a Client. The fact that our relationship with the Client is a business-to-business relationship does not affect the application of the GDPR or equivalent data protection law to the personal data of those individuals, and the rights described in Section 15 apply to them in full.

Where a Client is located outside the European Economic Area, we apply the same standard of protection to personal data provided in connection with the Audit, Gap Report and Certification process as we apply to personal data originating within the EEA.

17. Contact Details

18. Changes to this Privacy Notice

We may update this Notice from time to time to reflect changes in our practices or in applicable law. The date at the top of this Notice indicates when it was last updated. Where changes are material, we will take reasonable steps to bring them to your attention, including through the Website.

Résumé de la politique de confidentialité

Ce site utilise des cookies afin que nous puissions vous fournir la meilleure expérience utilisateur possible. Les informations sur les cookies sont stockées dans votre navigateur et remplissent des fonctions telles que vous reconnaître lorsque vous revenez sur notre site Web et aider notre équipe à comprendre les sections du site que vous trouvez les plus intéressantes et utiles.