
PRIVACY POLICY
How we collect, use, and protect your personal information
Last updated: October 6, 2026, Version 3.1
Who We Are
The controller is IESF (International Esports Federation), an organization with its registered seat at 615, 6F, Suyeonggangbyeon-daero 140, Haeundae-gu, Busan, Korea (further referred to only as "IESF" or "controller").
Controller Contact Details:
Email: office@iesf.org
Phone: +82 2 715 6668
Data Protection Officer (DPO):
IESF has appointed a Data Protection Officer responsible for overseeing data protection strategy and compliance. For any questions, concerns, or requests related to the processing of your personal data, you may contact the DPO directly:
Email: privacy@iesf.org
Address: Data Protection Officer, IESF, 615, 6F, Suyeonggangbyeon-daero 140, Haeundae-gu, Busan, Korea
Data We Collect
We collect and process the following categories of personal data depending on how you interact with our services:
Account Registration Data
- Full name, email address, and password (hashed)
- Date of birth (to verify age eligibility and enforce age requirements)
- Nationality and country of residence
- Profile picture (optional)
OAuth Provider Data
If you choose to sign in using a third-party OAuth provider, we receive and store the following data from the respective provider:
- Google: Name, email address, profile picture, and Google account ID
- Discord: Username, discriminator, email address, avatar, and Discord user ID
- Twitch: Display name, email address, profile image, and Twitch user ID
We do not receive or store your passwords from OAuth providers. We only request the minimum permissions necessary for authentication.
Technical Data
- IP address, browser type, and user agent string
- Device information and operating system
- Access timestamps and referring URLs
Site Analytics
With your consent (cookie banner), we collect aggregate site analytics — page path, page title, referrer, user agent, hashed IP, country, device type, and time-on-page — to understand how the site is used. We do not collect names, emails, or precise locations for analytics purposes. Raw analytics data is dropped after 90 days; aggregate counts are retained indefinitely. We run our own first-party tracker on our own servers; no third-party analytics like Google Analytics is used. You can opt out at any time by rejecting cookies.
The same tracker also notes whether the browser has been counted before (a yes or no note in your browser storage), the window width rounded to the nearest 100 pixels, the region of your country, and any campaign tags (utm) in the link you arrived by. On the World Esports Championship pages (the championship event page here and wec.iesf.org) it also keeps counters of where on a page people click (a position on a grid and the name of the element, never its text and never anything typed), how far down the page people scroll, how fast the page paints, and how many browser errors happen. These counters hold no address, no account and no identifier, are not collected on pages that can show personal details (athlete and delegate links, nation pages, dashboards, admin), and are kept for 12 months. Do Not Track and Global Privacy Control are respected on wec.iesf.org, where you can also stop the measuring on its privacy page.
Legal Bases for Processing (GDPR Article 6)
We process your personal data only when we have a valid legal basis under Article 6 of the General Data Protection Regulation (GDPR). The following table outlines the legal basis for each processing activity:
Account Creation and Management
Legal Basis: Article 6(1)(b) — Performance of a contract
Processing is necessary for the performance of the contract between you and IESF when you create an account and use our services.
Competition Registration and Participation
Legal Basis: Article 6(1)(b) — Performance of a contract
Processing your data (name, DOB, nationality, team affiliation) is necessary to register you for and administer esports competitions.
Age Verification and Guardian Consent
Legal Basis: Article 6(1)(c) — Legal obligation
Processing date of birth and guardian details is necessary to comply with legal obligations regarding the protection of minors.
OAuth Authentication (Google, Discord, Twitch)
Legal Basis: Article 6(1)(a) — Consent
You provide explicit consent when authorizing IESF to access your account data from a third-party OAuth provider during sign-in.
Newsletter and Marketing Communications
Legal Basis: Article 6(1)(a) — Consent
We only send marketing communications with your explicit opt-in consent, which you may withdraw at any time.
Security, Fraud Prevention, and Anti-Cheat
Legal Basis: Article 6(1)(f) — Legitimate interest
Processing IP addresses, device data, and behavioral patterns is necessary for our legitimate interest in maintaining platform security and competition integrity.
Analytics and Platform Improvement
Legal Basis: Article 6(1)(f) — Legitimate interest
Aggregated and anonymized usage data is processed for our legitimate interest in understanding how our services are used and improving the user experience.
Data Sharing with Member Federations and Partners
Legal Basis: Article 6(1)(b) — Performance of a contract / Article 6(1)(f) — Legitimate interest
Sharing competition-related data with member federations and tournament partners is necessary for the performance of competition services and our legitimate interest in organizing international esports events.
Competition Data Handling
When you participate in IESF-sanctioned esports competitions, we collect and process additional data specific to the competition context:
- Player Profiles: In-game names, game-specific IDs, team affiliations, and player rankings
- Match Data: Competition results, match statistics, scores, and performance metrics
- Eligibility Data: Passport or national ID information (for nationality verification), date of birth verification, and anti-doping compliance records. For the World Esports Championship this includes one health-related question, whether the athlete holds a Therapeutic Use Exemption; the answer is yes or no only and we ask for no medical detail
- World Esports Championship Athlete Details: Your gender (male or female, as it appears on your official documents), an optional middle name, your shirt size, a passport-style photograph of your face for your accreditation pass, your own WhatsApp number and email address, the game IDs your title needs (for example a Steam ID, a Discord ID or a Mobile Legends player ID, or a link to an HLTV or Dotabuff profile), whether you are a professional player (and if so your team's name and social media links), links to your own Facebook, Instagram or X accounts if you wish to give them, your in-game role, and the city and airport you fly from and the city and airport you fly to (where you land). If you wish, you can tick a box for dietary needs and a box for accessibility needs and add a few words; we no longer ask whether you hold a Therapeutic Use Exemption. When a team is handed in, the person who submits it gives their name, WhatsApp number and the legal name of their organisation. For past championships, IESF also keeps the names of the people who took part, with their country, title and championship, taken from the published results on iesf.gg, the IESF competition platform. This is a record of the results only: it is not linked to any account or Gamer Pass profile, and anyone named in it can ask IESF through the contact page to have their name removed. You are asked, with a short explanation of why and for how long, whether you want these details kept for future entries; a box you tick or leave empty, and you can change your mind. Athletes must be at least 16 years old on the first day of the championship; an athlete who is 16 or 17 on that day also needs a parent or guardian's consent, on a form the guardian signs and you upload, or through an email we send them.
- World Esports Championship Travel and Welfare Details: Where the region your national federation belongs to requires it, athletes and members of a national delegation are also asked for their passport number, expiry date and a scan, visa details (middle name, nationality, place of birth, home address, phone number, and where and when the passport was issued) and a photograph for the visa application, the city and airport they fly from, their arrival and departure dates and a copy of their flight ticket, an emergency contact, and any dietary or access needs. Members of a delegation are also asked for a photograph and a shirt size for their accreditation pass and kit, and for their date of birth, gender, nationality, place of birth, home address, and phone and WhatsApp numbers, and must be at least 18 years old on the first day of the championship.
- Media Content: Photos, videos, and livestream footage captured during competitions
A national federation may enter these details, including passport, visa, flight ticket, emergency contact, dietary and access details, for one of its own athletes or delegation members who has asked it to. The federation confirms each time that it holds the person's authority to do so, the person is emailed which groups of details were entered (never the details themselves) and can correct any of them, and our record shows that the federation entered them, which federation account did so, and when. For an athlete who has asked it to, the federation's own delegate may also record the athlete's consent to take part, when the athlete cannot reach their own link; the record then says the consent was given by the delegate on the athlete's behalf (never as the athlete's own), which account did so, when, and the delegate's internet address and browser, and the delegate uploads the signed consent document. Only the IESF Secretariat and that federation can open the signed consent document. If the athlete later gives the consent themselves, their own consent replaces it.
When a save replaces something, our audit trail also notes what was replaced: the old gamer name (which is public anyway), only the fact that a shirt size was replaced, and for a name, date of birth, gender or game ID a marker that cannot be turned back into the old value; it holds no passport, photograph or health detail. This record and the audit trail behind it are kept as the history of how an entry was made, are not part of the automatic deletion described under Retention, and no deletion date has been set for them.
A federation can enter passport, visa, flight ticket, emergency contact, dietary and access details but can never read them back: it sees only whether each one is on file, and the two flight dates. Only the IESF Secretariat can read them, and the Therapeutic Use Exemption answer as well. A federation sees the other details for its own athletes and delegation members only.
The local organising committee sees names, roles, arrival and departure dates, where a person flies in from, shirt sizes, and whether a passport scan and visa photo are on file, and nothing about the competition; it does not see passports, tickets, photographs, dates of birth, gender, emergency, dietary or access details, or game IDs. The photograph is seen only by the IESF Secretariat, the person's own national federation and the person, and is never published; the local organising committee does not see it.
To let the Secretariat work with them, copies of the passport scan, the visa photo and the accreditation photograph of an athlete may be kept in a private Google Drive folder. Who can open it is controlled by the Google Drive sharing settings of that folder, which the IESF Secretariat administers. Google stores the files for us. They are never shared by link or made public. A copy in that folder is deleted when the original is deleted, replaced or removed on the dates above, so it is never kept longer than the original.
Competition results and player rankings are considered public information and may be published on the IESF website, shared with media partners, and distributed to member federations. Individual player statistics may also be shared with game publishers for the purpose of anti-cheat enforcement. Once a national team for the World Esports Championship has been locked, and the public teams pages have been switched on, the gamer name, role, country and title of each team member are shown publicly on the IESF website. A real name is never shown, and anyone under 18 is counted but not named.
Retention: Competition data, including match results and player statistics, is retained indefinitely as part of IESF's historical records. For the World Esports Championship, an athlete's name, gamer name, country, title and championship are kept permanently as the historic record of who took part. Passport scans, visa photos, flight tickets and travel details are deleted 14 days after the championship ends, the Therapeutic Use Exemption yes or no answer, dietary, access and emergency contact answers after 90 days.
The dietary needs and accessibility needs boxes, and any words typed beside them, are deleted 90 days after the championship ends, are seen only by the IESF Secretariat, and are never kept for future entries, even if the athlete ticked the box to keep their details.
The name, WhatsApp number and organisation name given by the person who submits a team are deleted 12 months after the championship ends (IESF may set a shorter period, never a longer one); the team, its country and its title stay as the record.
Date of birth, middle name, gender, shirt size, the accreditation photograph, the signed consent document (where a federation delegate recorded the consent for the athlete), WhatsApp number, email address, game IDs, social media links, professional-player details (team name and its social media links), in-game role and the technical details recorded when consent was given (internet address and browser) 14 days after the last championship the athlete is entered in ends, unless the athlete ticked the box to keep their details for future entries. For an athlete who ticked it, those details are kept for at most 12 months after the last championship they are entered in ends (the Secretariat may set a shorter period, never a longer one); an athlete entered in a later championship keeps them for it, and the period starts again after that one. An athlete who agreed before the box existed was told 12 months and keeps that. Anyone can ask for their details to be deleted sooner.
Visa details, including phone number, home address and place of birth, go with the travel details after 14 days, and a shirt size copied into the travel details goes then too. The email address an invitation was sent to and the reason the Secretariat gave when it did not approve a person a federation asked to add are deleted 12 months after the championship ends.
Athletes must be at least 16 years old on the first day of the championship. An athlete who is 16 or 17 needs a parent or legal guardian's consent, given either through a link emailed to the guardian or on a printed form that the guardian signs and the athlete uploads. The guardian's name, email address and relationship, and the signed form, are kept for at most 12 months after the championship ends so that consent can be shown to have been given, and are then deleted; only the date consent was given is kept. Only the IESF Secretariat can open the signed form.
Deletion is automatic and runs once a day; it is switched on after the last championship IESF has scheduled has ended (IESF may switch it on sooner), so the details of an earlier championship can wait until then.
For members of a national delegation, the passport scan, visa photo, flight ticket, date of birth, nationality, place of birth, home address, phone and WhatsApp numbers and travel details are deleted 14 days after the championship ends, emergency contact, dietary and access answers after 90 days, and the photograph, shirt size, the email address the invitation was sent to, the words describing a role entered as “Other”, the position in the federation typed for them and the reason a federation gave for replacing a delegate, 12 months after it ends; their name, national federation and role on the delegation are kept permanently as the record of who was on it.
When a passport scan is uploaded the person may be asked whether to remove it after the championship or keep it for future championships; the question is offered only when IESF has switched it on, and until then every passport is removed on the date above. Removing it is the default. If someone chooses to keep it, only the scan and its expiry date are kept, until the passport expires or they ask us to delete it, and the passport number and every other detail are still deleted 14 days after the championship ends.
The record of who entered or changed what (when a federation or the Secretariat filled in a section on someone’s behalf, and the confirmation that the person had agreed to it) and the audit log are kept for as long as the championship records are kept. They show who did it and when, not the details themselves, which are deleted on the dates above. IESF has not yet set a period for this record and will set one.
Passport scans provided by event speakers are governed by the shorter period set out in “Event Speakers” below.
Event Speakers
If you are invited to speak at an IESF event, we ask you to complete a speaker profile through a personal link. No account is created and no password is needed. We collect two distinct sets of information, for two distinct purposes.
- Profile Data (published): Your name, role, organisation, biography and photograph, published on the event page with your consent.
- Contact and Social Handles (not published): Your email address, WhatsApp number and any social media handles you provide. These are used by the organising team to reach you and to plan event promotion. They are not displayed on the website.
- Travel and Visa Data (not published): Your departure city and airport and a scan of your passport, collected under a separate consent and used only for your travel arrangements and, where applicable, visa-related support. It is seen only by the IESF Secretariat, who are based in Busan, Korea; it is never published, never shared outside IESF, and is deleted 14 days after the event ends.
Passport scans are accessible only to IESF administrators and the IESF Secretariat, who prepare the invitation letters. Every access is recorded. They are never published, never shared with member federations, and never used for any purpose other than your travel to the event.
Retention: Passport scans and travel details are deleted automatically 14 days after the event ends. Published speaker profiles are retained as part of the event's historical record. Contact details are retained for the duration of our working relationship with you.
Because speakers have no account on this platform, requests to access, correct or delete your speaker data cannot be made through an account settings page. Email info@iesf.org and we will action your request and confirm in writing.
Summit Registration
Attending an IESF summit is an application, not an automatic booking: you submit your details, IESF reviews them, and approval is what confirms your place. Registration data is never published on the website.
- Your details: Name, email address, phone number, job title, organisation, country, age and gender. Your LinkedIn profile is optional. Used to assess your application and to contact you about the event.
- Your professional interests: The field you work in, who you would like to connect with, and why you are attending. Used to plan the programme and introductions.
- Accessibility and catering needs: Some events ask about dietary requirements or access needs. These can reveal information about your health or beliefs, so they are special category data and are collected only under a separate, explicit consent that you may decline while still registering. They are stored apart from the rest of your application and are excluded from every attendee list and export.
- Age: we ask your age for event planning. Summits are open to attendees of any age, students included, so the age is not used to accept or refuse anyone. We ask for an age rather than a date of birth, because the age is all we need. Gender is asked for event planning and reporting under our legitimate interest (Article 6(1)(f)) in understanding who attends; a choice is required but “Prefer not to say” is one of the options, and choosing it is a complete answer.
- Photography: Photos and videos taken at the event may be used by IESF for promotional and communications purposes. You are told this when you register, and asked to confirm you understand it rather than to agree to it. Our lawful basis is legitimate interest (Article 6(1)(f)) — documenting and promoting our own events — not consent, because a permission you cannot refuse and still attend would not be freely given. You have the right to object: tell us at info@iesf.org and we will keep you out of published material.
- Consent record: The time, IP address and browser you consented from, kept as proof that consent was given.
Accessibility and catering answers are readable only by IESF administrators and the IESF Secretariat, who arrange the catering and access. They are read one attendee at a time and every access is recorded. Members of the IESF Board can see the attendee list but cannot see these answers.
Retention:
- Accessibility and catering answers are deleted automatically 3 months after the event ends, once catering and access arrangements are settled.
- Applications that were declined or withdrawn are deleted entirely 90 days after the event ends.
- Approved registrations are kept for 7 years after the event, because who attended is part of IESF's record of it. After 7 years everything except your name, the event and its dates is deleted — your email address, phone number, employer, job title, LinkedIn profile, country and all of your answers are cleared automatically.
Like speakers, summit attendees have no account on this platform, so these requests cannot be made through an account settings page. Email info@iesf.org to access, correct, or delete your registration data, to withdraw a consent you have given, or to object to processing we carry out under legitimate interest — including the use of your photograph. We will action your request and confirm in writing.
Cookies
We use cookies and similar technologies to enhance your experience on our platform. When you visit our login page, we set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we set cookies to save your authentication session. These cookies are essential for the platform to function and include JWT authentication tokens. Session cookies expire when you log out; persistent login cookies (if "Remember Me" is selected) last for up to two weeks.
For more detailed information about the cookies we use and how to manage your cookie preferences, please see our Cookie Policy.
Embedded Content from Other Websites
Pages on this site may include embedded content (e.g. videos, images, articles, social media feeds). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Who We Share Your Data With
We may share your personal data with the following categories of recipients:
- IESF Member Federations: National esports federations that are members of IESF, for the purpose of organizing and administering national and regional competitions
- Tournament Platform Partners: Third-party platforms used to host IESF-sanctioned competitions
- Anti-Cheat and Integrity Providers: Services that ensure fair play and competition integrity
- Service Providers: Hosting, email, analytics, and other infrastructure providers that process data on our behalf under data processing agreements
- Legal and Regulatory Bodies: Where required by law or to protect IESF's legal rights
Personal data may be transferred to countries outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or transfers to countries with an adequacy decision.
How Long We Retain Your Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Specific retention periods include:
- Account data: Retained for the lifetime of your account, plus 2 years after account deletion to comply with legal obligations
- Competition results and rankings: Retained indefinitely as part of IESF's historical sports records
- Identity verification documents and personal details of athletes: Passport scans, visa photos, flight tickets and travel details are deleted 14 days after the championship ends, emergency contact, dietary and access answers 90 days after it ends, the Therapeutic Use Exemption answer 90 days after it ends, and date of birth, gender, shirt size, accreditation photographs, game IDs, contact details, social media links and consent details 14 days after the last championship the athlete is entered in ends, or at most 12 months after the last championship the athlete is entered in ends if the athlete ticked the box to keep their details for future entries. Names, gamer names, countries and titles are kept as the historic record
- Identity verification documents and personal details of delegation members: Passport scans, visa photos, flight tickets, dates of birth, nationalities, places of birth, home addresses, middle names, contact email addresses, phone and WhatsApp numbers and travel details are deleted 14 days after the championship ends, emergency contact, dietary and access answers 90 days after it ends, and photographs, shirt sizes, the invitation email address, and the words describing a role entered as “Other”, 12 months after it ends. Names, national federations and delegation roles are kept as the record of who was on the delegation
- Requests to claim a player profile: When you ask to claim an existing player profile, what you write to show it is yours, and the note a reviewer gives when a request is not approved, are deleted 12 months after the request is decided, or 12 months after you made it if it is never decided or you withdraw it; the record that a request was made and how it was decided is kept.
- Nominations for the IESF Ordinary General Meeting: These documents are used only to run the IESF Ordinary General Meeting election. The candidate's name, member nation and position are part of the meeting's permanent record and appear in the final agenda. The photo, CV and letters are seen only by your federation and the IESF Secretariat. If the candidate is elected we keep them until three years after the meeting, the length of the term; otherwise we delete them twelve months after the meeting. Drafts that are never submitted are deleted 90 days after the submission deadline.
- Technical logs: Retained for 12 months for security and debugging purposes
- Consent records: Retained for 5 years after consent is withdrawn, as required for compliance documentation
- Support requests: When you delete your account, your support requests and our replies are kept as our record of the help we gave, together with the name and email address you gave us on them. They are no longer linked to an account, and nobody who later registers that address can see them
When data is no longer required, it is securely deleted or anonymized so that it can no longer be associated with you.
What Rights You Have Over Your Data
Under the GDPR and applicable data protection laws, you have the following rights regarding your personal data. If you exercise any of the rights below, we will respond to your request within 30 days of its receipt. In justified cases, we may extend this period to 60 days, which we will inform you about.
Right of Access
You have the right to obtain from the controller confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the following information: the purposes of the processing; the recipients or categories of recipient to whom the personal data have been disclosed, in particular recipients in third countries; the envisaged period for which the personal data will be stored. The data subject also has the right to obtain a copy of the personal data that are being processed.
Right to Rectification
If you believe IESF is processing incorrect, inaccurate, or outdated personal data about you, you have the right to obtain the rectification of personal data. It is important for us to process accurate personal data about you, so be sure to use this right whenever any of your personal data, which is important to your relationship with us, changes. Based on your corrected or up-to-date information, we will rectify the personal data we process about you.
Right to Erasure ('Right to be Forgotten')
You shall have the right to obtain from the controller the erasure of personal data concerning you where one of the following grounds applies and there are no statutory exclusions:
- The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed
- The data subject withdraws consent on which the processing is based, and where there is no other legal basis for the processing
- The data subject objects to the processing of personal data, processed on the basis of legitimate interest, due to their specific situation and there are no overriding legitimate grounds for the processing
Right to Restriction of Processing
You shall have the right to obtain from the controller restriction of processing where one of the following applies:
- If you contest the accuracy of the personal data being processed, for a period enabling the controller to verify the accuracy
- The processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead
- We no longer need the personal data for the processing, but they are required by you for the establishment, exercise, or defence of legal claims
- You object to the processing of personal data pending the verification of whether the legitimate grounds of the controller override those of the data subject
In these cases, IESF will not delete your personal data but will mark it and restrict its processing for certain purposes.
Right to Data Portability
You shall have the right to receive the personal data concerning you, which you have provided to a controller, and the processing is carried out by automated means in a structured, commonly used, and machine-readable format. You have the right to transmit those data to another controller. If it is technically feasible, we will directly transmit your personal data to another controller.
Right to Object and Automated Individual Decision-Making
You shall have the right to object, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on our interest, including profiling based on those provisions. Where personal data are processed for direct marketing purposes, you shall have the right to object at any time to the processing of personal data concerning you.
You also have the right to object if your personal data is processed automatically, which may result in a decision that has legal effects on you or otherwise affects you significantly.
In the event of an objection to the processing of your personal data that are being processed on a legal basis of IESF's legitimate interest, IESF will assess the situation based on the information provided by you and inform you whether IESF's legitimate interest prevails in a particular situation and the processing will continue or your rights as a data subject prevail and the processing will be stopped.
Right to Withdraw Consent
If your personal data are being processed based on the consent, you are entitled to withdraw this consent at any time. However, withdrawal of consent has no impact on the legality of processing resulting from consent before its withdrawal.
Right to Lodge a Complaint
If you believe that IESF is processing your personal data in violation of the GDPR or applicable data protection laws, you have the right to lodge a complaint with a supervisory authority in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement.
How to Exercise Your Rights
You may exercise any of your data subject rights by contacting our Data Protection Officer at privacy@iesf.org.
Important: Please state your name, surname, e-mail address, or permanent address in your request. If you do not provide us with this information, your request will not be accepted. We require this additional information to verify your identity and not to disclose your personal information to an unauthorized person.
Data Breach Notification
IESF takes the security of your personal data seriously. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, IESF will:
- Notify the supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. The notification will include the nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed to address the breach.
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34. The notification will describe the nature of the breach in clear and plain language, provide the DPO's contact details, describe likely consequences, and outline the measures taken to address or mitigate the breach.
- Document all breaches regardless of severity, including the facts of the breach, its effects, and the remedial actions taken. This documentation is maintained to enable the supervisory authority to verify compliance.
Reporting a suspected breach: If you believe your personal data has been compromised or you have identified a security vulnerability on the IESF platform, please contact our Data Protection Officer immediately at privacy@iesf.org.
Questions About Privacy?
If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer.
Contact DPO