Official website policy

Privacy Policy

How ECCIRA collects, uses, protects and manages personal information through its official website.

Effective August 2026. The Authority may update this document from time to time; the version published here is the one in force.

1. Purpose and scope

The Eastern Caribbean Citizenship by Investment Regulatory Authority (ECCIRA, the “Authority”) is the independent regional regulator of the Citizenship by Investment industry in the Eastern Caribbean. This Privacy Policy explains how the Authority handles personal information when a person visits eccira.org, contacts the Authority using details published on the website, or uses an authorised administrative area connected to it.

The Policy covers information handled through the website and related correspondence. It does not replace any privacy notice, confidentiality requirement or records-management rule that applies to the Authority’s wider regulatory, supervisory, employment, procurement or stakeholder activities.

2. Our privacy commitments

In handling personal information, the Authority undertakes to:

  • collect only what is necessary for a lawful and specified purpose;
  • use it fairly, transparently and only for purposes compatible with the one for which it was collected;
  • maintain appropriate administrative, technical and organisational safeguards;
  • keep it only for as long as it is required; and
  • respect the rights available to individuals under applicable law.

3. Information we collect

3.1 Public website visitors

The public website does not require visitors to create an account and does not contain public submission forms. Visitors can read published content without giving their name or contact details.

The hosting infrastructure nevertheless records standard technical and security information: internet protocol address, browser and device type, operating system, pages requested, the date and time of each request, the referring page, an approximate location derived from network information, and security or diagnostic events.

3.2 Correspondence and enquiries

When a person contacts the Authority by email, telephone or another published channel, the Authority receives whatever that person chooses to provide. This may include a name, contact details, an organisation, a role, the substance of the enquiry, attachments and any related correspondence.

3.3 Authorised website administrators

The content-management area is restricted to authorised users. In operating it, the Authority and its service providers process account identifiers, authentication information, essential session cookies, access times, administrative actions, security events and audit records. Passwords and other credentials are handled only through approved systems and procedures.

3.4 Information contained in published materials

Official notices, media releases, recruitment materials, consultation documents and other publications may contain personal information where publication is lawful, authorised and necessary for the Authority’s functions. The Authority takes care not to publish personal information that is excessive, inaccurate or unsuitable for public release.

4. How we collect information

The Authority receives website-related personal information:

  • directly from a person who contacts it;
  • automatically through hosting, security and diagnostic systems when the website is accessed;
  • from authorised staff, participating governments, public bodies or service providers who supply it for lawful publication or website administration; and
  • from publicly available sources, where use of the information is lawful and relevant to the Authority’s functions.

5. Purposes for which information is used

Website-related personal information is used to:

  • operate, secure, maintain and improve the website;
  • detect, investigate and prevent misuse, fraud, cyber incidents and unauthorised access;
  • respond to enquiries, manage correspondence and keep an appropriate official record;
  • administer authorised accounts, content workflows and publication approvals;
  • publish official information and maintain the Authority’s public record;
  • measure website capacity, performance and reliability;
  • meet legal, regulatory, audit, records-management and accountability obligations; and
  • establish, exercise or defend legal rights, and support the lawful exercise of the Authority’s functions.

6. Legal authority for processing

The Authority processes personal information only where it has lawful authority to do so. Depending on the circumstances and the law that applies, that authority may rest on the performance of its public and regulatory functions, compliance with a legal obligation, the handling of a request or item of correspondence, the protection of the website and its systems, or an individual’s consent.

Where processing rests on consent, that consent may be withdrawn at any time. Withdrawal does not affect processing already carried out lawfully, or information the Authority is required to retain.

7. Cookies, local storage and similar technologies

The public website does not use advertising cookies, social-media tracking pixels or behavioural profiling technologies. A visitor’s display preference, such as light or dark mode, is stored locally in that visitor’s browser and is not transmitted to the Authority.

The restricted administrative area uses essential authentication and security technologies when an authorised user signs in. These maintain the session and protect the service. If the Authority later introduces analytics, optional cookies or other tracking technologies, it will update this Policy and give any notice or choice the law requires, before or when they come into use.

8. Sharing and disclosure

The Authority does not sell, rent or trade personal information. It discloses or makes information available only where this is necessary and lawful, including to:

  • technology providers supplying hosting, database, authentication, source-control, security, communications or maintenance services;
  • professional advisers, auditors and contractors bound by appropriate duties of confidentiality;
  • participating governments, public authorities, law-enforcement bodies, courts or tribunals, where disclosure is authorised or required by law; and
  • any other body where disclosure is necessary for the lawful performance of the Authority’s functions, the protection of rights or safety, or the investigation of suspected wrongdoing.

Service providers may process information only for authorised purposes, and are subject to appropriate contractual, confidentiality and security requirements.

9. Processing outside the Eastern Caribbean

Some technology providers store or process information in jurisdictions outside the Eastern Caribbean. Where that happens, the Authority assesses the provider and applies appropriate contractual, organisational and technical safeguards, consistent with applicable law.

10. Security

The Authority applies measures designed to protect personal information against accidental or unlawful loss, alteration, destruction, disclosure, misuse and unauthorised access. These include access controls, authentication, least-privilege permissions, encryption in transit, system monitoring, backups, software maintenance, audit logging and incident-response procedures.

No website, network or storage system can be guaranteed completely secure. Anyone who believes that the website, or information associated with it, has been compromised should contact the Authority promptly at info@eccira.org.

11. Retention and disposal

Personal information is kept only for as long as it is needed for the purpose for which it was collected, to maintain an official record, or to meet legal, regulatory, audit, security and accountability requirements. Retention periods vary with the nature and sensitivity of the record, the applicable records schedule, and whether a dispute, investigation or legal hold is in place.

When information is no longer required, the Authority deletes, anonymises or securely disposes of it, subject to applicable law and archival obligations.

12. Individual rights

Subject to applicable law and to any lawful exception, an individual may request access to the personal information held about them, ask for inaccurate or incomplete information to be corrected, request deletion or restriction, object to certain processing, or withdraw consent where consent is the basis for processing.

A request should be sent to info@eccira.org, with enough detail to identify the requester, the record concerned and the action sought. The Authority may ask for evidence of identity and authority before responding. A request may be refused or limited where the law permits or requires this, including where disclosure would adversely affect another person’s rights, confidentiality, legal privilege, a law-enforcement activity or the Authority’s regulatory functions.

13. Children

The website is intended for a general and professional audience and is not designed to collect personal information from children. If the Authority learns that a child has provided personal information through the website without appropriate authority, it will take reasonable steps to delete or otherwise address that information in accordance with applicable law.

14. Automated decision-making and marketing

The website does not use personal information to make solely automated decisions producing legal or similarly significant effects. The Authority does not use website technical data for commercial advertising, and does not sell personal information for marketing purposes.

15. External links and downloadable documents

The website links to external sites and makes documents available for download. External sites are governed by their own privacy practices and security arrangements, which the Authority does not control. Visitors should review the privacy information published by the operator of any external site they use.

16. Changes to this Policy

The Authority may amend this Policy to reflect changes in law, in its functions, in the website or in its information-handling practices. The current version and its effective date are published at eccira.org, and material changes will be highlighted or otherwise communicated where appropriate.

17. Contact and complaints

Questions, requests or concerns about website privacy may be sent to info@eccira.org, or addressed to the Authority’s regional office in the Eastern Caribbean. The Authority will deal with the matter in accordance with applicable law and its approved procedures. Where applicable law gives a right to complain to a competent data-protection or oversight authority, contacting ECCIRA first does not affect that right.