Certified Sanctions Compliance Entity (CSCE)
Effective date: 01.08.2026 | Last updated: 11.08.2026
1. Introduction
Certified Sanctions Compliance Entity (“CSCE”) provides an independent Audit, Gap Report and Certification service that assesses whether a company’s sanctions compliance programme meets recognised EU and international standards.
We are accountable for how we handle personal data. We can demonstrate our compliance with data protection law on request, and we build privacy safeguards into our services and systems from the outset (privacy by design and by default).
This Notice applies to the personal data of visitors to our website, individuals who contact us, and Corporate Representatives involved in the Audit, Gap Report and Certification process described in Section 8.
2. Definitions
- CSCE, we, us or our means Certified Sanctions Compliance Entity, the controller of the personal data described in this Notice.
- Website means sanctionscertificate.eu.
- Client means a company that engages CSCE for an Audit, Gap Report and/or Certification.
- Corporate Representative means an individual acting on behalf of a Client or prospective Client, such as an employee, officer or authorised representative.
- Audit means the sanctions-compliance audit described in Section 8.
- Gap Report means the gap report described in Section 8.
- Certification means the certification described in Section 8, which results in an “Approved” or “Pending” status.
- Personal Data, Processing, Controller and Processor have the meaning given to them in the GDPR.
- GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
3. Who We Are
CSCE is operated by Rymarz, Zdort, Maruta, Wachta, Gasiński, Her i Wspólnicy, with its registered office at Prosta 18, 00-850 Warszawa, registered under number KRS 0000026546. You can contact us using the details set out in Section 17.
4. Scope of this Privacy Notice
This Notice applies to:
- visitors to the Website;
- individuals who submit an enquiry through our contact form or otherwise contact us;
- Corporate Representatives of Clients and prospective Clients involved in the Audit, Gap Report and Certification process.
This Notice does not apply to third-party websites or services that we may link to, including social media platforms, which are governed by their own privacy notices.
5. Categories of Personal Data We Collect
- Contact details: name, surname, business email address, company name, job title, telephone number.
- Enquiry content: any information included in a message submitted through the contact form or sent to us by email.
- Engagement data: personal data of Corporate Representatives provided in connection with an Audit, such as name, role, email address, and personal data contained in documents or evidence submitted for the purposes of the Audit.
- Technical data: IP address, browser and device information, and information collected through cookies and similar technologies (see Section 9).
We do not intentionally collect special category data (as defined in Article 9 GDPR) through the Website. We ask Clients not to include special category data in documents submitted for the Audit unless it is strictly necessary and relevant to the assessment.
6. Sources of Personal Data
We collect personal data:
- directly from you, when you complete the contact form, correspond with us, or provide documents for the Audit;
- from the Client you represent, where a Client submits personal data of its employees or representatives in connection with the Audit, Gap Report and Certification process;
- automatically, through cookies and similar technologies when you visit the Website (see Section 9).
Personal Data Received from Clients (Article 14 GDPR)
Where we receive personal data relating to Corporate Representatives from our Clients rather than directly from the individuals concerned, we process that data solely for the purposes described in this Notice. Such data typically consists of contact details (name, role, business email address, telephone number) and personal data appearing in documents and evidence submitted for the purposes of the Audit (see Section 5).
We expect our Clients, as the party best placed to do so, to ensure that the individuals concerned have been provided with all information required by applicable data protection law (including this Notice) before their personal data is disclosed to us, or to ensure that an applicable exemption applies.
Where it is not possible to provide this information directly to each individual, or doing so would involve a disproportionate effort – for example, because a large number of Corporate Representatives are named in documents submitted during an Audit – we rely on the exemption available under Article 14(5)(b) GDPR. In such cases, we make this Notice publicly available on the Website and take appropriate measures to protect the individuals’ rights, including by limiting our use of their data to the purposes described in this Notice.
7. Purposes and Legal Bases
The table below summarises why we process personal data and the legal basis we rely on. Retention periods are set out in Section 12.
|
Purpose |
Legal basis |
|
Responding to enquiries submitted through the contact form |
Our legitimate interest in responding to enquiries addressed to us, including responding fully where information is provided on a voluntary basis (Art. 6(1)(f) GDPR). Where a specific enquiry amounts to a request to take steps, at your request, prior to entering into a contract, Art. 6(1)(b) GDPR applies instead |
|
Providing the Audit, Gap Report and Certification services under the agreement concluded directly with the Client (e.g. where the Client is a sole trader) |
Performance of a contract with the Client, or steps taken at the Client’s request prior to entering into a contract (Art. 6(1)(b) GDPR) |
|
Providing the Audit, Gap Report and Certification services in relation to Corporate Representatives acting on behalf of a corporate Client |
Our legitimate interest in performing the agreement concluded with our Client and in delivering the Certification service (Art. 6(1)(f) GDPR) |
|
Compliance with legal obligations (e.g. accounting, tax, anti-money-laundering checks) |
Compliance with a legal obligation (Art. 6(1)(c) GDPR) |
|
Publication of Certification status, where applicable (see Section 8.5) |
Consent (Art. 6(1)(a) GDPR), or our legitimate interest in maintaining a verifiable record of Certifications issued (Art. 6(1)(f) GDPR) |
|
Website analytics (Google Analytics, Google Tag Manager) |
Consent given through the cookie banner (Art. 6(1)(a) GDPR) |
|
General correspondence not related to an existing contract |
Our legitimate interest in responding to correspondence addressed to us (Art. 6(1)(f) GDPR) |
|
Establishing, exercising or defending legal claims |
Our legitimate interest in protecting our legal position (Art. 6(1)(f) GDPR) |
8. The CSCE Certification Process
8.1 Overview
CSCE’s core service is a three-step process: an Audit of a company’s sanctions compliance controls, a Gap Report setting out prioritised findings and a remediation roadmap, and a Certification confirming the outcome of the assessment (Approved or Pending).
8.2 Audit
During the Audit, we process personal data of Corporate Representatives who act as contact points, provide information, or are named in documents and evidence submitted by the Client. This may include name, role, contact details, and personal data appearing incidentally in submitted materials.
8.3 Gap Report
The Gap Report is prepared on the basis of the Audit findings. It may reference the individuals responsible for specific controls or remediation actions within the Client organisation.
8.4 Certification
Following the Audit and, where applicable, remediation, we issue a certificate reflecting the Client’s compliance status (Approved or Pending).
8.5 Public Register
As part of the CSCE service, we may publish a public register of certified entities on the Website. The register is designed to allow third parties – such as counterparties, banks and regulators – to verify a Client’s Certification status (Approved or Pending) without contacting us directly. This register is one of the core features supporting the credibility of the CSCE Certification.
The register displays information about the certified entity itself. It is not designed to identify individual Corporate Representatives, and we do not include personal data of Corporate Representatives in the register.
The legal basis for maintaining the register is our legitimate interest in providing a transparent, verifiable record of Certifications issued, which is a core part of the value of the CSCE service (Art. 6(1)(f) GDPR); where a specific form of publication requires it, we instead rely on the Client’s consent (Art. 6(1)(a) GDPR). A Client may request removal of its entry from the register in accordance with the terms of its agreement with CSCE.
8.6 Communication with Clients
We use the contact details of Corporate Representatives to communicate about the progress and outcome of the Audit, Gap Report and Certification, and to respond to related queries.
8.7 Legal Claims
We may process personal data connected with the Certification relationship to establish, exercise or defend legal claims arising from or in connection with our services.
8.8 Confidentiality of Client Materials
Documents and evidence submitted during the Audit are treated as confidential business information. Access is limited to personnel involved in delivering the services and to authorised subcontractors bound by equivalent confidentiality obligations.
9. Cookies and Website Analytics
9.1 Cookie Notice
The Website uses cookies and similar technologies. Strictly necessary cookies are used without consent, as they are essential for the Website to function. All other categories require your consent, given through the cookie banner, and can be withdrawn at any time through the cookie settings link in the Website footer. We do not use advertising or behavioural profiling cookies.
9.2 Google Analytics 4
We use Google Analytics 4 to understand how visitors use the Website (e.g. page views, session duration, traffic sources), on an aggregated basis. IP anonymisation is enabled where supported by the tool. This processing takes place only with your consent.
9.3 Google Tag Manager
Google Tag Manager, where used, is a tag management system that loads Google Analytics and other approved scripts on the Website.
9.4 Contact Form
When you submit an enquiry through the contact form available on the Website, we process the personal data you provide, such as your name, business e-mail address and the content of your message, for the purpose of responding to your enquiry and communicating with you.
Providing the requested data is voluntary but necessary for us to respond to your enquiry.
9.5 LinkedIn
We maintain a LinkedIn company page. Any interaction with that page is also governed by LinkedIn’s own privacy policy. We do not control how LinkedIn processes personal data of visitors to our page.
9.6 Managing Your Cookie Preferences
You can change or withdraw your cookie consent at any time using the cookie settings link available in the Website footer, or by adjusting your browser settings.
10. Sharing Personal Data
We disclose personal data only to the extent necessary for the purposes described in this Notice, to the following categories of recipients, acting as our processors or, where relevant, as independent controllers:
- hosting providers;
- cloud service providers;
- CRM system providers;
- certification management system providers;
- IT service providers;
- law firms;
- auditors;
- accounting service providers;
- analytics service providers;
- cybersecurity service providers.
We require our processors to protect personal data to a standard consistent with the GDPR. We may also disclose personal data to public authorities where required by law.
11. International Transfers
Personal data is primarily processed within the European Economic Area (EEA). Where personal data is transferred outside the EEA, this happens only on the basis of an appropriate transfer mechanism, and in accordance with the following approach.
11.1 Transfer assessment. Whenever personal data is transferred to a third country, we assess the legal basis for the transfer and, where required by law, implement appropriate supplementary technical and organisational measures to ensure a level of protection essentially equivalent to that guaranteed within the European Economic Area. This reflects the approach required following the Court of Justice’s Schrems II judgment.
11.2 Transfer mechanisms. Depending on the recipient, we rely on one or more of the following mechanisms:
- EU-U.S. Data Privacy Framework (“DPF”): used where the recipient is a certified DPF participant, such as Google LLC for Google Analytics and (where applicable) Google Tag Manager;
- Standard Contractual Clauses (“SCC”): used where the recipient is not covered by an adequacy decision or the DPF;
- Transfer Impact Assessments (“TIA”): carried out where required to evaluate whether the chosen transfer mechanism provides adequate protection in the recipient’s jurisdiction, and to identify any supplementary measures needed.
You can request further information about the safeguards applicable to a specific transfer by contacting us using the details in Section 17.
12. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Notice, in accordance with the following schedule. The periods below reflect our proposed retention approach; please confirm them against CSCE’s operational and record-keeping practice before publication.
|
Category of data / purpose |
Retention period |
|
Contact form enquiries that do not lead to an engagement |
For as long as necessary to respond to the enquiry and, where appropriate, for the period necessary to establish, exercise or defend legal claims in accordance with the applicable limitation periods under Polish law |
|
Audit, Gap Report and Certification records (including personal data of Corporate Representatives) |
For the duration of the Certificate’s validity, plus 6 years from the end of the engagement, reflecting the general limitation period for civil claims under Polish law |
|
Accounting and tax records |
5 years from the end of the calendar year in which the relevant tax obligation arose, in accordance with Polish tax law |
|
Website analytics data (Google Analytics) |
14 months, being the default Google Analytics retention setting, unless configured otherwise in our Google Analytics account |
|
Records kept for the establishment, exercise or defence of legal claims |
Until the relevant claims become time-barred (generally up to 6 years under Polish law, depending on the nature of the claim) |
13. Security Measures
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including:
- access controls and encryption in transit;
- access on a least-privilege basis, limited to personnel who need it to perform their role;
- multi-factor authentication for access to key systems;
- logging of access to key systems;
- periodic security reviews of our systems and processes.
All personnel and contractors with access to personal data are subject to confidentiality obligations. We maintain a documented incident-response procedure, including notification of personal data breaches to the competent supervisory authority and affected individuals where required by law.
Privacy by design and by default. We take data protection into account when designing new features of the Website and the Audit, Gap Report and Certification process, and we configure our systems, by default, to collect and retain only the personal data necessary for the specific purpose in question.
14. Artificial Intelligence Statement
CSCE does not use artificial intelligence or automated means to make decisions producing legal effects concerning you, or similarly significantly affecting you, without meaningful human involvement. Any AI-assisted tools used internally to support the Audit are reviewed by a qualified sanctions compliance professional before any conclusion is reached or communicated to the Client.
15. Your Rights
Subject to the conditions set out in applicable data protection law, you have the right to:
- access the personal data we hold about you and obtain a copy of it;
- rectification of inaccurate or incomplete personal data;
- erasure of personal data that is no longer necessary for the purposes for which it was collected;
- restriction of processing in certain circumstances;
- data portability, where processing is based on consent or on a contract and is carried out by automated means;
- object to processing based on our legitimate interest, including for direct marketing purposes, and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with a competent supervisory authority – in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), or the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of these rights, please contact us using the details in Section 17. We may request additional information to verify your identity before responding to your request. We aim to respond within one month of receiving a verifiable request and will inform you if we need to extend this period.
16. International Business Customers and Corporate Representatives
Most of the individuals whose personal data we process in connection with the Audit, Gap Report and Certification process are Corporate Representatives acting in a professional capacity on behalf of a Client. The fact that our relationship with the Client is a business-to-business relationship does not affect the application of the GDPR or equivalent data protection law to the personal data of those individuals, and the rights described in Section 15 apply to them in full.
Where a Client is located outside the European Economic Area, we apply the same standard of protection to personal data provided in connection with the Audit, Gap Report and Certification process as we apply to personal data originating within the EEA.
17. Contact Details
- General enquiries: contact@sanctionscertificate.eu
- Data protection queries and requests to exercise your rights: contact@sanctionscertificate.eu
- Postal address: Prosta 18, 00-850 Warszawa
18. Changes to this Privacy Notice
We may update this Notice from time to time to reflect changes in our practices or in applicable law. The date at the top of this Notice indicates when it was last updated. Where changes are material, we will take reasonable steps to bring them to your attention, including through the Website.