V0 · 2026-05-16Draft V0People + Companies

Confidentiality Policy

Protection of information obtained or generated during all certification activities. An ethical and contractual commitment to candidates, clients and regulators.

1Statement

FVR protects confidential information obtained or generated during all certification activities. Confidentiality is an ethical and contractual commitment to candidates, clients, interested parties and regulators.

2Scope

Applies to all information obtained during the certification cycle in both service lines (17021 and 17024), including:

  • Personal data of candidates, clients and client employees
  • Audit files (17021) and assessment files (17024)
  • Unpublished findings (major NCs, minor NCs, observations)
  • Client financial and operational information
  • AI model code and data (17024 line)
  • Question bank
  • Cryptographic keys
  • Records of in-house and subcontracted personnel
  • Confidential commercial information (quotes, contracts, fee schedules)

3Principles

  1. Least privilege: each role accesses only what its function requires.
  2. Informed consent: the candidate/client agrees to the use of their information by contract.
  3. No external disclosure without written consent, unless legally required.
  4. Encryption at rest and in transit for information at levels 3 (Confidential) and 4 (Restricted).
  5. Limited retention in line with the information retention policy.

4Personnel obligations

  • Signing a confidentiality agreement on joining
  • Renewal of the declaration every 3 years (bundled with contract and policies)
  • Survives the end of the relationship: 5 years
  • No discussion of cases outside the controlled work environment
  • Immediate notification of any actual or suspected incident
  • Return of information when the relationship ends

5Disclosure required by law

When a competent authority requires information by legal order: Executive Management is notified first, legal counsel validates the order, and where applicable FVR informs the affected client before disclosure (unless legally prohibited). The handover is documented in a log.

6Information levels

Information is classified into four levels: Public, Internal, Confidential and Restricted.

7Incidents

Any unauthorized access, leak, loss or suspicion thereof is handled through the internal incident procedure. Maximum internal reporting time: 2 hours. Reporting to affected parties follows the applicable regulation (Mexico: INAI ≤ 72 hours for personal data).

8Sanctions

SeverityAction
NegligenceMandatory training + written warning
Unauthorized accessDisciplinary action + report to the Safeguarding Committee
Deliberate leakTermination + legal action
Commercial exploitation of confidential informationLegal action + report to the Accreditation Body
ISO/IEC 17024 · clause 4.4 · ISO/IEC 17021-1 · clause 8.4
Request signed version