Global Agenda International™ · Legal & Compliance Center
Privacy & Compliance Notice
Global Agenda International ("GAI", "Global Agenda", "we", "us") is an independent international news, intelligence and opportunities publisher. This Notice explains, in detail, how we collect, use, disclose, retain and safeguard personal information across our newsrooms, websites, mobile apps, newsletters, podcasts, events, data room, APIs and member services (collectively, the "Service"), and the rights you have under the privacy laws of the countries in which we operate.
We have written this Notice to mirror the structure used by leading international news organisations so that readers, sources, subscribers, advertisers and regulators can locate the same information in the same place across the industry. Defined terms have the meaning given in the applicable law of your jurisdiction (for example, "personal data" under the EU/UK GDPR has the same meaning as "personal information" under the California Consumer Privacy Act).
Effective date / last updated: 23 July 2026. A summary of material changes since the previous version appears in Section 38.
1. About this Notice
This Notice is our principal disclosure under the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), Brazil's Lei Geral de Proteção de Dados (Law 13.709/2018, "LGPD"), Canada's PIPEDA and Québec Law 25, South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA"), Nigeria's Data Protection Act 2023, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), the People's Republic of China Personal Information Protection Law ("PIPL"), Japan's APPI, Korea's PIPA, Australia's Privacy Act 1988, New Zealand's Privacy Act 2020, and other comparable laws.
Supplementary, country-specific addenda are published below where local law requires additional disclosures or grants additional rights. In the event of a conflict between this Notice and a country-specific addendum applicable to you, the addendum prevails.
2. Who We Are & Controller Information
Global Agenda International is the data controller (or "business" under US state law) of personal information processed through the Service. For editorial activities, the responsible publisher is the GAI Editorial Board; for subscriptions, billing, events and corporate services, the responsible entity is GAI's commercial operating company.
- General enquiries: info@globalagenda.online
- Data Protection Officer: dpo@globalagenda.online
- Legal & Compliance: legal@globalagenda.online
- Editor-in-Chief: editor@globalagenda.online
- Phone: +1.202.559.8612
- Website: www.globalagenda.online
Our EU representative under Art. 27 GDPR and our UK representative under the UK GDPR can be contacted via the DPO mailbox above; full contact details are provided on request.
3. Scope & Applicability
This Notice applies to information collected from: (a) readers and visitors to our websites and apps; (b) registered users, members and subscribers; (c) newsletter and podcast subscribers; (d) advertisers, sponsors, partners and event participants; (e) sources, contributors and freelancers; (f) job applicants; and (g) representatives of public authorities and businesses we interact with. It does not apply to the personal information of our employees, which is governed by an internal staff privacy notice.
4. Summary of Key Practices
- We do not sell personal information for money.
- We do not knowingly "share" personal information for cross-context behavioural advertising as defined by California law without consent.
- We do not use your personal information to train third-party AI models.
- We honour the Global Privacy Control (GPC) browser signal as a valid opt-out of sale and sharing.
- We apply strong encryption in transit (TLS 1.2+) and at rest, multi-factor authentication for staff, least-privilege access controls and 24/7 security monitoring.
- We provide a dedicated SecureDrop-style channel for confidential sources and treat journalistic material as privileged.
5. Categories of Personal Information We Collect
Consistent with the categories enumerated in Cal. Civ. Code § 1798.140, GDPR Art. 4 and equivalent provisions, we may collect:
- Identifiers: name, email address, postal address, phone number, username, unique device identifiers, IP address, cookie IDs and similar.
- Customer records: billing address, payment-card last four digits, subscription tier, transaction history (full card numbers are handled directly by our PCI-DSS Level 1 payment processor).
- Commercial information: purchases, ad-buying activity, event tickets, data-room interactions.
- Internet activity: articles read, search queries, scroll depth, reading time, referring URL, browser type, device characteristics and approximate location inferred from IP.
- Geolocation: approximate (city-level) location from IP; precise geolocation only with your express consent (for example, for an event check-in).
- Audio, electronic, visual: photographs and recordings at events you attend; voicemail and call recordings to our editorial tip lines (with notice).
- Professional or employment information: job title, employer, sector, professional interests — for B2B subscribers and event delegates.
- Inferences: reading-preference profiles used to recommend coverage and curate newsletters.
- Sensitive information (handled with heightened safeguards): account credentials; precise geolocation; contents of mail and messages where we are not the intended recipient; information you voluntarily provide as a source that may reveal political opinions, religious beliefs, trade-union membership, health, sexual orientation, racial or ethnic origin, biometric data, or criminal allegations.
6. Sources of Personal Information
- Directly from you — registration, comments, subscriptions, tips.
- Automatically — via cookies, server logs and SDKs.
- From third parties — payment processors, identity-verification providers, single sign-on providers (Google, Apple, LinkedIn), employer-sponsored group-subscription administrators, publicly available sources used in journalism, and partners who jointly run events.
7. How We Use Personal Information
- To deliver the Service, including authentication, paywall and entitlements.
- To process subscriptions, payments and refunds.
- To send transactional, editorial and (with consent where required) marketing emails.
- To personalise homepages, newsletters and recommendations.
- To conduct, support and publish journalism in the public interest.
- To detect fraud, abuse, scraping and security threats.
- To measure audience and content performance using aggregated analytics.
- To comply with legal obligations, including DSA transparency reports.
- To establish, exercise or defend legal claims and to enforce our Terms.
8. Legal Bases for Processing (EU/UK)
- Contract (Art. 6(1)(b)): to provide subscriptions, member services and event attendance.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, product analytics, editorial research, direct marketing to existing customers, and the functioning of an independent press in a democratic society.
- Consent (Art. 6(1)(a) / Art. 9(2)(a)): non-essential cookies, marketing newsletters to prospects, processing of special-category data outside journalism.
- Legal obligation (Art. 6(1)(c)): tax, accounting, anti-money-laundering and lawful-request responses.
- Journalistic exemption: Art. 85 GDPR, Schedule 2 Part 5 DPA 2018 and equivalent national derogations apply to editorial processing.
- Vital interests / public interest: rarely, for crisis-reporting and public-safety alerts.
9. Cookies, Pixels & Similar Technologies
We use first-party and limited third-party cookies, local storage, server-side tagging and software development kits in our mobile apps. Categories: strictly necessary, functional, analytics, and marketing/measurement. You can manage non-essential cookies at any time via the "Cookie settings" link in our footer or in your browser controls. Detailed cookie inventory is published in our Cookie Policy.
10. Online Advertising & Measurement
Advertising on the Service is predominantly contextual — keyed to article topic rather than to your behaviour. Where we offer audience-based or sponsored advertising, it is delivered using first-party data with privacy-preserving measurement (aggregated conversions, no cross-site profiles). We do not place pixels that enable third-party advertisers to build cross-publisher behavioural profiles without your consent.
11. Disclosures & Service Providers
We share personal information with vetted vendors who act on our behalf under written data processing agreements with confidentiality and security obligations equivalent to those in Art. 28 GDPR / § 1798.140(ag) CCPA. Categories include: cloud hosting and database infrastructure, content delivery and DDoS mitigation, payment processing, email delivery, analytics, customer support, AI inference for translation and summarisation, fraud and identity-verification services, and professional advisers (auditors, lawyers).
We may disclose personal information: (a) in connection with a corporate transaction (merger, acquisition, financing or sale of assets), subject to confidentiality commitments; (b) to protect the rights, property, safety or freedom of the press of GAI, our users, our journalists or the public; (c) to comply with valid legal process — see Section 30.
12. International Data Transfers
We operate globally and may transfer personal information across borders. Where data leaves the EEA, UK or Switzerland we rely on: the European Commission's adequacy decisions; the EU–US Data Privacy Framework and its UK and Swiss extensions; the Standard Contractual Clauses (Commission Decision 2021/914) supplemented by transfer-risk assessments; the UK International Data Transfer Agreement and Addendum; and, in limited cases, derogations under Art. 49 GDPR (including the journalism public-interest derogation). Comparable mechanisms apply under LGPD, PIPL, POPIA and other regimes.
13. Data Retention
- Account & subscriber data — for the duration of your account plus 24 months.
- Billing & tax records — 7 years.
- Server access logs — 90 days.
- Security and audit logs — up to 2 years.
- Newsletter consent records — 3 years after withdrawal.
- Editorial archives — indefinitely, in the public interest.
- Source-protection materials — retained only as long as necessary, then secure-deleted.
14. Information Security
We maintain an information-security programme aligned with ISO/IEC 27001 and the NIST Cybersecurity Framework. Controls include TLS 1.2+ encryption in transit and AES-256 at rest; hardware-backed key management; role-based access control with least privilege; Row-Level Security in our databases; mandatory multi-factor authentication for staff; 24/7 logging and anomaly detection; quarterly vulnerability scans and annual third-party penetration tests; secure-development training; and a documented incident-response plan. We will notify supervisory authorities and affected individuals of qualifying personal data breaches within the timeframes required by applicable law (e.g., 72 hours under GDPR/UK GDPR).
15. Your Privacy Rights & Choices
Subject to the limits and exemptions in applicable law (including the journalistic exemption), you may have rights to: access; correct; delete; restrict; object; port; withdraw consent; opt out of sale, sharing or targeted advertising; and not be subjected to solely automated decisions with legal effects. Submit requests via dpo@globalagenda.online. We respond within the statutory period (generally 30 days under GDPR; 45 days under CCPA, extendable). We will verify your identity proportionate to the sensitivity of the request and will not discriminate against you for exercising your rights.
You may also designate an authorised agent to act on your behalf, and you may appeal a denial by replying to our response email; the appeal is reviewed by a senior member of our Legal & Compliance team independent of the original decision.
16. US State Privacy Rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Minnesota, Maryland or Rhode Island (and other states as their laws come into force), you have rights to access, correct, delete and port your personal information, and to opt out of (i) "sale" or "sharing" of personal information, (ii) targeted advertising, and (iii) certain profiling. You may also limit the use of sensitive personal information. We honour Global Privacy Control as a valid opt-out signal. To exercise your rights, use the contact methods in Section 39.
17. California Notice at Collection & Shine the Light
In the preceding 12 months we have collected the categories of personal information listed in Section 5 for the business purposes listed in Section 7 and disclosed them to the service-provider categories listed in Section 11. We have not sold personal information for monetary consideration. California residents may also request, once per calendar year, information about disclosures of personal information to third parties for those parties' direct-marketing purposes ("Shine the Light", Cal. Civ. Code § 1798.83).
18. European Economic Area, United Kingdom & Switzerland
In addition to the rights described above, you may lodge a complaint with your local supervisory authority — for example, the UK Information Commissioner's Office (ICO), Ireland's Data Protection Commission, France's CNIL, Germany's BfDI, or the Swiss FDPIC. For Switzerland, references to GDPR should be read as references to the revised Swiss Federal Act on Data Protection (revFADP).
19. Brazil (LGPD)
Our LGPD legal bases mirror those above (Art. 7 and Art. 11). The data controller's contact for Brazilian data subjects is the DPO mailbox. You may lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
20. Canada (PIPEDA / Québec Law 25)
We comply with the federal Personal Information Protection and Electronic Documents Act and, for Québec residents, Law 25 (Act respecting the protection of personal information in the private sector). You may file a complaint with the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
21. South Africa, Nigeria & African Union
POPIA rights are exercised through our Information Officer, reachable at the DPO mailbox. Complaints may be lodged with the Information Regulator (South Africa). For Nigerian residents, we comply with the Nigeria Data Protection Act 2023 and the NDPC; for other African Union members we follow the Malabo Convention principles and applicable national laws.
22. Australia, New Zealand & Asia-Pacific
We handle personal information in accordance with the Australian Privacy Principles (Privacy Act 1988 (Cth)) and New Zealand's Information Privacy Principles (Privacy Act 2020). Complaints may be made to the OAIC (Australia) or the Office of the Privacy Commissioner (New Zealand).
23. China, Japan & Korea
Where PIPL applies, we comply with cross-border-transfer requirements and provide PIPL rights of access, correction, deletion and portability through the DPO mailbox. We comply with Japan's APPI (including cross-border transfer notices) and Korea's PIPA.
24. Middle East & North Africa
Where applicable, we comply with the UAE Federal Decree-Law No. 45 of 2021, the Saudi Personal Data Protection Law, Bahrain Law No. 30 of 2018, Qatar Law No. 13 of 2016, Israel's Protection of Privacy Law, and the DIFC Data Protection Law 2020.
25. Automated Decisions, Profiling & Artificial Intelligence
We use AI to translate articles, generate summaries, transcribe audio, suggest related coverage and detect abusive comments. These systems are classified as limited risk under the EU AI Act (Regulation 2024/1689). No solely automated decision produces legal or similarly significant effects on you. Our newsroom maintains a documented AI usage policy: AI-assisted content is reviewed by a human editor; AI is not used to generate verbatim attributions; and we disclose the use of AI in articles where it materially affects the work product.
26. Children's & Minors' Privacy
The Service is intended for adults. We do not knowingly collect personal information from children under 16 (or the equivalent local age of digital consent — 13 in the United States under COPPA, 14 in Spain, etc.) without verifiable parental consent. If you believe a child has provided us with personal information, contact us at dpo@globalagenda.online and we will delete it.
27. Health, Financial & Other Sensitive Data
We do not seek sensitive personal information from readers. Where you voluntarily provide such information to journalists (for example, while being interviewed), we process it under the journalistic exemption with heightened confidentiality. Financial information used for billing is processed by our PCI-DSS Level 1 payment processor; we do not store full payment-card numbers on our systems.
28. Journalistic Privilege & Source Protection
Confidential sources and journalistic material are protected under Article 10 of the European Convention on Human Rights and the case-law of the European Court of Human Rights (Goodwin v UK; Sanoma Uitgevers v Netherlands); the EU Media Freedom Act (Regulation 2024/1083); the Council of Europe Recommendation R(2000)7; the UK Contempt of Court Act 1981 s.10; the US Privacy Protection Act of 1980 (42 U.S.C. § 2000aa); the proposed federal PRESS Act and US state shield laws; and equivalent protections in other jurisdictions. We will resist, through all available legal means, any attempt to compel disclosure of journalistic material or to identify a confidential source.
29. Newsroom Confidentiality & SecureDrop
For maximum confidentiality, sources are encouraged to use anonymous channels (a dedicated SecureDrop-style instance, Signal at our published tip-line number, or postal mail with no return address). Information received through these channels is segregated from our general systems, accessible only to a small number of journalists, and is not subject to routine analytics or backup beyond what is necessary for editorial integrity.
30. Government, Legal & Law-Enforcement Requests
We require lawful, specific and proportionate process before disclosing personal information to government or law-enforcement authorities. We push back on overbroad requests, seek to narrow their scope, and, where lawful, notify affected users so they may seek their own counsel. National-security gag orders are challenged where possible. We publish an annual Transparency Report describing the volume and nature of requests received and our responses.
31. Digital Services Act (DSA) Transparency
As a publisher subject to the EU Digital Services Act (Regulation 2022/2065), we provide: notice-and-action mechanisms for illegal content; statements of reasons for any content moderation actions; a clear internal complaints process; out-of-court dispute settlement; and an annual DSA Transparency Report. We do not present targeted advertising to minors and do not use special-category data for advertising.
32. Accessibility & Plain-Language Commitments
We target WCAG 2.2 Level AA across the Service. A plain-language summary of this Notice is available on request from the DPO mailbox. Alternative formats (large print, audio) are provided free of charge.
33. Third-Party Sites, Embeds & Social Login
Our articles may embed content from third parties (video, podcasts, social media). Those services have their own privacy practices over which we do not exercise control. Where possible we use privacy-enhanced embeds that do not load tracking until you interact with the player. If you sign in via Google, Apple or LinkedIn, those providers will receive information necessary to authenticate you.
34. Mobile Apps & Push Notifications
Our mobile apps may request permissions for notifications, photo library access (for avatar uploads) and microphone access (for audio submissions). All permissions are opt-in. Push notifications are sent via Apple Push Notification service and Firebase Cloud Messaging; you can disable them at any time in your device settings.
35. Events, Conferences & Award Programmes
For events we may collect delegate information including dietary requirements and accessibility needs; these are treated as sensitive and shared only with the venue and catering staff strictly necessary for the event. Photographs and recordings may be made at events; notice will be displayed and you may opt out.
36. Whistleblowing & EU Directive 2019/1937
Wrongdoing within GAI may be reported confidentially via whistleblower@globalagenda.online or through our external secure reporting channel. Reports are handled in compliance with the EU Whistleblower Protection Directive (2019/1937) and equivalent national laws; reporters are protected from retaliation.
37. Complaints & Dispute Resolution
If you are dissatisfied with our handling of your personal information, please first contact our DPO. You also have the right to lodge a complaint with your local data protection authority, the supervisory authority of your habitual residence, the place of the alleged infringement, or our lead supervisory authority.
38. Changes to this Notice
We may update this Notice from time to time. Material changes will be notified by email and/or on-site banner at least 14 days before they take effect. Prior versions are archived and available on request.
39. How to Contact Us
Global Agenda International™ — Privacy & Compliance Office
Email: dpo@globalagenda.online
Legal: legal@globalagenda.online
General: info@globalagenda.online
Phone: +1.202.559.8612
Web: www.globalagenda.online
© 2026 Global Agenda International™. All rights reserved. This Notice is provided for informational purposes and does not create contractual rights beyond those expressly set out in our Terms of Service. Where translated, the English-language version prevails in case of conflict.
