PRIVACY POLICY: ISC2 ANNAPOLIS JUNCTION CHAPTER
I. PURPOSE The purpose of this Privacy Policy is to establish and document the ISC2 Annapolis Junction Chapter (AJ Chapter) data privacy protection requirements and obligations with respect to applicable Federal and State privacy laws, regulations, statutes, and legislation. Furthermore, this document details the AJ Chapter’s governance and oversight strategy for controlling and monitoring members, affiliates, and contacts’ personal data throughout the data lifecycle: collection, use, processing, storage, dissemination, and disposal.
II. SCOPE This policy applies to all AJ Chapter personnel, tangible or intangible assets, or automated processes acting on behalf of a person(s) that process, store, transmit, receive, access, or distribute personal data collected by the chapter on its members, affiliates, and contacts. Any users or administrators that intentionally circumvent or deviate from this policy may be subject to account suspension, access revocation, or legal actions.
III. MANAGEMENT COMMITMENT The AJ Chapter’s President and Management Committee is committed to overseeing, managing, and improving the information security and privacy program to continuously mitigate a diverse set of risks, threats, and vulnerabilities. The Management Committee support, leadership, and guidance will ensure all users and administrators with access to member’s data adhere to the requirements set forth in this policy.
IV. RELEVANT AJ CHAPTER POLICIES
- Security Breach Notification Policy: 200.03
V. REFERENCED LAWS, LEGISLATION, AND FRAMEWORKS
- Children’s Online Privacy Protection Act (COPPA)
- Maryland Online Data Privacy Act of 2024 (MODPA)
- Personal Information Protection Act (PIPA), Maryland Commercial Law: §14–3504
- NIST Privacy Framework: Version 1.0
VI. PRIVACY POLICY PROVISIONS
1. Information We Collect
1.1 The AJ Chapter maintains a system of records for all chapter members, affiliates, and contacts. The AJ Chapter will only collect, process, and store the minimum amount of data required to maintain membership status, chapter and event interests, and continuing professional education (CPE) credits.
- 1.1.1 Personal Information: First, Middle, and Last Name; Home Address; Phone Number; Email; Veteran Status; Student Enrollment Status; Employment Status; and Photographs.
- 1.1.2 Financial Information: Banking services, card processing networks, and virtual payment tokens. Note: The Chapter utilizes PCI-compliant third-party processors; raw credit card numbers are not stored on Chapter-owned systems.
- 1.1.3 Professional Information: Job Title, Career Level, Certifications, ISC2 Membership ID, ISC2 Membership Status, and Communication Preferences.
2. Information We Never Collect
2.1 The AJ Chapter will never request, collect, process, or store the following:
- 2.1.1 Protected Health Information (PHI): Medical records, Patient IDs, Claims data, or Insurance status.
- 2.1.2 Sensitive PII: Social Security Numbers, Driver’s License/Passport Numbers, Ethnicity, or Religious beliefs.
- 2.1.3 Federal Tax Information: Tax returns, W2/1099 forms, or Income/Tax liabilities.
- 2.1.4 Biometric Data: Fingerprints, Facial/Iris scans, or Voice patterns.
3. Data Processing & Safeguards
3.1 The AJ Chapter adheres to stringent security standards:
- 3.1.1 Consent: We request explicit consent prior to the collection or use of personal data.
- 3.1.2 Automated Collection: Our website uses cookies to enhance user experience. Users may opt-out via browser settings.
- 3.1.3 Third-Party Sharing: Data is shared only with trusted partners (e.g., ISC2 Global, Springly Membership Management ) for operational purposes. We do not sell data to third parties.
- 3.1.4 Technical Controls: We leverage encryption (in transit and at rest), access controls based on the Principle of Least Privilege, and separation of duties.
4. Member Rights & Retention
- 4.1 Right to Access/Modify: Members may access or request modifications to inaccurate records by contacting info@isc2ajchapter.org.
- 4.2 Right to Opt-Out: Members may opt-out of data collection at any time. Requests will be processed within 14 business days.
- 4.3 Retention Period: In alignment with ISC2 audit requirements, the retention period is five (5) years for PII data. Following this period, or upon dissociation from the chapter, data will be securely disposed of unless required for ongoing contact.
Copyright 2026, ISC2 Annapolis Junction Chapter. All Rights Reserved. ISC2, CC, CISSP, CCSP
SSCP, CGRC, ISSAP, ISSEP, ISSMP, CSSLP, and CBK are registered
certification, service, and trademarks of International Information System Security
Certification Consortium, Inc.