This Personal Data Protection Notice is provided to ensure that persons whose personal data is being collected by Headquarters Supreme Allied Commander Transformation (HQ SACT), acting as Personal Data Controller (Controller) and NATO Communications and Information Agency (NCIA) acting as the Personal Data Processor (Processor) are informed about the management of their personal data in accordance with the NATO Personal Data Protection Framework Policy. Nothing in this Notice shall be deemed a waiver, express or implied, of the privileges and immunities of HQ SACT.
Contact details of HQ SACT, acting as a Controller:
POC: HQ SACT Personal Data Protection Officer
Address: 7857 Blandy Road Suite 100 Norfolk
VA 23551-2490
Email: hqsact.jadladmin@nato.int
What Personal Data Is Collected By HQ SACT:
|
Field |
Purpose |
Justification |
|
Username |
Credentialing and Authentication |
Retained for use in authentication and validation of a unique user identity. The user will submit their login credentials and will be verified against an internal database. |
|
Password |
Credentialing and Authentication |
Apply password policy (min 12 chars, complexity rules, no common words). Retained for use in authentication and validation of a unique secret key associated with a unique user identity (username). The user will submit their login credentials and will be verified against an internal database. |
|
Email address |
Registration, Verification, Authentication, and Recovery |
Retained for usage in the verification of user access permissions during the account registration process. Also used as a method of login credentialing and authentication in addition to serving as the primary means of password recovery for accounts. |
|
First Name |
Account Identification and Records |
JADL uses Application Programming Interface (API) protocols as a means of organizing and utilizing user data for site functionality. First Name is a required field for the identification of user accounts within an internal database. Also used in certificates, transcripts, and internal records pertaining to course completion. |
|
Last name |
Account Identification and Records |
JADL uses API protocols as a means of organizing and utilizing user data for site functionality. Last Name is a API required field for the identification of user accounts within an internal database. Also used in certificates, transcripts, and internal records pertaining to course completion. |
|
Gender |
Mandatory Reporting |
Mandatory field due to ACT GENAD Office annual reporting requirement to NATO HQ, in accordance with the NATO Policy and Action Plan on Women, Peace and Security. |
|
Country / Time zone |
Localization |
Pre-fill based on IP or organization. Retained solely for localization and maintaining UI consistency across a global presence. |
|
Phone Number |
Security and Access Control |
Retained solely for communication related to trouble ticket handling information purposes. Most systems require a phone number in order to create a ticket. |
|
IP address |
Legal compliance and reporting |
Recording the IP address, alongside a timestamp, acts as evidence that a specific user accepted the Terms of Use and personal data privacy notice. Also may be used for browsing activity information collection through cookies. |
|
Profile photo |
Identification and social interaction |
When provided as optional is used to identify the user and improve social learning. |
We do not collect, nor maintain special categories personal data, such as related to racial or ethnic origin, sexual orientation, political, philosophical, religious opinions or activities, as well as genetic, biometric data and data concerning health. If you provide any special categories of personal data to us, you consent to the collection and processing of this special categories of personal data by virtue of providing this information.
We share your personal data under the following circumstances:
The HQ SACT may share collected personal data outside HQ SACT and its subordinate Commands in the following situations:
Our basis for processing collected personal data:
HQ SACT relies on the following for processing collected personal data:
HQ SACT stores your personal data:
Your data is stored by the Processor by direction of the Controller in a manner consistent with / as prescribed by NATO policies and procedures. We only store and retain personal data collected through HQ SACT JADL as described above and when needed for the purposes defined above. Personal data is retained only as long as necessary for the specific purpose for which it was collected. HQ SACT use the identified purpose for processing your data as a guideline to determine the appropriate timeframe for storing your data. The HQ SACT will safely dispose of your data after 2 years from deleting of your account in line with NATO policies and procedures.
At HQ SACT, we are committed to keeping your data secure. To that end, we have adopted appropriate technical and organisational measures to duly protect your processing, and against theft, accidental loss, destruction, or damage, with enhanced security measures for high-risk personal data.
Use of Cookies:
HQ SACT uses cookies to improve your browsing experience. Cookies are small text files stored on your device to remember your preferences, analyse website traffic, and personalize content. There are two main types of cookies used on our website:
Most web browsers are automatically configured to accept cookies. However, you can configure your browser to inform you of each cookie sent, or to prevent them from being saved on your hard drive. If you refuse cookies, we cannot guarantee your full access to our website; you may experience it running at reduced speed or be unable to access to all services.
Your rights related to your personal data:
You can take the following actions concerning your personal data (or on behalf of certain family members such as young children):
Please be aware that following exceptions to the release of personal data apply:
Personal data shall not be made available if to do so would involve disproportionate resources for HQ SACT, or would be impossible. In such cases, we shall provide access to the extent reasonable.
How to complain:
Please address your concerns to the HQ SACT by email address: hqsact.jadladmin@nato.int
Further updates:
HQ SACT reserves the right to review and update this notice as needed. Please note the most current date indicated above.