ICSME 2026
Mon 14 - Fri 18 September 2026 Benevento, Italy

pursuant to Article 13 of Regulation EU 2016/679 — GDPR

This Privacy Notice explains how Centro Regionale Information Communication Technology scrl processes personal data provided by individuals through the registration form for the 42nd IEEE International Conference on Software Maintenance and Evolution (ICSME26) and its co-located events (SCAM and VISSOFT), which will take place in Benevento, Italy, from Monday, 14 September to Friday, 18 September 2026.

1. Data Controller

The Data Controller is:

Centro Regionale Information Communication Technology scrl
Legal office: Via Traiano Palazzo ex poste snc - 82100 Benevento
Email: privacy@cerict.it
Certified email / PEC, if applicable: cerict@pec.it

Where applicable, the Data Protection Officer — DPO — may be contacted at:
privacy@cerict.it

2. Categories of personal data processed

For the purposes of registration and participation in the conference, the following categories of personal data may be processed:

  • identification data: name and surname;
  • contact details: email address and, where requested, phone number;
  • professional or academic information: institution, affiliation, role, position, department;
  • participation-related information: selected sessions, attendance at social events or dinner, certificate requests, organizational preferences;
  • administrative and accounting data, where applicable: billing details, tax code/VAT number, billing address, payment information;
  • any dietary or logistical requirements provided by the participant;
  • any accessibility or accommodation needs;
  • images, photographs, audio and video recordings, and event recordings, where applicable.

Information relating to dietary requirements, health, disability, religious beliefs, or similar matters may fall within special categories of personal data. Such data will only be requested where necessary for the proper organization of the event and will be processed with enhanced safeguards.

3. Purposes and legal bases of processing

Personal data will be processed for the following purposes.

a) Management of registration and participation in the event

Personal data will be used to register participants, confirm registrations, prepare badges, manage venue access, organize sessions, send logistical communications, and issue attendance certificates, where applicable.

Legal basis: performance of pre-contractual or contractual measures requested by the data subject and/or the legitimate interest of the Controller in organizing the event.

b) Operational communications relating to the conference

Contact details may be used to send communications strictly related to the event, such as confirmations, program updates, timetable changes, venue information, organizational materials, and practical instructions.

Legal basis: performance of the relationship with the participant and/or the legitimate interest of the Controller.

c) Administrative, accounting, and tax obligations

Where the event involves registration fees, reimbursements, invoicing, or other administrative requirements, personal data will be processed to comply with applicable legal obligations.

Legal basis: compliance with legal obligations.

d) Management of dietary, logistical, or accessibility requirements

Any information voluntarily provided by the participant regarding dietary, logistical, or accessibility requirements will be processed solely to facilitate the proper organization of services related to the event.

Legal basis: explicit consent of the data subject where special categories of personal data are processed; in other cases, performance of the service requested by the participant.

e) Photographic and audio-video documentation of the event

Photographs, audiovisual recordings, or event recordings may be taken during the conference to document the event and communicate its activities through institutional channels, websites, social media, newsletters, scientific reports, or informational materials.

For panoramic images, general event recordings, or documentation not focused on individual participants, processing may be based on the Controller’s legitimate interest in documenting and communicating the initiative.

For close-ups, interviews, testimonials, promotional content, or uses where the participant is clearly recognizable and is the main subject of the image or video, processing will be based on the participant’s specific consent.

Legal basis: legitimate interest of the Controller, where applicable; consent of the data subject for specific, promotional, or individualized uses.

f) Sending communications about future events or initiatives

Subject to separate and optional consent, the email address may be used to send communications concerning future conferences, events, calls for papers, scientific initiatives, or activities related to Centro Regionale Information Communication Technology scrl.

Legal basis: consent of the data subject.

The data subject may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

g) Possible sharing of the participants list

Where applicable, certain data — such as name, surname, affiliation, and email address — may be included in a participants list shared with other registered participants, speakers, sponsors, or event partners.

Such sharing will take place only within the limits indicated in the registration form and, where necessary, on the basis of the participant’s specific consent.

Legal basis: consent of the data subject or legitimate interest of the Controller, depending on the specific sharing arrangements.

Note: if the list includes email addresses or is shared with sponsors/partners for promotional purposes, a separate, specific consent should be collected.

4. Nature of the provision of data

Data necessary for registration are required to participate in the conference. Failure to provide such data may prevent registration or access to services connected with the event.

The provision of data for additional purposes, such as newsletters, future communications, inclusion in non-essential participants lists, promotional use of images, or indication of special requirements, is optional. Refusal to provide consent for these additional purposes will not affect participation in the event.

5. Methods of processing

Personal data will be processed using electronic, telematic and, where necessary, paper-based tools, in accordance with the principles of lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity and confidentiality.

The Controller adopts appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, disclosure, or unauthorized alteration.

6. Recipients of personal data

Personal data may be processed by authorized staff of the Controller and disclosed, where necessary, to the following parties:

  • providers of the registration platform;
  • email, hosting, cloud, or database management service providers;
  • the venue, reception staff, and conference secretariat;
  • providers of logistics, catering, badge printing, interpretation, or technical support services;
  • photographers, videographers, streaming providers, or communication agencies, where involved;
  • administrative, tax, or legal consultants;
  • public authorities or other parties where disclosure is required by law.

Such parties may, depending on the circumstances, act as processors, independent controllers, or authorized persons.

7. Transfer of data outside the European Economic Area

Personal data will preferably be processed within the European Economic Area.

The registration process may involve the use of third-party digital tools, including Google Forms / Google Workspace and Neartail, where used for registration data collection, form management, storage of responses, and calculation of registration fees.

Where these tools or their sub-processors involve the transfer of personal data to countries outside the European Economic Area, such transfers will take place in accordance with Articles 44 et seq. of the GDPR, on the basis of adequacy decisions, Standard Contractual Clauses, data processing agreements, or other appropriate safeguards provided for by applicable law.

Payments are managed directly by Centro Regionale Information Communication Technology scrl (CERICT) and are not processed through Neartail.

Participants may request further information about the safeguards adopted for international data transfers by contacting privacy@cerict.it.

8. Data retention period

Personal data will be retained for the time necessary to fulfill the purposes for which they were collected.

In particular:

  • Registration and participation: Until the final administrative and financial closure of the event, and as long as necessary for legal or documentation purposes.
  • Accounting and taxes: For the mandatory retention period required by applicable laws.
  • Consent-based data: Only until you choose to withdraw your consent.
  • Photos and videos (Website and printed materials): For as long as necessary to document and promote the event, unless you request their removal.
  • Photos and videos (Social media): Online on the event’s official social media platforms until you request their deletion.
  • Dietary or accessibility requirements: Deleted immediately after the event ends, as soon as they are no longer needed for organizational purposes.

9. Rights of data subjects

Data subjects may exercise, within the limits provided by the GDPR, the following rights:

  • right of access to personal data;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to object;
  • right to data portability, where applicable;
  • right to withdraw consent at any time, for processing based on consent.

Requests may be sent to: privacy@cerict.it

10. Complaint to the supervisory authority

Data subjects who believe that the processing of their personal data infringes the GDPR have the right to lodge a complaint with the competent supervisory authority.

In Italy, the supervisory authority is the Garante per la protezione dei dati personali.

11. Withdrawal of consent

Where processing is based on consent, the data subject may withdraw consent at any time by writing to privacy@ceric.it or by using any available tools, such as an unsubscribe link in email communications.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

12. Updates to this Privacy Notice

This Privacy Notice may be updated in the event of organizational, technical, or regulatory changes. The updated version will be made available through link to privacy page / event page / registration form.

Last updated: June 22nd, 2026