Banner image

Privacy Policy

Privacy Policy


KAICIID is committed to processing personal data in an accountable and non-discriminatory manner.

As an autonomous intergovernmental organization, enjoying privileges and immunities, KAICIID is not bound by national or regional data protection legislation, such as the EU's General Data Protection Regulation (GDPR). Instead, KAICIID processes, or ensures the processing of, personal data for the pursuit of its mandate in accordance with its own internal Policy on the Protection of Personal Data.

In line with this Policy, KAICIID processes personal data in accordance with KAICIID’s Principles on Personal Data Protection and Privacy (“Principles”) set out below. Nothing in or relating to these Principles shall constitute a waiver, express or implied, of any of the privileges and immunities of KAICIID under its Establishment Agreement, its Headquarters Agreement with Portugal, or public international law.

The Principles are based on the “Personal Data Protection and Privacy Principles”, adopted by the UN High-Level Committee on Management (HLCM) at its 36th Meeting on 11 October 2018, which can be found at https://www.unsystem.org/privacy-principles.


Fair and Legitimate Processing

KAICIID should process personal data in a fair manner, in accordance with its mandate and governing instruments and on the basis of any of the following: (i) the consent of the data subject; (ii) the best interests of the data subject, consistent with the mandate of KAICIID; or (iii) the mandate and governing instruments of KAICIID.

Purpose Specification

Personal data should be processed for specified purposes, which are consistent with the mandate of KAICIID and take into account the balancing of relevant rights, freedoms and interests. Personal data should not be processed in ways that are incompatible with such purposes.

Proportionality and Necessity

The processing of personal data should be relevant, limited and adequate to what is necessary in relation to the specified purposes of personal data processing.


Personal data should only be retained for the time that is necessary for the specified purposes.


Personal data should be accurate and, where necessary, up-to-date to fulfill the specified purposes.


Personal data should be processed with due regard to confidentiality.


Appropriate organizational, administrative, physical and technical safeguards and procedures should be implemented to protect the security of personal data, including against or from unauthorized or accidental access, damage, loss or other risks presented by data processing.


Processing of personal data should be carried out with transparency to the data subjects, as appropriate and whenever possible. This should include, for example, provision of information about the processing of their personal data as well as information on how to request access, verification, rectification, and/or deletion of that personal data, insofar as the specified purpose for which personal data is processed is not frustrated.


In carrying out its mandated activities, KAICIID may transfer personal data to a third party, provided that, under the circumstances, KAICIID satisfies itself that the third party affords appropriate protection for the personal data.


KAICIID should have adequate guidelines and mechanisms in place to adhere to these Principles.

Should you have any questions or concerns about the protection or processing of your personal data by KAICIID, please contact [email protected].