Skip to content

How we handle personal data.

LEAD Conservation works with personal data about the people who keep wild places safe — rangers, instructors and the teams that manage them. This notice explains what we hold, why, who can see it, and the rights you and your organisation have over it. We keep it in plain language on purpose.

Who is responsible
LEAD Conservation Foundation (stichting), the Netherlands
Data protection contact
privacy@leadconservation.org
Where data is hosted
Within the European Economic Area
We never
Sell your data, or share identifiable personnel data with funders
Your rights
Access, correct, delete, export, object — any time
Supervisory authority
Autoriteit Persoonsgegevens (NL)

Who we are

LEAD Conservation Foundation is a not-for-profit foundation (stichting) registered in the Netherlands, based at Plataanlaan 19, 6708 PT Wageningen. We set and support a professional standard for conservation security, and we run the myLEAD platform through which partner organisations manage their people's training, certification and development.

For any question about your personal data, or to exercise any of the rights below, contact our data protection lead at privacy@leadconservation.org.

The two roles we play

Data protection law distinguishes between the organisation that decides why data is processed (the controller) and the one that processes it on the controller's behalf (the processor). Which role we hold depends on the data.

We are the processor

your personnel's data in myLEAD

When a partner organisation puts data about its rangers and staff into myLEAD, that organisation is the controller — it owns the data. We process it only on their instructions, under a Data Processing Agreement.

We are the controller

our own contacts and website

For people who contact us, subscribe, donate, or browse our website, LEAD is the controller and decides how that limited data is used.

If you are a ranger or staff member whose data sits in myLEAD, your employer or organisation is the first point of contact for your data. We support them in answering you, and you can always reach us directly too.

What data we hold

In myLEAD (on behalf of partner organisations)

  • Identity and contact details — name, role, organisation, contact information;

  • Engagement status and unit or post;

  • Training and certification records, qualifications and course history;

  • Assessment outcomes, competency stage and eligibility status;

  • Development-pathway and course-place allocations;

  • Account and audit metadata — who changed a record, and when.

The platform is not designed to hold special categories of data (such as health or biometric data), and organisations are asked not to enter such data except where specifically agreed.

On our website and in our work as controller

  • Contact details you give us when you email, enquire, partner or donate;

  • Basic, privacy-respecting analytics about how the website is used.

Why we process it, and our lawful basis

We process personnel data to deliver the myLEAD services on the controller's behalf: to register people, allocate and track development pathways and course places, record assessments and certifications, coordinate training, and report on programme outcomes in aggregated, anonymised form that does not identify individuals.

Depending on the context, our lawful bases under the GDPR are the performance of a contract, our (or the controller's) legitimate interests in running a professional certification programme, compliance with a legal obligation, and — where required — consent. Where we rely on legitimate interests, we balance them against your rights and freedoms.

Who can see it

Access is tightly limited:

  • Your own organisation sees only its own people. One partner can never see another's personnel.

  • LEAD staff see what they need to run the programme and support you, on a least-privilege basis.

  • Sub-processors — carefully selected service providers (such as our hosting and platform partner) — process data only under written contracts with the same protections set out here.

We do not sell personal data, and we do not share identifiable personnel data with funders, donors or other third parties. Funder and public reporting uses aggregated, anonymised figures only.

International transfers

Personal data in myLEAD is hosted within the European Economic Area (EEA). Because our partners operate across Africa, Asia and beyond, the data may be accessed by authorised users from outside the EEA. Where that happens, or where a service provider sits outside the EEA, we rely on an adequacy decision or on appropriate safeguards under the GDPR — such as the European Commission's Standard Contractual Clauses — to keep the protection with the data wherever it travels.

How long we keep it

We keep personnel data for as long as the partner organisation uses the services, and as long as needed to maintain a meaningful record of training and certification. When a partnership ends, we return or securely delete the organisation's data at their choice, keeping only what the law requires us to retain. Contact, donation and financial records are kept only as long as needed for their purpose or a legal obligation.

Little Guide feedback is anonymised one year after submission: we remove the email address, free-text feedback and technical visitor data, while retaining only the guide, rating, language and submission date for aggregated analysis. Metadata for successfully delivered emails is deleted after one year. LEAD’s own consent and optional visitor cookies expire after one year.

How we protect it

We hold personal data under appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control, an audit trail that records who changed each record and when, regular backups, staff confidentiality undertakings, and a defined breach-response process. Our systems are built to the controls of recognised security standards (ISO/IEC 27001 and ISO/IEC 27701 / GDPR), hosted on certified infrastructure, with formal certification on our roadmap.

Partner organisations can review the full terms on which we process their people’s data in our Data Processing Agreement, which sets out our security measures and sub-processors in detail.

Your rights

Under the GDPR you have the right to access your data, to have it corrected or deleted, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent where we rely on it. To exercise any of these, contact your organisation (for data held in myLEAD) or us directly at privacy@leadconservation.org. We respond without undue delay and within the timeframes the law sets.

Questions & complaints

We would always rather hear from you first, so please contact us with any concern about how we handle your data. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority in your own country. We may update this notice as our services and the law evolve. The date at the top shows when it was last revised.

Partnering with LEAD?

Your people's data stays yours. Read exactly how we hold and protect it, or talk to us.