Visor del documento
Nombre Último Cambio
Prometric (en) - Política de Privacidad y Puerto Seguro 13-may-2017 | 3,95%
Cambio importante indicado
# Antigua Versión Nueva Versión
0 Prometric Privacy Policy – updated 26 January 2017 Prometric Privacy Policy – updated 12 April 2017
1
2
3
4 Prometric Privacy Policy Prometric Privacy Policy
5
6
7 Prometric is committed to protecting the personal data and information of employees, test Prometric is committed to protecting the personal data and information of employees, test
8 candidates, website visitors and other individuals with whom we interact. We have a Global candidates, website visitors and other individuals with whom we interact. We have a Global
9 Privacy Policy that sets forth a formal process to protect the security and appropriate use of the Personal Privacy Policy that sets forth a formal process to protect the security and appropriate use of the Personal
10 Data we collect for our own purposes and on behalf of our clients, the test sponsors. This Privacy Policy Data we collect for our own purposes and on behalf of our clients, the test sponsors. This Privacy Policy
11 helps ensure that Personal Data is collected, transferred, and stored properly and in compliance with Data helps ensure that Personal Data is collected, transferred, and stored properly and in compliance with Data
12 Protection Laws. Protection Laws.
13
14 This Privacy Policy explains how we use, maintain and disclose personal data and information that we This Privacy Policy explains how we use, maintain and disclose personal data and information that we
15 collect from individuals both online and offline, such as in our new hire processes, candidate registration collect from individuals both online and offline, such as in our new hire processes, candidate registration
16 and scheduling and test centers. and scheduling and test centers.
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53 Prometric Privacy Policy – updated 26 January 2017 Page 2 Prometric Privacy Policy – updated 12 April 2017 Page 2
54 Table of Contents Table of Contents
55
56 I. Privacy Notice I. Privacy Notice
57
58 II. Information Security II. Information Security
59
60 III. Prometric’s Practices for the Collection and Use of Personal Data III. Prometric’s Practices for the Collection and Use of Personal Data
61 A. Personal Data A. Personal Data
62 B. How Prometric Collects Personal Data B. How Prometric Collects Personal Data
63 C. Privacy Statement for Biometrics (for Candidates) C. Privacy Statement for Biometrics (for Candidates)
64 D. Individual Rights D. Individual Rights
65 E. How Prometric Uses Personal Data E. How Prometric Uses Personal Data
66 F. Why Personal Data is Disclosed by Prometric F. Why Personal Data is Disclosed by Prometric
67 G. Onward Transfer G. Onward Transfer
68 H. Notices to Residents of Countries Outside the United States H. Notices to Residents of Countries Outside the United States
69 I. Opt-Out Choices I. Opt-Out Choices
70 J. Access and Correction J. Access and Correction
71 K. Privacy Policies of Third Parties K. Privacy Policies of Third Parties
72 L. Cookies and Other Data Collection Technologies L. Cookies and Other Data Collection Technologies
73 M. Social Media Interactions M. Social Media Interactions
74 N. Tell-a-Friend Functions N. Tell-a-Friend Functions
75 O. Mobile Applications O. Mobile Applications
76 P. Privacy Shield Certification P. EU-U.S. Privacy Shield Certification
77 Q. U.S.-Swiss Safe Harbor Certification Q. Swiss-U.S. Privacy Shield Certification
78 R. U.S. Social Security Number Policy Statement R. U.S. Social Security Number Policy Statement
79 S. California Privacy Rights S. California Privacy Rights
80
81 IV. Dispute Resolution Process IV. Dispute Resolution Process
82
83 V. How to Contact Us V. How to Contact Us
84
85 VI. Changes to Privacy Policy VI. Changes to Privacy Policy
86
87
88
89
90
91
92 Prometric Privacy Policy – updated 26 January 2017 Page 3 Prometric Privacy Policy – updated 12 April 2017 Page 3
93
94 I. Privacy Notice I. Privacy Notice
95
96 Prometric is committed to protecting the privacy and security of all personal data and information that we Prometric is committed to protecting the privacy and security of all personal data and information that we
97 process in order to provide testing services to our clients, the test sponsors. This Privacy Notice provides process in order to provide testing services to our clients, the test sponsors. This Privacy Notice provides
98 a summary of our practices with regard to all of the personal data and information we collect and use in a summary of our practices with regard to all of the personal data and information we collect and use in
99 connection with testing services we offer for our clients, and includes personal data and information connection with testing services we offer for our clients, and includes personal data and information
100 processed for the purpose of employing individuals to support those testing services. processed for the purpose of employing individuals to support those testing services.
101
102 Prometric collects and processes personal data and information only for legitimate business purposes. Prometric collects and processes personal data and information only for legitimate business purposes.
103 Personal data and information of exam candidates is collected and processed only as instructed or permitted Personal data and information of exam candidates is collected and processed only as instructed or permitted
104 by our clients, the test sponsors. We will collect and process that information that is reasonably needed to by our clients, the test sponsors. We will collect and process that information that is reasonably needed to
105 register an exam candidate for a test (including verifying eligibility to take an exam and verifying the identity register an exam candidate for a test (including verifying eligibility to take an exam and verifying the identity
106 of the exam taker), administer the exam (including protecting the security and integrity of the testing of the exam taker), administer the exam (including protecting the security and integrity of the testing
107 process), processing the exam results, and resolving any issues that may have occurred during the testing process), processing the exam results, and resolving any issues that may have occurred during the testing
108 process. process.
109
110 If permitted under applicable law, we may communicate with exam candidates regarding other testing If permitted under applicable law, we may communicate with exam candidates regarding other testing
111 events offered by Prometric and our test sponsors. Candidates may opt-out of receiving these events offered by Prometric and our test sponsors. Candidates may opt-out of receiving these
112 communications at any time, as provided below. communications at any time, as provided below.
113
114 We may disclose candidate personal data and information to the applicable test sponsor, who will use that We may disclose candidate personal data and information to the applicable test sponsor, who will use that
115 information in accordance with its own privacy policies. information in accordance with its own privacy policies.
116
117 Personal data and information of potential and/or active employees is collected and processed only for Personal data and information of potential and/or active employees is collected and processed only for
118 legitimate business purposes, including but not limited to, verifying identity and credentials, where allowed legitimate business purposes, including but not limited to, verifying identity and credentials, where allowed
119 by law to process background checks and confirm suitability for employment, processing payroll, complying by law to process background checks and confirm suitability for employment, processing payroll, complying
120 with statutory and regulatory employment requirements, and to confirm the safety and security of with statutory and regulatory employment requirements, and to confirm the safety and security of
121 employees both on an on-going basis and in the event of a major weather or security-related event. employees both on an on-going basis and in the event of a major weather or security-related event.
122
123 We will at all times maintain reasonable and appropriate security controls to protect the personal data and We will at all times maintain reasonable and appropriate security controls to protect the personal data and
124 information of our candidates and employees. We have special controls to protect any sensitive personal information of our candidates and employees. We have special controls to protect any sensitive personal
125 data and information (such as government issued identification numbers and biometrics) that may be data and information (such as government issued identification numbers and biometrics) that may be
126 collected for security and identity verification purposes. For additional information about Prometric’s collected for security and identity verification purposes. For additional information about Prometric’s
127 information security practices please see below. information security practices please see below.
128
129 We may disclose personal data and information to our affiliates and data processors as needed to provide We may disclose personal data and information to our affiliates and data processors as needed to provide
130 the services that candidates and the test sponsors have requested and to perform the functions necessary the services that candidates and the test sponsors have requested and to perform the functions necessary
131 to run a global business. These entities are all contractually bound to limit use of all personal data and to run a global business. These entities are all contractually bound to limit use of all personal data and
132 information they come in contact with as needed to perform only the services requested. information they come in contact with as needed to perform only the services requested.
133
134 We will also always disclose personal data and information when required to do so by law, such as in We will also always disclose personal data and information when required to do so by law, such as in
135 response to a subpoena, to law enforcement agencies and courts with proper jurisdiction to request such response to a subpoena, to law enforcement agencies and courts with proper jurisdiction to request such
136 information, or in response to regulatory inquiries. information, or in response to regulatory inquiries.
137
138 Prometric will comply with the privacy and data collection and processing laws of the local jurisdiction of Prometric will comply with the privacy and data collection and processing laws of the local jurisdiction of
139 the individual from whom information is being collected. With the exception of biometric data, the personal the individual from whom information is being collected. With the exception of biometric data, the personal
140 data and information of exam candidates and employees based outside of the United States will be data and information of exam candidates and employees based outside of the United States will be
141 transferred, with the express consent of the individual, to Prometric, test sponsors and data processers in transferred, with the express consent of the individual, to Prometric, test sponsors and data processers in
142 the United States and elsewhere in the world only to facilitate the purpose for which it was collected. the United States and elsewhere in the world only to facilitate the purpose for which it was collected.
143 Prometric will always protect the privacy and security of all personal data and information that it collects, Prometric will always protect the privacy and security of all personal data and information that it collects,
144 regardless of where it is processed. Exam candidates located outside of the United States who do not regardless of where it is processed. Exam candidates located outside of the United States who do not
145 provide the appropriate consent necessary for Prometric to transfer personal data and information to the provide the appropriate consent necessary for Prometric to transfer personal data and information to the
146 Prometric Privacy Policy – updated 26 January 2017 Page 4 Prometric Privacy Policy – updated 12 April 2017 Page 4
147 United States for processing understand that they may not be able to test with Prometric, and may be United States for processing understand that they may not be able to test with Prometric, and may be
148 referred directly to their test sponsor for alternative testing solutions where available. Potential and active referred directly to their test sponsor for alternative testing solutions where available. Potential and active
149 Prometric employees located outside of the United States who do not provide the appropriate consent Prometric employees located outside of the United States who do not provide the appropriate consent
150 necessary for Prometric to transfer personal data and information to the United States for processing of necessary for Prometric to transfer personal data and information to the United States for processing of
151 payroll and other employment related functions understand that they may not be eligible for employment payroll and other employment related functions understand that they may not be eligible for employment
152 with Prometric. with Prometric.
153
154 If you have questions about your privacy rights or other information related to Privacy, please see Section If you have questions about your privacy rights or other information related to Privacy, please see Section
155 V. “How to Contact Us”, below. V. “How to Contact Us”, below.
156
157 II. Information Security II. Information Security
158
159 Security protection is an undercurrent that runs through every part of Prometric's business. All of our Security protection is an undercurrent that runs through every part of Prometric's business. All of our
160 technologies feature multiple layers of encryption and protection so constituents and stakeholders alike can technologies feature multiple layers of encryption and protection so constituents and stakeholders alike can
161 rest assured that their intellectual property and Personal Data are being properly protected from theft while rest assured that their intellectual property and Personal Data are being properly protected from theft while
162 it is on our systems. We operate information technology facilities that meet or exceed industry standards, it is on our systems. We operate information technology facilities that meet or exceed industry standards,
163 with secure back-ups at off-site locations, where all sensitive data is securely stored and protected. with secure back-ups at off-site locations, where all sensitive data is securely stored and protected.
164
165 Prometric draws on industry best practices and guidance from sources such as the National Institute of Prometric draws on industry best practices and guidance from sources such as the National Institute of
166 Standards and Technology (NIST), Payment Card Industry (PCI) and standards promulgated by the Standards and Technology (NIST), Payment Card Industry (PCI) and standards promulgated by the
167 International Standards Organization (ISO) including, but not limited to, ISO/IEC 27018:2014 (Code of International Standards Organization (ISO) including, but not limited to, ISO/IEC 27018:2014 (Code of
168 practice for protection of personally identifiable information (PII) in public clouds acting as PII processors) practice for protection of personally identifiable information (PII) in public clouds acting as PII processors)
169 and ISO/IEC 27001:2013 (Security techniques -- Information security management systems -- and ISO/IEC 27001:2013 (Security techniques -- Information security management systems --
170 Requirements) to design and maintain its information security program. Prometric's Information Security Requirements) to design and maintain its information security program. Prometric's Information Security
171 Program is reviewed several times each year by multiple third party organizations to ensure it meets or Program is reviewed several times each year by multiple third party organizations to ensure it meets or
172 exceeds the highest benchmarks available for security and data privacy. exceeds the highest benchmarks available for security and data privacy.
173
174 III. Prometric’s Practices for the Collection and Use of Personal Data III. Prometric’s Practices for the Collection and Use of Personal Data
175
176 The following explains our practices with regards to all “Personal Data” collected and used by Prometric. The following explains our practices with regards to all “Personal Data” collected and used by Prometric.
177
178 A. Personal Data A. Personal Data
179
180 “Personal Data” is any non-public personal information, as such term is defined under Title V of the U.S. “Personal Data” is any non-public personal information, as such term is defined under Title V of the U.S.
181 Gramm-Leach-Bliley Act, 15 U.S.C. s. 6801 et seq. and the rules and regulations issued thereunder; any Gramm-Leach-Bliley Act, 15 U.S.C. s. 6801 et seq. and the rules and regulations issued thereunder; any
182 “personal data” as defined in EU Directive 95/46/EC or any equivalent or similar concept of personal data “personal data” as defined in EU Directive 95/46/EC or any equivalent or similar concept of personal data
183 or personal information under any applicable law; any “personal data” as defined in Malaysian Act 709 of or personal information under any applicable law; any “personal data” as defined in Malaysian Act 709 of
184 the Personal Data Protection Act of 2010, or any other information that specifically identifies an individual, the Personal Data Protection Act of 2010, or any other information that specifically identifies an individual,
185 such as name, residential and office address or social security number, together, in each case, with any such as name, residential and office address or social security number, together, in each case, with any
186 other information that relates to an individual who has been so identified and can be used to identify, locate other information that relates to an individual who has been so identified and can be used to identify, locate
187 or contact such individual. It includes, but is not limited to: or contact such individual. It includes, but is not limited to:
188  Personal contact details  Personal contact details
189
190  Assessment details, including candidate ID number, examinations taken and when, scores related  Assessment details, including candidate ID number, examinations taken and when, scores related
191 to those exams, how many times an exam or any particular section of exams have been taken; to those exams, how many times an exam or any particular section of exams have been taken;
192
193  Employment information such as social security number, passport number or any other identifying  Employment information such as social security number, passport number or any other identifying
194 information required by a government entity to confirm eligibility for employment; information required by a government entity to confirm eligibility for employment;
195
196  Credit card information;  Credit card information;
197
198  Residence and country of citizenship;  Residence and country of citizenship;
199
200 Prometric Privacy Policy – updated 26 January 2017 Page 5 Prometric Privacy Policy – updated 12 April 2017 Page 5
201  Photographs;  Photographs;
202
203  Signature;  Signature;
204
205  Audio and Video recordings;  Audio and Video recordings;
206
207  Fingerprint images and templates for Biometric Enabled Check-In;  Fingerprint images and templates for Biometric Enabled Check-In;
208
209  Information from identification, verification, or eligibility documents;  Information from identification, verification, or eligibility documents;
210
211  Transaction and Relationship Information including elements that reveal candidate test patterns,  Transaction and Relationship Information including elements that reveal candidate test patterns,
212 test locations, test results, and information about how Prometric websites and applications are test locations, test results, and information about how Prometric websites and applications are
213 used. used.
214
215 B. How Prometric Collects Personal Data B. How Prometric Collects Personal Data
216
217 In most cases, Prometric collects Personal Data directly from the individual through direct interactions In most cases, Prometric collects Personal Data directly from the individual through direct interactions
218 including applying for employment and during the hiring process, registering on our website, scheduling a including applying for employment and during the hiring process, registering on our website, scheduling a
219 test or taking a test. In some cases, Prometric collects Personal Data from third parties. For example, we test or taking a test. In some cases, Prometric collects Personal Data from third parties. For example, we
220 may receive information from employment agencies, test sponsors, or even from third party data suppliers may receive information from employment agencies, test sponsors, or even from third party data suppliers
221 who enhance our files and help us better understand our customers. These third parties may use cookies, who enhance our files and help us better understand our customers. These third parties may use cookies,
222 web beacons, and other similar technologies to collect or receive information from Prometric’s website and web beacons, and other similar technologies to collect or receive information from Prometric’s website and
223 elsewhere on the internet to provide us with data measurement services and target ads that address the elsewhere on the internet to provide us with data measurement services and target ads that address the
224 search criteria of our customers. search criteria of our customers.
225
226 When a candidate visits Prometric’s website, registers or takes an exam, uses our applications, or contacts When a candidate visits Prometric’s website, registers or takes an exam, uses our applications, or contacts
227 us, we also collect transaction information for customer service purposes. us, we also collect transaction information for customer service purposes.
228
229 If an individual interacts with Prometric online, we use cookies and other technological tools to collect If an individual interacts with Prometric online, we use cookies and other technological tools to collect
230 information about the use of our website and applications. We treat this information as Personal Data information about the use of our website and applications. We treat this information as Personal Data
231 when it is associated with an individual’s Contact Information. For more information about cookies and when it is associated with an individual’s Contact Information. For more information about cookies and
232 other technologies, please see Section M. Cookies and Other Data Collection Technologies, below. other technologies, please see Section M. Cookies and Other Data Collection Technologies, below.
233
234 To help ensure the security and integrity of the testing process, we may also collect information in our test To help ensure the security and integrity of the testing process, we may also collect information in our test
235 centers using technological means, such as identification document scanners, fingerprint scanners, digital centers using technological means, such as identification document scanners, fingerprint scanners, digital
236 cameras, and audio-video surveillance monitoring equipment. In each case, we only use these technologies cameras, and audio-video surveillance monitoring equipment. In each case, we only use these technologies
237 as permitted by applicable laws. If a candidate testing program uses a biometric enabled check in process as permitted by applicable laws. If a candidate testing program uses a biometric enabled check in process
238 at the test center, please see Section C. Privacy Statement for Biometrics, directly below. at the test center, please see Section C. Privacy Statement for Biometrics, directly below.
239
240 C. Privacy Statement for Biometrics (for Candidates) C. Privacy Statement for Biometrics (for Candidates)
241
242 Where selected by the test sponsor, Prometric’s Biometric Enabled Check-In System is designed to improve Where selected by the test sponsor, Prometric’s Biometric Enabled Check-In System is designed to improve
243 the security and integrity of the testing process in a way that protects test candidate privacy while ensuring the security and integrity of the testing process in a way that protects test candidate privacy while ensuring
244 test candidate identity. The Biometric Enabled Check-In System converts a fingerprint image to a digital test candidate identity. The Biometric Enabled Check-In System converts a fingerprint image to a digital
245 image that is used for identity verification purposes, detects and prevents fraud and misrepresentation, image that is used for identity verification purposes, detects and prevents fraud and misrepresentation,
246 maintains the integrity of the testing process, and improves the security of test centers. maintains the integrity of the testing process, and improves the security of test centers.
247
248
249
250 1. How the Biometric Enabled Check-In System Works 1. How the Biometric Enabled Check-In System Works
251
252 By placing the index finger on a scanner in a Prometric Test Center, the Biometric Enabled Check-In System By placing the index finger on a scanner in a Prometric Test Center, the Biometric Enabled Check-In System
253 equipment captures an image of the fingerprint and creates a digitized representation of the fingerprint (a equipment captures an image of the fingerprint and creates a digitized representation of the fingerprint (a
254 Prometric Privacy Policy – updated 26 January 2017 Page 6 Prometric Privacy Policy – updated 12 April 2017 Page 6
255 “template”). The fingerprint image and template are paired with other Personal Data provided to Prometric “template”). The fingerprint image and template are paired with other Personal Data provided to Prometric
256 by the candidate (such as name and other identifying information), allowing Prometric to identify the by the candidate (such as name and other identifying information), allowing Prometric to identify the
257 candidate accurately during the testing process and over repeated testing sessions for the same test candidate accurately during the testing process and over repeated testing sessions for the same test
258 sponsor. sponsor.
259
260 For security purposes, all biometric data is securely transferred to and stored within Prometric’s Central For security purposes, all biometric data is securely transferred to and stored within Prometric’s Central
261 Data Center. Prometric manages the security and confidentiality of the data, to protect it from unauthorized Data Center. Prometric manages the security and confidentiality of the data, to protect it from unauthorized
262 access, use, disclosure, or alteration, and to retain and destroy the data in accordance with applicable access, use, disclosure, or alteration, and to retain and destroy the data in accordance with applicable
263 law. law.
264
265 2. Purposes and Uses for Biometric Data 2. Purposes and Uses for Biometric Data
266
267 Biometric data is solely used by Prometric to: (1) administer tests and verify a candidate’s identity on an Biometric data is solely used by Prometric to: (1) administer tests and verify a candidate’s identity on an
268 ongoing basis as they participate in present and future assessments with the same test sponsor; (2) pre- ongoing basis as they participate in present and future assessments with the same test sponsor; (2) pre-
269 populate candidate credentials at most Prometric test center facilities consequently reducing the time populate candidate credentials at most Prometric test center facilities consequently reducing the time
270 required during the check-in process; (3) detect and prevent fraud and misrepresentation by unauthorized required during the check-in process; (3) detect and prevent fraud and misrepresentation by unauthorized
271 candidates; (4) maintain the integrity of the testing process; (5) improve security of test centers by candidates; (4) maintain the integrity of the testing process; (5) improve security of test centers by
272 detecting and preventing unauthorized access to secure areas; and (6) as required by law. detecting and preventing unauthorized access to secure areas; and (6) as required by law.
273
274 3. Disclosures of Biometric Data 3. Disclosures of Biometric Data
275
276 As a matter of policy, Prometric does not disclose biometric data to any third party (including test sponsors). As a matter of policy, Prometric does not disclose biometric data to any third party (including test sponsors).
277 However, in the event of an investigation of cheating, unauthorized testing, or other misconduct, Prometric However, in the event of an investigation of cheating, unauthorized testing, or other misconduct, Prometric
278 may disclose the biometric data to the test sponsor or to law enforcement agencies and/or other third may disclose the biometric data to the test sponsor or to law enforcement agencies and/or other third
279 parties involved in the investigation of misconduct. Prometric will also disclose Personal Data, information parties involved in the investigation of misconduct. Prometric will also disclose Personal Data, information
280 and other records only in relation to lawful requests by regulatory, legal or government agencies with and other records only in relation to lawful requests by regulatory, legal or government agencies with
281 jurisdiction and/or authority to make such requests. jurisdiction and/or authority to make such requests.
282
283 4. Security and Data Retention 4. Security and Data Retention
284
285 Prometric and its subcontractors shall at all times protect a candidate’s Personal Data with operational, Prometric and its subcontractors shall at all times protect a candidate’s Personal Data with operational,
286 administrative, technical and physical security safeguards. Unless a candidate’s personal data or fingerprint administrative, technical and physical security safeguards. Unless a candidate’s personal data or fingerprint
287 images are being used in connection with an active security investigation; the test sponsor, Prometric images are being used in connection with an active security investigation; the test sponsor, Prometric
288 and/or the biometric vendor on behalf of the test sponsor, shall retain candidate data collected through the and/or the biometric vendor on behalf of the test sponsor, shall retain candidate data collected through the
289 Biometric Check-In System in accordance with the law in the jurisdiction in which the data was obtained, Biometric Check-In System in accordance with the law in the jurisdiction in which the data was obtained,
290 or for a maximum of five years from the date of the last assessment or the expiration of the purpose for or for a maximum of five years from the date of the last assessment or the expiration of the purpose for
291 which the candidate’s data was collected; whichever time period is shorter, or as otherwise required by a which the candidate’s data was collected; whichever time period is shorter, or as otherwise required by a
292 test sponsor. test sponsor.
293
294 Other Personal Data collected by Prometric during test registration, new hiring, or any other administrative Other Personal Data collected by Prometric during test registration, new hiring, or any other administrative
295 process is retained by Prometric in accordance with its record retention guidelines, and may also be sent process is retained by Prometric in accordance with its record retention guidelines, and may also be sent
296 to a test sponsors and/or retained in accordance with the test sponsor’s record retention guidelines. to a test sponsors and/or retained in accordance with the test sponsor’s record retention guidelines.
297
298 5. Data Processing 5. Data Processing
299
300 Prometric complies with all local privacy laws in the collection and processing of Personal Data or Prometric complies with all local privacy laws in the collection and processing of Personal Data or
301 information, including biometric data such as fingerprint images. This includes but is not limited to, as information, including biometric data such as fingerprint images. This includes but is not limited to, as
302 required, providing disclosures on Prometric processes and procedures for the collection and processing of required, providing disclosures on Prometric processes and procedures for the collection and processing of
303 Personal Data (for example, this Privacy Policy and the Statements contained herein), obtaining consent of Personal Data (for example, this Privacy Policy and the Statements contained herein), obtaining consent of
304 the individual, and/or adherence to local Data Protection Laws in the regions where Prometric conducts the individual, and/or adherence to local Data Protection Laws in the regions where Prometric conducts
305 business. When a candidate submits to biometrics at a Prometric testing site, regardless of where the site business. When a candidate submits to biometrics at a Prometric testing site, regardless of where the site
306 is located globally, the biometric data is collected, transferred, processed and stored in Prometric’s data is located globally, the biometric data is collected, transferred, processed and stored in Prometric’s data
307 center located in Ireland, where allowed by the applicable jurisdiction where the biometric data is collected. center located in Ireland, where allowed by the applicable jurisdiction where the biometric data is collected.
308 Prometric Privacy Policy – updated 26 January 2017 Page 7 Prometric Privacy Policy – updated 12 April 2017 Page 7
309 Where required by law, candidates will be required to expressly consent to the collection, transfer and Where required by law, candidates will be required to expressly consent to the collection, transfer and
310 processing of Personal Data, including biometric data. processing of Personal Data, including biometric data.
311
312 D. Individual Rights D. Individual Rights
313
314 A candidate or employee may, at any time: A candidate or employee may, at any time:
315  request access to and correction of Personal Data;  request access to and correction of Personal Data;
316  make any inquiries, requests or complaints in relation to the use of Personal Data;  make any inquiries, requests or complaints in relation to the use of Personal Data;
317  withdraw consent to the processing of personal data (including fingerprint data)  withdraw consent to the processing of personal data (including fingerprint data)
318 In each case, the individual should direct requests and inquiries to Prometric’s Data Protection Manager In each case, the individual should direct requests and inquiries to Prometric’s Data Protection Manager
319 using the contact information in Section V. “How to Contact Us” below. Complaints should be filed pursuant using the contact information in Section V. “How to Contact Us” below. Complaints should be filed pursuant
320 to the Dispute Resolution Process outlined in Section IV. to the Dispute Resolution Process outlined in Section IV.
321
322
323 E. How Prometric Uses Personal Data E. How Prometric Uses Personal Data
324
325 Prometric uses Personal Data to fulfill requests for information and services, to administer testing programs Prometric uses Personal Data to fulfill requests for information and services, to administer testing programs
326 securely and efficiently, and to operate our business. For example: securely and efficiently, and to operate our business. For example:
327
328 1. Test Candidates 1. Test Candidates
329
330  Prometric will respond to candidate requests for information about tests and testing opportunities,  Prometric will respond to candidate requests for information about tests and testing opportunities,
331 facilitate registration for exams, and provide testing services to both candidates and test sponsors facilitate registration for exams, and provide testing services to both candidates and test sponsors
332 (including test scheduling and administration, security and detection of cheating, test scoring, reporting (including test scheduling and administration, security and detection of cheating, test scoring, reporting
333 and analysis of results, and customer service). Where permitted by law, Prometric may send exam and analysis of results, and customer service). Where permitted by law, Prometric may send exam
334 candidates commercial communications and offers for additional testing or training services on behalf candidates commercial communications and offers for additional testing or training services on behalf
335 of test sponsors. of test sponsors.
336
337  Prometric, on behalf of its test sponsors, will use biometric data solely to: (1) administer the tests and  Prometric, on behalf of its test sponsors, will use biometric data solely to: (1) administer the tests and
338 verify identity, (2) protect privacy, (3) detect and prevent fraud and misrepresentation by unauthorized verify identity, (2) protect privacy, (3) detect and prevent fraud and misrepresentation by unauthorized
339 candidates, (4) maintain the integrity of the testing process, (5) preserve security of test centers by candidates, (4) maintain the integrity of the testing process, (5) preserve security of test centers by
340 detecting and preventing unauthorized access to secure areas, and (6) as required by law. detecting and preventing unauthorized access to secure areas, and (6) as required by law.
341
342 2. Employees (Potential, Active & Former) 2. Employees (Potential, Active & Former)
343
344  Prometric will use information supplied by individuals who have applied for employment with Prometric  Prometric will use information supplied by individuals who have applied for employment with Prometric
345 for recruitment and other customary human resources purposes, such as payroll processing, business for recruitment and other customary human resources purposes, such as payroll processing, business
346 continuity and disaster recovery planning, and to satisfy corporate governance and regulatory continuity and disaster recovery planning, and to satisfy corporate governance and regulatory
347 obligations. obligations.
348
349 Prometric will also use Personal Data collected from employees to document employment-related Prometric will also use Personal Data collected from employees to document employment-related
350 decisions and to comply with government record keeping and reporting requirements. By law, decisions and to comply with government record keeping and reporting requirements. By law,
351 Prometric must maintain certain personnel records on applicants and current and past employees. The Prometric must maintain certain personnel records on applicants and current and past employees. The
352 Human Resources department is responsible for overseeing the record keeping for all personnel Human Resources department is responsible for overseeing the record keeping for all personnel
353 information. Access to information is limited to persons inside Prometric who need to know for business information. Access to information is limited to persons inside Prometric who need to know for business
354 purposes and released to persons outside of Prometric only with authorization or as required by law. purposes and released to persons outside of Prometric only with authorization or as required by law.
355 Employees may view their personnel file by submitting a request to Human Resources. Upon receipt of Employees may view their personnel file by submitting a request to Human Resources. Upon receipt of
356 this request, an appointment will be scheduled during which the employee may view their file in the this request, an appointment will be scheduled during which the employee may view their file in the
357 presence of a member of the Human Resources Department. presence of a member of the Human Resources Department.
358
359 Prometric Privacy Policy – updated 26 January 2017 Page 8 Prometric Privacy Policy – updated 12 April 2017 Page 8
360 3. Legitimate Business Purposes 3. Legitimate Business Purposes
361
362  Prometric also uses Personal Data as needed to manage everyday business needs such as payment  Prometric also uses Personal Data as needed to manage everyday business needs such as payment
363 processing and financial account management, backup purposes to facilitate business continuity, test processing and financial account management, backup purposes to facilitate business continuity, test
364 center management, business planning, contract management, website administration, fulfillment, center management, business planning, contract management, website administration, fulfillment,
365 analytics, security and fraud prevention, corporate governance, business continuity and disaster analytics, security and fraud prevention, corporate governance, business continuity and disaster
366 recovery planning, auditing, reporting and compliance with any legal or regulatory obligations. recovery planning, auditing, reporting and compliance with any legal or regulatory obligations.
367
368 F. Why Personal Data Is Disclosed by Prometric F. Why Personal Data Is Disclosed by Prometric
369
370 Prometric DOES NOT share Personal Data with third parties for their own marketing purposes. Prometric Prometric DOES NOT share Personal Data with third parties for their own marketing purposes. Prometric
371 requires its subcontractors and vendors who have access to Personal Data to provide, at a minimum, the requires its subcontractors and vendors who have access to Personal Data to provide, at a minimum, the
372 same levels of protection as provided by Prometric concerning Personal Data. Where Prometric is required same levels of protection as provided by Prometric concerning Personal Data. Where Prometric is required
373 to transfer Personal Data onward to a third party to further the performance of a legitimate business to transfer Personal Data onward to a third party to further the performance of a legitimate business
374 purpose, Prometric will remain liable for the proper use, processing, and storage of such data in a manner purpose, Prometric will remain liable for the proper use, processing, and storage of such data in a manner
375 that is consistent with the purposes for which it was collected. We limit our sharing of all Personal Data as that is consistent with the purposes for which it was collected. We limit our sharing of all Personal Data as
376 follows: follows:
377
378 1. Test Candidates 1. Test Candidates
379
380  Prometric may disclose Personal Data of exam candidates to test sponsors, which will use and disclose  Prometric may disclose Personal Data of exam candidates to test sponsors, which will use and disclose
381 Personal Data in accordance with their own privacy policies. Prometric acts as a processor for test Personal Data in accordance with their own privacy policies. Prometric acts as a processor for test
382 sponsors, who are our clients. We send candidate Personal Data and test results to the test sponsors sponsors, who are our clients. We send candidate Personal Data and test results to the test sponsors
383 so that they can provide candidates with the accreditation, service, license or credentials sought. so that they can provide candidates with the accreditation, service, license or credentials sought.
384
385  Prometric may share Personal Data with our affiliates and authorized test centers, which may only use  Prometric may share Personal Data with our affiliates and authorized test centers, which may only use
386 Personal Data for the purposes listed above. For example, we will provide Personal Data to the test Personal Data for the purposes listed above. For example, we will provide Personal Data to the test
387 center so that it is prepared for exam candidates on test day. center so that it is prepared for exam candidates on test day.
388
389  Prometric may share Personal Data with our service providers to facilitate candidate and test sponsor  Prometric may share Personal Data with our service providers to facilitate candidate and test sponsor
390 requests. Service providers are bound by law or contract to protect Personal Data and only use such requests. Service providers are bound by law or contract to protect Personal Data and only use such
391 Personal Data in accordance with Prometric’s requirements and instructions. Personal Data in accordance with Prometric’s requirements and instructions.
392
393 2. Employees (Potential, Active & Former) 2. Employees (Potential, Active & Former)
394
395  Prometric may share Personal Data with our service providers, such as our payroll processors, benefits  Prometric may share Personal Data with our service providers, such as our payroll processors, benefits
396 providers, and performance measurement vendors to facilitate employee compensation, benefit providers, and performance measurement vendors to facilitate employee compensation, benefit
397 elections and claims, and performance and growth goals, objectives and milestones. Service providers elections and claims, and performance and growth goals, objectives and milestones. Service providers
398 are bound by law or contract to protect Personal Data and only use such Personal Data in accordance are bound by law or contract to protect Personal Data and only use such Personal Data in accordance
399 with Prometric’s requirements and instructions. with Prometric’s requirements and instructions.
400
401 3. Legitimate Business Purposes 3. Legitimate Business Purposes
402
403  Prometric may disclose Personal Data where needed to affect the sale or transfer of business assets,  Prometric may disclose Personal Data where needed to affect the sale or transfer of business assets,
404 to enable payment processing, to enforce our rights, protect our property, or protect the rights, to enable payment processing, to enforce our rights, protect our property, or protect the rights,
405 property or safety of others, or as needed to support external auditing, compliance and corporate property or safety of others, or as needed to support external auditing, compliance and corporate
406 governance functions. We will also disclose Personal Data when required to do so by law, such as in governance functions. We will also disclose Personal Data when required to do so by law, such as in
407 response to a subpoena including to law enforcement agencies and courts in the United States, response to a subpoena including to law enforcement agencies and courts in the United States,
408 Member-States of the European Union, India, Malaysia, China, Japan and other countries where we Member-States of the European Union, India, Malaysia, China, Japan and other countries where we
409 operate. operate.
410
411 4. Investigative, Legal & Government Requests 4. Investigative, Legal & Government Requests
412
413 Prometric Privacy Policy – updated 26 January 2017 Page 9 Prometric Privacy Policy – updated 12 April 2017 Page 9
414  In the event of an investigation of cheating, unauthorized testing, or other misconduct, Prometric may  In the event of an investigation of cheating, unauthorized testing, or other misconduct, Prometric may
415 disclose the biometric data to the test sponsor or to law enforcement agencies and/or other third disclose the biometric data to the test sponsor or to law enforcement agencies and/or other third
416 parties involved in the investigation of misconduct. We also may provide access to Personal Data when parties involved in the investigation of misconduct. We also may provide access to Personal Data when
417 legally required to do so, to cooperate with police investigations or other legal proceedings, to protect legally required to do so, to cooperate with police investigations or other legal proceedings, to protect
418 against misuse or unauthorized use of our intellectual property, to limit our legal liability and protect against misuse or unauthorized use of our intellectual property, to limit our legal liability and protect
419 our rights, or to protect the rights and safety of our employees, candidates, clients or the public. In our rights, or to protect the rights and safety of our employees, candidates, clients or the public. In
420 those instances, the information is provided only for that limited purpose. those instances, the information is provided only for that limited purpose.
421
422 Please note that we may also use and disclose information about an individual that is not considered Please note that we may also use and disclose information about an individual that is not considered
423 Personal Data. For example, we may publish reports that contain aggregated and statistical data about Personal Data. For example, we may publish reports that contain aggregated and statistical data about
424 our test candidates or website visitors. These reports do not contain any information that would enable the our test candidates or website visitors. These reports do not contain any information that would enable the
425 recipient to contact, locate or identify the individual that is the subject of the information disclosed. recipient to contact, locate or identify the individual that is the subject of the information disclosed.
426
427 We will not share Personal Data in ways unrelated to those described above without providing an individual We will not share Personal Data in ways unrelated to those described above without providing an individual
428 with an opportunity to opt out of such use or disclosure or otherwise prohibit such unrelated uses or with an opportunity to opt out of such use or disclosure or otherwise prohibit such unrelated uses or
429 disclosures. disclosures.
430
431 G. Onward Transfer G. Onward Transfer
432
433 Prometric may employ other companies and individuals to perform functions on our behalf which require Prometric may employ other companies and individuals to perform functions on our behalf which require
434 us to transfer Personal Data and other information to a third party data controller, processor or vendor. us to transfer Personal Data and other information to a third party data controller, processor or vendor.
435 Our employees, agents and contractors who have access to Personal Data and information are contractually Our employees, agents and contractors who have access to Personal Data and information are contractually
436 required to protect the information in a manner that is consistent with this Privacy Policy and the principles required to protect the information in a manner that is consistent with this Privacy Policy and the principles
437 of the Privacy Shield with regards to transfer, processing or use of Personal Data. We do not transfer of the Privacy Shield with regards to transfer, processing or use of Personal Data. We do not transfer
438 information to third parties who are not acting in a contractual capacity as Prometric's agent or on information to third parties who are not acting in a contractual capacity as Prometric's agent or on
439 Prometric's behalf. Prometric will, at all times, remain liable for Personal Data that it transfers onward to Prometric's behalf. Prometric will, at all times, remain liable for Personal Data that it transfers onward to
440 a third party. a third party.
441
442 H. Notices to Residents of Countries Outside the United States H. Notices to Residents of Countries Outside the United States
443
444 Prometric is headquartered in the United States of America. All Personal Data of International candidates, Prometric is headquartered in the United States of America. All Personal Data of International candidates,
445 with the exception of biometric data, who do business with or international employees who are employed with the exception of biometric data, who do business with or international employees who are employed
446 by Prometric will be accessed from or transferred to the United States, or to our affiliates and data by Prometric will be accessed from or transferred to the United States, or to our affiliates and data
447 processors elsewhere in the world for the appropriate processing, use and storage. “International processors elsewhere in the world for the appropriate processing, use and storage. “International
448 candidates” and “international employees” are candidates or employees residing outside of the United candidates” and “international employees” are candidates or employees residing outside of the United
449 States on a permanent basis who do not hold a United States passport. All international candidates and States on a permanent basis who do not hold a United States passport. All international candidates and
450 employees will be required to provide express consent for the collection, transfer and processing of Personal employees will be required to provide express consent for the collection, transfer and processing of Personal
451 Data to the United States. By continuing to provide Prometric with Personal Data, through registration or Data to the United States. By continuing to provide Prometric with Personal Data, through registration or
452 scheduling as an exam candidate or through the employment hiring process, a candidate or employee scheduling as an exam candidate or through the employment hiring process, a candidate or employee
453 continues to consent to the transfer of Personal Data to the United States until such consent is expressly continues to consent to the transfer of Personal Data to the United States until such consent is expressly
454 withdrawn in writing to Prometric’s Data Protection Manager using the contact information provided withdrawn in writing to Prometric’s Data Protection Manager using the contact information provided
455 below. Prometric will always protect the privacy and security of Personal Data pursuant to our Information below. Prometric will always protect the privacy and security of Personal Data pursuant to our Information
456 Security Guidelines, Policies and Procedures, regardless of the location where it is originally collected or Security Guidelines, Policies and Procedures, regardless of the location where it is originally collected or
457 ultimately processed or stored. ultimately processed or stored.
458
459
460
461
462
463 I. Opt-Out Choices I. Opt-Out Choices
464
465 Individuals can always limit the information provided to Prometric. However, Prometric abides by the Individuals can always limit the information provided to Prometric. However, Prometric abides by the
466 policies of its clients, the test sponsors, regarding the Personal Data of candidates that must be collected policies of its clients, the test sponsors, regarding the Personal Data of candidates that must be collected
467 Prometric Privacy Policy – updated 26 January 2017 Page 10 Prometric Privacy Policy – updated 12 April 2017 Page 10
468 in order for Prometric to administer a test on behalf of the test sponsor. Individuals that do not wish to in order for Prometric to administer a test on behalf of the test sponsor. Individuals that do not wish to
469 provide Personal Data required by the test sponsor will need to contact the test sponsor to make other provide Personal Data required by the test sponsor will need to contact the test sponsor to make other
470 testing arrangements. testing arrangements.
471
472 As permitted by applicable law, individuals may also withdraw consent to the processing of Personal Data. As permitted by applicable law, individuals may also withdraw consent to the processing of Personal Data.
473 However, exercising this right may prevent Prometric’s ability to deliver any further assessments from the However, exercising this right may prevent Prometric’s ability to deliver any further assessments from the
474 test sponsor to the individual withdrawing consent, and the test sponsor may refuse to distribute the test sponsor to the individual withdrawing consent, and the test sponsor may refuse to distribute the
475 individual’s exam results. individual’s exam results.
476
477 Commercial Emails/Direct Marketing Commercial Emails/Direct Marketing
478 Individuals can limit the communications that Prometric sends via direct marketing. To opt-out of Individuals can limit the communications that Prometric sends via direct marketing. To opt-out of
479 commercial emails, simply click the link labeled “unsubscribe” at the bottom of any email sent by Prometric. commercial emails, simply click the link labeled “unsubscribe” at the bottom of any email sent by Prometric.
480 Please note that even if opting-out of commercial emails, Prometric may still need to contact candidates Please note that even if opting-out of commercial emails, Prometric may still need to contact candidates
481 with important transactional information about their Prometric account or scheduled exam. For example, with important transactional information about their Prometric account or scheduled exam. For example,
482 Prometric will still send testing confirmations and reminders, information about test center changes and Prometric will still send testing confirmations and reminders, information about test center changes and
483 closures, and information about test results even if commercial emails have been opted-out. closures, and information about test results even if commercial emails have been opted-out.
484
485 Third-Party Ad Targeting Third-Party Ad Targeting
486 To opt out of being targeted by many third party advertising companies, third parties that collect or receive To opt out of being targeted by many third party advertising companies, third parties that collect or receive
487 information from mobile applications and use that information to provide measurement services and information from mobile applications and use that information to provide measurement services and
488 targeted advertising, or for more information about third party advertising please visit the Network targeted advertising, or for more information about third party advertising please visit the Network
489 Advertising Initiative (NAI) at www.networkadvertising.org. Individuals may also visit Advertising Initiative (NAI) at www.networkadvertising.org. Individuals may also visit
490 www.aboutads.info/choices to learn about opting-out of third-party collection and use of information for www.aboutads.info/choices to learn about opting-out of third-party collection and use of information for
491 ad targeting. Prometric will never provide Personal Data to third parties other than for the purpose for ad targeting. Prometric will never provide Personal Data to third parties other than for the purpose for
492 which the Personal Data was originally collected. which the Personal Data was originally collected.
493
494 For questions about opt-out choices or for assistance with opting-out, please contact Prometric’s Data For questions about opt-out choices or for assistance with opting-out, please contact Prometric’s Data
495 Protection Manager using the contact information in Section V. “How to Contact Us”, below. If sending a Protection Manager using the contact information in Section V. “How to Contact Us”, below. If sending a
496 letter, please include name, address, email address, and a brief explanation of the opt-out communications letter, please include name, address, email address, and a brief explanation of the opt-out communications
497 request. request.
498
499 J. Access to Personal Data J. Access to Personal Data
500
501 1. Access & Correction 1. Access & Correction
502
503 Prometric respects an individual’s right to access and correct their Personal Data. Exam candidates and Prometric respects an individual’s right to access and correct their Personal Data. Exam candidates and
504 Prometric employees have the right with respect to access to: Prometric employees have the right with respect to access to:
505
506  obtain confirmation from Prometric of whether or not Personal Data that relates to them is being  obtain confirmation from Prometric of whether or not Personal Data that relates to them is being
507 processed; processed;
508  have such data communicated to them so that verification of its accuracy and lawfulness of the  have such data communicated to them so that verification of its accuracy and lawfulness of the
509 processing can be confirmed; and processing can be confirmed; and
510  have the data corrected, amended or deleted where it is inaccurate or processed in violation of  have the data corrected, amended or deleted where it is inaccurate or processed in violation of
511 applicable law. applicable law.
512
513 Exam candidates and Prometric employees may request access to and correction of their Personal Data at Exam candidates and Prometric employees may request access to and correction of their Personal Data at
514 any time; however, must supply Prometric with sufficient information to allow us to confirm the identity of any time; however, must supply Prometric with sufficient information to allow us to confirm the identity of
515 the person making the request for access. Candidates and employees may even self-correct such the person making the request for access. Candidates and employees may even self-correct such
516 information by performing the following: information by performing the following:
517
518 For candidates with an online account, simply log into the account at any time to access and update the For candidates with an online account, simply log into the account at any time to access and update the
519 information provided to Prometric. information provided to Prometric.
520
521 Prometric Privacy Policy – updated 26 January 2017 Page 11 Prometric Privacy Policy – updated 12 April 2017 Page 11
522 Employees may update their Personal Data by logging into Dayforce and updating their profile information. Employees may update their Personal Data by logging into Dayforce and updating their profile information.
523
524 For assistance updating Personal Data, please contact Prometric using the contact information in Section For assistance updating Personal Data, please contact Prometric using the contact information in Section
525 V. “How to Contact Us”, below. V. “How to Contact Us”, below.
526
527 2. Restriction to Access 2. Restriction to Access
528
529 Prometric will only restrict access to information to the extent that disclosure is likely to interfere with the Prometric will only restrict access to information to the extent that disclosure is likely to interfere with the
530 safeguarding of important countervailing public interests, or to the extent that the requests for access safeguarding of important countervailing public interests, or to the extent that the requests for access
531 become so excessive and/or repetitive as to cause an undue burden to the organizational resources that become so excessive and/or repetitive as to cause an undue burden to the organizational resources that
532 must be expended in order to fulfill such requests. In such a situation, Prometric may charge a fee for must be expended in order to fulfill such requests. In such a situation, Prometric may charge a fee for
533 excessively repetitive requests for access to cover the costs of its resources to fulfill such requests. In excessively repetitive requests for access to cover the costs of its resources to fulfill such requests. In
534 addition, where personal information is processed solely for research or statistical purposes, access may addition, where personal information is processed solely for research or statistical purposes, access may
535 be denied. Other reasons that Prometric may deny or limit access include: be denied. Other reasons that Prometric may deny or limit access include:
536
537  Interference with the execution or enforcement of the law or with private causes of action, including  Interference with the execution or enforcement of the law or with private causes of action, including
538 the prevention, investigation or detection of offenses or the right to a fair trial; the prevention, investigation or detection of offenses or the right to a fair trial;
539  Disclosure where the legitimate rights or important interests of others would be violated;  Disclosure where the legitimate rights or important interests of others would be violated;
540  Breaching a legal or other professional privilege or obligation;  Breaching a legal or other professional privilege or obligation;
541  Prejudicing employee security investigations or grievance proceedings or in connection with  Prejudicing employee security investigations or grievance proceedings or in connection with
542 employee succession planning and corporate re-organizations; or employee succession planning and corporate re-organizations; or
543  Prejudicing the confidentiality necessary in monitoring, inspection or regulatory functions  Prejudicing the confidentiality necessary in monitoring, inspection or regulatory functions
544 connected with sound management, or in future or ongoing negotiations involving the organization. connected with sound management, or in future or ongoing negotiations involving the organization.
545
546 K. Privacy Policies of Third Parties K. Privacy Policies of Third Parties
547
548 This Privacy Policy only addresses the use and disclosure of information by Prometric. Test sponsors have This Privacy Policy only addresses the use and disclosure of information by Prometric. Test sponsors have
549 their own privacy policies and data collection, use and disclosure practices, and Prometric is not responsible their own privacy policies and data collection, use and disclosure practices, and Prometric is not responsible
550 for compliance with their practices. All individuals are encouraged to familiarize themselves with the privacy for compliance with their practices. All individuals are encouraged to familiarize themselves with the privacy
551 policies and data collection practices of any organization that they interface with. policies and data collection practices of any organization that they interface with.
552
553 L. Cookies and Other Data Collection Technologies L. Cookies and Other Data Collection Technologies
554
555 When an individual visits the Prometric website or uses Prometric’s mobile applications, we collect certain When an individual visits the Prometric website or uses Prometric’s mobile applications, we collect certain
556 information by automated means, using technologies such as cookies, pixel tags, browser analysis tools, information by automated means, using technologies such as cookies, pixel tags, browser analysis tools,
557 server logs, web beacons, and other similar technologies to ensure that the Prometric website offers the server logs, web beacons, and other similar technologies to ensure that the Prometric website offers the
558 best possible experience. In many cases, the information we collect using cookies and other tools is only best possible experience. In many cases, the information we collect using cookies and other tools is only
559 used in a non-identifiable way, without any collection of Personal Data. For example, we use information used in a non-identifiable way, without any collection of Personal Data. For example, we use information
560 we collect about all website users to optimize Prometric websites and capabilities, to understand and we collect about all website users to optimize Prometric websites and capabilities, to understand and
561 measure website traffic patterns, and to send target offerings based on such patterns. Use of the measure website traffic patterns, and to send target offerings based on such patterns. Use of the
562 Prometric website indicates a user’s agreement to the use of cookies and consent to receive Prometric website indicates a user’s agreement to the use of cookies and consent to receive
563 other cookies that may be presented while visiting the Prometric website. other cookies that may be presented while visiting the Prometric website.
564
565 In some cases, Prometric does associate the information collected using cookies and other technology with In some cases, Prometric does associate the information collected using cookies and other technology with
566 an individual’s Personal Data. an individual’s Personal Data.
567
568 1. Types of data collected and technologies used: 1. Types of data collected and technologies used:
569
570  When an individual visits the Prometric website, cookies may be placed on the individual’s technological  When an individual visits the Prometric website, cookies may be placed on the individual’s technological
571 device. Cookies are small text files that websites send to a computer or other Internet-connected device device. Cookies are small text files that websites send to a computer or other Internet-connected device
572 to uniquely identify a browser or to store information or settings in a browser. Cookies allow a website to uniquely identify a browser or to store information or settings in a browser. Cookies allow a website
573 provider to recognize a repeat user of the website each time the user returns. Cookies also help a provider to recognize a repeat user of the website each time the user returns. Cookies also help a
574 website provider deliver a customized experience to each user and enable a website provider to detect website provider deliver a customized experience to each user and enable a website provider to detect
575 Prometric Privacy Policy – updated 26 January 2017 Page 12 Prometric Privacy Policy – updated 12 April 2017 Page 12
576 certain kinds of fraud. In many cases, individuals can manage cookie preferences and opt-out of having certain kinds of fraud. In many cases, individuals can manage cookie preferences and opt-out of having
577 cookies and other data collection technologies used by adjusting the settings on their browsers. All cookies and other data collection technologies used by adjusting the settings on their browsers. All
578 browsers are different, but visiting the “help” section of a browser to learn about cookie preferences browsers are different, but visiting the “help” section of a browser to learn about cookie preferences
579 and other privacy settings may be of assistance. and other privacy settings may be of assistance.
580
581  Prometric websites may use Flash Cookies (also known as Local Stored Objects) and similar  Prometric websites may use Flash Cookies (also known as Local Stored Objects) and similar
582 technologies to personalize and enhance each individual’s online experience. The Adobe Flash Player technologies to personalize and enhance each individual’s online experience. The Adobe Flash Player
583 is an application that allows rapid development of dynamic content, such as video clips and is an application that allows rapid development of dynamic content, such as video clips and
584 animation. Prometric uses Flash cookies for security purposes and to help remember settings and animation. Prometric uses Flash cookies for security purposes and to help remember settings and
585 preferences similar to browser cookies, but these are managed through a different interface than the preferences similar to browser cookies, but these are managed through a different interface than the
586 one provided by an individual’s web browser. To manage Flash cookies, please see Adobe’s website one provided by an individual’s web browser. To manage Flash cookies, please see Adobe’s website
587 at http://kb2.adobe.com/cps/526/52697ee8.html or visit www.adobe.com. Prometric does not use at http://kb2.adobe.com/cps/526/52697ee8.html or visit www.adobe.com. Prometric does not use
588 Flash cookies or similar technologies to serve its own interest-based advertising. Flash cookies or similar technologies to serve its own interest-based advertising.
589
590  Pixel tags and web beacons are tiny graphic images placed on website pages or in some Prometric  Pixel tags and web beacons are tiny graphic images placed on website pages or in some Prometric
591 emails that allow us to determine whether an individual has performed a specific action. When an emails that allow us to determine whether an individual has performed a specific action. When an
592 individual accesses these pages or opens or clicks on an email the pixel tags and web beacons generate individual accesses these pages or opens or clicks on an email the pixel tags and web beacons generate
593 a notice of that action. These tools allow Prometric to measure responses to our communications and a notice of that action. These tools allow Prometric to measure responses to our communications and
594 improve our web pages and promotions. improve our web pages and promotions.
595
596  Prometric server logs and other tools collect information from devices used to access Prometric  Prometric server logs and other tools collect information from devices used to access Prometric
597 websites, such as operating system type, browser type, domain, and other system settings, as well as websites, such as operating system type, browser type, domain, and other system settings, as well as
598 the language a system uses and the country and time zone where the device accessing the Prometric the language a system uses and the country and time zone where the device accessing the Prometric
599 website is located. Prometric server logs also record the IP address of the devices used to connect to website is located. Prometric server logs also record the IP address of the devices used to connect to
600 the Internet, and may enable Prometric to collect information about the websites being visited by an the Internet, and may enable Prometric to collect information about the websites being visited by an
601 individual before and after accessing the Prometric site. Collecting IP addresses and related data is individual before and after accessing the Prometric site. Collecting IP addresses and related data is
602 standard practice on the Internet, and Prometric treats IP addresses as Personal Data. We use IP standard practice on the Internet, and Prometric treats IP addresses as Personal Data. We use IP
603 addresses for purposes such as calculating website usage levels, helping diagnose server problems, addresses for purposes such as calculating website usage levels, helping diagnose server problems,
604 administering the website and combating fraudulent and/or malicious web activity. We also collect administering the website and combating fraudulent and/or malicious web activity. We also collect
605 customary information from web browsers, such as Media Access Control (MAC) addresses, device customary information from web browsers, such as Media Access Control (MAC) addresses, device
606 type, screen resolution, operating system version and internet browser type and version. Prometric type, screen resolution, operating system version and internet browser type and version. Prometric
607 uses this information to ensure that our websites function properly for all devices and browsers and uses this information to ensure that our websites function properly for all devices and browsers and
608 for security purposes. for security purposes.
609
610 Prometric may have relationships with third party advertising companies to place advertisements on its Prometric may have relationships with third party advertising companies to place advertisements on its
611 websites and to perform analytics and reporting functions for its websites. These third party advertising websites and to perform analytics and reporting functions for its websites. These third party advertising
612 companies may place cookies on individual’s computers when visiting Prometric’s website so that the companies may place cookies on individual’s computers when visiting Prometric’s website so that the
613 website can display targeted advertisements to the user. Prometric expects third party advertising website can display targeted advertisements to the user. Prometric expects third party advertising
614 companies to use reasonable efforts to respect browser do-not-track signals by not delivering targeted companies to use reasonable efforts to respect browser do-not-track signals by not delivering targeted
615 advertisements to website visitors whose browsers have a do-not-track setting enabled. Additionally, advertisements to website visitors whose browsers have a do-not-track setting enabled. Additionally,
616 Prometric does not knowingly allow these third party advertising companies to collect Personal Data in this Prometric does not knowingly allow these third party advertising companies to collect Personal Data in this
617 process, and does not give any Personal Data to them. process, and does not give any Personal Data to them.
618
619 To learn about how to opt-out of third party collection and use of information for ad targeting please see To learn about how to opt-out of third party collection and use of information for ad targeting please see
620 Section J. - Opt-Out Choices, Third Party Ad Targeting. Section J. - Opt-Out Choices, Third Party Ad Targeting.
621
622 M. Social Media Interactions M. Social Media Interactions
623
624 Prometric’s websites offer each individual user the ability to share content with friends using social media, Prometric’s websites offer each individual user the ability to share content with friends using social media,
625 such as Facebook and Twitter. Use of the “like” button, sharing buttons and other tools are subject to such as Facebook and Twitter. Use of the “like” button, sharing buttons and other tools are subject to
626 each social media platform’s privacy policies. each social media platform’s privacy policies.
627
628 Prometric Privacy Policy – updated 26 January 2017 Page 13 Prometric Privacy Policy – updated 12 April 2017 Page 13
629 Prometric websites also use Facebook Social Plugins. If a user is logged into Facebook while browsing on Prometric websites also use Facebook Social Plugins. If a user is logged into Facebook while browsing on
630 Prometric’s website, Facebook Social Plugins allows Facebook to share information about a user’s activities Prometric’s website, Facebook Social Plugins allows Facebook to share information about a user’s activities
631 on Prometric’s website with other Facebook users who use Prometric’s website. For example, Social Plugins on Prometric’s website with other Facebook users who use Prometric’s website. For example, Social Plugins
632 allows Facebook to show a user’s Likes and comments on Prometric pages to the user’s Facebook allows Facebook to show a user’s Likes and comments on Prometric pages to the user’s Facebook
633 friends. Facebook Social Plugins also allows users to see their friends’ Facebook activity on Prometric’s friends. Facebook Social Plugins also allows users to see their friends’ Facebook activity on Prometric’s
634 website. Prometric does not receive or control any of the content from Facebook Social Plugins. For more website. Prometric does not receive or control any of the content from Facebook Social Plugins. For more
635 information about Facebook Social Plugins and other social media tools, click here. information about Facebook Social Plugins and other social media tools, click here.
636
637 Prometric may allow a website user to sign in to their online account using Facebook Connect. If an Prometric may allow a website user to sign in to their online account using Facebook Connect. If an
638 individual chooses to do this, we may collect information necessary to facilitate social interactions such as individual chooses to do this, we may collect information necessary to facilitate social interactions such as
639 friend lists, birthday, check-ins, basic profile information and the user’s profile picture, but only if the privacy friend lists, birthday, check-ins, basic profile information and the user’s profile picture, but only if the privacy
640 settings selected by the individual within Facebook allow it. Prometric will use the information collected to settings selected by the individual within Facebook allow it. Prometric will use the information collected to
641 create and facilitate an interactive social experience. In doing so, we will always comply both with the create and facilitate an interactive social experience. In doing so, we will always comply both with the
642 terms of this Privacy Policy as well as with Facebook Connect terms regarding use of Facebook profile terms of this Privacy Policy as well as with Facebook Connect terms regarding use of Facebook profile
643 information. information.
644
645 N. Tell-A-Friend Functions N. Tell-A-Friend Functions
646
647 Prometric offers “tell-a-friend” functionality on our websites. If individuals choose to use this function, we Prometric offers “tell-a-friend” functionality on our websites. If individuals choose to use this function, we
648 will collect Contact Information of a user’s friends. We will automatically send the friends a one-time email will collect Contact Information of a user’s friends. We will automatically send the friends a one-time email
649 with the information specified or inviting them to visit the Prometric site. Prometric uses this information with the information specified or inviting them to visit the Prometric site. Prometric uses this information
650 for the sole purpose of sending a one-time email and does not retain the information. for the sole purpose of sending a one-time email and does not retain the information.
651
652 O. Mobile Applications O. Mobile Applications
653
654 Prometric offers mobile applications that allow individuals to access their Prometric accounts, interact with Prometric offers mobile applications that allow individuals to access their Prometric accounts, interact with
655 Prometric online and receive other information via smartphones and devices. All Personal Data collected by Prometric online and receive other information via smartphones and devices. All Personal Data collected by
656 Prometric via our mobile applications is protected and processed only by the terms of this Privacy Policy. Prometric via our mobile applications is protected and processed only by the terms of this Privacy Policy.
657
658 When an individual downloads Prometric’s mobile applications, he or she may choose to allow Prometric to When an individual downloads Prometric’s mobile applications, he or she may choose to allow Prometric to
659 obtain their precise location from the mobile device. We use this information to customize our response to obtain their precise location from the mobile device. We use this information to customize our response to
660 candidate and potential customer requests. For example, if a candidate is searching for a test center we candidate and potential customer requests. For example, if a candidate is searching for a test center we
661 can display only ones in their area based on the location of the mobile device and provide access to real- can display only ones in their area based on the location of the mobile device and provide access to real-
662 time maps. We may also offer automatic ("push") notifications. Prometric will provide push notifications time maps. We may also offer automatic ("push") notifications. Prometric will provide push notifications
663 only to those customers who opt-in to receive such notifications from us. No one is required to provide only to those customers who opt-in to receive such notifications from us. No one is required to provide
664 location information to Prometric or to enable push notifications to use any of our mobile apps. Questions location information to Prometric or to enable push notifications to use any of our mobile apps. Questions
665 about location and notification privacy should be directed to mobile service providers or the manufacturer about location and notification privacy should be directed to mobile service providers or the manufacturer
666 of such devices to learn how to adjust location and privacy settings. of such devices to learn how to adjust location and privacy settings.
667
668 To learn about how to opt-out of third party collection and use of information for ad targeting please see To learn about how to opt-out of third party collection and use of information for ad targeting please see
669 Section J. - Opt-Out Choices, Third Party Ad Targeting. Section J. - Opt-Out Choices, Third Party Ad Targeting.
670
671
672
673 P. Privacy Shield Certification P. EU-U.S. Privacy Shield Certification
674
675 Prometric maintains self-certification for and complies with the EU-U.S. Privacy Shield Principles regarding Prometric maintains self-certification for and complies with the EU-U.S. Privacy Shield Principles regarding
676 the collection, use, and retention of Personal Data from individuals located in the European Economic Area the collection, use, and retention of Personal Data from individuals located in the European Economic Area
677 and other countries that recognize the principles of the Privacy Shield Framework for the collection, transfer and other countries that recognize the principles of the Privacy Shield Framework for the collection, transfer
678 and processing of Personal Data to the United States. Prometric commits to the Privacy Shield Principles and processing of Personal Data to the United States. Prometric commits to the Privacy Shield Principles
679 including, but not limited to notice, choice, onward transfer, security, data integrity and purpose limitation, including, but not limited to notice, choice, onward transfer, security, data integrity and purpose limitation,
680 access, and recourse, enforcement, and liability for all Personal Data received from individuals residing in Prometric Privacy Policy – updated 26 January 2017 Page 14 the EU. Prometric submits to the investigatory and enforcement powers of the United States Federal Trade Commission (“FTC”) related to all matters concerning Personal Data and privacy. To learn more about the access, and recourse, enforcement, and liability for all Personal Data received from individuals residing in the EU. Prometric submits to the investigatory and enforcement powers of the United States Federal Trade Prometric Privacy Policy – updated 12 April 2017 Page 14 Commission (“FTC”) related to all matters concerning Personal Data and privacy. To learn more about the
681 Privacy Shield program, and to view Prometric’s certification, please visit https://www.privacyshield.gov/. Privacy Shield program, and to view Prometric’s certification, please visit https://www.privacyshield.gov/.
682
683 Q. U.S.-Swiss Safe Harbor Framework Certification Prometric complies with the US-Swiss Safe Harbor Framework as set forth by the US Department of Q. Swiss-U.S. Privacy Shield Certification Prometric maintains self-certification for and complies with the Swiss
684 Commerce regarding the collection, use, and retention of Personal Data from Switzerland. Prometric has -U.S. Privacy Shield Principles regarding the collection, use, and retention of Personal Data from
685 certified that it adheres to the Safe Harbor individuals located in Switzerland for the
686 Privacy collection, transfer and processing of Personal Data to the United States. Prometric commits to the Privacy
687 Principles of notice, choice, onward transfer, security, data integrity Shield Principles including, but not limited to notice, choice, onward transfer, security, data integrity and
688 , access, and enforcement. If there is any conflict between the policies in this privacy polic purpose limitation, access, and recourse, enforcement, and liability for all Personal Data received from
689 y and the Safe Harbor Privacy Princip individuals residing in Switzerland. Prometric submits to the investigatory authority and enforcement
690 les, the Safe Harbor Privacy Principles shall govern with respect to the powers of the United States Federal Trade Commission (“FTC”) and, where applicable, to the S
691 transfer of Personal Data of residents of Switzerland wiss Data
692 . To learn more about the US-Swiss Safe Harbor and to view our certification page, please visit http://www.export.gov/safeharbor/swiss. Protection and Information Commissioner related to all matters concerning Personal Data and privacy. To learn more about the Privacy Shield program, and to view Prometric’s certification, please visit https://www.privacyshield.gov/.
693 R. U.S. Social Security Number Protection Policy Statement R. U.S. Social Security Number Protection Policy Statement
694
695 Prometric collects Social Security numbers and other sensitive Personal Data in the ordinary course of Prometric collects Social Security numbers and other sensitive Personal Data in the ordinary course of
696 business related to employees, and only where required by the test sponsor for candidates. We have business related to employees, and only where required by the test sponsor for candidates. We have
697 implemented reasonable technical, physical and administrative safeguards to help protect the Social implemented reasonable technical, physical and administrative safeguards to help protect the Social
698 Security numbers and other sensitive Personal Data from unlawful use and unauthorized disclosure. Security numbers and other sensitive Personal Data from unlawful use and unauthorized disclosure.
699 Prometric associates and contractors are required to follow these established procedures, both online and Prometric associates and contractors are required to follow these established procedures, both online and
700 offline. offline.
701
702 Access to Social Security numbers is limited to those employees and contractors who have a need to access Access to Social Security numbers is limited to those employees and contractors who have a need to access
703 the information to perform contractual obligations for Prometric. Social Security numbers are only disclosed the information to perform contractual obligations for Prometric. Social Security numbers are only disclosed
704 to third parties in accordance with Prometric’s established policies in accordance with a legitimate business to third parties in accordance with Prometric’s established policies in accordance with a legitimate business
705 purpose. Prometric will only disclose Social Security numbers to those test sponsors, service providers, purpose. Prometric will only disclose Social Security numbers to those test sponsors, service providers,
706 auditors, advisors, and/or successors-in-interest who are legally or contractually obligated to protect them auditors, advisors, and/or successors-in-interest who are legally or contractually obligated to protect them
707 or as required or permitted by law. or as required or permitted by law.
708
709 S. California Privacy Rights S. California Privacy Rights
710
711 California Civil Code Section 1798 allows California residents to ask companies with whom they have an California Civil Code Section 1798 allows California residents to ask companies with whom they have an
712 established business relationship to provide certain information about the companies’ sharing of Personal established business relationship to provide certain information about the companies’ sharing of Personal
713 Data with third parties for direct marketing purposes. Data with third parties for direct marketing purposes.
714
715 Prometric does not share any California consumer Personal Data with third parties for Prometric does not share any California consumer Personal Data with third parties for
716 marketing purposes without consent. marketing purposes without consent.
717
718 If you are a test candidate, Prometric will provide your Personal Data to your test sponsor, who may use If you are a test candidate, Prometric will provide your Personal Data to your test sponsor, who may use
719 the information in accordance with its own privacy policies. the information in accordance with its own privacy policies.
720
721 California residents who wish to request further information about Prometric’s compliance with this law or California residents who wish to request further information about Prometric’s compliance with this law or
722 have questions or concerns about Prometric’s privacy practices may contact us using the contact have questions or concerns about Prometric’s privacy practices may contact us using the contact
723 information in Section V. “How to Contact Us”, below. information in Section V. “How to Contact Us”, below.
724
725
726 IV. Dispute Resolution Process IV. Dispute Resolution Process
727 With respect to Personal Data (both candidate and human resource/employee data), Prometric commits to
728 cooperate with the EU Data Protection Authorities (“DPAs”) by providing recourse for individuals to whom
729 the data relates, implementing follow-up procedures for verifying that the attestations and assertions made
730 in this Privacy Policy are true, and taking responsibility for obligations to remedy problems arising out of A. Filing Complaints
731 Prometric Privacy Policy – updated 26 January 2017 Page 15 any failure to comply with the Principles and the consequences thereof. Prometric will cooperate with the Prometric Privacy Policy – updated 12 April 2017 Page 15
732 DPAs in any investigation or resolution of complaints brought under the Privacy Shield and will comply with
733 any reasonable advice given by the DPAs where the DPAs take the view that Prometric needs to take
734 specific action to comply with the Privacy Shield Principles.
735
736 A. Filing Complaints
737 Exam candidates and employees who have concerns or complaints regarding Prometric’s collection and Exam candidates and employees who have concerns or complaints regarding Prometric’s collection and
738 processing of Personal Data must first utilize Prometric’s internal complaint resolution process by contacting processing of Personal Data must first utilize Prometric’s internal complaint resolution process by contacting
739 Prometric’s Data Protection Manager using the contact information in Section V, “How to Contact Us”, and Prometric’s Data Protection Manager using the contact information in Section V, “How to Contact Us”, and
740 providing a detailed written description of the issue and/or complaint. Prometric will respond to all providing a detailed written description of the issue and/or complaint. Prometric will respond to all
741 complaints related to Personal Data issues in forty-five (45) days or less. complaints related to Personal Data issues in forty-five (45) days or less.
742
743 B. Independent Recourse Mechanism B. Independent Recourse Mechanism
744
745 1. Candidates 1. Candidates
746
747 After exhausting Prometric’s internal complaint process, if an exam candidate is not satisfied with the After exhausting Prometric’s internal complaint process, if an exam candidate is not satisfied with the
748 resolution, he or she may file a complaint with the Better Business Bureau Council of Greater Maryland resolution, he or she may file a complaint with the Better Business Bureau Council of Greater Maryland
749 (“BBB”), an alternative dispute resolution provider based in the United States. Prometric is an A+ accredited (“BBB”), an alternative dispute resolution provider based in the United States. Prometric is an A+ accredited
750 business with the BBB, and the BBB will review all complaints and make a determination as to whether the business with the BBB, and the BBB will review all complaints and make a determination as to whether the
751 complaint should be referred for arbitration or mediation. complaint should be referred for arbitration or mediation.
752
753 BBB Website: http://www.bbb.org/greater-maryland/ BBB Website: http://www.bbb.org/greater-maryland/
754 BBB Telephone: 410-347-3990 BBB Telephone: 410-347-3990
755 BBB Fax: 410-347-3936 BBB Fax: 410-347-3936
756
757 2. Employees 2. Employees
758
759 Employees that have exhausted the internal mechanism for filing complaints above, or who are Employees that have exhausted the internal mechanism for filing complaints above, or who are
760 uncomfortable utilizing such mechanism, should submit complaints, concerns or inquiries to Prometric’s uncomfortable utilizing such mechanism, should submit complaints, concerns or inquiries to Prometric’s
761 Ethics Committee for review. Information on submission of complaints or inquiries to the Ethics Committee Ethics Committee for review. Information on submission of complaints or inquiries to the Ethics Committee
762 can be found in the Prometric Code of Business Conduct, Confidential and Anonymous Reporting, pgs. 39- can be found in the Prometric Code of Business Conduct, Confidential and Anonymous Reporting
763 40.
764
765 C. EU Data Protection Authorities
766 .
767
768 C. Additional Recourse Mechanisms under Privacy Shield
769
770 With respect to Personal Data of residents of the European Union and Switzerland under the EU-US/Swiss-
771 Prometric has further committed to refer unresolved privacy complaints of residents of the European Union US Privacy Shield Principles (both candidate and human resource/employee data), Prometric has further committed to refer unresolved privacy complaints
772 under the EU-US Privacy Shield Principles to the local EU Data Protection Authoriti and to cooperate with the EU DPAs under the EU-U.S.
773 Privacy Shield and the Swiss Federal Data Protection and Information Commissioner FDPIC under the Swiss-
774 U.S. Privacy Shield by providing recourse for individuals to whom the data relates, implementing follow-up
775 procedures for verifying that the attestations and assertions made in this Privacy Policy are true, and taking
776 responsibility for obligations to remedy problems arising out of any failure to comply with the Principles
777 and the consequences thereof. Prometric will cooperate with the DPAs and/or FDPICs in any investigation
778 or resolution of complaints brought under the Privacy Shield and will comply with any reasonable advice
779 given by the DPAs or FDPICs where the DPAs or FDPICs take the view that Prometric needs to take specific
780 es. action to comply with the Privacy Shield Principles.
781 If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.privacyshield.gov for more information and to file a complaint. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.privacyshield.gov for more information and to file a complaint.
782
783 D. Arbitration D. Arbitration
784
785 Prometric will submit to arbitration for certain residual claims only where claimed violations of the Privacy Prometric will submit to arbitration for certain residual claims only where claimed violations of the Privacy
786 Shield Principles have not been resolved after exhausting all of the available dispute resolution mechanisms Shield Principles have not been resolved after exhausting all of the available dispute resolution mechanisms
787 above. An individual who wishes to invoke arbitration must take the following steps prior to initiating an above. An individual who wishes to invoke arbitration must take the following steps prior to initiating an
788 arbitration claim: (1) raise the claimed violation directly with Prometric and afford Prometric with an arbitration claim: (1) raise the claimed violation directly with Prometric and afford Prometric with an
789 opportunity to resolve the issue within 45-days; (2) make use of the independent recourse mechanism; opportunity to resolve the issue within 45-days; (2) make use of the independent recourse mechanism;
790 and (3) raise the issue through their local Data Protection Authority to the U.S. Department of Commerce and (3) raise the issue through their local Data Protection Authority to the U.S. Department of Commerce
791 (“USDOC”) and afford the USDOC with an opportunity to resolve the issue. Prometric Privacy Policy – updated 26 January 2017 Page 16 This arbitration option may not be invoked if an individual’s same claimed violation of the Privacy Shield (“USDOC”) and afford the USDOC with an opportunity to resolve the issue. Prometric Privacy Policy – updated 12 April 2017 Page 16 This arbitration option may not be invoked if an individual’s same claimed violation of the Privacy Shield
792 Principles (1) has previously been subject to binding arbitration; (2) was the subject of a final judgment Principles (1) has previously been subject to binding arbitration; (2) was the subject of a final judgment
793 entered in a court action to which the individual was a party; (3) was previously settled by the parties; or entered in a court action to which the individual was a party; (3) was previously settled by the parties; or
794 (4) if an EU Data Protection Authority has authority to resolve the claimed violation directly with the (4) if an EU Data Protection Authority has authority to resolve the claimed violation directly with the
795 organization. organization.
796
797
798 V. How to Contact Us V. How to Contact Us
799
800 Please contact Prometric directly with any questions or comments about our privacy practices or this Privacy Please contact Prometric directly with any questions or comments about our privacy practices or this Privacy
801 Policy and the statements contained herein. You can reach us via email at Policy and the statements contained herein. You can reach us via email at
802 DataProtectionManager@prometric.com or via mail to: DataProtectionManager@prometric.com or via mail to:
803
804 Data Protection Manager Data Protection Manager
805 Legal Department Legal Department
806 Prometric Inc. Prometric Inc.
807 1501 South Clinton Street 1501 South Clinton Street
808 Baltimore, Maryland 21224 USA Baltimore, Maryland 21224 USA
809
810 If sending a letter, please include name, address, email address, and a brief explanation of your information If sending a letter, please include name, address, email address, and a brief explanation of your information
811 request, inquiry or complaint. request, inquiry or complaint.
812
813 For inquiries or assistance related to time sensitive issues concerning exams such as scheduling, For inquiries or assistance related to time sensitive issues concerning exams such as scheduling,
814 cancellations, eligibility, payment, name changes or other test related issues, please visit cancellations, eligibility, payment, name changes or other test related issues, please visit
815 https://www.prometric.com/en-us/contact-us/pages/default.aspx for the most expeditious resolution of https://www.prometric.com/en-us/contact-us/pages/default.aspx for the most expeditious resolution of
816 your issue. your issue.
817
818
819 VI. Changes to Privacy Policy VI. Changes to Privacy Policy
820
821 From time to time, Prometric may update this Privacy Policy to reflect new or different privacy practices or From time to time, Prometric may update this Privacy Policy to reflect new or different privacy practices or
822 changes to the law. We will place a notice online when we make material changes to this Privacy Policy or changes to the law. We will place a notice online when we make material changes to this Privacy Policy or
823 the statements contained herein. Additionally, if the changes will materially affect the way we use or the statements contained herein. Additionally, if the changes will materially affect the way we use or
824 disclose previously-collected Personal Data, we will notify impacted individuals about the change by sending disclose previously-collected Personal Data, we will notify impacted individuals about the change by sending
825 a notice to the primary email address associated with the account impacted. a notice to the primary email address associated with the account impacted.
826
827