Privacy Policy

Privacy Policy

EC-Council is committed to protecting your privacy and developing technology that gives you the most powerful and safe online experience. This Statement of Privacy applies to all EC-Council websites and governs data collection and usage. By using the EC-Council website, you consent to the data practices described in this statement. At EC-Council, the privacy and security of our customers, respondents, and visitors are of paramount importance. EC-Council is committed to protecting the data you share with us.

What type of personal information do we gather?

We will collect certain personal information about you during the course of your relationship with us. This may include interactions through our website, training centers, meetings with our representatives- from our authorised partners and other third parties.

The personal data we collect may include:

EC-Council, through various web-platforms that help our members to register, reset passwords, get training, partner with us, etc. collects personally identifiable information such as e-mail addresses, names, home or work addresses, telephone numbers, organization names, etc. EC-Council also collects anonymous demographic information, which is not unique to you, such as your ZIP code, age, gender, preferences, interests, and favorites.

EC-Council does not collect, use, or disclose sensitive personal information, such as race, religion, or political affiliations without your explicit consent.

Where do we collect Personal Information about you?

  • Information You Give Us

    You may choose to apply for specific information or services on topics such as products, training, white papers, brochures, etc. which may require you to fill out forms and share your personal information. This information is irrespective of your membership. EC-Council asks you to allow representatives of EC-Council to contact you for the purpose asked.

  • Data you provide to Us:

    EC-Council may collect different data from or about you depending on how you use EC-Council Services. Below are some examples to help you better understand the data we collect.

    When you create an account and use our Services, including through a third-party platform, we collect any data you provide directly, including, but not limited to data about your accounts on other Services. We may obtain certain information through your social media or other online accounts if they are connected to your EC-Council account. If you login to EC-Council via social media platforms e.g. Facebook or join EC-Council sponsored WhatsApp Group, another third-party platform or service, we ask for your permission to access certain information about that other account. For example, depending on the platform or service we may collect your name, profile picture, membership account ID , login email address, location, physical location of your access devices, gender, birthday, and list of friends or contacts.

    Those platforms and services make information available to us through their APIs. The information we receive depends on what information you (via your privacy settings) or the platform or service decide to give us.

    If you access or use our Services through a third-party platform or service, or click on any third-party links, the collection, use, and sharing of your data will also be subject to the privacy policies and other agreements of that third party.

  • Automatic Information

    We receive and store certain types of information whenever you interact with us. For example, like many websites, we use cookies and we obtain certain types of information when your web browser accesses or any of our subdomains, advertisements, and other content served by or on behalf of on other websites. We may use this information for internal analysis and to provide you with location-based services, such as advertising, search results, and other personalized content.

  • E-mail Communications

    To help us make our emails communication more useful and interesting, we often receive a confirmation when you open email from, if your computer supports such capabilities. If you do not want to receive e-mail or other mail from us, please edit your customer communication preferences.

  • Information from Other Sources

    We might receive information about you from other sources and add it to our account information.

    By using or continuing to use the site you agree to our use of your information (including sensitive personal information) in accordance with this Privacy Notice, as may be amended from time to time by at its discretion. You also agree and consent to us collecting, storing, processing, transferring, and sharing information (including sensitive personal information) related to you with third parties or service providers for the purposes as set out in this Privacy Notice.

    We may be required to share the aforementioned information with government authorities and agencies for the purposes of verification of identity or for the prevention, detection, investigation, prosecution, or punishment of cyber incidents or offenses. You agree and consent to EC-Council to disclose your information if required under applicable law.

    EC-Council encourages you to review the privacy statements of websites you choose to link to from EC-Council so that you can understand how those websites collect, use, and share your information. EC-Council is not responsible for the privacy statements or content on websites outside of the EC-Council family of websites.

How and why do we use your personal information?

  • How EC-Council Uses Such Information

    EC-Council collects and uses your personal information to operate the EC-Council website and deliver the services you have requested. EC-Council also uses your personally identifiable information to inform you of other products or services available from EC-Council and its affiliates. EC-Council may also contact you via surveys to conduct research about your opinion of current services or of potential new services that may be offered. Some of the ways we may use personal information include:

    Delivering a product or service you have requested.

    Analyzing, supporting, and improving our products and your online experience.

    Personalizing websites, newsletters, and other communications.

    Administering and processing your certification exams.

    To comply with our obligations under the law, including record-keeping, reporting, accounting, tax, etc.

    Sending communications to you, including for marketing or customer satisfaction purposes, either directly from EC-Council or from our external partners.

  • Website Visitors

    EC-Council may collect, record, and analyze information from visitors to our websites. We may record your IP address and use cookies. Furthermore, EC-Council may collect and process any personal data that you volunteer to share with us via our website forms, such as when you register for events or sign up for information and newsletters. This data is used to deliver customized content and advertising within EC-Council to customers whose behavior indicates that they are interested in a subject area. If you provide EC-Council with your social media details, EC-Council may retrieve publicly available information about you from social media.

    Who do we share your personal information with?

    EC-Council does not sell, rent, or lease your personal information to third parties without your explicit consent

    We share your personal information with our other Group companies for internal reasons, primarily for business and operational purposes.

    EC-Council shares personal information in the following ways:

    EC-Council may, from time to time, contact you on behalf of external business partners about a particular offering that may be of interest to you. In those cases, your unique, personally identifiable information (e-mail, name, address, telephone number) is not transferred to the third party. However, EC-Council may share data with trusted partners to help us perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries. All such partners are prohibited from using your personal information except to provide these services to EC-Council, and they are required to maintain the confidentiality of your information.

    EC-Council websites will disclose your personal information, without consent, only if required to do so by law or in the good faith belief that such action is necessary to: (a) conform to the edicts of the law or comply with legal process served on EC-Council or the site; (b) protect and defend the rights or property of EC-Council; and, (c) act under exigent circumstances to protect the personal safety of users of EC-Council or the public.

    How EC-Council stores the personal information it collects?

    EC-Council stores your personally identifiable information such as name, contact number, email address, etc. on a secure server which is encrypted and is accessible only to EC-Council’s applications other third party websites or applications. EC Council may be required to share personal information with its affiliates, advisors and auditors in other countries where it may be processed. If we or our affiliates or our service providers transfer personal information outside of the country of origin, we always require that appropriate safeguards are in place to protect the information when it is processed.

    How EC-Council secures your personal information?

    We take appropriate technical and organizational measures to secure your information and to protect it against unauthorized or unlawful use and accidental loss or destruction, including:

    Only sharing and providing access to your information to the minimum extent necessary, subject to confidentiality restrictions where appropriate, and on an anonymized basis wherever possible;

    Using secure servers to store your information;

    Verifying the identity of any individual who requests access to information prior to granting them access to information; and

    Using Secure Sockets Layer (SSL) software or other similar encryption technologies to encrypt any payment transactions you make on or via our website.

    How long do we keep your personal information?

    We will retain your personal information as needed to fulfill the purposes for which it was collected. We will retain and use your personal information as necessary to comply with our business requirements, legal obligations, resolve disputes, protect our assets, and enforce our agreements.

    We determine standard retention periods for different categories of personal information in our possession. Where it isn’t possible to determine standard retention periods, we do so, on the basis of the following criteria:

    our relationship with you.

    the legal obligations we are subject to.

    the legal basis we have for processing your data (consent, performance of contract, etc.).

    the purposes and uses of your data (this includes present and future uses).

    the level of risk with retaining or using your data.

    your rights under the GDPR and other relevant laws.

    any other relevant circumstances.

    As EC-Council is a certification body, we store users information relevant to the upgrading or renewing their certification which includes submission of ECE Credits in line with the certification ECE policy

What legal basis do we have for using your personal information?

We process your personal information on the following legal bases:

  • Consent

    We use consent to process your data for certain purposes such as when you consent to receive marketing communication, when you express interest in associating with us or to know more about us, etc. You can withdraw your consent at any time by writing to us at the e-mail addresses provided below, or by clicking on the opt-out link.

  • Performance of Contract

    In order to perform the contract between us, we process various types of contact/financial/service related information. This also enables us to provide you with our products and/or services in line with the contractual obligations of our contract along with our Terms of Use via the EC Council websites.

  • Legitimate Interests

    Provided that such processing shall not outweigh your rights and freedoms, we may use your personal information for our legitimate interests which include legal obligations, direct marketing, market research, web analytics/profiling, compliance abidance, customer service, record-keeping, review, research and analysis, to fulfil our legal obligations under applicable laws, security, storage, etc. You’ve the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on legitimate interests. More information on this right and on how to exercise it is set out below.

Do we use Cookies to collect personal information on you?

  • What is a “Cookie”

    A cookie is a small text file sent by a web server and stored by the website on your computer to let the web browser keep track of information about your browsing on that site. Cookies are useful in helping the web browser remember specific information about your preferences, location, session details, etc. You can go to the preference or content setting of your web browser to delete the cookies pertaining to any website at any time.

  • EC-Council Cookies

    At EC-Council, we give you the option to opt-out of cookies in order to let you control your privacy. Though we do recommend that for a good web experience, you allow EC-Council to store cookies.

  • Turn Off or Opt-Out of Cookies

    Rejecting cookies may restrict your browsing experience on EC-Council websites related to important features such as login, location-specific data, and other demography-dependent info.EC-Council does not share cookie information with any other website nor do we sell this data to any third party.

What rights do you have in relation to the personal information we hold on you, in compliance to GDPR?

By law, you have several rights when it comes to your personal information. Further information and advice about your rights can be obtained from the data protection regulator in your country.

Rights What does this mean?
1. The right to be informed EC-Council is publishing this Privacy Policy Statement to keep our users informed as to what we do with their personal information and what are their rights, in a clear, transparent and easily understandable manner.
2. The right of access You have the right to obtain access to your information that we are processing and certain other information, in accordance with data protection law. Contact EC-Council if you wish to access the personal information EC-Council holds about users/data subjects.
3. The right to rectification You are entitled to have your information corrected if it’s inaccurate or incomplete.
4. The right to erasure This is also known as ‘the right to be forgotten’. If users want EC-Council to erase all personal data and we do not have a legal reason to continue to process and hold it, please contact us at [email protected] or [email protected] This is not a general right to erasure; there are exceptions.
5. The right to restrict processing You have rights to ‘block’ or suppress further use of your information. User have the right to ask EC-Council to restrict how we process user data. This means we are permitted to store the data but not further process it. We keep just enough data to make sure we respect our users request in the future.
6. The right to data portability EC-Council allows to obtain and reuse personal data for purposes across services in a safe and secure way without this effecting the usability of user data.
7. The right to withdraw consent If users have given us their consent to process their data but change their mind later, they have the right to withdraw their consent at any time, and EC-Council stop processing their data. Users can write to [email protected] or [email protected] or

What is our Opt-Out Policy?

Users may unsubscribe from our marketing communications by clicking on the “unsubscribe” link located on the bottom of our e-mails, or by sending us email us at [email protected] or [email protected] or Customers cannot opt out of receiving transactional emails related to their account with us or our Services, like aspen emails, certification renewal emails.

How can you contact us?

EC-Council welcomes your comments regarding this Privacy Policy Statement. If you believe that EC-Council has not adhered to this Privacy Policy Statement, please contact EC-Council at [email protected]/ [email protected] We will use commercially reasonable efforts to promptly determine and remedy the problem. We usually act on requests and provide information free of charge but may charge a reasonable fee to cover our administrative costs of providing the information for, baseless or excessive/repeated requests, or further copies of the same information. Alternatively, the law may allow us to refuse to act on the request.

Updates to this EC-Council Privacy Policy Statement

EC-Council will occasionally update Privacy Policy Statement to reflect company and customer feedback. EC-Council encourages you to periodically review this Policy Statement to be informed of how EC-Council is protecting your information. All rights reserved by EC-Council.