Internal Audit Academy BV Privacy Policy for the European IIA Conference 2026.
Who is the controller?
Internal Audit Academy BV (BE0589935390), located at De Kleetlaan 5BC, 1831 Diegem is responsible for the processing of personal data as shown in this privacy policy. Internal Audit Academy BV is organizing the European IIA Conference 2026. This privacy policy outlines how we collect, use, and protect the personal data of the conference participants.
About your privacy
Your privacy is important to us, and we protect your personal data in accordance with applicable data protection legislation, specifically the General Data Protection Regulation 2016/679 (“GDPR”).
What is personal data?
Personal data is information relating to an identified or identifiable natural person. This includes information such as name, company, e-mail, and phone number.
What principles do we apply to the processing of personal data?
For all processing of personal data, we apply the following principles. Personal data will be:
a) processed fairly and lawfully; b) collected for specific, explicit and legitimate purposes and not processed in a manner incompatible with those purposes; c) adequate, relevant and not excessive; d) accurate and, where necessary, up to date; e) kept in an identifiable form for no longer than necessary; and f) kept secure.
From whom do we collect personal data?
We collect personal data from participants of the European conference and visitors of this website.
How do we collect personal data?
We collect information directly from you when you visit this website or register for the conference.
On what legal basis do we process your data?
The following legal bases may apply depending on the nature of the processing.
- Performance of a contract: to manage your registration and participation in the conference;
- Legal obligations: for accounting, tax, and regulatory compliance;
- Legitimate interests: for event organization, communication, and security;
- Consent: where required, such as for marketing communications, optional data sharing with sponsors, and cookies.
Where processing is based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
What personal data do we collect?
The categories of personal data we collect are as follows:
- Personal identification data such as name, company, e-mail address, and phone number.
- Payment information such as proof of payment
- Electronic identification: tracking results of your usage of this website (also see our cookie policy)
For what purposes do we use your personal data?
We use your personal data for the following purposes:
- Event administration and communication;
- Providing you with information about the conference;
- Sharing relevant information with our sponsors[ka1] and with ECIIA aisbl.
With whom do we share your personal data?
We share your personal data with ECIIA aisbl. Where applicable, limited personal data (such as name, company, and professional role) may be shared with conference sponsors for conference-related purposes only. Such sharing will be subject to appropriate contractual safeguards and, where required, your consent.
We have contractual safeguards in place to ensure the protection of your personal data when disclosing it to these third parties. Your personal data will never be rented or sold to third parties for commercial purposes.
We enter into a processing agreement with third parties who process your data on our behalf to ensure the same level of security and confidentiality of your data. If your personal data is transferred to a country outside the European Union or to an international organization, this will be done in accordance with the applicable regulations and only if an equivalent level of data protection is provided.
How long do we keep your personal data?
Your personal data will be retained for 24 months after the conference, unless we are legally required to retain it for a longer period. After this period, your data will be securely deleted.
How do we protect your personal data?
We have implemented administrative, technical, and organizational measures to protect your personal data against destruction, loss, alteration, unwanted disclosure, and unauthorized access or modification .
In the event that your data is part of a data breach, we will act in accordance with the GDPR and the guidelines of the Data Protection Authority.
What are your rights and how can you exercise them?
You have the legal right under articles 15-22 of the GDPR to:
- Access your personal data;
- Rectify, complete or update your data;
- Erase your personal data (‘right to be forgotten’);
- Restrict the processing of your personal data;
- Object to the processing of your personal data;
- Receive your personal data in a structured, commonly used and machine-readable format and to (have) transmit(ted) your personal data to another organization.
To exercise these rights, please contact us at privacy@iiabelgium.org. A proof of identity may be required.
You also have the right to lodge a complaint with your Data Protection Authority. The Belgian Data Protection Authority can be reached at this link.
Contact
If you have any questions, comments, or complaints in relation to this privacy policy or our processing of your personal data, please feel free to contact us by regular mail to Internal Audit Academy BV, De Kleetlaan 5BC, 1831 Diegem or via privacy@iiabelgium.org.
Update of the Privacy Policy
Internal Audit Academy BV reserves the right to modify this privacy policy to comply with legislation or its practices. You are invited to consult the policy for any updates.
[ka1]eigenlijk moet dit op basis van consent