Choose language:


NEPCon Confidentiality Policy


NEPCon’s certification procedures rely on our clients’ trust in that commercially sensitive and other types of confidential information will not be revealed to unauthorized parties. Any NEPCon staff or consultants who are found to be in deliberate breach of confidentiality will be immediately excluded from participation in NEPCon’s activities. NEPCon reserves the right to initiate legal action against any party found to have acted in breach of a confidentiality agreement.

All NEPCon personnel related to our auditing services is required to sign a confidentiality agreement with NEPCon where they agree to maintain complete confidentiality in terms of all client organization documentation, interviews, conversations, and any information related to the certification assessment or audit process for the organization/source under assessment.


Assessors shall not make or distribute copies of any documents or reports, or discuss the content of these reports with other parties unless specifically authorized by the task manager (who is also bound by a confidentiality agreement).

In cases when pictures are taken in relation to certification for purposes other than for audit evidence, permission to use the pictures is sought from the client. All documents, data and other evidence provided to, or collected by, the assessor in conducting an assessment or audit must be returned to NEPCon or the client, or be destroyed. When in doubt about the confidential nature of information, assessors should refer questions or public requests for information directly to the technical expert responsible for the service.

The above-described policy does not apply to information which is already public and/or is required to be publicly available by the applicable certification scheme. The client is informed by relevant NEPCon staff about the types of information which are required to be publicly available. Public information includes, but is not limited to:
  • Information found in the public summary sections of the audit report (clients can always review and comment on the report prior to publication);
  • Information provided by the client for use on the certification related websites (e.g. certified products, species, forest area);
  • Information about the client organization, received from sources other than the client, which is not of a sensitive nature;
  • Information that is available in the public domain.
NEPCon follows best practices in relation to IT security and applies reasonable security measures to safeguard all electronic client information and communication.