FINETAX Global Alliance ("FINETAX") — The Global Alliance in Capital Markets, Corporate and Taxation — is committed to protecting the personal information of its members, directors, mentors, partners, and collaborators as a fundamental institutional value, directly connected to the respect for human dignity and the trust that sustains its institutional relationships.
This Personal Data Protection Policy has been developed in compliance with applicable United States federal and state privacy laws, including the California Consumer Privacy Act — CCPA (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act — CPRA, applicable provisions of New York State law, federal regulations governing nonprofit organizations under Section 501(c)(3) of the Internal Revenue Code, and, where applicable, the Brazilian Lei Geral de Proteção de Dados Pessoais — LGPD (Law No. 13.709/2018) and the European General Data Protection Regulation — GDPR (EU Regulation 2016/679).
FINETAX Global Alliance assumes the institutional commitment to handle personal information with responsibility, transparency, and strict observance of the rights of data subjects, recognizing that data protection is not merely a legal obligation, but a concrete expression of its core values of ethics, integrity, and respect.
TITLE I — GENERAL PROVISIONS
Chapter I — Scope of Application
Section 1 This Policy applies to all operations involving the processing of personal information carried out by FINETAX Global Alliance, in any of its jurisdictions of operation, involving data of:
I — members regularly admitted to the organization's institutional programs, including the FINETAX Undergraduate Program and the FINETAX Professional Master's Program;
II — applicants to the organization's selection processes;
III — members of the Executive Board, the FINETAX Global Alliance Council, and the Mentors Council;
IV — alumni, collaborators, institutional partners, and service providers;
V — any other individuals whose personal information is processed in connection with the activities of FINETAX Global Alliance.
Section 2 For the purposes of this Policy, the following definitions apply:
I — Personal Information: any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, as defined under applicable law, including the CCPA;
II — Sensitive Personal Information: personal information that reveals a consumer's social security number, financial account information, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of private communications, genetic data, biometric information, health information, or information concerning a consumer's sex life or sexual orientation;
III — Processing: any operation or set of operations performed on personal information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, dissemination, or any other form of making available;
IV — Data Subject / Consumer: any identified or identifiable natural person to whom the personal information relates;
V — Business / Controller: FINETAX Global Alliance, through its legally constituted entities in the United States of America and Brazil, which determines the purposes and means of processing personal information;
VI — Service Provider / Processor: any natural or legal person that processes personal information on behalf of FINETAX Global Alliance under a written contract;
VII — Data Protection Officer (DPO): the individual designated by FINETAX Global Alliance to serve as the primary point of contact between the organization, data subjects, and applicable regulatory authorities on matters relating to data protection.
Chapter II — Governing Principles
Section 3 The processing of personal information by FINETAX Global Alliance shall, in all circumstances, be governed by the following principles:
I — Purpose Limitation: personal information shall be collected and processed for specified, explicit, and legitimate purposes, as disclosed to the data subject at the time of collection. Processing for purposes incompatible with those originally declared is prohibited.
II — Data Minimization: the processing of personal information shall be limited to what is adequate, relevant, and reasonably necessary in relation to the purposes for which it is processed.
III — Accuracy: FINETAX Global Alliance shall take reasonable steps to ensure that personal information is accurate and, where necessary, kept up to date.
IV — Storage Limitation: personal information shall be retained only for as long as necessary to fulfill the declared purposes or to comply with applicable legal obligations.
V — Security and Integrity: FINETAX Global Alliance shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, protecting personal information against unauthorized or unlawful processing, accidental loss, destruction, or damage.
VI — Transparency: FINETAX Global Alliance shall provide clear, accessible, and accurate information to data subjects about how their personal information is collected, used, and shared.
VII — Accountability: FINETAX Global Alliance shall be responsible for, and be able to demonstrate compliance with, its obligations under this Policy and applicable data protection laws.
VIII — Non-Discrimination: FINETAX Global Alliance shall not discriminate against any individual for exercising their rights under this Policy or applicable law.
TITLE II — LEGAL BASIS FOR PROCESSING
Chapter I — Lawful Bases for Processing Personal Information
Section 4 FINETAX Global Alliance processes personal information on the following lawful bases, in accordance with applicable law:
I — Consent: where the data subject has given clear, affirmative, and informed consent to the processing of their personal information for one or more specific purposes;
II — Performance of a Contract: where processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract;
III — Compliance with a Legal Obligation: where processing is necessary for compliance with a legal obligation to which FINETAX Global Alliance is subject, including obligations under United States federal and state law and Brazilian law;
IV — Legitimate Interests: where processing is necessary for the purposes of the legitimate interests pursued by FINETAX Global Alliance or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject;
V — Protection of Vital Interests: where processing is necessary to protect the vital interests of the data subject or of another natural person.
Section 5 The processing of sensitive personal information shall only be carried out in accordance with the specific requirements of applicable law, including the CCPA/CPRA and applicable federal regulations, and shall, as a general rule, require the explicit consent of the data subject, unless otherwise permitted by law.
Chapter II — Consent
Section 6 When processing personal information based on consent, FINETAX Global Alliance shall:
I — request consent in a clear, prominent, and easily understandable manner, separate from other terms and conditions;
II — inform the data subject, in advance, of the specific purpose for which consent is being requested;
III — ensure that consent is freely given, meaning that the refusal to consent shall not result in unjustified disadvantage to the data subject;
IV — maintain adequate records of obtained consents, including the date, the means by which consent was obtained, and the declared purpose.
Section 7 Data subjects may withdraw their consent at any time by contacting the Data Protection Officer through the channels provided by the organization. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to the withdrawal.
TITLE III — CATEGORIES OF PERSONAL INFORMATION COLLECTED AND PURPOSES
Chapter I — Categories of Personal Information Processed
Section 8 FINETAX Global Alliance may collect and process the following categories of personal information, to the extent necessary to fulfill its institutional purposes:
I — Identifiers: full name, date of birth, nationality, government-issued identification numbers (Social Security number, passport number, taxpayer identification number, or equivalent), student registration numbers, and other information necessary to identify the data subject;
II — Contact Information: residential address, email address, telephone number, professional social media profiles, and other means of communication provided by the data subject;
III — Academic Information: academic records, institution of origin, field of study, grades, academic productions, participation in the organization's programs and activities, and other information of an academic nature;
IV — Professional Information: résumé, professional experience, field of practice, position held, and other professional information provided by the data subject;
V — Financial Information: banking and payment information, where necessary for the processing of participation fees or for the receipt of resources by authorized participants, in accordance with applicable law;
VI — Usage and Navigation Data: IP address, access and usage data from institutional digital platforms, access logs, and other data generated by the data subject's interaction with the organization's systems;
VII — Communications Data: records of institutional communications between the data subject and the organization, where necessary for the fulfillment of declared purposes.
Chapter II — Purposes of Processing
Section 9 Personal information collected by FINETAX Global Alliance shall be used exclusively for the following purposes:
I — academic and administrative management of institutional programs, including participation tracking, performance assessment, and issuance of certificates and declarations;
II — conducting selection processes, including evaluation of candidates and communication of results;
III — institutional communication with members, partners, and collaborators, including dissemination of information about activities, events, and opportunities offered by the organization;
IV — issuance of certificates, badges, declarations, and institutional recognitions;
V — compliance with legal and regulatory obligations in the jurisdictions in which the organization operates;
VI — financial and operational management of the organization, including payment processing and budget control;
VII — development, improvement, and enhancement of the organization's programs and institutional services;
VIII — protection of the rights and legitimate interests of the organization in potential judicial, administrative, or arbitration proceedings;
IX — promotion of professional and academic networking among members of the global FINETAX Global Alliance network, upon specific and informed consent of the data subject where required by applicable law.
TITLE IV — RIGHTS OF DATA SUBJECTS
Chapter I — Rights Under the CCPA/CPRA and Applicable Law
Section 10 FINETAX Global Alliance recognizes and shall honor the following rights of data subjects, in accordance with the CCPA/CPRA and other applicable privacy laws:
I — Right to Know: the right to request that FINETAX Global Alliance disclose: (a) the categories of personal information it has collected about the consumer; (b) the categories of sources from which the personal information is collected; (c) the business or commercial purpose for collecting, selling, or sharing personal information; (d) the categories of third parties to whom personal information is disclosed; and (e) the specific pieces of personal information collected about the consumer;
II — Right to Delete: the right to request the deletion of personal information collected from the consumer, subject to exceptions permitted by applicable law;
III — Right to Correct: the right to request the correction of inaccurate personal information maintained by the organization;
IV — Right to Opt-Out of Sale or Sharing: where applicable, the right to opt out of the sale or sharing of personal information with third parties for cross-context behavioral advertising;
V — Right to Limit Use of Sensitive Personal Information: the right to direct FINETAX Global Alliance to limit the use and disclosure of sensitive personal information to that which is necessaryy to perform the services or provide the goods requested;
VI — Right to Non-Discrimination: the right not to receive discriminatory treatment for exercising any privacy rights under applicable law;
VII — Right of Access: the right to access the personal information maintained by the organization in a portable, readily usable format, to the extent technically feasible.
Chapter II — Exercising Rights
Section 11 Data subjects may exercise their rights by submitting a verifiable request to the Data Protection Officer through the channels designated by FINETAX Global Alliance. The request must include sufficient information to allow the organization to verify the identity of the requestor and understand the nature of the request.
Section 12 FINETAX Global Alliance shall respond to verifiable consumer requests within 45 (forty-five) days of receipt, as required by the CCPA. This period may be extended by an additional 45 (forty-five) days where reasonably necessary, provided the consumer is notified of the extension and the reasons for it within the initial 45-day period.
Section 13 FINETAX Global Alliance shall not charge a fee for processing a verifiable consumer request unless the request is manifestly unfounded or excessive, in which case a reasonable fee may be charged, or the organization may decline to act on the request, with a reasoned explanation.
Section 14 FINETAX Global Alliance shall establish and maintain at least two designated methods for submitting requests to know, including, at a minimum, a toll-free telephone number and, where the organization maintains an internet website, a website address, in accordance with applicable law.
TITLE V — DISCLOSURE, SHARING, AND INTERNATIONAL TRANSFER OF PERSONAL INFORMATION
Chapter I — Disclosure to Third Parties
Section 15 FINETAX Global Alliance may disclose personal information to third parties in the following circumstances:
I — to institutional partners, universities, and affiliated entities, strictly for the fulfillment of the purposes of the programs in which the data subject is enrolled, under an appropriate contractual instrument ensuring the same level of protection guaranteed by this Policy;
II — to service providers acting as data processors on behalf of the organization, including digital platforms, information technology services, and system providers, under a written contract imposing equivalent obligations to those set forth in this Policy;
III — to governmental, judicial, or regulatory authorities, where required by law or by court or administrative order;
IV — to the organization's legal advisors, auditors, and consultants, where disclosure is strictly necessary for the exercise of their functions, always under an obligation of confidentiality.
Section 16 FINETAX Global Alliance does not sell personal information of its members or program participants, as defined under the CCPA. The organization does not engage in the sharing of personal information for cross-context behavioral advertising purposes without the prior consent of the data subject.
Chapter II — International Transfers of Personal Information
Section 17 Given its international nature, FINETAX Global Alliance may transfer personal information between its entities in the United States of America and Brazil, subject to the following conditions:
I — transfers shall be carried out on the basis of appropriate safeguards, including standard contractual clauses or other mechanisms recognized by applicable law, ensuring that personal information transferred internationally receives an equivalent level of protection to that guaranteed by applicable law in the jurisdiction of origin;
II — where transfers involve personal information of European Economic Area residents, such transfers shall comply with the requirements of the GDPR, including the use of adequacy decisions, standard contractual clauses, binding corporate rules, or other recognized transfer mechanisms;
III — transfers shall be documented and assessed by the Data Protection Officer, who shall maintain records of all international transfer mechanisms in place.
TITLE VI — SECURITY AND INCIDENT MANAGEMENT
Chapter I — Security Measures
Section 18 FINETAX Global Alliance shall implement reasonable and appropriate technical, administrative, and physical safeguards to protect personal information against unauthorized access, disclosure, use, modification, or destruction, including:
I — access controls and authentication measures to restrict access to personal information to authorized personnel only;
II — encryption of sensitive personal information in transit and at rest;
III — logging and auditing of access to systems containing personal information;
IV — regular security training and awareness programs for all personnel with access to personal information;
V — vulnerability management and regular updates of systems used for processing personal information;
VI — tested and regularly updated incident response plans.
Chapter II — Data Breach Notification
Section 19 In the event of a security incident involving personal information that triggers notification obligations under applicable law, FINETAX Global Alliance shall:
I — promptly contain the incident and assess its scope and impact;
II — notify affected data subjects in accordance with the requirements of applicable state and federal breach notification laws, including the New York SHIELD Act and other applicable state laws, without unreasonable delay;
III — notify relevant regulatory authorities, where required by applicable law, within the timeframes established by such authorities;
IV — provide affected data subjects with the information required by applicable law, including the nature of the information involved, the steps individuals can take to protect themselves, and contact information for further inquiries;
V — document the incident, the measures taken, and all notifications made, for purposes of accountability and continuous improvement.
TITLE VII — DATA PROTECTION OFFICER
Section 20 FINETAX Global Alliance shall designate a Data Protection Officer (DPO), appointed by the Executive Board, responsible for:
I — serving as the primary point of contact between the organization, data subjects, and applicable regulatory authorities, including the California Privacy Protection Agency and other relevant authorities;
II — advising the organization and its personnel on matters relating to data protection and compliance with this Policy;
III — receiving, assessing, and responding to requests from data subjects relating to the exercise of their rights;
IV — overseeing the organization's compliance with applicable data protection laws and this Policy;
V — coordinating the response to data security incidents involving personal information;
VI — preparing periodic reports on the state of data protection within the organization, to be submitted to the Executive Board and, where pertinent, to the FINETAX Global Alliance Council.
Section 21 The name and contact details of the Data Protection Officer shall be made publicly available on the organization's institutional channels, in an easily accessible location.
TITLE VIII — RETENTION AND DELETION OF PERSONAL INFORMATION
Section 22 Personal information processed by FINETAX Global Alliance shall be retained for no longer than is necessary to fulfill the declared purposes or to comply with applicable legal obligations, in accordance with the following general criteria:
I — personal information of program members: retained during the period of participation in the program and for up to five (5) years after the termination of the institutional relationship, for purposes of certificate issuance and responding to data subject requests;
II — personal information of unsuccessful applicants: retained for up to two (2) years after the conclusion of the selection process in which they participated;
III — financial information: retained for the periods required by applicable tax and accounting legislation in each jurisdiction;
IV — information related to disciplinary proceedings: retained for the period necessary for the exercise of rights in potential judicial, administrative, or arbitration proceedings.
Section 23 Upon the expiration of the applicable retention period, personal information shall be securely deleted or anonymized using appropriate technical procedures, with the date and method of deletion recorded for audit purposes.
TITLE IX — FINAL PROVISIONS
Section 24 This Policy shall be reviewed annually or whenever changes in legislation, regulatory requirements, or the organization's data processing practices so require.
Section 25 All members of FINETAX Global Alliance shall be trained on the contents of this Policy and on data protection best practices, with training required at the time of onboarding and periodically updated thereafter.
Section 26 Violations of this Policy by any member of FINETAX Global Alliance shall subject the violator to the sanctions provided in the Institutional Code of Ethics and Conduct, without prejudice to civil, administrative, and criminal liability under applicable law.
Section 27 This Policy enters into force upon its approval by the FINETAX Global Alliance Council, revoking any prior instruments that conflict with it.
