Governance
Confidentiality Policy
Carbon Verification Limited’s policy for the management and protection of confidential information obtained or created during verification activities, in accordance with ISO/IEC 17029:2019 Clause 10.4.
Policy Statement
The verification process requires clients to share commercially sensitive information, including energy consumption data, operational processes, financial data, supply chain structures and strategic plans. The willingness of clients to provide this information — openly and without reservation — is essential to the integrity of the verification process.
Carbon Verification Limited is committed to safeguarding all confidential information obtained from or created about clients during verification activities. This commitment extends to all personnel involved in verification, including directors, employees, contracted auditors and technical reviewers.
What We Treat as Confidential
Unless otherwise agreed with the client or required by law, all information obtained from or about a client during verification activities is treated as proprietary and confidential. This includes, but is not limited to, GHG inventory data and supporting calculations, activity data and source documentation, organisational structures and boundary information, operational processes and technologies, information about reduction targets, strategies and investments, financial data disclosed in connection with the verification, and the content of findings reports and draft verification statements prior to formal issuance.
Information that the client has already placed in the public domain — for example, published sustainability reports, CDP submissions, or publicly filed accounts — is not subject to confidentiality obligations under this policy.
How We Protect Confidential Information
Legally enforceable agreements. In accordance with ISO/IEC 17029 Clause 10.4.1, all confidential information is managed through legally enforceable agreements. All personnel involved in verification activities — whether employees, directors or contracted individuals — are bound by confidentiality obligations as a condition of their engagement.
Access control. Confidential client information is accessible only to those personnel directly involved in the verification engagement and to the directors responsible for oversight.
Secure storage and transmission. All client data is stored securely and transmitted using appropriate safeguards. Records are retained in accordance with our document retention policy and destroyed securely at the end of the retention period.
No secondary use. Confidential client information is used solely for the purpose of the verification engagement. It is not used for marketing, benchmarking, statistical analysis, or any other purpose without the explicit written consent of the client.
Information in the Public Domain
In accordance with ISO/IEC 17029 Clause 10.4.2, Carbon Verification Limited informs the client in advance of any information it intends to place in the public domain in connection with the verification engagement. This would typically be limited to the fact that a verification statement has been issued, the client’s name, and the scope and period of the verified inventory — and only with the client’s prior agreement.
Verification statements themselves may be shared by the client at their discretion. Carbon Verification Limited does not publish verification statements without the client’s consent unless required by a programme or regulatory authority.
Disclosure Required by Law
Where Carbon Verification Limited is required by law or authorised by contractual arrangements to release confidential information, the client will be notified of the information released, unless notification is prohibited by law. We will disclose only the minimum information necessary to satisfy the legal requirement.
Information From Third Parties
In accordance with ISO/IEC 17029 Clause 10.4.5, information about a client obtained from sources other than the client — for example, through a complaint or from a regulatory authority — is treated as confidential between the client and Carbon Verification Limited. The identity of the source is not disclosed to the client unless the source has provided consent.
Document reference: CVL-POL-CON-001
Version: 7.8
Effective date: 1st April 2026
Review date: 31st March 2027
Approved by: Glenn Wilkinson, Technical Director, Carbon Verification Limited