Privacy Policy
This Privacy Policy explains how the Patent Mediation and Arbitration Centre of the Unified Patent Court (“PMAC”), acting as Data Controller for the processing activities falling within its functions, collects and processes your Personal Data in a lawful, transparent and appropriate manner.
The policy outlines what data is gathered, how it is used and the choices you have to manage it.
Certain separate administrative processing activities relating to recruitment and employment administration invoicing, accounting, financial control, central IT administration, procurement and contracts, are carried out under the responsibility of the Unified Patent Court (“UPC”) and are subject to the applicable UPC’s privacy policy.
Data Controller and contact details
Patent Mediation and Arbitration Centre of the Unified Patent Court (“PMAC”)
Lisbon seat: Palácio da Justiça de Lisboa, Rua Marquês de Fronteira, 1098-001 Lisbon, Portugal
Ljubljana seat: Tomšičeva 6, 1000 Ljubljana, Slovenia
Email: contact-pmac@unifiedpatentcourt.org
Privacy Policy
Glossary of terms
Personal Data means any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data Controller means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
Data Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller.
Data Subject means the identified or identifiable natural person whose Personal Data are collected and processed by a Data Controller or processed on behalf of the Controller by a Data Processor.
Data Protection Officer means a person designated by the Data Controller who monitors compliance with the applicable data protection framework and acts as contact point for data protection matters.
Recipient means a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
Pseudonymization means any Processing of Personal Data such that it can no longer be attributed to a specific Data Subject without the use of additional data.
For more details and/or for additional definitions in the context of Data Protection, refer to Article 4 GDPR
Legal framework for the protection of Personal Data
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) is the European standard in relation to data protection. The GDPR has applied since 25 May 2018 and applies to public and private entities that process Personal Data where the conditions set out in Article 3 of the GDPR are met.
The PMAC forms part of the UPC. Where applicable, PMAC processes Personal Data respecting the Guidelines for the Protection of Personal Data in the Unified Patent Court (“Guidelines”), which are based on the principles and safeguards of the GDPR. In the event of any conflict between the Guidelines and the GDPR, the provisions of the GDPR shall prevail.
What is the purpose of this policy?
This Privacy Policy explains how Personal Data are collected and processed by the Data Controller in a lawful, fair, transparent and secure manner.
This Policy explains:
what Personal Data the Data Controller collects through forms submitted to PMAC, including within the PMAC CMS, ADR services (including mediation, arbitration, expert determination), contact channels, events and training, and other communications, and within the PMAC website;
for what purposes the Data Controller uses Personal Data;
the legal basis on which the Data Controller processes Personal Data;
with whom Personal Data may be shared;
how long Personal Data are retained; and
what rights Data Subjects may exercise.
How and why do we collect data?
The Data Controller may obtain Personal Data when you:
contact PMAC by email, phone, post, contact form, or in person;
submit a request for or participate in an ADR proceeding, including via the PMAC CMS;
browse the PMAC website;
complete or submit a form provided by the PMAC
Personal data are processed only to the extent necessary for the relevant purpose.
The legal basis for processing of Personal Data are set forth in Article 6(1) of the GDPR. Depending on the specific processing activity, Personal Data are processed based on one or more legal grounds stipulated therein.
Where consent is the legal basis, the Data Subject has the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
Where requests, submissions, supporting documents or correspondence contain special categories of Personal Data, such data are processed only where an applicable condition under Article 9(2) of the GDPR is met, including where processing is necessary for the establishment, exercise or defence of legal claims pursuant to Article 9(2)(f) of the GDPR.
What Personal Data do we collect?
Via website browsing and the use of strictly necessary cookies: session identifiers, preferences, technical and security-related information;
Via contact form or other means of communication: name, country of residence, email address, and message content;
Via PMAC forms, ADR services and case administration: names and contact details of parties, representatives and other participants, professional details and procedural roles, information contained in requests, responses, submissions, supporting documents and correspondence, payment-related information;
Via applications for inclusion in, and administration of, lists of mediators, arbitrators, experts and other neutrals: name, contact details, nationality, languages, professional qualifications and experience, areas of expertise, relevant professional memberships, information necessary to assess eligibility, availability, appointment-related information, and information necessary for conflict-of-interest checks;
Via the publication of professional profiles of neutrals on the PMAC website, where applicable: name, professional experience, languages, present function, areas of expertise and other professional information approved for publication by the Data Subject;
Via events, training and other PMAC activities: name, contact details, organisation and professional function, registration and attendance information, payment status where applicable, and photographs or recordings where applicable;
Via registration for and use of the PMAC CMS: identification and contact details, account and user-profile information, authentication information, electronic-signature or certificate information, and technical, access and security logs.
PMAC website browsing and cookies
The PMAC website uses only strictly necessary cookies required for its proper technical operation and security. A cookie is a data file, which typically includes a unique identifier sent to a web browser from a visited website and stored on the user’s device. The pages and images, along with a cookie, are downloaded to the device.
This is a standard and common procedure as cookies help to improve the efficiency and usability of the PMAC website.
How to control and delete cookies
We will not use cookies to collect personally identifiable information about you and only strictly necessary cookies are used to store your cookie preferences. However, you may restrict or block the cookies used by the PMAC website through your browser settings.
Be aware that restricting cookies may affect the functionality of the PMAC website.
The cookies used by the PMAC website are as follows:
cookies-agreed | website | 100 days | To record that the user has acknowledged or dismissed the cookie information notice |
cookie-agreed-version | website | 100 Days | To record the version of the cookie information notice acknowledged by the user. |
Spam Protection
Forms on the PMAC website (www.pmac-upc.org) are protected against automated submission by using a challenge mechanism. The service we use for this is Cloudflare's Turnstile. It allows us to:
avoid tracking cookies: Turnstile does not use cookies for tracking or ad retargeting;
have minimal data collection: Turnstile processes "Signals" from the client side, such as IP addresses, user-agent headers, and browser characteristics, to detect bots. The purpose of collecting these signals is exclusively for bot detection and not to "identify, profile or target any individuals".
Cloudflare processes these signals on behalf of the Data Controller for the purpose of providing the Turnstile service. Cloudflare may also process the signals as an independent Data Controller for the purpose of improving Turnstile’s bot-detection capabilities, in accordance with Cloudflare’s Turnstile Privacy Addendum.
What do we do with your information and on what legal basis?
The Data Controller may process Personal Data for the following purposes:
receiving, examining, registering and administering requests for ADR procedures, including mediation, arbitration and expert determination, and administering the related proceedings. Personal Data are processed pursuant to Article 6(1)(e) of the GDPR where necessary for the PMAC to perform its functions under the applicable legal and procedural framework. Information relating to payments and invoicing is processed pursuant to Article 6(1)(e) of the GDPR where necessary to verify whether the fees required for the commencement or continuation of the relevant ADR proceeding have been paid and to associate the payment with the relevant proceeding. The issuance of invoices, receipt and allocation of payments, accounting and retention of financial records are carried out by the competent UPC services;
handling enquiries, communicating with parties, representatives, neutrals, experts and other authorised participants. Personal Data are processed pursuant to Article 6(1)(e) of the GDPR where necessary to respond to enquiries concerning PMAC’s functions, its activities and proceedings;
establishing, maintaining and updating lists of mediators, arbitrators, experts and other neutrals, verifying their qualifications and experience, carrying out conflict checks, and administering their appointment to the PMAC proceedings. Personal Data are processed pursuant to Article 6(1)(e) of the GDPR where necessary for the PMAC to perform its functions. Where professional profiles are published on the PMAC website on an optional basis, the publication is based on the Data Subject’s consent pursuant to Article 6(1)(a) of the GDPR;
organising events, training and other activities relating to mediation, arbitration and alternative dispute resolution. Personal Data are processed pursuant to Article 6(1)(e) of the GDPR where necessary for the PMAC to perform its functions. Where participation is based on individual registration or payment, processing necessary to administer that participation may also be based on Article 6(1)(b) of the GDPR. Where photographs, recordings or contact details are used for an optional publication or promotional purpose, processing is based on consent pursuant to Article 6(1)(a) of the GDPR;
retaining and archiving PMAC case files and related procedural records. Personal Data are processed pursuant to Article 6(1)(e) of the GDPR where retention is necessary for the administration of the PMAC proceedings and the performance of PMAC’s functions;
operating, maintaining, and securing the PMAC website and related systems. Personal Data are processed pursuant to Article 6(1)(e) of the GDPR where necessary for the operation, security and proper functioning of the PMAC website and systems.
Recipients of Personal Data:
authorised PMAC and UPC staff;
appointed mediators, arbitrators, experts and other neutrals;
parties and their authorised representatives, where necessary for the relevant PMAC service or proceeding;
service providers acting as Data Processors on behalf of the Data Controller;
competent authorities or oversight bodies, where required by applicable law or rules;
Data Processors
Personal Data may be shared with relevant external service providers that assist in the performance of all or part of the Data Controller’s activities, including, without limitation, IT and cloud service providers.
Personal Data are hosted on servers located within the EU/EEA or in countries covered by an adequacy decision adopted by the European Commission. Where Personal Data are transferred to a country outside the EU/EEA that is not covered by an adequacy decision, appropriate safeguards are implemented in accordance with the GDPR, including standard contractual clauses where applicable. External service providers and sub-processors are also required to implement appropriate technical and organisational measures and comply with the applicable data protection requirements.
Data Processors and all the staff explicitly authorized by the Data Controller are committed to appropriate processing, ensuring that the rights of the Data Subject are safeguarded in strict compliance with the GDPR.
How long Personal Data are retained?
Personal Data will not be retained for longer than is necessary in relation to the purposes for which they are processed, unless a longer retention period is justified by applicable legal obligations, audit requirements, dispute resolution, or the establishment, exercise or defense of legal claims. Upon expiry of the applicable retention period, the personal data will be securely deleted or anonymised
Categories of Personal Data | Retention | Notes |
Account / user profile data | 6 months | Personal Data retained for 6 months after closure of an account for account administration, audit and detection of data leakage and malicious actions |
Electronic signature license / certificate data | 10 years | Personal Data retained for 10 years after expiry or revocation of the license for audit, security, and legal claims |
PMAC Case Management System (CMS) | 10 years | Personal Data retained for 10 years after final case closure for enforcement, challenge, legal claims |
Applications for inclusion in lists of mediators, arbitrators, experts and other neutrals | 2 years | Personal Data retained for 2 years after decision on non-admitting to the list for administration of the selection procedure, respond to queries or complaints and demonstrate compliance with the applicable selection criteria |
Records concerning mediators, arbitrators, experts and other neutrals included on lists | 5 years | Personal Data retained for 5 years after removal from the list for the administration of the list, appointments, conflict of interest checks |
Helpdesk and inquiries | 5 years | Personal Data retained for 5 years after the closure of inquiry, to comply with audit, accountability, incident response and legal claims |
Event and training registration and attendance data | 10 years | Personal Data retained for 10 years after completion of the event or training activity or event administration, attendance records and evaluation |
Photographs and recordings from events and training | period necessary for the publication | Personal Data retained for period necessary for the publication or communication purpose or until consent is withdrawn where consent is the legal basis |
Information relating to the payment status of ADR fees | 10 years | Personal Data retained for 10 years after final closure of the case |
What are Data Subjects rights?
The GDPR grants the following rights to the Data Subjects (for more details and for the relevant preconditions, see Articles 12 to 22 of the GDPR):
The right to be informed: Data Subjects must be informed on what the Data Controller does with Personal Data in a concise, transparent, intelligible and easily accessible form, using clear and plain language. This is the purpose of this Policy;
The right of access: Data Subjects have the right to obtain confirmation as to whether Personal Data concerning them are being processed and, where that is the case, to obtain access to those Personal Data and the information provided for in Article 15 of the GDPR;
The right to rectification: Data Subjects may request the rectification of inaccurate Personal Data concerning them and the completion of incomplete Personal Data.
The right to erasure: in some circumstances, Data Subjects can ask the Data Controller to delete any Personal Data the Data Controller holds about Data Subjects, under the “right to be forgotten”.
The right to restrict processing: in some circumstances, Data Subjects can obtain restriction of certain types of processing.
The right to object: where Personal Data are processed pursuant to Article 6(1)(e) of the GDPR, Data Subjects may object to the Processing on grounds relating to their particular situation. The Data Controller may continue the Processing only where compelling legitimate grounds exist or where it is necessary for the establishment, exercise or defence of legal claims.;
The right to data portability: Data Subjects may, subject to the conditions of Article 20 of the GDPR, receive the Personal Data they have provided in a structured, commonly used and machine-readable format.
The right to withdraw consent: where the processing is based on Data Subjects consent, Data Subjects may withdraw their consent at any time, without this affecting the processing carried out before such withdrawal and without prejudice to any retention or processing that may be required from us by law.
The right not to be subject to automated decision-making including profiling: Data Subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects Data Subjects, unless such processing is necessary for the performance of a contract, authorised by law, or based on Data Subjects explicit consent.
The right to lodge a complaint with the supervisory authority: if Data Subjects believe that Personal Data are being processed in a way that does not comply with the GDPR, Data Subjects have the right to lodge a complaint with competent data protection supervisory authority.
Exercise of Data Subjects’ rights
Data Subjects can exercise their rights by sending an email to dpo@unifiedpatentcourt.org. Requests will be processed without undue delay and, in any event, within one month of receipt (the period may be extended by two further months where necessary, taking into account the complexity and number of the requests). Where a request is manifestly unfounded or excessive, the Data Controller may charge a reasonable fee or refuse to act on the request in accordance with Article 12(5) of the GDPR. Where the Data Controller refuses to act on a request, the requester will be informed of the reasons for the refusal and of the possibility of lodging a complaint with the competent supervisory authority and seeking a judicial remedy.
Policy updates
The Data Controller reserves the right to modify, update, add or remove parts of this Policy at any time. Data Subjects are invited to consult this Privacy Policy periodically in order to remain informed of any changes.
What is the effective date of this policy?
This Policy was last updated on 31 July 2026.
Who is your contact for data privacy enquiries?
For enquiries concerning the Data Controller’s processing activities, please contact PMAC at contact-pmac@unifiedpatentcourt.org. For data privacy enquiries, please contact:
Unified Patent Court
1, Rue du Fort Thüngen
L-1499 Luxembourg
Email : dpo@unifiedpatentcourt.org
A complaint may be lodged with the Commission Nationale pour la Protection des Données (https://cnpd.public.lu) (“CNPD”), address: 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg, if a Data Subject believes that the processing of their Personal Data does not comply with applicable data protection regulations.