CFA Institute Privacy Policy
CFA Institute (collectively, “CFA Institute,” “we,” “our,” or “us”) is a 501(c)(6) not-for-profit professional membership association committed to leading the investment profession globally. Our headquarters is located at 915 East High Street, Charlottesville, VA, 22902, USA, and we own and operate this website (the “Site”). We operate subsidiaries or branch offices in the United Kingdom, the United Emirates, India, Mainland China, and Hong Kong.
This Privacy Policy explains how we process information from or about you when you use our websites, services, applications, software, products, and other digital services that link to this policy, or if you otherwise engage in business or interact with us, such as at events and conferences and through direct interactions with CFA Institute staff (collectively the “Services”).
Please read this Privacy Policy carefully to understand how we handle your information. By using the Services or otherwise providing us with your information you consent to our processing and transfer of your information as we describe here. Any jurisdiction-specific section below will prevail to the extent of an inconsistency with this Privacy Policy.
Cross-Border Transfers
CFA Institute is headquartered in the United States. We may transfer and store your Personal Information outside your home country, including in countries that may not provide the same level of data protection.
We implement appropriate safeguards for such transfers, such as standard contractual clauses where required. You may contact us for more information.
Information We Collect
The information we collect about you depends on the Services you use, how you use them, and the information you provide to us. We collect information in three main ways: (1) information you provide directly to us; (2) information we collect automatically through technology when you use the Services; and (3) information we collect from other sources.
Information you provide directly to us:
When you use our Services, you may provide certain information directly to us. For example, you may provide us with information when you when you create an account, register for exams or events, enroll in certificates or programs, apply for scholarships, subscribe to a newsletter, interact with us through social media, participate in surveys or research, or communicate and interact with us for customer service or other purposes.
The categories of information we may collect directly from you (which could vary by affiliate or brand) include:
- Contact and account identifiers, such as name, address, telephone number, email address, and login credentials.
- Commercial and financial information, such as financial account information and purchase and transaction history. Note that sometimes your financial account information (e.g., credit card data) is collected by third-party payment processors on our behalf in connection with your purchase.
- Demographic information, such as your interests, preferences, age, and gender.
- Location information, which may be general location derived from your IP address.
- Professional or employment-related information, you may provide us with data about yourself, such as your employment, professional credentials, qualifications, and professional discipline history, in connection with certain training or certification programs offered as part of the Services.
- Educational information, which may include information about your educational background, institution name, and graduation dates, which may be collected and/or required in connection with our Services.
- Health information, which may include information about physical and mental conditions that impact your ability to access our services or that you provide as part of an accommodations request.
- Inference information, which is information we derive or infer about your potential interests and behaviors based on other information we collect.
Please note that some of the information we collect from and about you may be considered “sensitive information” under applicable laws. CFA Institute complies with these laws in its processing of sensitive information.
Information we collect automatically through technology when you use the Services:
When you use our Services, we may automatically collect certain information using a variety of technologies, including cookies and similar tools. Please refer to the Online Analytics section below for more information about cookies.
Some of the information we automatically collect when you use our Services includes:
- Information about the device you use to access the Services, such as your IP address, MAC address, browser language, unique device identifiers, the state or country from which you accessed the Services, operating system, Internet connection type and service provider, Wi-Fi network, and software and hardware attributes (including device IDs, operating system, and browser type).
- Information about how you use the Services, including referring and exit URLs, the links you click, the date and time you accessed the Services, error logs, and other similar information.
- Location information such as general location derived from your computer’s IP address or information about nearby WiFi access points and cell towers that may be transmitted when you use certain Services.
Information we collect from other sources:
We may receive information about you from service providers, business partners, event sponsors, publicly available databases (e.g., criminal and civil liability records), and professional or social networking platforms. When we combine or link information that we receive from third parties with information we already hold, we use that information in accordance with this Privacy Policy.
How We Use Your Information
We may use the information we collect to:
- Provide and manage the Services you have requested, such as managing membership, programs, scholarships, exams, events, and processing applications, orders, and payments you submit to us
- Communicate with you, for example, about your programs, membership, changes to our terms, conditions, and policies; as well as, in accordance with applicable law, marketing
- Improve and personalize our offerings and Services, including bug detection and error reporting, to understand how users interact with our Services, improve usability and effectiveness of our website, and perform research and analytics.
- Secure our Services, for fraud prevention, and legal compliance, such as detecting security incidents and protecting against malicious, deceptive, fraudulent, or illegal activity.
- To conduct due diligence and misconduct screening to help us identity potential misconduct or risks related to our members and candidates; however, these processes are subject to human review, and we do not make decisions that produce legal or similarly significant effects solely based on automated processing.
- Other purposes for which we seek your consent. We may also use your information for a specific purpose that we communicate to you. We will ask for your consent to process your information for such purpose in accordance with applicable legal requirements.
Legal Bases for Processing
Where required by law we rely on one or more of the following legal bases for processing your information:
- Contractual necessity: Where use of your information is necessary to perform our obligations under a contract or commitment to you. For example, to provide the services you’ve requested from us, or to comply with our terms of service.
- Legitimate interests or uses: Where use of your information furthers our legitimate interests or the legitimate interests of others, or is a reasonable, legitimate use of your information such as to improve our products and services, secure our Services, detect fraud or misconduct, make and receive payments, defend our legal rights, or marketing when permitted.
- Compliance with legal obligations. For example, keeping track of purchases for tax and auditing purposes.
- Consent: Where you have consented to our processing of your information for a particular purpose.
How We Disclose Your Information
We may disclose your information to:
- Service providers and vendors. We engage third parties who provide hosting, content development, payment processing, marketing, or IT services to support our services and other operations. These parties act on our instructions and are under contract to use your information only in connection with the services they perform on our behalf. Note that online payment processing is handled by our third-party payment providers and CFA Institute does not store your full payment card information.
- Member Societies. If you create an account on our Services and provide your mailing address, register for a CFA Institute educational program or certificate, or become a CFA Institute member, we may share your information with the CFA Institute Member Society closest to your mailing address. The Member Society may contact you to communicate the broad range of educational, networking and career support benefits that societies offer, and which complement CFA Institute products and services. If you receive these Member Society communications and no longer wish to receive them, you may opt-out with the Member Society directly.
- Event sponsors and attendees. For some CFA Institute events, we may make certain information of attendees available to other attendees and event sponsors. This will be disclosed to event attendees. The information made available may include name, employer, address, and email address.
- Employers. Under certain circumstances, we may share information of candidates, members, or other customers with their employers to validate membership or program status.
- Regulators, law enforcement authorities, courts, and others for the protection of CFA Institute and others. We share information as required by law or at the request of government regulatory or other law enforcement officials and the courts including if required to do so by law or in a good faith belief that such disclosure is reasonably necessary to comply with legal process (for example, a subpoena or court order). In China, Personal Information of CFA Charterholders is shared with the Occupational Skill Testing Authority (OSTA) of the Ministry of Human Resources and Social Security (MOHRSS). We may also share professional conduct information related to members and candidates with regulators. We may disclose your information with a good faith belief such disclosure is reasonably necessary to (a) enforce our terms of service or sale, this Privacy Policy, or other contracts with you, including investigation of potential violations; (b) respond to claims that any content violates the rights of third parties; or (c) protect the rights, property, or personal safety of CFA Institute or others.
- Partners such as prep providers, sponsors, educational and research institutions. If you authorize us to do so by opting in, we may share your Personal information with select third parties that offer services or products that may be of interest to you. These third parties include exam preparation providers, exhibitors and sponsors of CFA Institute events, University Program Partners and the CFA Institute Research Foundation.
- The general public through our Member Directory. We make CFA Institute members’ name, location and charter/membership status publicly available through the CFA Institute online Member Directory, which is searchable on our Services, as well as by phone and email upon a third party’s request. Members may choose to make additional information available on the Member Directory by changing their account preferences. Names of individuals holding any CFA Institute-issued certificate is available to the general public.
- Other organizations in connection with mergers or acquisitions. In the future, we may merge with other organizations. If a portion or all of our assets are transferred to a third party in these circumstances, we may disclose your information as part of the merger.
- Other situations. We may also disclose your information in other situations where legally permitted, including in order to perform tasks or services that you have requested.
De-identified Information
We may de-identify information we collect so the information cannot reasonably identify you or your device, or we may collect information that is already in de-identified form. Our use and disclosure of de-identified information is not subject to any restrictions under this Privacy Policy, and we may use and disclose it to others for any purpose, without limitation.
Online Analytics and Advertising
We use cookies and similar technologies (such as web beacons, device identifiers, log files, and local storage) to operate our Services, improve performance, analyze usage, enhance security, personalize content, and deliver advertising. We also work with third-party analytics and advertising companies who place their own cookies or similar technologies on your browser or device when you visit our Services and other third-party websites, in order to provide analytics to us or serve customized advertisements to you.
These technologies can be grouped into categories related to their purpose:
- Essential: enable core functionality of our Services and cannot be turned off
- Targeted advertising: deliver and measure advertising related to our offerings
- Personalization: allow the Services to remember functionality choices you make (e.g., remembering your username) and provide enhanced personalization
- Analytics: measure website performance, user interactions, and identify technical issues
When you visit our site, you may use our cookie banner (in applicable jurisdictions) and/or cookie preferences management tool to determine and select which categories of these technologies are active on our Services during your visit. At any time, you may change your preferences by clicking on the Cookie Preferences link in the website footer.
In addition to using cookies and other tracking technologies to serve digital advertising, we also may share limited information (such as your email address) in a hashed or otherwise pseudonymous format with social and professional networking platforms. These platforms use the information to identify users who also have accounts with them (audience-matching) and to deliver CFA Institute advertising to those users.
You may opt out of the targeted advertising and audience-matching advertising described above. If you wish to opt out of our processing or sharing of your information for online targeted advertising purposes, opt out of the targeted advertising cookies using the Cookie Preferences tool.
If you do not want your information shared for audience matching, you may withdraw consent to CFA Institute marketing communications as described below, or you may adjust your settings in the relevant platforms so those networks may not use your information in this manner.
Your Privacy Rights & Choices
We provide you with the ability to request certain actions with respect to your information, including the right to:
- Withdraw your consent to the processing of your information for certain processing purposes, where the processing purpose was based on your consent.
- Request access to your information.
- Request information about the categories of information we process about you.
- Request the correction of your information (including completing any incomplete information or updating any obsolete information).
- Request the deletion of your information, subject to legal, regulatory, or legitimate business retention requirements.
- Restrict or object to certain processing of your information.
- Request data portability, allowing you to receive your information in a structured, commonly used, and machine-readable format for transmission to another entity.
You may exercise these rights by contacting us at [email protected]. You may also opt-out of our processing of your information for targeted advertising in the manner described above.
Withdrawal of consent will not affect the legality of processing carried out before withdrawal. We will cease processing your personal data within a reasonable time after withdrawal, unless we are permitted or required to continue processing under the DPDP Law or other applicable law.
Please note that these rights are limited under your applicable local data protection law. If you seek to exercise any of these rights, our obligation to respond is limited by and subject to the law applicable to you. You also may have the right to lodge a complaint with a relevant data protection authority.
Updating Your Personal Information and Communication Preferences
If you have a CFA Institute account, you may view your Personal Information on file with us at any time by visiting Your Account (account login required) on the CFA Institute website, where you may change update your Personal Information.
You may change your preferences for how we contact you at any time by visiting "My Account" and selecting "Preferences" on the CFA Institute website, or by contacting us using the information provided under the “Contact Us” section of this Policy.
You can also opt out of receiving marketing emails from us by following the instructions at the bottoms of the email. Please note that your request will take some time to process, in accordance with applicable law. After you opt out, you will still receive transactional communications from us regarding your account or important legal information.
Children’s Privacy
Our Services are not directed at children. If we become aware that we have collected data without legally valid parental consent from children under an age where such consent is required under applicable laws of the relevant jurisdiction, we will take reasonable steps to delete it as soon as possible.
Retention of Your Information
We retain your information for as long as necessary to provide services, comply with legal and regulatory obligations, resolve disputes, and maintain business records. When no longer needed for the purpose collected, data will be securely deleted or anonymized, subject to applicable laws.
Retention periods are determined based on:
- Legal and regulatory requirements (e.g., financial, employment, and data protection laws).
- Contractual obligations (e.g., agreements with members and test-takers).
- Business needs (e.g., maintaining certification records for professional verification).
- Fraud prevention and security (e.g., investigating unauthorized access).
- User requests (e.g., data deletion under applicable laws).
For participants in certificate and credential programs, we may retain your information indefinitely as proof of your program status.
Security of Your Information
We maintain appropriate technical, physical, and administrative safeguards to protect against unauthorized access, disclosure, alteration, or destruction. While we strive to protect information, we cannot ensure the security of the information you transmit. We recommend you take every precaution in protecting your information when you are on the Internet.
Social Media Interactions and Links to Third-Party Sites
The Services may offer opportunities to engage in social networking, interact with others and/or submit or post messages or other content, such as on CFA Institute blogs ("CFA Institute Networking Sites"). The Services may also provide for interactions with third party websites or services including social media websites through plug-ins. Please note that any information or materials that you post or submit through such CFA Institute Networking Sites will be publicly posted to everyone that has access to the relevant Services. Posts to third party social media or other sites ("Social Media Sites"), including any content on our Services that you "share" or "like," will be controlled by and subject to the terms of such social media or other sites. We encourage you to use caution when you submit any information or materials on or through any CFA Institute Networking Sites or interact with third party websites or services through plug-ins.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our data collection and use practices, the features of our Services, or advances in technology. You should review the Privacy Policy periodically, and you can know if the Privacy Policy has changed since the last time, you reviewed it by checking the “Last Updated” at the beginning of the document. By continuing to use the Services, you are confirming that you have read and understood the latest version of this Privacy Policy. If material changes affect previously collected information, we will notify you and obtain consent where required.
Contact Us
For further information about CFA Institute's Privacy Policy, and to exercise your data rights, please contact Customer Service at [email protected].
For purposes of services provided to residents of Mainland China, CFA Institute (USA) Beijing Representative Office, Unit 5501, 55/F China World Tower B, No. 1 Jianguomenwai Avenue, Chaoyang District, Beijing 100004, China, serves as the handler of personal information. You may contact CFA Institute’s China Data Privacy Representative at: [email protected].
For the purpose of services provided to residents of India, for any questions regarding processing of personal data, please contact the data privacy officer of CFA Institute via email at: [email protected].
Additional Information for Individuals in Mainland China
If you are located in Mainland China and when the Chinese data protection laws apply, our local entity CFA Institute (USA) Beijing Representative Office ("CFA Institute China RO") in Mainland China may transfer your information it collected to other regions outside of Mainland China via the Internet connecting our information systems.
If you are a charterholder or a candidate in Mainland China, CFA Institute China RO may transfer the following information of yours: Personal basic profile including e-mail address and CDE User Manager ID (CFA internal marketing serial number).
If you are a potential candidate have otherwise signed up for marketing and communications from CFA Institute, CFA Institute China RO may transfer the following information of yours: Personal basic profile including name, e-mail address, and phone number; Personal education and work information including company name and job title.
The overseas recipient is CFA Institute, and the transfers do not involve sensitive personal information.
When CFA Institute China RO stores or transfers your information outside of Mainland China, it will take necessary steps to ensure that your information is treated as securely as it would be within Mainland China and under the Personal Information Protection Law (PIPL).
CFA Institute China RO only transfers your information to the extent necessary and works with the overseas recipient to process it in a secure manner to protect your legitimate rights and interests and to avoid causing harms to you. CFA Institute China RO and the overseas recipient will only retain your information for the minimum necessary retention period unless otherwise required by applicable laws.
CFA Institute China RO may conclude a standard contract for the cross-border transfer of personal information with the overseas recipient and, in such a case, you may be considered as a third-party beneficiary and be entitled to exercise the third-party beneficiary rights if you do not expressly refuse within 30 days upon your acceptance of this Privacy Policy.
Your acceptance of this Privacy Policy is considered as your separate consent permitting us to transfer and store your information outside of Mainland China.
For purposes of services provided to residents of Mainland China, CFA Institute (USA) Beijing Representative Office, Unit 5501, 55/F China World Tower B, No. 1 Jianguomenwai Avenue, Chaoyang District, Beijing 100004, China, serves as the handler of personal information. You may contact CFA Institute's China Data Privacy Representative at: [email protected].
Additional Information for Individuals in India
This section applies to individuals in India whose personal data is processed by CFA Institute in connection with the Services, including where such personal data is processed by CFA Institute's Indian subsidiary, CFA Institute India Private Limited ("CFAIIPL"). It supplements, and should be read together with, the rest of this Privacy Policy. Where there is a conflict between this section and the rest of this Privacy Policy in respect of individuals in India, this section shall prevail to the extent required by the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as amended from time to time (together, the "DPDP Law").
For purposes of the DPDP Law, CFA Institute and CFAIIPL act as the "Data Fiduciary" in respect of personal data of individuals in India ("Data Principals") collected for or through the Services.
Your Rights and Duties as a Data Principal
In addition to the rights described elsewhere in this Privacy Policy, and subject to the exceptions and conditions set out in the DPDP Law, you have the right to: (i) obtain a summary of the personal data we are processing about you and of the related processing activities, together with the identities of other data fiduciaries and data processors with whom your personal data has been shared and a description of the personal data shared; and (ii) nominate another individual to exercise your rights under the DPDP Law in the event of your death or incapacity.
You agree to comply with the duties of a Data Principal under DPDP Law and other applicable laws, including (i) not impersonating another person while providing personal data for a specified purpose; (ii) not suppressing any material information while providing personal data for any document, unique identifier, proof of identity or proof of address issued by the government; (iii) not registering any false or frivolous grievance or complaint with us or the Data Protection Board of India; and (iv) furnishing only such information as is verifiably authentic, while exercising your right to correction or erasure.
Persons with Disability
If we are made aware that a Data Principal is a person with disability who has a lawful guardian, we will observe due diligence to verify that consent given on their behalf is provided by a validly appointed guardian, as required under the DPDP Law.