Legal & Regulatory Register

The register of legal and regulatory requirements pertinent to the scope of our ISO 20252:2019 certification — including the privacy legislation of every jurisdiction in which we run fieldwork.
Document reference
ERL-QMS-REG-01
Version
1.0
Approved
9 September 2026
Next scheduled review
September 2027
Register owner
Managing Director, supported by the Quality & Data Protection lead
Certified scope covered by this register

The delivery of behavioural market research based on ecommerce experiences — the scope of the company’s ISO 20252:2019 certification.

Privacy and data protection legislation is included in this register and is listed first, jurisdiction by jurisdiction, in section 1 below. The Statement of Applicability for the same scope is published on the ISO 20252 page.

1. Privacy and data protection legislation

Every jurisdiction in which the company recruits research participants, or from which client personal data is received, is listed here. A market is not opened for fieldwork until its privacy regime has been entered in this register and the panel supplier contract reflects it.
Jurisdiction Legal or regulatory requirement Relevance to the certified scope How the requirement is met
Switzerland (seat of the company) Federal Act on Data Protection (FADP / nLPD, revised text in force 1 September 2023) and the Data Protection Ordinance (DPO) Home jurisdiction of emazing-retailing SA, Geneva. Governs all processing of participant and client personal data carried out by the company. Record of processing activities maintained; participant privacy notice issued at recruitment; documented retention and deletion schedule; breach notification to the FDPIC within the statutory deadline.
European Union / EEA General Data Protection Regulation (Regulation (EU) 2016/679) Applies extraterritorially (Art. 3(2)) wherever research participants are located in the EEA, which covers a large share of fieldwork. Lawful basis recorded per study; data protection impact assessment where observational or passive metering is used; data processing agreements and Standard Contractual Clauses with panel suppliers and sub-processors; documented data subject request procedure.
European Union / EEA ePrivacy Directive 2002/58/EC as implemented in national law, and national cookie and electronic marketing rules Cookies, SDKs and any device-level metering used inside simulated store environments, and analytics on emazingretailing.com. Consent banner on the public website; separate, explicit opt-in for any passive metering, withdrawable at any time without affecting the participant’s incentive.
European Union Regulation (EU) 2024/1689 (AI Act) Monitoring item. Would become directly relevant if AI-assisted analysis or synthetic respondents were introduced into client deliverables. No high-risk AI system is deployed within the certified scope. Reviewed at each register review; any change of position is recorded in the change log below.
United Kingdom UK GDPR and Data Protection Act 2018; Privacy and Electronic Communications Regulations 2003 (PECR) UK-resident participants and UK-established clients. Same operational controls as for the GDPR; transfers out of the UK made under the IDTA or the UK Addendum to the SCCs.
United States (California) California Consumer Privacy Act as amended by the CPRA Participants resident in California, and the Act’s definitions of “sale”, “sharing” and sensitive personal information. Participant data is never sold or shared for cross-context behavioural advertising; notice at collection given at recruitment; opt-out and deletion routes published on the privacy page.
United States (other states) VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), TDPSA (Texas) and successor state privacy statutes Participants recruited in those states. Operated to a single highest-common-denominator participant notice and rights process rather than state-by-state variants, so that a newly effective state act does not create a gap.
United States (federal) Children’s Online Privacy Protection Act (COPPA); Section 5 of the FTC Act Minimum participant age, and the prohibition on deceptive research or marketing claims. Age screening at recruitment; participants are 18 or over unless a specific parental-consent protocol is agreed with the client in writing in advance.
Canada PIPEDA; Quebec Law 25 (Act to modernise legislative provisions as regards the protection of personal information) Canadian participants, including Quebec-specific consent and transfer assessment duties. Meaningful consent at recruitment, purpose limitation, and disclosure that data may be processed outside Canada.
China Personal Information Protection Law (PIPL, 2021); Cybersecurity Law (2017); Data Security Law (2021) Fieldwork with participants located in mainland China, and the resulting cross-border transfer of personal information. Separate, specific consent obtained for cross-border transfer; the local panel partner acts as the collecting entity; the transfer mechanism (CAC standard contract or applicable exemption) is confirmed per project before fieldwork opens; wherever the protocol allows, only aggregated or de-identified results leave the country.
Japan Act on the Protection of Personal Information (APPI), as amended in 2022 Japanese participants and transfers of their data to the company in Switzerland. Purpose of use notified at recruitment; foreign-transfer disclosure naming the recipient country and the protections in place; incident handling aligned to the Personal Information Protection Commission’s notification timelines.
Brazil Lei Geral de Proteção de Dados (Law 13.709/2018, LGPD); Consumer Defence Code (Law 8.078/1990) Brazilian participants, and the consumer-facing content presented inside simulated store environments. Documented legal basis per study; data subject rights handled to ANPD expectations; international transfer safeguards in the panel contract; simulated retail environments carry a clear notice that they are a research simulation and not a live store.
Mexico Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations Mexican participants. Privacy notice (aviso de privacidad) supplied at the point of recruitment; ARCO rights (access, rectification, cancellation, opposition) route documented and monitored by the register owner.
Saudi Arabia Personal Data Protection Law (Royal Decree M/19 of 2021, as amended) and its Implementing Regulations, supervised by SDAIA Participants resident in the Kingdom. Consent and notice prepared to SDAIA requirements; transfer of personal data outside the Kingdom assessed per project against the transfer conditions; the local panel partner’s standing under the PDPL is checked before fieldwork opens.
Other active markets Australia Privacy Act 1988 (Australian Privacy Principles); India Digital Personal Data Protection Act 2023; Singapore PDPA; South Africa POPIA; UAE Federal Decree-Law 45/2021 Markets entered at client request. Listed so that the entry exists before, not after, the first project. Reviewed and confirmed at project set-up. No market is opened for fieldwork until its regime is entered here and reflected in the panel supplier contract.

2. Research standards, codes and professional obligations

The standards and codes to which the company is certified or has declared adherence, and which govern how studies are designed, run and reported.
Jurisdiction Legal or regulatory requirement Relevance to the certified scope How the requirement is met
International ISO 20252:2019 — Market, opinion and social research, including insights and data analytics The certified standard itself. Annexes D, E and F are attested; Annexes A, B and C are excluded. Scope and Statement of Applicability published on the ISO 20252 page and reviewed annually under Clause 4.1.1.
International ICC/ESOMAR International Code on Market, Opinion and Social Research and Data Analytics Participant rights, transparency, the duty not to mislead, and the separation of research from selling. Applied to all study designs; research is never used as a pretext for sales or direct marketing.
International ESOMAR/GRBN guidance on online research, passive data collection and research with participants recruited from online panels Directly relevant to Annex D (digital observation) and Annex E (self-completion), which are the attested annexes. Informed consent covers what is observed, for how long and by whom; participants may withdraw without losing their incentive.
Contractual Client master services agreements, data processing agreements and supplier codes of conduct Client-specific obligations frequently exceed the statutory baseline (data residency, retention, sub-processor approval, security attestations). Project-specific obligations are recorded at contract signature and checked at project close-out.

3. Other legal requirements pertinent to the scope

Requirements outside privacy law that bear directly on how research within the certified scope is delivered.
Jurisdiction Legal or regulatory requirement Relevance to the certified scope How the requirement is met
Switzerland Swiss Code of Obligations; Federal Act against Unfair Competition (UCA/LCD), in particular Art. 3(1)(o) Contract formation with clients and suppliers; unsolicited electronic marketing. Opt-out honoured on all outbound electronic communication; sender identity and a working unsubscribe route in every message.
US / UK / EU CAN-SPAM Act (US); PECR (UK); GDPR Art. 21 and national marketing rules (EU) The company’s own business-to-business marketing, which sits alongside but must never be confused with research recruitment. Marketing and research contact lists are kept separate. Research participants are never contacted for marketing purposes.
International Copyright, trade mark and unfair competition law in the markets where studies run Simulated marketplace and product-page environments reproduce client assets and, where the protocol requires it, competitor and retailer trade dress. The client warrants its rights in supplied assets in the master services agreement; third-party material is reproduced only to the extent needed to replicate a shopping environment for research, is shown only to recruited participants in a closed environment, and is destroyed with the project data.
International Confidentiality and trade secret obligations (contractual and statutory) Unreleased products, pricing strategies and pack designs are routinely tested before launch. Non-disclosure agreements with clients, staff and suppliers; access to project material limited to the assigned project team.
Local (per market) Participant incentive, consumer and tax rules applicable to research incentives Incentives are paid to participants in every market in which fieldwork runs. Incentives are administered by the contracted panel supplier of record in each market, which carries the local reporting obligation under its panel terms.

How this register is maintained

Where the register is held

The controlled master is held in the company’s quality management system document set under reference ERL-QMS-REG-01. This page is the published copy, maintained in step with the master so that clients, research participants, auditors and other interested parties can consult it without having to request it.

Who owns it

The Managing Director owns the register, supported by the Quality & Data Protection lead. No entry may be added, amended or removed without the owner’s approval.

How often it is reviewed

Formally reviewed at least annually, in the same cycle as the Statement of Applicability required by Clause 4.1.1 of ISO 20252:2019, and additionally whenever one of the triggers below occurs.

What triggers an out-of-cycle review

A new market being opened for fieldwork; a new or amended privacy statute or implementing regulation in a listed jurisdiction; a change of panel supplier or sub-processor; a new client contractual obligation that exceeds the statutory baseline; a data breach or a complaint from a participant or regulator; and any change to the certified scope itself.

How changes are identified

Regulatory monitoring through ESOMAR and industry association updates, supervisory authority publications in the listed jurisdictions, panel supplier compliance notices, and external legal advice where a change materially affects how a market is run.

What evidence is retained

Each review is minuted with the date, the reviewer, the entries examined and the outcome. Review records are retained for the current and preceding certification cycles and are available to the certification body on request.

Revision history

Version Date Change Approved by
1.0 9 September 2026 Register published in this form. Privacy legislation entries added for China, Japan, Brazil, Mexico and Saudi Arabia alongside the existing Swiss, EU/EEA, UK, US and Canadian entries. Managing Director