COPYRIGHT AND INTELLECTUAL PROPERTY NOTICE
© 2025 Converged Security Institute (CSI). All rights reserved.
Copyright Ownership: This document, including all content, methodologies, frameworks, and technical specifications contained herein, is the exclusive intellectual property of the Converged Security Institute (CSI), Martorell, Catalonia, Spain.
Author Rights: Prof. Dr. Vladimir Bunic retains moral rights as the primary author of this standard under applicable intellectual property laws, while all commercial and distribution rights belong to CSI.
Permitted Use: This document may be reproduced and distributed for internal organisational use by entities seeking CSI Trustmark certification under Policy Code ST-CSF.DPP.001. Educational and research institutions may use this document for non-commercial academic purposes with proper attribution.
Prohibited Use: No part of this publication may be reproduced, distributed, transmitted, or stored in any form or by any means for commercial purposes without the express written permission of CSI. Modification, adaptation, or creation of derivative works based on this document is strictly prohibited without prior written authorisation from CSI.
Attribution Requirements: Any use of this document must include the following attribution: "ST-CSF.DPP.001 Data Protection and Privacy Standard for Converged Security Framework, ©2025 Converged Security Institute (CSI), authored by Prof. Dr. Vladimir Bunic."
Disclaimer: While CSI has made every effort to ensure the accuracy and completeness of this document, CSI makes no warranties, express or implied, regarding the content and disclaims all liability for any damages resulting from the use or misuse of this information.
Contact for Permissions: For licensing inquiries, commercial use permissions, or derivative work authorisations, contact: certification@convergedsecurity.es
Document Version: ST-CSF.DPP.001-01 | Publication Date: 10 November 2025 | Legal Jurisdiction: This copyright notice is governed by Spanish intellectual property law and European Union copyright directives.
MULTI-JURISDICTIONAL COMPLIANCE
This document and all associated materials are protected by copyright law under European Union Directive 2001/29/EC (Information Society Directive), Database Directive 96/9/EC, and Directive 2004/48/EC on the enforcement of intellectual property rights. © 2025 Converged Security Institute (CSI). All rights reserved throughout the European Economic Area.
Under EU law, reproduction, distribution, or public communication requires prior written authorization from CSI, except for quotations used in critical reviews, teaching purposes, and certain non-commercial educational uses permitted under Article 5 of Directive 2001/29/EC. Any unauthorized use may result in civil and criminal liability under national implementations of EU intellectual property directives.
United Kingdom Copyright and Intellectual Property Protection
This work is protected under UK copyright law following the Copyright, Designs and Patents Act 1988 (as retained and amended post-Brexit under the European Union (Withdrawal) Act 2018). Fair dealing provisions under Sections 29, 30, and 32 apply only to research, private study, criticism, review, and reporting current events with appropriate acknowledgment. The Intellectual Property Act 2014 and Trade Marks Act 1994 provide additional protection for CSI trademarks and service marks within UK jurisdiction. Unauthorized use of protected marks constitutes trademark infringement under UK law.
United States Copyright and Intellectual Property Protection
This work is protected under United States federal copyright law (17 U.S.C. § 101 et seq.) and registered with the U.S. Copyright Office. Fair use provisions (17 U.S.C. § 107) apply only to criticism, comment, news reporting, teaching, scholarship, and research purposes, considering the four statutory factors: purpose and character of use, nature of copyrighted work, amount used, and effect on market value. CSI trademarks are protected under the Lanham Act (15 U.S.C. § 1051 et seq.) and state trademark laws. Digital Millennium Copyright Act (DMCA) procedures apply to online infringement claims. Violations may result in statutory damages up to $150,000 per work under 17 U.S.C. § 504(c).
COMPREHENSIVE PRIVACY AND DATA PROTECTION COMPLIANCE
European Union GDPR and Privacy Compliance
Processing of personal data in connection with this document complies with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR). CSI acts as data controller for certification and training records, with lawful basis under Article 6(1)(f) for legitimate interests in security certification and Article 6(1)(b) for contract performance. Data subjects have rights under Chapter III GDPR including access (Article 15), rectification (Article 16), erasure (Article 17), portability (Article 20), and objection (Article 21). Requests should be directed to: privacy@convergedsecurity.es. Cross-border transfers comply with Chapter V GDPR using Standard Contractual Clauses or adequacy decisions. CSI maintains records of processing activities under Article 30 GDPR and implements privacy by design and by default under Article 25. Data protection impact assessments are conducted for high-risk processing under Article 35. Supervisory authority: Spanish Agency for Data Protection (AEPD).
United Kingdom Data Protection and Privacy
UK data processing complies with the Data Protection Act 2018 (incorporating UK GDPR) and Privacy and Electronic Communications Regulations (PECR) 2003. CSI maintains UK representative registration with the Information Commissioner's Office (ICO) under Article 27 UK GDPR. International transfers from the UK comply with Chapter V UK GDPR using International Data Transfer Agreements or adequacy regulations. Data subjects retain equivalent rights to EU GDPR. UK supervisory authority contact: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF.
United States Privacy Law Compliance
US data processing complies with applicable federal and state privacy laws including California Consumer Privacy Act (CCPA) as amended by California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), and Colorado Privacy Act (CPA) where applicable based on user location and business thresholds. Under CCPA/CPRA, California residents have rights to know, delete, correct, and opt-out of sale/sharing of personal information. Requests can be submitted via privacy@convergedsecurity.es or toll-free at 1-833-CSI-PRVCY. CSI does not sell personal information and provides 12-month lookback for data requests. Federal sector compliance includes Family Educational Rights and Privacy Act (FERPA) for educational records, Health Insurance Portability and Accountability Act (HIPAA) for covered entities, and Federal Trade Commission Act Section 5 for unfair or deceptive practices.
CROSS-BORDER DATA TRANSFER GOVERNANCE
EU-US Data Transfer Framework
Transatlantic data transfers utilize EU-US Data Privacy Framework (DPF) where applicable, supplemented by Standard Contractual Clauses (SCCs) approved by European Commission Implementing Decision 2021/914. Transfer impact assessments evaluate third-country access risks under Schrems II doctrine.
UK-US Data Bridge
UK-US data sharing follows Extension to the EU-US Data Privacy Framework for UK personal data transfers, with UK International Data Transfer Agreements serving as additional safeguards. UK adequacy assessment for US transfers pending final government determination.
Multi-State US Privacy Harmonization
Cross-state data processing implements unified privacy controls addressing varying state requirements including Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), and emerging state privacy legislation. Privacy management platform ensures consistent consumer rights exercise across jurisdictions.
LEGAL ENFORCEMENT AND DISPUTE RESOLUTION
European Union Legal Framework
EU-related disputes are subject to Brussels I Regulation (Recast) for jurisdiction and Rome I/II Regulations for applicable law. Courts of the Member State where CSI is established (Spain) have primary jurisdiction. Alternative dispute resolution available through European Consumer Centres Network.
United Kingdom Jurisdiction
UK disputes subject to English or Scottish courts depending on defendant domicile. Commercial Court procedures apply for intellectual property matters. Consumer disputes may utilize alternative dispute resolution through approved ADR schemes under Alternative Dispute Resolution for Consumer Disputes Regulations 2015.
United States Federal and State Courts
US federal courts have jurisdiction over copyright matters under 28 U.S.C. § 1338. State courts maintain concurrent jurisdiction for privacy law violations. Class action procedures follow Federal Rule of Civil Procedure 23. DMCA safe harbor provisions apply to qualifying online service providers.
CONTACT INFORMATION FOR MULTI-JURISDICTIONAL COMPLIANCE
European Union and Spain: legal.eu@convergedsecurity.es | Converged Security Institute, Legal Department EU, C/ Example Street 123, 08760 Martorell, Barcelona, Spain
United Kingdom: info@convergedsecurity.es | CSI UK Legal Representative, [UK Address Upon Appointment]
United States: info@convergedsecurity.es | CSI USA Legal Counsel, [US Address Upon Appointment]
Privacy Rights Requests (All Jurisdictions): info@convergedsecurity.es | Privacy Officer, Converged Security Institute
Legal Jurisdiction Hierarchy: Spanish Law (Primary) | EU Law (Superseding) | UK Law (Parallel) | US Law (Territorial) | International Treaties (Overriding)