Global Privacy Consulting, ZZP, established at Groetkerkplein 26, (3011 GD) Rotterdam Netherlands, is responsible for the processing of personal data as set out in this privacy statement.

 Contact details:

https://www.global-privacy.com/

Groetkerkplein 26
3011 GD Rotterdam, Netherlands
+31 06 19893469

Email: john@global-privacy.com

1. Personal data processed by Global Privacy Consulting

Global Privacy Consulting, ZZP (“GPC”) processes your personal data because you use our services and/or because you provide it to GPC yourself.

 GPC respects your personal data and ensures that the personal information provided to GPC, or otherwise obtained by GPC, is treated confidentially.

 Personal data concerns all information relating to an identified or identifiable natural person. An identifiable natural person is someone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors characteristic of the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

 The following implements the duty to inform laid down in the GDPR to the data subject(s) whose personal data GPC processes.

 Below you will find an overview of the personal data processed by GPC:

  1. (Potential) clients, employees and other business relations (of clients)

  • First and last name; 

  • Address and place of residence;

  • Company name (if, for example, your company is called Jan van der Meer BV and thus refers to your first and last name);  

  • Phone number;

  • Email address;

  • Photos or camera footage of you if you participate in our knowledge sessions or events;

  • Other personal data that you actively provide, for example in correspondence (e-mail), meetings, by telephone or via web forms, during breakfast sessions or networking meetings. This may include your title, position, bank account number or other financial details, your gender and the names of your children or partner, dietary requirements, and accessibility during breakfast sessions;

  • In the context of the Anti-Money Laundering and Counter-Terrorism Financing Act (“Wwft”), UBO registration, or any due diligence obligations to which GPC may be subject, you may also be asked to provide your proof of identity or passport, in which case GPC requests that you black out unnecessary information. This can be done using an ID cover, third-party applications such as the KopieID app or similar apps;

  • Other sensitive data, such as data concerning a person's race, religion, political opinions, trade union membership, or health, sexual behavior, or orientation, may also be processed if this is necessary for the provision of legal services and you have given explicit consent for this. 

2.      Website visitor 

  • Internet browser and device type;

  • Optional username;

  • Timestamps;

  • Browsing behavior and website visits;

  • IP address;

  • Cookie consent;

3.      Applicants

  • Name and address details, email address, telephone number, identity details;

  • Information mentioned on the CV or in the correspondence;

  • Diplomas, transcripts, references and other work or study evaluation documents 

4.      Counterparties or other third parties

  • First and last name;

  • Address and place of residence;

  • Company name (if your company is called Jan van der Meer BV, for example, and therefore refers to your first and last name);

  • Phone number;

  • Email address;

  • Other personal data actively provided, for example in correspondence (e-mail), meetings, or by telephone. This may also include special categories of personal data concerning a person's race, religion, political opinions, trade union membership, health data, or data regarding sexual behaviour or orientation, which may be processed if this is necessary for the provision of legal services and that party has given consent to the processing of such personal data.

2. For what purpose and on what basis GPC processes personal data

GPC processes your personal data for the following purposes and uses the following legal bases under the GDPR for this purpose:

1. GPC processes your personal data because this is necessary to conclude and execute a potential agreement with you, such as providing professional consulting services, referrals to third-parties with your express consent and in conjunction with the Service provided by GPD, providing advice or disseminating knowledge, for example during breakfast sessions. This applies to:        

  • (potential) clients to provide services, conduct client due diligence and issue quotations, to refer to third-parties in relation to GPC’s services, and to collect invoices for work performed;

  • parties from whom GPC purchases business and/or services; 

  • (potential) suppliers;

  • other clients or contractors.

2. GPC processes your personal data if you have given (explicit) consent for this, such as sending the newsletter or direct marketing, processing special personal data, and improving product and service extensions, for example by using analytical cookies.

3. GPC processes your personal data if it is legally obliged to do so, for example in the context of tax returns, the Anti-Money Laundering Act (Wwft), or similar laws and regulations.

4. GPC processes your personal data if it has a legitimate interest in doing so. For example, to inform you about changes to our services and products and improvements to services and/or the website.

3. Automated decision-making 

GPC does not make decisions based on automated processing regarding matters that could have (significant) consequences for individuals.

4. How long we retain personal data

GPC does not retain your personal data for longer than is strictly necessary to achieve the purposes for which your data is collected. GPC retains the personal data of clients, business relations, opposing parties, and third parties for the retention period pursuant to applicable laws and regulations, such as our codes of conduct and professional rules.

If no statutory retention obligation applies, GPC will delete the (or part of the) personal data no later than 5 years after the termination of the handling of the case. It may also occur that your personal data is retained by GPC for a longer retention period in order to comply with applicable law or legal obligations. For example and not limited to: 7 years in order to comply with statutory (tax) retention periods, and a retention period of 20 years if the (special) personal data is required in the context of (professional) liability.

Special personal data, such as dietary requirements provided for a breakfast session or networking meeting, will be deleted immediately after the event.

GPC retains the personal data of website visitors mentioned by GPC, such as (internet browser and device type, any username, browsing behavior, and timestamps) that GPC processes, for a maximum of 2 years.

GPC retains data about applicants for a maximum of 4 weeks after the last contact, unless the applicant gives permission to retain the data longer.

5. Sharing personal data with third parties

GPC does not sell your data to third parties and provides it only if this is necessary for the execution of our agreement with you. For example, it may be necessary to provide your data to a regulatory authority, another service provider who needs to provide advice or other third-parties. You will be asked for permission or informed of the purpose and reason for the proposed disclosure, unless GPC is prohibited by applicable law from doing so.

Furthermore, GPC uses external server space for the storage of (parts of) our administration, of which your personal data forms a part. For this reason, your personal data is provided to our server space provider.

GPC may use a newsletter mailing service, your personal data (email address and first and last name) are ultimately passed on to the provider of this service, provided that you have given consent to receive our mailing. 

It may occur that GPC is required to share your data with third parties pursuant to a legal obligation, for example at the request of the Tax and Customs Administration or a supervisory body. In that case, GPC will only share the necessary information and nothing more.

GPC enters into a data processing agreement with companies that process your data on our behalf, to ensure the same level of security and confidentiality of your data.

GPC remains responsible in principle for these processing activities.

6. AI policy 

GPC may make use of applications based on artificial intelligence (AI) in its services. These applications provide support in, among other things, file analysis, translations, drafting (legal) documents, improving the quality of our services, text formatting and correction, and structuring internal and external processes more efficiently.

No personal data of clients is shared in open and publicly accessible AI systems unless explicit consent has been obtained. Personal data of clients is only processed in AI systems if the processing takes place within a closed and controlled system that complies with the obligations of the GDPR and other applicable laws and regulations. The ultimate responsibility regarding the use of AI for service, advice, procedural documents, and other communication in your file lies with GPC. In short, the use of AI by GPC takes place within the framework of applicable laws and regulations, and the internal (AI) policy of GPC.

7. Cookies, or similar techniques, used by GPC

GPC may use functional, analytical, and tracking cookies. A cookie is a small text file that is stored in the browser of your computer, tablet, or smartphone when you first visit this website. GPC may also use cookies with purely technical functionality. These ensure that the website works properly and that, for example, your preference settings are remembered. These cookies are also used to ensure the website functions correctly and can be optimized. In addition, we may place cookies that track your browsing behavior so that we can offer tailored content and advertisements.

If these cookies are being employed, during your first visit to our website, GPC already informed you about these cookies and asked for your permission to place them.

You can opt out of cookies by setting your internet browser to no longer store cookies. Additionally, you can also delete all information previously stored via your browser settings.

Cookies may also placed on the website of GPC by third parties. These are, for example, advertisers and/or social media companies.

On our website, you may find hyperlinks to websites of others, such as and for example, LinkedIn and Instagram. If these buttons are clicked, personal data is processed by the relevant party. GPC is not responsible for the content of those websites or the services they offer, nor is it responsible for the protection and security of your personal data that you provide to those websites.

8. How GPC secures personal data

GPC takes the protection of your data seriously and takes appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure, and unauthorized modification.

If you have the impression that your data is not properly secured or there are indications of misuse, please contact the office or via john@global-privacy.com. GPC will also inform you immediately if there is a data breach that has adverse consequences for your privacy and as required by applicable law.  

GPC has in any case taken the following measures to protect your personal data:

  • Security software, such as a virus scanner and firewall;

  • Pseudonymizing and encrypting Personal Data where possible; 

  • Access to laptops and computers is encrypted and 2-factor authentication is used for remote working;

  • Within the organization, Employees are aware of the security measures for Personal Data;

  • Adequate procedures regarding the (technical) security of Personal Data and acts accordingly (not leaving laptops unattended, secure USB sticks, etc.);

  • Burglar alarm and/or other physical measures for access security;

  • Secure connections;

  • Secure transmission of Personal Data via the internet (e.g. e-mail) by means of technical measures. Please note that no method of transmission via the internet or electronic storage is 100% secure, and GPC cannot guarantee absolute security;

  • Backup (in (fire)safe locations) and recovery;

  • Strong password management;

  • Personal data is not stored on private equipment. 

9. View, modify or delete data

You have a number of rights under the GDPR:

  • You have the right to ask GPC to allow you to access your own personal data;

  • If there is reason to do so, you may also request GPC to supplement your personal data or to correct inaccuracies;

  • In addition, you have the right to request the erasure of your personal data or to restrict the use of your personal data. You can also withdraw your previously provided consent;

  • You can also object to the collection and use of your data at GPC or file a complaint with the Dutch Data Protection Authority. You can file a complaint via the following  link .

  • Upon request, GPC will provide you with information regarding the balancing of interests undertaken by GPC within the framework of the legal basis of 'processing based on a legitimate interest', insofar as applicable to you;

  • Finally, you may request GPC to provide you with your personal data or to transfer that data to another party;

  • To exercise your rights, you can contact GPC using the contact details at the top of this statement.

  • If there is any doubt regarding your identity, GPC may request a copy of your proof of identity. Please black out your passport photo, MRZ (machine readable zone, the strip of numbers at the bottom of the passport), passport number, and Citizen Service Number (BSN) on this copy. This is to protect your privacy. We will respond to your request as soon as possible and within four weeks at the latest.

10. Changes to this privacy statement

GPC reserves the right to make changes, additions, or modifications to this privacy statement if deemed necessary. The most current version can be viewed on our website at all times. This version was last updated 5 October 2026.   

If you have any further questions or would like more information about the collection and use of your personal data, please feel free to contact GPC.