Skip to main content
If you continue browsing this website, you agree to our policies:
x

Personal Data Protection Notice


This Personal Data Protection Notice is provided to ensure that persons whose personal data is being collected by Headquarters Supreme Allied Commander Transformation (HQ SACT), acting as Personal Data Controller (Controller) and NATO Communications and Information Agency (NCIA) acting as the Personal Data Processor (Processor) are informed about the management of their personal data in accordance with the NATO Personal Data Protection Framework Policy. Nothing in this Notice shall be deemed a waiver, express or implied, of the privileges and immunities of HQ SACT.

 

Contact details of HQ SACT, acting as a Controller:

POC: HQ SACT Personal Data Protection Officer

Address: 7857 Blandy Road Suite 100 Norfolk
VA 23551-2490

Email: hqsact.jadladmin@nato.int

What Personal Data Is Collected By HQ SACT:

 

Field

Purpose

Justification

Username

Credentialing and Authentication

Retained for use in authentication and validation of a unique user identity. The user will submit their login credentials and will be verified against an internal database.

Password

Credentialing and Authentication

Apply password policy (min 12 chars, complexity rules, no common words).

Retained for use in authentication and validation of a unique secret key associated with a unique user identity (username).  The user will submit their login credentials and will be verified against an internal database.

Email address

Registration, Verification, Authentication, and Recovery

Retained for usage in the verification of user access permissions during the account registration process. Also used as a method of login credentialing and authentication in addition to serving as the primary means of password recovery for accounts.

First Name

Account Identification and Records

JADL uses Application Programming Interface (API) protocols as a means of organizing and utilizing user data for site functionality. First Name is a required field for the identification of user accounts within an internal database. Also used in certificates, transcripts, and internal records pertaining to course completion.

Last name

Account Identification and Records

JADL uses API protocols as a means of organizing and utilizing user data for site functionality. Last Name is a API required field for the identification of user accounts within an internal database. Also used in certificates, transcripts, and internal records pertaining to course completion.

Gender

Mandatory Reporting

Mandatory field due to ACT GENAD Office annual reporting requirement to NATO HQ, in accordance with the NATO Policy and Action Plan on Women, Peace and Security.

Country / Time zone

Localization

Pre-fill based on IP or organization. Retained solely for localization and maintaining UI consistency across a global presence. 

Phone Number

Security and Access Control

Retained solely for communication related to trouble ticket handling information purposes. Most systems require a phone number in order to create a ticket.

IP address

Legal compliance and reporting

Recording the IP address, alongside a timestamp, acts as evidence that a specific user accepted the Terms of Use and personal data privacy notice. Also may be used for browsing activity information collection through cookies.

Profile photo

Identification and social interaction

When provided as optional is used to identify the user and improve social learning.

 

We do not collect, nor maintain special categories personal data, such as related to racial or ethnic origin, sexual orientation, political, philosophical, religious opinions or activities, as well as genetic, biometric data and data concerning health. If you provide any special categories of personal data to us, you consent to the collection and processing of this special categories of personal data by virtue of providing this information.

 

We share your personal data under the following circumstances:

The HQ SACT may share collected personal data outside HQ SACT and its subordinate Commands in the following situations:

  • With other NATO bodies to ensure proper functioning.
  • With other members of the particular event, training, workshop and otherwise same community of interest.
  • With external service providers to ensure proper information management, such as supporting day-to-day office management, IT system management, data storage and similar.
  • If necessary and when in accordance with NATO policies, directives including national security.

 

Our basis for processing collected personal data:


HQ SACT relies on the following for processing collected personal data: 

  • Your consent, that is expressed by your active actions in creating your JADL account and using the services and functionalities of JADL. You can remove your consent at any time by deleting your profile with the caveat that the active use of JADL is contingent on the collection and use of your personal data. 
  • ACT’s legitimate interest to communicate information about NATO activities, develop and improve our website, maintain communication, organize event and protect NATO staff members, assets, and information.

HQ SACT stores your personal data:

Your data is stored by the Processor by direction of the Controller in a manner consistent with / as prescribed by NATO policies and procedures. We only store and retain personal data collected through HQ SACT JADL as described above and when needed for the purposes defined above. Personal data is retained only as long as necessary for the specific purpose for which it was collected. HQ SACT use the identified purpose for processing your data as a guideline to determine the appropriate timeframe for storing your data. The HQ SACT will safely dispose of your data after 2 years from deleting of your account in line with NATO policies and procedures.

 

At HQ SACT, we are committed to keeping your data secure. To that end, we have adopted appropriate technical and organisational measures to duly protect your processing, and against theft, accidental loss, destruction, or damage, with enhanced security measures for high-risk personal data.

Use of Cookies:

HQ SACT uses cookies to improve your browsing experience. Cookies are small text files stored on your device to remember your preferences, analyse website traffic, and personalize content. There are two main types of cookies used on our website:

  • Functional Cookies: These cookies are essential for the website to function properly. They remember your language preferences and browsing behaviour, allowing for a seamless user experience.
  • Analytical Cookies: These cookies collect anonymous data about website usage to help us understand how visitors interact with our content and improve its effectiveness.

Most web browsers are automatically configured to accept cookies. However, you can configure your browser to inform you of each cookie sent, or to prevent them from being saved on your hard drive. If you refuse cookies, we cannot guarantee your full access to our website; you may experience it running at reduced speed or be unable to access to all services.

 

Your rights related to your personal data:

You can take the following actions concerning your personal data (or on behalf of certain family members such as young children):

  • Obtain confirmation as to whether your personal data is being processed.
  • Access your personal data, subject to further exceptions outlined. 
  • Rectify inaccurate or incomplete personal data or erase your personal data in case it is no
    longer necessary for the purpose it was collected or it was processed in a manner contradictory to the specific purpose. 
    • If you wish for your personal data to be erased from JADL, please contact the JADL Administrative Help desk at HQ SACT. 
    • Names of any data subject acting in an official capacity from NATO information of permanent value shall not be deleted.
  • Object to the processing if you believe that there is no legitimate basis for processing your personal data.
  • Complain and appeal regarding HQ SACT’s decisions with regard to your personal data and any related requests.

 

Please be aware that following exceptions to the release of personal data apply:

  • In case there is a possibility of adverse effect to the rights of others. 
  • There are possible violations of NATO policies on the release of classified or non-classified information;
  • Due to ongoing inquiries, investigations or disciplinary proceedings.
  • In case personal data is related to legal advice, used in litigation or deliberative proceedings;
  • In case data is processed for the purpose of security, intelligence or counter-intelligence activities.

Personal data shall not be made available if to do so would involve disproportionate resources for HQ SACT, or would be impossible. In such cases, we shall provide access to the extent reasonable.

 

How to complain:

Please address your concerns to the HQ SACT by email address: hqsact.jadladmin@nato.int

 

Further updates:

HQ SACT reserves the right to review and update this notice as needed. Please note the most current date indicated above.