Global Privacy Notice — India DPDP • EU GDPR • UK GDPR • UAE PDPL • Other Applicable Laws
Effective date: 24 September 2026 | Last updated: 24 September 2026
Purpose and Scope
This Privacy Policy explains how FEDA Global collects, uses, stores, shares and protects personal data when individuals use the website, apply for membership, register for events, participate in chapters or initiatives, submit business requirements, communicate with FEDA, appear in directories/media, or otherwise interact with FEDA.
FEDA intends to apply a privacy-by-design approach and comply with applicable data-protection laws based on the individual, processing activity and jurisdiction. These may include India’s Digital Personal Data Protection Act, 2023 and notified Rules; the EU General Data Protection Regulation (GDPR); UK data-protection law/UK GDPR as amended; UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection; and other applicable laws such as the California Consumer Privacy Act (CCPA), where statutory thresholds and territorial requirements are met.
Data We May Collect
⦁ Identity and contact data: name, title, photograph, date of birth where necessary, email, telephone/WhatsApp, postal address and country.
⦁ Professional and organizational data: company/institution, designation, industry, business profile, website, LinkedIn/profile links, membership category, professional biography and business requirements.
⦁ Membership and application data: eligibility information, documents submitted for verification, membership history, benefits used and correspondence.
⦁ Transaction data: invoices, payment status, transaction references, tax information and limited payment metadata. Full card data should be handled by authorized payment processors, not stored by FEDA unless necessary and compliant.
⦁ Event data: registrations, attendance, dietary/accessibility requirements where voluntarily provided, photographs/video, speaker information, travel/delegation information where relevant.
⦁ Business-facilitation data: sourcing requirements, products/services, supplier/buyer interests, investment or partnership requirements and communications.
⦁ Technical data: IP address, browser/device data, logs, cookie identifiers, approximate location inferred from IP, referral URLs and website interaction data.
⦁ Marketing preferences: newsletter subscription, event interests, consent records and opt-out choices.
⦁ Sensitive/special-category data only where necessary, lawful and appropriately protected; FEDA should avoid collecting such data by default.
How We Collect Data
We collect data directly from forms, applications, registrations, emails, calls, WhatsApp/business communications, event participation and member interactions; automatically through website technologies; from authorized representatives; and, where lawful, from public professional sources, event partners, chapters, referral partners or service providers.
Purposes and Lawful Bases
| Purpose | Examples | Typical Lawful Basis |
| Provide requested services | Membership, events, chapter participation, business enquiries, certificates, directories | Contract / steps at request / legitimate use / consent as applicable |
| Administration & security | Identity verification, payments, fraud prevention, records, IT security | Legal obligation / legitimate interests / permitted use |
| Networking & facilitation | B2B introductions, sourcing, partner referrals, delegations | Contract / consent / legitimate interests depending on context |
| Communications | Transactional notices, service updates, membership renewal | Contract / legal obligation / legitimate interests |
| Marketing | Newsletters, event promotions, offers | Consent or other lawful basis permitted locally; opt-out provided |
| Media & publicity | Event photos, member stories, speaker profiles | Consent or legitimate interests where lawful and balanced |
| Legal & compliance | Tax, accounting, disputes, regulatory requests | Legal obligation / establishment or defence of legal claims |
| Analytics & improvement | Website performance and audience measurement | Consent for non-essential cookies where required; legitimate interests only where lawful |
The lawful basis depends on jurisdiction. Under India’s DPDP framework, processing must rely on consent or another lawful ground/legitimate use recognized by the Act; GDPR terminology should not be copied mechanically into Indian notices.
Sharing of Personal Data
FEDA may share data only as reasonably necessary with:
⦁ Authorized FEDA chapters, committees, employees, volunteers and service teams on a need-to-know basis.
⦁ Payment processors, website/hosting providers, CRM/email/communications providers, cloud providers, analytics vendors and IT/security vendors.
⦁ Event venues, travel/delegation partners, professional advisers, auditors, insurers and operational vendors.
⦁ Business, sourcing, investment, legal/compliance or other partners when the individual asks FEDA to facilitate an introduction or service.
⦁ Government, courts, regulators, law-enforcement or other authorities where legally required.
⦁ Successor or restructuring entities in a lawful organizational transaction, subject to appropriate safeguards.
FEDA should not sell personal data for money. If any activity constitutes “sale” or “sharing” under a law such as the CCPA, FEDA must provide the required notice and opt-out mechanism.
International Data Transfers
Because FEDA operates and collaborates internationally, data may be accessed or processed across countries. Where a law restricts cross-border transfers, FEDA will use an applicable legal transfer mechanism and safeguards, such as adequacy decisions, standard contractual clauses, contractual/data-transfer agreements, consent where valid, or another lawful mechanism. The exact transfer mechanism should be documented by FEDA’s privacy/legal team for each major vendor and chapter.
Data Retention
FEDA retains personal data only as long as reasonably necessary for the stated purpose, legal/accounting obligations, dispute handling, fraud prevention and legitimate organizational records. The web/privacy team should adopt a written retention schedule. Suggested operational starting points, subject to counsel confirmation, are: active membership data for the membership period plus a reasonable archival period; financial/tax records for the statutory period; unsuccessful enquiries for a shorter marketing/operational period; event records according to operational/legal need; and consent/opt-out records for as long as needed to demonstrate compliance.
When retention is no longer justified, data should be securely deleted, anonymized or irreversibly aggregated.
Security
FEDA will use reasonable technical and organizational safeguards appropriate to risk, including access controls, role-based permissions, strong authentication, secure hosting, encryption where appropriate, backups, vendor controls, staff confidentiality, logging, incident response and periodic review. No internet system is completely secure, and FEDA cannot promise absolute security.
Individual Privacy Rights
Depending on applicable law, individuals may have rights to receive information about processing; access personal data; correct inaccurate data; request deletion/erasure; restrict processing; object to certain processing; withdraw consent; obtain portability; opt out of direct marketing; opt out of sale/sharing or certain targeted advertising; limit use of sensitive data; and obtain safeguards relating to solely automated decisions.
Requests may be sent to dl@fedaglobal.org (or the dedicated privacy address once created). FEDA may verify identity before fulfilling a request and may refuse or limit a request where permitted by law. Exercising privacy rights will not result in unlawful discrimination.
India — DPDP Compliance
For processing governed by India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as and when the relevant provisions apply, FEDA should provide clear notices, obtain valid consent where required, offer an effective withdrawal mechanism, maintain reasonable security safeguards, handle personal-data breaches as legally required, provide grievance mechanisms, and honor applicable Data Principal rights. The implementation timeline of notified provisions must be tracked by the legal/privacy team rather than assuming every rule commenced on the same date.
EU/EEA — GDPR
Where the EU GDPR applies, FEDA will identify a lawful basis for each processing purpose, provide transparent Articles 13/14 information, respect applicable rights, apply data minimization and storage limitation, implement processor contracts, assess international transfers, and use appropriate breach-response procedures. Where legally required, FEDA should appoint an EU representative and/or Data Protection Officer and publish the relevant contact details.
United Kingdom
Where UK data-protection law applies, FEDA will provide equivalent transparency and individual-rights processes, taking account of the UK GDPR framework and amendments including the Data (Use and Access) Act 2025. UK-specific implementation should be reviewed periodically against current ICO guidance.
UAE
Where UAE Federal Decree-Law No. 45 of 2021 applies, FEDA will process personal data in accordance with applicable consent/lawful-processing requirements, confidentiality and security duties, data-subject rights and cross-border transfer requirements. Any UAE chapter/vendor arrangement should identify which entity acts as controller/processor and who handles data-subject requests.
California and Other U.S. Privacy Laws
If FEDA becomes subject to the CCPA/CPRA or another U.S. state privacy law, it will provide the required notices and applicable rights, which may include rights to know/access, delete, correct, opt out of sale/sharing, limit certain sensitive-data uses and receive non-discriminatory treatment. Applicability depends on statutory thresholds and activities and should be assessed annually.
Children and Students
FEDA’s general business Services are not directed to young children. Student programs may include participants who are minors. Where a participant is below the age at which they can independently consent under applicable law, FEDA must obtain and verify parental/guardian authorization where required and apply heightened safeguards. The web team should configure age/guardian workflows for student membership rather than relying only on a general checkbox.
Marketing and WhatsApp/Email Communications
Marketing messages should identify FEDA, be relevant to the recipient relationship and include an easy unsubscribe/opt-out method. Transactional communications necessary to deliver membership, event or requested services may continue despite marketing opt-out. FEDA should maintain suppression lists so opted-out addresses are not inadvertently re-added.
Automated Decision-Making and Profiling
FEDA should not make solely automated decisions producing legal or similarly significant effects unless a lawful basis and required safeguards exist. If lead scoring, eligibility screening or AI tools materially affect individuals, FEDA should provide appropriate transparency and human review where required.
Data Breaches
FEDA should maintain an incident-response plan to investigate, contain, document and remediate personal-data breaches and notify regulators and affected individuals within applicable legal timelines when required. Vendors and chapters should be contractually required to report suspected incidents promptly to FEDA.
Complaints and Regulatory Rights
Individuals may first contact FEDA using the published privacy/grievance channel. Where applicable law provides it, individuals may also complain to the competent data-protection authority, including the Data Protection Board of India once applicable, an EU supervisory authority, the UK Information Commissioner’s Office, the UAE competent authority, or another local regulator.
Changes to this Privacy Policy
FEDA may update this Policy to reflect changes in law, technology, vendors or Services. The website will display the current effective date, and material changes will be communicated where required.