Back to top

Privacy Policy.

How EAAM collects, uses, discloses, stores and protects personal data across our website, membership, events and other activities. Last updated: 25 August 2026.

1. Introduction

European Association for Aquatic Mammals “EAAM”, is an organisation established in Belgium and operating internationally in connection with aquatic mammals, their welfare, conservation, research, education, professional cooperation and related activities.

EAAM is committed to protecting the privacy and personal data of its members, supporters, partners, researchers, professionals, volunteers, event participants, website visitors and other individuals with whom it interacts.

This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you visit our website, communicate with us, participate in our activities, become a member, attend an event, make a donation or otherwise interact with EAAM.

We process personal data in accordance with:

  • Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”);
  • applicable Belgian data protection legislation, including the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data; and
  • where relevant, other applicable privacy and data protection laws.

This Privacy Policy applies to the website and, where appropriate, to personal data processed in connection with EAAM’s activities.

2. Data Controller

For the purposes of the GDPR, the data controller is:

European Association for Aquatic Mammals

Registered office: Belgium

Registration: BCE/KBO 2012

Email: board@eaam.be

Website: www.eaam.be

EAAM has appointed a Data Protection Officer (“DPO”), the DPO may be contacted at:

Board@eaam.be

3. Personal Data We May Collect

The personal data we collect depends on how you interact with EAAM.

3.1 Identification and contact information

We may collect:

  • first name and surname;
  • title and professional position;
  • organisation or institution;
  • postal address;
  • country of residence;
  • email address;
  • telephone number;
  • other contact details voluntarily provided to us.

3.2 Membership information

Where EAAM operates a membership programme, we may process information such as:

  • membership category and status;
  • membership application information;
  • professional affiliation;
  • qualifications or professional interests;
  • membership history;
  • correspondence relating to membership;
  • membership fees and payment status;
  • information necessary to administer membership benefits and services.

3.3 Event and conference information

When you register for or participate in conferences, workshops, meetings, training sessions or other EAAM activities, we may collect:

  • registration details;
  • professional affiliation;
  • attendance information;
  • dietary or accessibility requirements where voluntarily provided and necessary;
  • travel or logistical information where relevant;
  • photographs or audio-visual recordings where permitted;
  • presentations, abstracts or other materials submitted by participants;
  • payment and invoicing information.

3.4 Donations and payments

Where EAAM accepts donations, membership fees or other payments, we may process:

  • donor or payer identification details;
  • amount and date of payment;
  • billing information;
  • transaction references;
  • donation history;
  • information required for accounting, taxation or legal compliance.

Payment card or banking information may be processed directly by an authorised third-party payment service provider. EAAM will not retain full payment-card details unless this is necessary and legally permitted.

3.5 Communications

When you contact EAAM by email, through a website form, social media, telephone or other communication channel, we may process:

  • your contact details;
  • the content of your communication;
  • attachments or documents you provide;
  • records of our correspondence with you.

3.6 Newsletter and communications data

If you subscribe to newsletters or other communications, we may process:

  • your name;
  • email address;
  • subscription preferences;
  • date and method of subscription;
  • consent records, where consent is relied upon;
  • information regarding delivery or interaction with communications where permitted by applicable law.

3.7 Website and technical information

When you use our website, certain technical information may be collected automatically, including:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • approximate geographical information derived from an IP address;
  • date and time of access;
  • pages visited;
  • referring website;
  • website navigation and interaction data;
  • cookie identifiers;
  • server and security logs.

For further information, please see Section 12, Cookies and Similar Technologies.

3.8 Professional, scientific and research-related information

Given the nature of EAAM’s activities, we may process professional or scientific information supplied by members, researchers, partner institutions or other participants, including:

  • professional position and institutional affiliation;
  • academic qualifications;
  • areas of expertise;
  • publications;
  • research interests;
  • conference abstracts;
  • professional biographies;
  • project participation; and
  • information relating to scientific, educational, conservation or animal-welfare initiatives.

3.9 Photographs and audio-visual material

EAAM may take or receive photographs, video recordings or audio recordings in connection with conferences, educational activities, research projects, public events or other activities.

Where required, EAAM will obtain consent or rely on another appropriate legal basis before using identifiable images or recordings.

Specific information may be provided at the relevant event or activity.

4. Special Categories of Personal Data

EAAM does not generally seek to collect special categories of personal data through its public website.

However, in limited circumstances, information revealing health data or other categories of sensitive personal data within the meaning of Article 9 GDPR may be provided to EAAM, for example in relation to accessibility requirements, dietary requirements or participation in specific activities.

Such information will only be processed where a valid legal basis under Articles 6 and 9 GDPR applies, including, where appropriate, explicit consent, and only to the extent necessary for the relevant purpose.

Please do not provide sensitive personal information to EAAM unless it is necessary and you have been requested or invited to do so.

5. Purposes and Legal Bases for Processing

EAAM processes personal data only where it has an appropriate legal basis.

Depending on the circumstances, we may process personal data for the following purposes.

5.1 Membership administration

We may process personal data to:

  • assess and manage membership applications;
  • maintain membership records;
  • collect membership fees;
  • provide membership services;
  • communicate with members;
  • organise voting, governance or association activities; and
  • administer membership benefits.

The legal basis will generally be the performance of a contract or steps taken at the individual’s request before entering into a contractual relationship, EAAM legitimate interests in managing the association, and/or compliance with legal obligations.

5.2 Conferences, meetings and events

We may process personal data to organise and administer conferences, workshops, training programmes, webinars, meetings and other events.

The legal basis may include performance of a contract, legitimate interests in organising EAAM’s activities, consent where required, and compliance with legal obligations.

5.3 Scientific, educational, conservation and professional activities

We may process relevant personal data to carry out EAAM objectives, including supporting scientific exchange, professional collaboration, education, conservation, research and animal-welfare initiatives relating to aquatic mammals.

Where applicable, processing will be based on EAAM legitimate interests, consent, contractual necessity, compliance with legal obligations or another lawful basis provided by the GDPR.

5.4 Responding to enquiries

We process information submitted through contact forms, emails or other channels in order to respond to questions, requests and correspondence.

The legal basis is generally our legitimate interest in communicating with interested persons or taking steps at the individual’s request.

5.5 Newsletters and communications

We may send newsletters, organisational updates, invitations and similar communications where you have consented to receive them or where another lawful basis permits such communications.

Where processing is based on consent, you may withdraw your consent at any time.

5.6 Donations and fundraising

Where applicable, we may process personal data to:

  • administer donations;
  • issue acknowledgements or receipts;
  • maintain financial records;
  • communicate with donors; and
  • comply with accounting, tax and other legal obligations.

The relevant legal basis may include performance of a contract, compliance with legal obligations and EAAM legitimate interests.

5.7 Website administration and security

We process technical and security information to:

  • operate and maintain the website;
  • prevent unauthorised access;
  • detect fraud, attacks and malicious activity;
  • troubleshoot technical problems;
  • maintain IT security; and
  • ensure the integrity of our systems.

This processing is generally based on EAAM legitimate interests in maintaining secure and reliable information systems.

5.8 Legal and regulatory compliance

We may process personal data where necessary to comply with Belgian, EU or other applicable legal obligations, respond to lawful requests from authorities, establish or defend legal claims, or protect EAAM’s legal rights.

6. Legitimate Interests

Where EAAM relies on legitimate interests under Article 6(1)(f) GDPR, those interests may include:

  • administering and developing EAAM;
  • communicating with members and stakeholders;
  • promoting EAAM activities and objectives;
  • facilitating professional and scientific collaboration;
  • improving our website and services;
  • ensuring IT and organisational security;
  • preventing fraud or misuse;
  • managing relationships with partners and service providers; and
  • establishing, exercising or defending legal claims.

Where required, we balance these interests against the rights, interests and reasonable expectations of the individuals concerned.

7. Where We Obtain Personal Data

We may obtain personal data:

  • directly from you;
  • from an organisation or institution with which you are affiliated;
  • from EAAM members or partner organisations;
  • from event organisers or professional partners;
  • from publicly available professional or scientific sources;
  • from service providers acting on our behalf; or
  • automatically through our website and related technologies.

Where personal data has not been obtained directly from the data subject, EAAM will provide the information required by Article 14 GDPR where applicable.

8. Sharing Personal Data

EAAM does not sell personal data.

We may share personal data where necessary with:

  • authorised EAAM officers, Board members, employees, contractors or volunteers;
  • affiliated organisations and project partners;
  • conference and event organisers;
  • universities, research organisations or scientific partners where appropriate;
  • website hosting and IT providers;
  • cloud-storage and software providers;
  • email and newsletter service providers;
  • payment service providers and financial institutions;
  • accountants, auditors, lawyers and professional advisers;
  • insurance providers;
  • public authorities, regulators, courts or law-enforcement bodies where legally required; and
  • other service providers necessary for EAAM legitimate activities.

Service providers acting as processors on EAAM behalf are required, where applicable, to process personal data only according to EAAM instructions and to implement appropriate confidentiality and security safeguards.

9. International Transfers of Personal Data

EAAM operates internationally and may cooperate with organisations, researchers, institutions, service providers and other partners located both inside and outside the European Economic Area (“EEA”).

As a result, personal data may in certain circumstances be transferred to or accessed from countries outside the EEA including the USA.

Where the GDPR applies to such transfers, EAAM will ensure that an appropriate transfer mechanism or safeguard is in place in accordance with Chapter V GDPR.

Depending on the circumstances, these safeguards may include:

  • an adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses (“SCCs”) approved by the European Commission;
  • Binding Corporate Rules, where applicable;
  • specific statutory derogations under Article 49 GDPR where their conditions are satisfied; or
  • another legally recognised transfer mechanism.

Where required, EAAM will also assess whether supplementary technical, contractual or organisational measures are necessary to provide an appropriate level of protection.

Individuals may contact EAAM at our email for further information regarding applicable safeguards.

10. Data Retention

EAAM retains personal data only for as long as reasonably necessary for the purposes for which it was collected and to comply with applicable legal, accounting, tax, contractual and regulatory requirements.

Retention periods depend on the nature and purpose of the processing.

In determining an appropriate retention period, EAAM considers:

  • the nature and sensitivity of the information;
  • the purposes for which it was collected;
  • the duration of the relationship with the individual;
  • applicable limitation periods;
  • legal and regulatory retention requirements;
  • potential disputes or legal claims; and
  • security considerations.

Where personal data is no longer required, it will be deleted, anonymised or securely archived where retention is legally required.

11. Your Rights Under the GDPR

Subject to the conditions and limitations established by applicable law, individuals have the following rights:

Right of access

You may request confirmation as to whether EAAM processes your personal data and obtain access to that data and certain information concerning its processing.

Right to rectification

You may request correction of inaccurate personal data and completion of incomplete information.

Right to erasure

You may request deletion of your personal data in circumstances provided by Article 17 GDPR.

The right to erasure is not absolute, and EAAM may retain information where processing remains necessary, for example to comply with a legal obligation or establish, exercise or defend legal claims.

Right to restriction of processing

You may request that EAAM restrict the processing of your personal data in circumstances provided by Article 18 GDPR.

Right to data portability

Where the legal requirements are met, you may request personal data you provided to EAAM in a structured, commonly used and machine-readable format and may have the right to transmit that data to another controller.

Right to object

Where EAAM processes personal data on the basis of legitimate interests, you may object to that processing on grounds relating to your particular situation.

Where personal data is processed for direct marketing purposes, you may object to such processing at any time.

Right to withdraw consent

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Rights relating to automated decision-making

Where applicable, you have rights under Article 22 GDPR in relation to decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.

EAAM does not currently intend to make such decisions through its general website activities. If this changes, appropriate information will be provided.

Exercising your rights

Requests may be submitted to our email.

EAAM may request reasonable information necessary to verify your identity before acting on a request.

We will respond within the time limits prescribed by applicable data protection law.

12. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Cookies may include:

Strictly necessary cookies — required for the website to function properly and for security or essential functionality.

Preference or functional cookies — used to remember choices and provide requested functionality.

Analytics cookies — used to understand how visitors interact with the website and improve its operation.

Third-party or marketing cookies — where applicable, used by third-party services or platforms for embedded content, communications, measurement or marketing purposes.

Where required by Belgian and EU law, non-essential cookies will not be placed or accessed until the user has provided valid consent.

Users must be given an effective opportunity to accept or reject non-essential cookies and to modify their preferences.

Detailed information about the specific cookies and technologies used on the website, their providers, purposes and retention periods should be provided in EAAM’s Cookie Policy and/or cookie preference centre.

13. Third-Party Websites and Services

Our website may contain links to websites, social networks, academic resources, payment platforms, partner organisations or other services operated by third parties.

EAAM does not control the privacy practices of independent third parties and is not responsible for their processing of personal data.

Users should review the privacy policies of those third parties before providing them with personal information.

14. Social Media

EAAM may maintain profiles or pages on social-media platforms.

When you interact with EAAM through such platforms, both EAAM and the relevant platform provider may process personal data.

The platform provider’s processing is governed by its own terms and privacy policy. In certain circumstances, EAAM and a platform provider may act as joint controllers for specific processing operations as defined by applicable law.

15. Children and Minors

EAAM recognises that the protection of children’s personal data requires particular care.

Our general website is not intended to collect personal data directly from children without an appropriate purpose and legal basis.

Where EAAM organises educational programmes, events, research activities or other initiatives involving children or minors, appropriate safeguards will be implemented in accordance with the GDPR and applicable Belgian or local law.

Where required, consent or authorisation will be obtained from a parent, guardian or other person legally authorised to act on behalf of the minor.

EAAM will seek to collect only the minimum amount of personal data necessary for the relevant activity.

16. Photographs, Videos and Events

Photographs or audio-visual recordings may be created during conferences, workshops, meetings or public activities.

Where individuals can be identified, EAAM will process such material on an appropriate legal basis and will provide specific information or obtain consent where required.

Individuals who have concerns regarding the use of an identifiable photograph or recording may contact our email.

The use of images for scientific documentation, publications, educational purposes, archives, news reporting or promotional communications may be subject to additional notices or consent arrangements depending on the circumstances.

17. Security of Personal Data

EAAM takes appropriate technical and organisational measures designed to protect personal data against:

  • accidental or unlawful destruction;
  • loss;
  • alteration;
  • unauthorised disclosure;
  • unauthorised access; and
  • other unlawful forms of processing.

Measures may include access controls, authentication mechanisms, data minimisation, secure backups, encryption where appropriate, confidentiality requirements and organisational procedures.

No internet transmission or electronic storage system can be guaranteed to be completely secure. EAAM therefore regularly reviews its security arrangements according to the nature and risks of the processing concerned.

18. Personal Data Breaches

EAAM maintains procedures for responding to suspected personal data breaches.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, EAAM will notify the competent supervisory authority where required by Article 33 GDPR.

Where a breach is likely to result in a high risk to affected individuals, EAAM will also communicate the breach to those individuals where required by Article 34 GDPR.

19. Automated Decision-Making and Profiling

Unless specifically indicated otherwise, the association does not use personal data collected through its website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

If EAAM introduces such processing in the future, this Privacy Policy or a specific privacy notice will be updated as required.

20. Data Protection Authority and Complaints

If you believe that EAAM has processed your personal data in violation of applicable data protection law, we encourage you to contact us first at our email in order to activate Probi Viri and Arbitrators.

You also have the right to lodge a complaint with a competent supervisory authority.

For EAAM as an organisation established in Belgium, the relevant Belgian supervisory authority is:

Belgian Data Protection Authority
Autorité de protection des données / Gegevensbeschermingsautoriteit
Rue de la Presse 35 / Drukpersstraat 35
1000 Brussels
Belgium

You may also have the right to lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence, place of work or place of the alleged infringement, in accordance with the GDPR.

21. Changes to This Privacy Policy

EAAM may amend this Privacy Policy from time to time to reflect:

  • changes to our activities;
  • changes to the website or services;
  • new technologies or service providers;
  • changes in applicable law or regulatory guidance; or
  • changes to our data-processing practices.

The current version will be published on our website with the date of the latest revision.

Where changes materially affect the way we process personal data, we will take reasonable steps to provide additional notice where required.

22. Contact Us

For questions about this Privacy Policy, the processing of your personal data or the exercise of your data protection rights, please contact:

European Association for Aquatic Mammals
Belgium

Email: Board@eaam.be

Website: www.eaam.be

Data Protection Officer: Mario Scaramella - External DPO

Effective date: 25 August 2026