Privacy
Purpose and Scope
The SDEWES Journals Privacy Policy sets out the principles and procedures governing the processing of personal data, protection of confidential information and respect for privacy rights in the submission, editorial assessment, peer review, production, publication and post-publication activities of journals published by SDEWES Centre.
This policy supports lawful, fair, transparent, secure and proportionate handling of personal data and confidential information while protecting editorial confidentiality, research participants and the integrity of the scholarly record.
It applies to submitted, accepted and published manuscripts, including regular articles, review articles, special issue papers, article collections, conference-linked submissions, supplementary materials, research data, peer-review records, editorial correspondence, appeals, complaints, corrections, retractions and other journal records.
It applies to authors, reviewers, Editors-in-Chief, Associate Editors, Guest Editors, Editorial Board members, readers, complainants, research participants, institutional representatives, SDEWES Centre staff or representatives and other individuals whose personal data are processed in connection with SDEWES journals.
This policy concerns journal publishing activities. Separate privacy or cookie notices may apply to conferences, membership, newsletters, website analytics, financial administration, employment and other non-journal activities of SDEWES Centre.
In this policy, the privacy handler means the person authorised by SDEWES Centre to receive or coordinate privacy requests, incidents or concerns. The responsible editor may participate where the matter affects a manuscript, peer review or published article, provided that the editor has no relevant competing interest.
Related guidance, statement templates, declaration forms and checklists relevant to this policy are listed in Appendix A: Related COPE and International Guidance and Appendix B: Practical Forms, Statements and Checklists.
Definitions and General Principles
Personal data means information relating to an identified or identifiable natural person.
Special-category personal data, as defined by applicable law, includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, genetic data, biometric data processed for the purpose of uniquely identifying a person, data concerning health, and data concerning a person’s sex life or sexual orientation. Other personal data may also be sensitive in context and require enhanced safeguards.
Confidential information includes submitted manuscripts, unpublished research, reviewer identities, peer-review reports, editorial deliberations, correspondence, institutional information and other material that is not intended for public disclosure.
Anonymisation means processing information so that an individual is no longer identifiable by reasonably available means. Pseudonymisation replaces or separates direct identifiers but may still allow re-identification and therefore normally remains personal-data processing.
SDEWES journals process personal data according to the principles of:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability.
Personal data must be collected and used only where necessary for a legitimate and identified journal purpose. Access must be limited to persons who require the information for an authorised purpose.
Special-category or other sensitive personal data should not be requested or retained unless necessary, proportionate, supported by an appropriate legal basis and protected by suitable safeguards.
Privacy rights must be balanced with editorial confidentiality, peer-review integrity, the rights of other persons, legal obligations and the need to maintain an accurate and transparent scholarly record.
Data Controller, Privacy Contact and Sources of Personal Data
For personal-data processing connected with SDEWES journal publishing, the data controller is:
International Centre for Sustainable Development of Energy, Water and Environment Systems (SDEWES Centre)
Ivana Lučića 5
10000 Zagreb, Croatia
VAT/OIB: HR32475284418
Privacy contact: insert dedicated privacy email or confirmed contact email
Data Protection Officer, where appointed: contact detail
SDEWES Centre may receive personal data:
- directly from authors, reviewers, editors, readers, complainants and other individuals;
- from corresponding authors or other co-authors;
- from institutions, funders, repositories, indexing services or other publishers;
- through ORCID, professional directories and publicly available institutional sources;
- through manuscript-submission, peer-review, production or payment systems; and
- from website or system-generated technical records.
Where personal data are obtained from another person or source, SDEWES Centre should provide the applicable privacy information where required and reasonably practicable.
Individuals may direct privacy enquiries and requests to the privacy contact identified above.
Categories, Purposes and Lawful Bases for Processing
SDEWES Centre may process personal data necessary for submission, editorial assessment, peer review, production, publication, indexing, preservation, communication, research-integrity assessment and operation of the journals.
Categories of personal data may include:
- names, affiliations, professional titles, email addresses, postal addresses and telephone numbers;
- ORCID iDs and professional profiles;
- manuscript and article metadata;
- author, reviewer and editor roles and assignments;
- reviewer expertise, invitations, responses, review reports and review history;
- editorial decisions, recommendations and correspondence;
- authorship, funding, competing-interest, research-ethics, generative-AI, copyright and data-availability declarations;
- appeals, complaints, corrections, retractions, privacy and research-integrity records;
- payment, invoicing or administrative information where required; and
- technical and security information generated by journal websites or systems.
Personal data may be processed for:
- creating and administering journal accounts;
- receiving and assessing manuscripts;
- selecting reviewers and managing peer review;
- communicating with authors, reviewers, editors and other parties;
- publishing author names, affiliations, ORCID iDs, declarations and article metadata;
- registering DOIs and providing metadata to indexing, preservation and discovery services;
- administering agreements, licences, charges and payments;
- preventing, detecting and assessing publication misconduct;
- handling appeals, complaints, privacy requests and post-publication actions;
- maintaining editorial, legal, financial and scholarly-record documentation; and
- protecting journal systems and confidential information.
Depending on the activity and applicable law, processing may be based on:
- performance of a contract or steps taken at the individual’s request before entering into a contract, where applicable;
- the legitimate interests pursued by SDEWES Centre or a third party in administering peer review, publication, research integrity, security and preservation of the scholarly record, where those interests are not overridden by the individual’s rights and freedoms;
- compliance with a legal obligation;
- consent, where consent is the appropriate and freely given basis; or
- another lawful basis available under applicable law.
Where special-category personal data are processed, SDEWES Centre must also identify and document an applicable condition under Article 9 of the GDPR or another applicable legal provision, in addition to the general lawful basis for processing.
Where consent is used, it may be withdrawn for future processing, but withdrawal does not make earlier lawful processing invalid.
Some information is necessary to submit, review or publish a manuscript. Where required information is not provided, SDEWES Centre may be unable to create an account, process a manuscript, arrange peer review, publish an article, respond to a request or fulfil another journal function.
Editorial decisions must be made by authorised human editors and must not be based solely on automated processing producing legal or similarly significant effects. Automated tools may support administrative, screening or quality-control activities, but must not replace independent editorial judgement.
Personal Data in Manuscripts, Research Data and Published Content
Authors must minimise personal, identifiable and confidential information included in manuscripts, figures, supplementary materials and repository files.
Personal or identifiable information may be submitted or published only where:
- its inclusion is necessary for the scholarly purpose;
- the research and publication are ethically justified;
- an appropriate legal basis exists;
- required ethics approval, consent or permission has been obtained; and
- proportionate privacy safeguards have been applied.
Consent to participate in research or to collect personal data does not automatically constitute consent to publish identifiable information. Where an individual could recognise themselves or reasonably be identified by others, specific publication consent or another valid basis may be required.
Particular care is required for:
- surveys, interviews, questionnaires and stakeholder engagement;
- direct quotations and case descriptions;
- photographs, audio or video recordings and screenshots;
- household, smart-meter, building-user or mobility data;
- precise geospatial and location data;
- vulnerable participants or small populations;
- confidential organisational or commercial information; and
- supplementary or repository files that may permit re-identification.
Authors should use anonymisation, aggregation, pseudonymisation, redaction, controlled access or another appropriate safeguard. Pseudonymised data must not be described as anonymous where re-identification remains reasonably possible.
Raw identifiable participant data should not normally be provided to the journal unless specifically requested and a lawful, secure and proportionate method of access has been arranged.
Where privacy affects public availability of data, authors must provide an accurate Data Availability Statement and use controlled or restricted access where appropriate under Research Data and Transparency.
Research approval, participant consent, vulnerable-group safeguards and publication of identifiable research information are governed primarily by Research Ethics.
The journal may require clarification, consent or permission documentation, revised wording, anonymisation, redaction, replacement files, restricted repository access or removal of unnecessary personal information before publication.
Published author information, article metadata and material forming part of the scholarly record may be distributed widely and preserved by repositories, indexing services and archives. Authors must therefore address privacy and publication-consent issues before publication.
Peer Review and Editorial Confidentiality
Submitted manuscripts, supplementary files, peer-review reports, reviewer identities, author responses, editorial correspondence and editorial deliberations must be treated as confidential except where disclosure is authorised or required for a legitimate editorial, ethical or legal purpose.
Editors, reviewers, Guest Editors, Editorial Board members, staff and other participants must:
- access confidential material only where necessary for their role;
- not disclose or distribute unpublished material without authorisation;
- not use unpublished information for personal, academic, financial or competitive advantage;
- not contact authors or reviewers outside authorised journal channels where this would compromise confidentiality;
- prevent unauthorised access to downloaded files and correspondence; and
- delete or securely dispose of local copies when they are no longer needed, where appropriate.
Reviewer and author identities must be protected or disclosed consistently with the peer-review model stated by the relevant journal, unless disclosure is authorised, required by law or necessary for a proportionate ethics or integrity process.
Reviewer reports and editorial records may be retained for editorial administration, quality assurance, appeals, complaints, publication-ethics assessment and protection of the scholarly record.
Information about possible misconduct may be shared with another journal, institution, funder or responsible body only where reasonably necessary, proportionate and supported by an appropriate basis. The information shared should be limited to what is needed to assess the concern.
Transfer of manuscripts or peer-review information between SDEWES journals must follow the applicable transfer procedure and privacy requirements. Reviewer identities or reports must not be transferred or reused contrary to the reviewer’s information, journal policy or applicable law.
Detailed peer-review procedures and reviewer obligations are governed by Peer Review Policy. Misuse of confidential information or manipulation of peer review may also be assessed under Publishing Ethics.
Recipients, Service Providers and International Transfers
SDEWES Centre may disclose personal data only where necessary for an authorised journal purpose.
Recipients may include:
- editors, reviewers and authorised journal staff;
- manuscript-submission, hosting, production and preservation providers;
- DOI-registration, indexing, abstracting and discovery services;
- payment and accounting providers;
- institutions, funders, repositories, data owners or other publishers where necessary to assess a legitimate concern;
- professional, technical or legal advisers; and
- public authorities where disclosure is required by law.
Public article metadata may include author names, affiliations, ORCID iDs, article title, abstract, keywords, funding information, declarations, citation information and related publication metadata.
Service providers processing personal data on behalf of SDEWES Centre must be subject to appropriate contractual, confidentiality, security and data-protection requirements.
Personal data must not be disclosed to institutions, funders, employers or other external parties merely because they request it. Disclosure must have a legitimate purpose and appropriate basis and must be limited to the information reasonably necessary.
Where personal data are transferred outside the European Economic Area, SDEWES Centre must use an applicable transfer mechanism or safeguard, such as an adequacy decision, approved contractual safeguards or another lawful mechanism.
Information about relevant categories of recipients and international transfers must be made available to individuals as required by applicable law.
Security, External Tools and Generative AI
SDEWES Centre must apply appropriate organisational and technical measures proportionate to the nature, context and risks of journal data processing.
Measures may include:
- role-based access controls;
- secure passwords and authentication;
- encrypted transfer and storage where appropriate;
- access logging and account management;
- secure backups and preservation;
- confidentiality requirements for editors, reviewers, staff and service providers;
- controlled deletion or archiving; and
- procedures for identifying and responding to security incidents.
Personal data and confidential records must not be copied, downloaded, exported or stored outside authorised systems unless necessary and adequately protected.
Authors, reviewers, editors and staff must not upload confidential manuscripts, reviewer reports, reviewer identities, editorial correspondence, personal data or unpublished research data to public or non-approved generative-AI tools.
External tools used for translation, language editing, plagiarism checking, image assessment, file conversion, communication or administration must be assessed for confidentiality, data use, retention, security, copyright and international-transfer implications.
Use of generative AI and AI-assisted technologies must comply with Generative AI Policy. Use of an external tool does not transfer responsibility for confidentiality, lawful processing or accuracy to the tool provider.
Data protection by design and by default must be integrated into the selection and configuration of new systems, workflows, plugins and service providers and into material changes to existing journal processes. By default, only the personal data necessary for each identified purpose should be processed, accessible and retained.
Data Retention and Preservation of the Scholarly Record
Personal data and editorial records must be retained only for as long as necessary for the purpose for which they were processed and for applicable legal, contractual, accounting, ethical, archival, security or scholarly-record requirements.
SDEWES Centre should maintain category-specific retention rules or documented retention criteria for:
- active and rejected submissions;
- published articles and article metadata;
- reviewer profiles and peer-review records;
- editorial correspondence and decision records;
- author declarations and publishing agreements;
- appeals, complaints and privacy requests;
- publication-ethics and research-integrity cases;
- correction, retraction and withdrawal records;
- invoicing and financial records; and
- system and security logs.
Published author information, article metadata, notices and records necessary to explain the publication history may need to be retained indefinitely as part of the scholarly record.
Records concerning rejected or withdrawn submissions should not be retained indefinitely without a documented editorial, legal, integrity or security reason.
When information is no longer required, it should be securely deleted, irreversibly anonymised or placed in an appropriately restricted archive.
Retention must not be extended merely because storage is convenient.
SDEWES Centre must maintain a documented retention schedule specifying the applicable retention period or more detailed retention criteria for each principal category of journal records. The applicable periods or criteria must be communicated through this policy, the relevant journal privacy notice, the submission system or another notice provided at the point of collection. The retention schedule must be reviewed periodically and applied consistently
Data Subject Rights and Privacy Requests
Individuals may contact the privacy contact identified in Section 3 to ask how their personal data are processed or to exercise rights available under applicable law.
Depending on the circumstances, rights may include:
- the right to be informed;
- access to personal data;
- correction of inaccurate or incomplete data;
- erasure;
- restriction of processing;
- objection to certain processing;
- data portability;
- withdrawal of consent where processing is based on consent; and
- rights relating to decisions based solely on automated processing, including profiling, where applicable.
SDEWES Centre may request information reasonably necessary to verify the requester’s identity or authority and to identify the relevant journal record.
Requests should be acknowledged promptly and handled within the timeframe required by applicable law. Where the GDPR applies, a substantive response is normally required within one month, subject to permitted extensions for complex or multiple requests.
Where necessary, because of the complexity or number of requests, the response period may be extended by up to two further months. The requester must be informed of the extension and the reasons for it within one month of receipt of the request. Requests are normally handled free of charge. A reasonable fee may be charged, or action may be refused, only where a request is manifestly unfounded or excessive, particularly because of its repetitive character.
These rights are not absolute. A request may be limited where necessary to:
- protect reviewer or editorial confidentiality;
- preserve an accurate scholarly record;
- protect the rights and freedoms of another person;
- comply with legal, financial or contractual obligations;
- establish, exercise or defend legal claims;
- retain evidence needed for a publication-ethics assessment; or
- maintain records required to explain an editorial or post-publication decision.
Where a request is declined or limited, the response should explain the principal reason, subject to confidentiality and legal restrictions.
Individuals may lodge a complaint with the competent supervisory authority. For SDEWES Centre in Croatia, the supervisory authority is the Croatian Personal Data Protection Agency (AZOP).
The Privacy Request Response Template listed in Appendix B should be used to record and communicate the handling of privacy requests.
Privacy Concerns, Personal Data Breaches and Corrective Action
A personal-data breach is a breach of security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorised disclosure of or access to, personal data. A wider privacy concern may also involve inappropriate collection, use, retention, sharing or publication of personal data without a security breach.
A person who identifies a potential privacy or confidentiality incident must report it promptly through the designated privacy route and must not attempt to conceal or resolve a serious incident informally.
SDEWES Centre should:
- record the date, source and nature of the concern;
- take immediate steps to contain or limit further exposure;
- preserve relevant evidence and system information;
- determine what personal data and individuals may be affected;
- assess the likelihood and severity of harm;
- document the assessment and decisions;
- correct or restrict affected records where appropriate;
- notify service providers or other controllers where necessary; and
- review whether procedural or technical improvements are required.
Where legally required, SDEWES Centre must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a notifiable personal-data breach. Where a breach is likely to create a high risk to affected individuals, those individuals must also be informed unless an applicable exception applies.
All personal-data breaches must be documented, including the known facts, affected data and individuals, likely effects, risk assessment, decisions and remedial action, whether or not notification is required. Where notification to the supervisory authority is made after the applicable 72-hour period, the reasons for the delay must be documented and provided as required.
Not every confidentiality concern constitutes a legally notifiable personal-data breach. The privacy handler must distinguish:
- a journal-policy confidentiality concern;
- a research-participant or publication-consent issue;
- an information-security incident;
- a personal-data breach; and
- a concern affecting the published scholarly record.
Where personal data in a manuscript, article, supplementary file or dataset require correction, restriction, replacement, removal, expression of concern or retraction, the action must be assessed under Corrections, Retractions and Withdrawals.
Research participant, consent and identifiable information concerns must also be assessed under Research Ethics. Data-sharing and repository concerns must also be assessed under Research Data and Transparency. Peer-review confidentiality and reviewer-identity concerns must also be assessed under Peer Review Policy.
Suspected deliberate misuse, concealment, retaliation or unethical disclosure of confidential information may also be assessed under Publishing Ethics.
Where a responsible editor or privacy handler has a relevant competing interest, independent handling must be arranged under Editorial Independence and Competing Interests and Funding Disclosure.
Formal complaints about the journal’s handling of a privacy matter may be submitted under Editorial Decision Appeals and Complaints.
The Privacy Concern and Data Protection Incident Checklist listed in Appendix B should be used to document triage, containment, risk assessment, notifications, corrective action and closure.
Policy Review and Updates
SDEWES Centre may review and update this policy periodically to reflect developments in privacy, data protection, publication ethics, peer review, research ethics, research data, artificial intelligence, open science, journal platforms, legal requirements and international standards.
Updated policies apply from the date of publication on the SDEWES Journals Policies website unless otherwise stated.
Appendix A. Related COPE and International Guidance
COPE Ethical Guidelines for Peer Reviewers
Provides principles concerning confidentiality of submitted manuscripts, reviewer identities, review materials, unpublished information and appropriate conduct during peer review.
COPE Council. COPE Guidelines: Sharing of information among editors-in-chief regarding possible misconduct
Provides guidance on when information concerning possible misconduct may be shared between journals and emphasises necessity, proportionality and confidentiality.
Regulation (EU) 2016/679 – General Data Protection Regulation
Provides the legal framework for the processing of personal data, controller and processor responsibilities, individual rights, security, breach notification and international transfers.
European Commission. Data protection explained
Provides an accessible explanation of personal data, processing, controller and processor roles, processing principles and individual rights.
European Commission. What information must be given to individuals whose data is collected?
Provides guidance on privacy-transparency information, including controller identity, purposes, lawful bases, retention, recipients, international transfers, rights and supervisory-authority complaints.
European Commission. Rules on international data transfers of personal data
Provides guidance on safeguards required when personal data are transferred outside the European Economic Area.
European Data Protection Board. Guidelines 9/2022 on personal data breach notification under GDPR
Provides guidance on identifying personal-data breaches, determining when a controller becomes aware of a breach, assessing risk and deciding whether supervisory-authority or individual notification is required.
Croatian Personal Data Protection Agency. Personal data protection – data subject rights
Provides information on exercising data-protection rights and the role of the Croatian supervisory authority.
Appendix B. Practical Forms, Statements and Checklists
The documents below provide practical support for identifying and reporting personal or identifiable information, protecting confidentiality in peer review, assessing privacy concerns and personal-data incidents, and responding to privacy enquiries or data-subject requests.
Privacy and Personal Data Statement Template
Author and journal guidance template – Used to prepare manuscript or article statements where personal data, identifiable information, participant quotations, photographs, recordings, survey or interview data, household or location data, or other privacy-relevant information are included, anonymised, restricted or excluded from publication.
Personal Data and Identifiable Information Declaration Form
Required author submission form, where applicable – Used to declare whether manuscripts, supplementary materials, research data, figures, images or related files contain personal, identifiable, confidential or privacy-restricted information; the applicable approval, consent or permission; safeguards applied; and any restrictions on publication or data availability. The corresponding author coordinates submission after confirming the relevant information with all authors.
Peer Review Confidentiality and Privacy Checklist
Internal editor, reviewer and editorial-office checklist – Used to support confidential and secure handling of manuscripts, reviewer identities, review reports, editorial correspondence, downloaded files, external tools and generative AI during editorial assessment and peer review.
Privacy Concern and Data Protection Incident Checklist
Internal editor and publisher checklist – Used by the privacy handler, responsible editor and, where appropriate, SDEWES Centre to record, contain and assess a privacy concern, confidentiality breach, unauthorised disclosure, personal-data exposure, reviewer-identity disclosure or security incident and to determine whether corrective action or legal notification is required.
Privacy Request Response Template
Editorial and publisher response template – Used by the privacy handler or SDEWES Centre to acknowledge, verify, assess and respond to requests for information, access, correction, restriction, erasure, objection, portability or other privacy rights, including reasons for any limitation and the applicable complaint route.