Legal
Confidentiality Policy
Last updated July 2026
- Signed confidentiality agreements for all staff and sub-contractors
- Records held securely, access restricted to authorised staff
- Advance notice where law compels disclosure
- Accreditation bodies granted access as of right
This statement sets out how itmad protects information obtained in the course of audits, inspections, certification activities, and any other dealings with an organisation.
Staff and sub-contractor requirements
All information received by or available to itmad staff, sub-contractors, or committee members — in whatever format — obtained in conducting audit activities, during other certification activities, or during any dealings with an organisation for any other reason, shall be regarded as strictly confidential. It shall not be divulged to any third party, other than as specified in ISO/IEC 17021-1:2015 and ISO/IEC 17065, without the express permission of the organisation or individual concerned. This requirement also extends to any organisation that has a legitimate right to audit or inspect itmad.
Where itmad is required by law to release confidential information to a third party, the client or individual concerned shall be notified in advance of the information provided, unless such notification is itself regulated by law.
Where an organisation is seen to be operating contrary to legal requirements, or has operating practices which pose a danger to staff, customers, or the environment, itmad reserves the right to report the incident immediately to the relevant authority. Any such reporting will only be undertaken with the permission of a CEO.
Access to records
All records are retained securely and are accessible only to authorised staff, whether held as paper records or as password-controlled electronic records. Sub-contractors are limited to accessing information they themselves produced in conducting an audit.
Records are made available only to organisations that can demonstrate a legitimate and legal right to view them, and specifically to accreditation bodies such as GAC, EIAC, and IAF.
Confidentiality declarations
All staff, sub-contractors, CEOs, and committee members are required to agree to the itmad confidentiality policy and to sign a confidentiality agreement. Sub-contractors additionally sign an agreement that carries the responsibility to maintain confidentiality.