Skip to content
Policy

Confidentiality Policy

How GMSQUEST protects all information obtained during certification activities against unauthorized disclosure, misuse or loss.

Policy Statement

GMSQuest Certifications Private Limited is committed to maintaining the confidentiality of all information obtained in the course of certification activities. We recognize that trust and integrity are fundamental to our operations and therefore ensure that all sensitive information is protected against unauthorized disclosure, misuse, or loss.

1. Scope of Confidential Information

Confidential information includes all data, documents, records, and knowledge obtained during certification activities, including audit evidence, client records, reports, business processes, and intellectual property.

Publicly available information, and information the client has agreed may be released, are not considered confidential.

2. Obligations of Personnel

All staff, auditors, technical experts, impartiality committee members, contractors, and certification decision-makers shall sign a Confidentiality Agreement prior to undertaking any certification-related activities.

Personnel are prohibited from disclosing client information to unauthorized parties, both during their engagement with GMSQuest and after termination of employment, contract, or committee membership. Confidentiality obligations continue indefinitely.

3. Disclosure of Information

Confidential information will not be disclosed to third parties without written consent from the client, except where required by law, accreditation body rules, or regulatory authorities. In such cases, disclosure to accreditation bodies, statutory authorities, or regulators shall not be considered a breach of confidentiality.

4. Public Information

Information that must be publicly available — such as certification status, scope, withdrawal and suspension — will be published in the Certified Client Directory without compromising confidential details.

5. Information Security

Client records, both physical and electronic, are stored securely and protected from unauthorized access. Access is restricted to authorized personnel only. Records are retained for at least one certification cycle plus one year. Electronic records are stored in secure, password-protected and encrypted systems with controlled access and regular backups.

6. Training & Awareness

All personnel, including employees, auditors, contractors, and committee members, shall undergo confidentiality training to ensure awareness of obligations. Training records shall be maintained.

7. Management Responsibility

The Managing Director is accountable for ensuring the implementation of this policy. Breaches of confidentiality will be investigated promptly, and disciplinary or legal action will be taken if necessary.

8. Complaints & Appeals Records

Records relating to complaints, appeals, and disputes shall be handled under strict confidentiality and only shared with authorized personnel or external parties as required by accreditation or law.

Commitment to Clients

This policy is communicated to all employees, auditors, and stakeholders of GMSQuest Certifications Private Limited and is made publicly available. All personnel are required to adhere strictly to confidentiality requirements to maintain the trust of our clients and the integrity of our certification services.

Your Organization. Global Standards.

Let’s Get You Certified.