Privacy statement
Capacity4dev is a growing online community for international cooperation professionals. Through the provision of innovative tools, the platform provides a forum for members to share ideas and expertise.
Quick links:
- Introduction
- Why and how do we process your personal data?
- On what legal ground(s) do we process your personal data?
- Which personal data do we collect and further process?
- How long do we keep your personal data?
- How do we protect and safeguard your personal data?
- Who has access to your personal data and to whom is it disclosed?
- What are your rights and how can you exercise them?
- Contact information
1. Introduction
The European Commission (hereafter ‘the Commission’) is committed to protect your personal data and to respect your privacy. The Commission collects and further processes personal data pursuant to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data (repealing Regulation (EC) No 45/2001).
This privacy statement explains the reason for the processing of your personal data, the way we collect, handle and ensure protection of all personal data provided, how that information is used and what rights you have in relation to your personal data. It also specifies the contact details of the responsible Data Controller with whom you may exercise your rights, the Data Protection Officer and the European Data Protection Supervisor.
The information in relation to the processing operation CAPACITY4DEV, undertaken by the Directorate-General for International Partnerships, Unit INTPA.D4 - Quality and Results, Evaluation, Knowledge Management - is presented below.
Capacity4dev is a growing online community for international cooperation professionals. Through the provision of innovative tools, the platform provides a forum for members to share ideas and expertise.
2. Why and how do we process your personal data?
Purpose of the processing operation: Directorate-General for International Partnerships (hereafter ‘DG INTPA’), Unit INTPA.D4 - Quality and Results, Evaluation, Knowledge Management (hereafter ‘INTPA.D4’, ‘Data Controller') collects and uses your personal information to allow for the provision of advanced services to registered users of Capacity4dev, and facilitate community building, collaboration and exchange among peers.
Capacity4dev was originally set up to support a comprehensive reform promoting capacity development: the Backbone Strategy on "Reforming Technical Cooperation (TC) and Project Implementation Units (PIU)". The platform has since expanded to incorporate a host of topic areas relevant to the international cooperation community.
The purpose of the data processing:
- Improve capacity development through learning and knowledge sharing and facilitating community building
- Offer personalised services to registered users: such as personalised activity streams, suggested contents on the platform, and notifications of contents (subscribed by the user in his/her profile).
- Facilitate/enhance collaboration among peers in the International Cooperation Community by providing networking possibilities (Private messaging, Commenting, contributing contents, setting up groups/projects, etc.)
- Improve the platform outreach to the benefit of international cooperation professionals through the Capacity4dev Ambassadors’ programme, which is aimed at raising awareness about Capacity4dev initiatives and content, through sharing knowledge on social media, articles, webinars and events.
- Report on trends for statistical purposes and to better understand the needs of the platform (in an effort to enhance services, performance, and features)
- Facilitate potential consultations on matters related to international cooperation and development1.
All data processing is transparent and abiding to the principle of users opting-in/out, and allowing the data they provide to be used for specific purposes.
Your personal data will not be used for an automated decision-making including profiling.
3. On what legal ground(s) do we process your personal data?
We process your personal data, because processing is necessary for the performance of a task carried out in the public interest (Article 5(1)(a) of Regulation 2018/1725).
The basis for the processing is laid down in the following Union law: Articles 11 and 21(1) of the Treaty of the European Union (TEU), as well as Articles 4(4) and 208 to 211 of the Treaty on the Functioning of the European Union. Specifically, Article 11 of the TEU states: “The institutions shall, by appropriate means, give citizens and representative associations the opportunity to make known and publicly exchange their views in all areas of Union action. The institutions shall maintain an open, transparent and regular dialogue with representative associations and civil society”. Capacity4dev was launched in 2009 as part of the Information and Communication action plan of the EuropeAid Backbone Strategy on "Reforming Technical Cooperation and Project Implementation Units for External Aid provided by the European Commission".
The plan included the development and deployment of an online information, communication and knowledge management system, for Commission services in Brussels and its Delegations, as well as Partner Countries and other external stakeholders.
In subsequent years, a number of strategies and objectives also reinforced the legal basis for the functioning of Capacity4dev, notably the Secretariat-General’s Communication to the Commission: Data, Information and Knowledge Management (2016), Single Integrated Framework for Collaboration (SIFC) (2021), and the European Commission Digital Strategy (2022). Specifically, of importance for DG INTPA is the Strategy on Learning & Knowledge Development (2014), followed by the Knowledge Management Strategy 2020-2024, and the INTPA strategic plan 2020-2024.
Moreover, INTPA.D4 processes your personal data based on your consent (Article 5(1)(d)). Specifically, your oral consent is asked for audio-visual recordings of webinars and conferences. Written consent on Capacity4dev is asked for being contacted by other users through the Capacity4dev platform. A specific authorisation form is signed (digital or paper version) by interviewees or users accepting to share their written testimonials: for taking and publication of photographs, making and publication of written testimonials, audio/visual recording and publishing of videos and podcasts. The material can be used on the Capacity4dev platform, for outreach purposes on Capacity4dev social media accounts, Soundcloud, YouTube and Spotify, as well as archived in the European Union’s online databases.
You can withdraw your consent at any time by contacting the Data Controller. All data processing is transparent and abiding to the principle of users’ opting-in/out.
4. Which personal data do we collect and further process
In order to carry out this processing operation, the Data Controller collects the following categories of personal data:
Each data subject must provide some personal data to create a user account (mandatory items are marked with * and are required to allow recognition from other members and specific communities):
Public Profile Data (publicly available on user profiles)
- First name *
- Last name *
- Job title/profession**
- Name of organisation *
- Department
- Type of organisation *
- Country (of residence) *
- Languages
- LinkedIn profile
- About you (description)/short biography **
- Topic(s)/sub-topic(s) of interest*
- Continent(s)/Countries of interest*
- Profile picture
Data marked with ** are not mandatory for registering to the Capacity4dev platform, but may need to be provided by users wishing to apply for the Capacity4dev Ambassadors’ programme or other specific campaigns such as call for members’ testimonials.
In the context of applications for the Capacity4dev Ambassadors’ programme as well as for specific members’ testimonials, above-listed personal data will be collected from interested users through an EUSurvey registration form2. Users will be asked to provide these data again when applying for the Capacity4dev Ambassadors’ programme in order to facilitate the application process.
Account Data (not publicly available)
- EU Login/ECAS Username
- User ID
Master administrators of the site (INTPA.D4 and R5 staff and staff of the external contractor) can view the e-mail, EU Login/ECAS username and User ID through the back-end administration panel. Access to these details may be necessary to provide troubleshooting.
The system collects additional data that is visible to administrators of the platform; this information includes:
- Last time/date of login
- Last time/date of access
This data provides an understanding of authenticated activity on the website and allows the identification of inactive accounts.
User files (not publicly available)
Users can upload files on the platform. Each user has his/her own private media library with every uploaded file or image. Only master administrators can view files in the back-end administration panel through a generic file interface, while other members cannot access another member’s media library files.
Published contents
Users voluntarily contribute materials to Capacity4dev by uploading files, inserting pictures or creating online posts. They are directly liable for the contents they post, as indicated in the Terms and Conditions of the platform. Users can at all times edit, unpublish, or delete any of their contributions. When leaving the platform, the content which had been posted by them, will appear as posted by a “Former Capacity4dev member”.
5. How long do we keep your personal data?
INTPA.D4 only keeps your personal data for the time necessary to fulfil the purpose of collection or further processing, namely for advanced services on Capacity4dev.
Personal data along with the user account will be kept on the site as long as the account is active and no request was made by the user to remove him from the system.
Users can delete their account themselves. Otherwise, the account can be deleted by an email request that will be verified by the system administrators.
For the future, INTPA.D4 intends to implement an automatic feature to detect inactive user accounts. In case of inactive user accounts, after 2 years of continuous inactivity and following two un-replied e-mail notifications from the administrators of the system, the user account will be deleted, along with the profile and personal data provided.
Possible cessation of all activities on the platform from the user will mark the beginning of the retention period, lasting up to two years as per cf. Commission Retention list, point 9.3.2. Following two years of inactivity, a reminder is sent to users, with a deadline in which the user can reactivate his/her account. Without users' reply, the account will be permanently deleted.
6. How do we protect and safeguard your personal data?
All personal data in electronic format (e-mails, documents, databases, uploaded batches of data, etc.) are stored either on the servers of the European Commission or its contractors. All processing operations are carried out pursuant to the Commission Decision (EU, Euratom) 2017/46 of 10 January 2017 on the security of communication and information systems in the European Commission.
The Commission’s contractors are bound by a specific contractual clause for any processing operations of your data on behalf of the Commission, and by the confidentiality obligations deriving from the transposition of the General Data Protection Regulation in the EU Member States (‘GDPR’ Regulation (EU) 2016/679).
In order to protect your personal data, the Commission has put in place a number of technical and organisational measures in place. Technical measures include appropriate actions to address online security, risk of data loss, alteration of data or unauthorised access, taking into consideration the risk presented by the processing and the nature of the personal data being processed. Organisational measures include restricting access to the personal data solely to authorised persons with a legitimate need to know for the purposes of this processing operation.
The Capacity4dev application is hosted within DG DIGIT's secure infrastructure with redundancy and fault tolerance mechanisms enabled.
Among measures, the Information Security Steering Board adopted the latest IT Security Strategy for the European Commission in February 2023.
Capacity4dev is published via HTTPS ensuring data encryption and providing reassurance about the information source's authenticity.
Further details: DG DIGIT’s security standards and policies: DG DIGIT’s security standards and policies.
7. Who has access to your personal data and to whom is it disclosed?
Access to your personal data is provided to the Commission staff responsible for carrying out this processing operation and to authorised staff according to the “need to know” principle. Such staff abide by statutory, and when required, additional confidentiality agreements.
Within the Commission:
- Capacity4dev team: The team includes members of the DG INTPA, from INTPA.D4 and INTPA.R5, as well as other DG INTPA staff on a need-to-know basis.
- DG DIGIT (The Directorate-General for Informatics) is responsible for the infrastructure where Capacity4dev is hosted; their DevOps team can access the system's database that contains personal data - however when exports are made, these are done in an anonymous (sanitized) manner to protect personal data 2
Outside INTPA:
- The Capacity4dev team also includes the support of external contractors - via the external consortium SQuaRE by MEL EWIV in charge of implementing the Meldea (Monitoring, Evaluation, Learning and Design for External Action) programme. The external contractor works under instructions of DG INTPA and abides by confidentiality clauses.
- Encrypted data sets are provided to external sub-contracted development partners to mimic web environments for development/maintenance. They abide by confidentiality clauses.
- Limited personal data is publicly available on the public profile of each Capacity4dev member.
The Capacity4dev team can access clusters of data by exporting lists of users, groups, and projects, to identify activity, trends, and allow maintenance of the platform.
The DG DIGIT DevOps team has access to database dumps that may contain personal data - they ensure these datasets are encrypted for security - and only share encrypted datasets to external sub-contractors.
Limited personal data is publicly available on the profile of each Capacity4dev member.
Each Capacity4dev user can edit their personal data and settings through their profile at any time. Data subjects can control membership access to Groups/Projects to join, request to join, leave, administer and own either environment.
Group/Project/Resources owners who wish to leave the platform shall delegate ownership to another member or archive/delete the environment (each Group/Project/Resource must have an owner who can decide further actions for the environment. The owner can also archive or unpublish these spaces by editing the Group/Project/Resource’s form).
When members contribute materials to a Group, these contributions can be edited or deleted by the Group’s administration team. Likewise, if users post a comment below a content contributed by another member – if this member deletes the content, the user’s comment will be deleted as well.
Capacity4dev master administrators carrying out maintenance on the platform may edit another user’s contributions following the introduction of new developments that have not correctly migrated data (for ex: updating a taxonomy label or editing the format of data for it to appear correctly when published). These interventions are limited to occasional manual fixes, without editing the actual content contributed by the user.
At times, some Groups may demonstrate prolonged inactivity and lack of leadership. As part of the maintenance of the platform, the Capacity4dev team may contact the owner and administrator of a group to recommend further actions (ex: archiving or merging contents to another relevant Group). Once clarified, Group members receive a notification e-mail of the intended action at least two weeks before it occurs – allowing them to respond if necessary.
8. What are your rights and how can you exercise them?
You have specific rights as a ‘data subject’ under Chapter III (Articles 14-25) of Regulation (EU) 2018/1725, in particular the right to access, your personal data and to rectify them in case your personal data are inaccurate or incomplete. Where applicable, you have the right to erase your personal data, to restrict the processing of your personal data, to object to the processing, and the right to data portability.
You can exercise your rights by contacting the Data Controller, or in case of conflict the Data Protection Officer. If necessary, you can also address the European Data Protection Supervisor. Their contact information is given under Heading 9 below.
Where you wish to exercise your rights in the context of one or several specific processing operations, please provide their description (i.e. their Record reference(s) as specified under Heading 10 below) in your request.
9. Contact information
The Data Controller
If you would like to exercise your rights under Regulation (EU) 2018/1725, or if you have comments, questions or concerns, or if you would like to submit a complaint regarding the collection and use of your personal data, please feel free to contact the Data Controller, INTPA.D4, capacity4dev@ec.europa.eu.
The Data Protection Officer (DPO) of the Commission
You may contact the Data Protection Officer (DATA-PROTECTION-OFFICER@ec.europa.eu) with regard to issues related to the processing of your personal data under Regulation (EU) 2018/1725.
The European Data Protection Supervisor (EDPS)
You have the right to have recourse (i.e. you can lodge a complaint) to the European Data Protection Supervisor (edps@edps.europa.eu) if you consider that your rights under Regulation (EU) 2018/1725 have been infringed as a result of the processing of your personal data by the Data Controller.
Where to find more detailed information?
The Commission Data Protection Officer (DPO) publishes the register of all processing operations on personal data by the Commission, which have been documented and notified to him. You may access the register via the following link: http://ec.europa.eu/dpo-register.
This specific processing operation has been included in the DPO’s public register with the following Record reference: DPR-EC-00540.3
[1] For details on data processing specific to consultations on international cooperation and development, please refer to the Privacy Statement for Targeted Consultation Activities organized by the European Commission.
[2] More information about the processing of personal data within the framework of EUSurvey can be found in the specific data processing record for EUSurvey: DPR-EC-01488.1.