Skip to content
← Home/Legal
DATA PROTECTION & TRUST

Privacy Policy & Data Protection Governance

Effective Date: August 17, 2026 · GDPR, CCPA & Global Standard Compliant

01. Commitment to Executive Privacy

The Business Security Alliance (BSA) is committed to the highest standards of data stewardship. We recognize that our members oversee critical physical and cybersecurity infrastructure for global enterprises, and confidentiality is fundamental to our mission.

Our No-Sell Guarantee: We do not sell, rent, monetize, or broker personal data, member directory information, or attendance rosters to third-party advertisers or data brokers under any circumstances.

02. Information We Collect

We only collect data necessary to provide verified Alliance memberships and digital services:

  • Account Identification: Full name, verified corporate email address, encrypted password hash, and member handle.
  • Professional Profile (Optional & Member-Controlled): Job title, employer organization, security discipline/field, years of experience, regional chapter affiliations, professional bio, telephone number, and social links.
  • Platform Telemetry & Engagement: Event registrations, CPD hours earned, completed knowledge resource modules, and community discussion contributions.

03. Granular Directory Privacy Controls

Every member maintains real-time, toggleable control over their public exposure via their Member Privacy Dashboard (/dashboard?tab=privacy):

LISTED

Discoverable in the directory search, filters, and chapter rosters.

UNLISTED

Profile page accessible via direct link only; hidden from public search.

HIDDEN

Profile returns Not Found; completely private and anonymous across the site.

04. Data Security & Encryption

All data in transit is protected by strict TLS 1.3 encryption with Perfect Forward Secrecy and HSTS preload enforcement. Passwords are cryptographically salted and hashed using multi-round bcrypt. Sensitive database records and session tokens are strictly scoped and guarded against unauthorized escalation.

05. Your Global Rights (GDPR / CCPA)

Regardless of your geographic jurisdiction, you have the right to:

  • Access & Portability: Export a machine-readable copy of your full member record and activity log.
  • Rectification: Edit or correct your profile, email, or privacy preferences at any time.
  • Erasure (Right to be Forgotten): Request the permanent deletion of your account and associated database records.

06. Data Protection Officer (DPO) Contact

For formal privacy inquiries, data subject access requests (DSAR), or compliance audits, contact our Data Protection Officer: