ICR Program
HomeProjectsCreditsTransactionsInsights
  • Welcome to the ICR program documentation
    • About ICR
      • ICR Team
        • Gudmundur Sigbergsson
        • Olafur "Oli" Torfason
        • Bjorn H. Helgason
        • Thordur "Thor" Agustsson
        • Alondra Silva Munoz
        • Dr. Rannveig Anna Guicharnaud
        • Robert Huldarsson
        • Ria Antil
        • Alvaro Vallejo Rendón
      • ICR's Mission Statement
      • ICR's Context
      • Leadership
        • Leadership and Commitment
        • Policies
          • Quality policy
          • KYC/KYB Compliance Policy
          • Grievance policy
          • Anti-Corruption Compliance Policy
          • Impartiality policy
          • ICR Privacy and Cybersecurity Policy
          • Diversity, Equality, and Inclusion policy
        • Organizational Roles, Responsibilities, and Authorities
          • Leadership
            • Chief Executive Officer (CEO)
            • Chief Operating Officer (COO)
            • Chief Technology Officer (CTO)
            • Chief Product Officer (CPO)
            • Chief Science Officer (CSO)
            • Chief Marketing Officer (CMO)
            • ICR Board
              • Members
                • Daníel F. Jónsson
                • Kristján I. Mikaelsson
              • ICR Board Procedures v3.0
            • ICR Program Advisory Panel
              • Members
              • ICR Program Advisory Panel 3.0
          • ICR Program Advisory Panel
            • Amit Sharma
            • Geetha Gopal
            • Javier Castro
          • Forums
            • ICR Project Proponent and Developer forum
              • ICR Project Proponent and Developer Forum Terms of Reference
            • ICR Stakeholder forum
              • ICR Stakeholder Forum - Terms of Reference
            • ICR VVB forum
              • ICR VVB Forum Terms of Reference
            • ICR Forum Guidelines
            • Forum Application
          • Committees
            • Appeals Committee
              • ICR Appeals Committee Terms of Reference
      • Articles of Association for International Carbon Registry ehf.
  • Fundamentals
    • Climate change
    • Kyoto protocol
    • Paris Agreement
      • Nationally Determined Contributions
      • Carbon Markets Under the Paris Agreement
    • Voluntary Carbon Markets
    • Compensation
      • ÍST 92
      • ISO 14068-1:2023
  • ICR Program
    • Overview
    • Fundamentals
      • ISO
        • ISO 14064
          • ISO 14064-1
          • ISO 14064-2
          • ISO 14064-3
          • ISO 14068-1
      • Project Origination
      • Additionality
      • ICR Registration Process
      • Validation and verification
        • Accreditation
    • Definitions
      • ICR Definitions v3.1
        • Version history
          • ICR Definitions v3.0
          • ICR Definitions v2.0
          • ICR Definitions v1.0
    • Methodology Development
      • Criteria
        • ICR Methodology Requirements v3.0
        • Version history
          • ICR Methodology Requirements 2.0
          • ICR Methodology Requirements 1.0
      • Procedural
        • ICR Methodology Approval Process v3.0
        • Version history
          • ICR Methodology Approval Process v2.0
          • ICR Methodology Approval Process v1.0
      • ICR Methodologies
        • Under development
          • M-ICR001
          • M-ICR002
          • M-ICR003
          • M-ICR004
          • M-ICR005:
          • M-ICR006
          • M-ICR007
          • M-ICR009
          • M-ICR011
        • Approved ICR Methodologies
      • Templates
        • Concept note
          • Older versions
        • Methodology description
          • Older versions
        • Methodology summary
          • Older versions
    • Project development
      • Criteria
        • ICR Requirement Document v6.0
          • Version history
            • ICR Requirement Document v5.0
            • ICR Requirement Document v4.0
      • Procedural
        • ICR Process Requirements v6.1
          • Version history
            • ICR Process Requirements v6.0
            • ICR Process Requirements v5.0
            • ICR Process Requirements v4.0 Final
            • ICR Process Requirements v3.0
        • ICR Article 6 2 procedures v1.0
      • Templates
        • Project concept description (PCD)
          • Older versions
        • Project design description (PDD)
          • Older versions
        • Monitoring report (MR)
          • Older versions
        • Project design description and monitoring report
          • Older versions
        • Letter of attestation
        • Non-performance report
          • Older versions
        • Non-permanence event report
          • Older versions
        • Non-permanence risk assessment
        • Non-performance risk assessment
      • Tools
        • ICR Tool for Environmental and Socio-economic Safeguards and Sustainable Development
      • Approved methodologies, modules and tools
        • ICR approved methodologies, modules and tools v4.0
    • Validation and verification
      • Validation and Verification Bodies
      • Criteria
        • ICR validation and verification specifications v2.0
          • Version history
            • ICR validation and verification specifications v1.0
      • Templates
        • Methodology validation report (MValR)
          • Older versions
        • Validation report (ValR)
          • Older versions
        • Verification report (VerR)
          • Older versions
        • Validation and verification report (ValVerR)
          • Older versions
    • Terms and conditions
      • Terms and Conditions - Users
      • Terms and Conditions - Project
      • ICR Terms and Conditions Market Participants
      • Fee Schedule 2024-2025
      • 🔦ICR KYC/KYB Complience Policy
      • ICR Terms and Conditions - Organizations
        • Older versions
          • ICR Terms and Conditions - Organizations
    • Public consultation
      • Methodologies
        • 2023
          • M-ICR0001
          • M-ICR0002
          • M-ICR0003
          • M-ICR0004
          • M-ICR0005
        • 2024
          • M-ICR0006
        • 2025
          • M-ICR009
          • M-ICR007
          • M-ICR011
      • ICR Program
        • 2023
          • Specifications to guide validation and verification
          • Program revision August 2023
        • 2024
          • Program Revision - July 2024
    • Grievance
      • ICR Grievance process
        • Submit a Complaint
    • Document Library
      • Documents
  • Biodiversity Program
    • Overview
    • Fundamentals
    • Definitions
    • Requirements
      • Templates
        • Concept note
    • Public consultation
    • Document Library
    • Fee Schedule - Biodiversity Pilot Phase 2024-2025
  • Carbonregistry.com
    • Marketplaces
      • Terms and Conditions - Trading Hub
    • On Chain
      • How it works
      • Credit data
      • Contracts
      • Retiring Credits Onchain
    • Registry user guide
      • Introduction
      • Get started
        • Create a user account
          • User profile
            • Authentication
            • Documents
            • API
          • KYC
        • Create an organizational account
          • KYB
      • Account management
        • User account management
        • Organizational account management
          • Projects
          • Users
          • Documentation
          • Settings
          • API
      • Project proponents and developers
        • Registering a project
          • Create a New Project
            • New Project Home Screen
            • Project mitigations
            • Project location
            • Benefits
            • Documents and files
            • People and Organizations
              • People
              • Organizations
            • Home screen tabs
              • Overview
              • Mitigations
              • Benefits
              • Documents
              • People
              • Media
              • VVB
            • Submit for ICR Review
          • Manage a project
          • Transition
          • Page
          • Transition
          • Validation/verification
          • Authorized representatives
          • Finish
        • Credits
          • Ex-ante issuance
          • Ex-post issuance
          • Transferring credits
          • Retiring credits
          • Cancelling credits
        • Side Panel
        • Page 1
      • Organizations
        • Account management
        • Credits
        • Retiring credits
      • Insights
    • API
      • Apps
        • Using ICR apps
          • Approve new permissions
          • Review installations
        • Creating ICR apps
          • About creating ICR apps
            • Best practices
          • Registering an ICR app
            • Permissions
            • Webhooks
              • Webhook actions and payloads
              • Handle deliveries
              • Validate deliveries
              • Handle failed deliveries
            • Callback URLs
        • Authentication
          • Authenticate as an app
          • Generate a JWT
          • Authenticate as an installation
          • App private keys
          • Authenticate as an organization
        • Examples
          • Setting up an ICR app
          • Requesting credit action for organization
          • Interacting with the organization warehouse
      • Endpoints
        • V0.5
          • Apps
          • Organizations
          • Inventory
          • Projects
          • Retirements
          • Warehouse
          • Credits
          • Documents
          • Utility
        • V1 - Beta
          • Organizations
          • Projects
          • Transactions
          • Retirements
          • Credit actions
          • Subaccounts
          • Utility
      • Environments
      • Versions
      • Authentication
    • The Credit Bundler
      • Purchasing Credits
      • Post Purchase: Accepting Credits
  • Quality management system
    • ICR QMS
Powered by GitBook
LogoLogo
On this page
  • Purpose
  • Scope
  • Privacy Principles
  • Lawfulness, Fairness, and Transparency
  • Data Minimization
  • Accuracy and Retention
  • Security and Confidentiality
  • Risk Assessment
  • Rights of Individuals
  • Cybersecurity Standards
  • Access Control
  • Data Protection
  • Device and Endpoint Security
  • Email and Communication Security
  • Cloud Services and Third-Party Vendors
  • Data Sharing and Agreements
  • Breach Response and Notification
  • Responsibilities
  • Enforcement
  • Policy Review
  1. Welcome to the ICR program documentation
  2. About ICR
  3. Leadership
  4. Policies

ICR Privacy and Cybersecurity Policy

Purpose

The purpose of this policy is to outline ICR’s commitment to:

  • Protecting personal and sensitive information, including data entrusted to us by our stakeholders

  • Securing our digital infrastructure, systems, and services against cybersecurity threats

  • Complying with applicable privacy and cybersecurity laws and standards, both in Iceland and globally

This policy ensures the responsible management of data and promotes a culture of trust, integrity, and accountability.

Scope

This policy applies to:

  • All ICR employees, contractors, board members, and interns

  • Third parties who access or process ICR data or systems

  • All personal data, registry data, and digital systems owned or managed by ICR

It covers activities across our digital operations, including www.carbonregistry.com, cloud platforms, communications, and employee devices.

Privacy Principles

ICR handles personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable laws. We follow these key principles:

Lawfulness, Fairness, and Transparency

We collect personal data only for legitimate purposes and inform individuals about how their data is used.

Data Minimization

Only the minimum necessary data is collected for a defined purpose.

Accuracy and Retention

We strive to keep data accurate and up to date. Personal data is retained only as long as necessary and then securely deleted or anonymized.

Security and Confidentiality

Personal data is protected against unauthorized access, alteration, or loss using appropriate technical and organizational measures.

Risk Assessment

  • ICR conducts regular cybersecurity risk assessments to identify vulnerabilities and threats that could affect information systems and personal data.

  • Risk assessments are used to inform security controls and ensure that appropriate mitigating actions are in place.

  • All identified risks are documented, tracked, and managed through established procedures

Rights of Individuals

We respect the rights of individuals, including:

  • Access to their personal data

  • Correction or deletion of incorrect data

  • Objection to or restriction of processing

  • Data portability

Cybersecurity Standards

ICR is committed to maintaining a secure digital environment for our employees, stakeholders, and users.

Access Control

  • Access to systems is granted based on job role and the principle of least privilege.

  • Strong, unique passwords and multi-factor authentication (MFA) are required.

Data Protection

  • All sensitive and personal data is encrypted in transit and at rest.

  • Personal data may not be stored on unauthorized devices or platforms.

  • Secure backup systems are maintained.

Device and Endpoint Security

  • Company devices must be protected with antivirus software and regular updates.

  • Remote access must be via secure VPNs.

  • Employees must report lost or stolen devices immediately.

Email and Communication Security

  • Staff must stay alert to phishing, scams, and malicious attachments.

  • Sensitive data must only be transmitted through secure, approved channels.

Cloud Services and Third-Party Vendors

  • All third-party vendors must meet ICR’s privacy and security standards.

  • Data processing agreements are signed with any provider that handles personal or registry data.

Data Sharing and Agreements

ICR ensures that all data shared with third parties is protected through robust Data Sharing Agreements (DSAs). These agreements are designed to outline the expectations and responsibilities for handling sensitive data, ensuring compliance with privacy regulations, and mitigating potential risks associated with data sharing.

Breach Response and Notification

If a data breach or cybersecurity incident occurs:

  1. Report immediately to the IT administrator or privacy officer

  2. The incident response team will assess and mitigate the breach

  3. If personal data is affected, data subjects and authorities will be notified as required by law

  4. A post-incident review will be conducted to improve controls

Responsibilities

Role

Responsibilities

Employees & Contractors

Follow privacy and security policies, protect access credentials and sensitive data, report incidents or suspicious activity promptly, and complete required training.

IT & Security Leads

Maintain cybersecurity infrastructure, enforce technical controls (e.g., access management, encryption), monitor systems, manage security incidents, and support secure architecture decisions.

CTO

Oversee GDPR compliance, act as the contact point for supervisory authorities and data subjects, advise on data protection impact assessments (DPIAs), and monitor internal privacy controls.

Leadership

Ensure adequate resources and support for data protection and cybersecurity programs; promote a culture of compliance, ethics, and transparency.

Third-Party Vendors

Adhere to agreed privacy and security standards

Enforcement

Violation of this policy may result in disciplinary action, including termination of access, employment, or contracts. In some cases, legal consequences may follow.

Policy Review

This policy is reviewed annually or whenever significant legal, technological, or organizational changes occur. Employees and stakeholders are encouraged to provide feedback.


Questions or Concerns? Contact: privacy@carbonregistry.com or your local IT/security representative.


PreviousImpartiality policyNextDiversity, Equality, and Inclusion policy

Last updated 2 months ago

229KB
ICR PCS policy v2.0.pdf
pdf