Privacy Notice concerning our
Carillon PKI
Data Processing Activity

(Boeing Data Processing Activity ID Number: 7670)

The Boeing Company and its group of companies seek to maintain the privacy, accuracy, and confidentiality of personal data that we collect and use.

We have established privacy and security measures both internally and (where applicable) in our relations with third parties to safeguard personal information in our data processing activities.

We hope that the following questions and answers addressing privacy issues related to our "Carillon PKI" data processing activity are as concise, transparent, and intelligible as possible.  We welcome your suggestions for improvement of any of the content presented below.

 

Question

Answer

What corporate entities determine the purposes and means of processing of the personal data in this activity?

(These are the "Controllers" under the EU General Data Protection Regulation and other applicable laws.)

Carillon Information Security Inc. and The Boeing Company
Who represents these entities with regard to privacy issues? The Boeing Global Privacy Office is responsible for privacy issues related to this activity.  Contact information for the Boeing Global Privacy Office appears below this table.

(The Boeing Global Privacy Office will route issues to the appropriate Data Protection Officer where applicable.)

What other entity may process this personal data on behalf of Carillon Information Security Inc. and The Boeing Company (including its fully integrated subsidiaries around the globe)?

(This is the "Processor" under the EU General Data Protection Regulation and other applicable laws.)

Not Applicable - there is no other processor
Whose personal data is intended to be processed by this activity? This activity is intended to process the personal information of:
  • Employees
  • Customers
  • Non-Boeing Individuals with BEMS IDs (consultants, purchased services, suppliers, etc.)

It is not intended to process the personal information of individuals in other categories.

What categories of personal data are processed by this activity? Highly-Sensitive Personally Identifiable Information:

  • Passport Number
  • Other National ID Number
  • Other Government ID Number
  • Driver's License Number
  • Full Date of Birth

Sensitive Personally Identifiable Information:

  • Citizenship
  • Gender or Gender Identity

What are the purposes of processing personal data in this activity? The personal information will be used to collect users identity proofing per Aviation Industry Standard Digital Information Security ATA spec 42 (reference Appendix 4, section 3.2.3.2) requirement.
What is the legal basis for processing personal data in this activity? Processing is necessary for purposes of legitimate interests pursued by Carillon Information Security Inc. and The Boeing Company: 
  • Complying with legal, law enforcement, court and regulatory bodies' requirements

Is the data subject (the person to whom the data relates) required to provide personal information for this processing activity, and what would be the possible consequences of failing to do so? Provision of personal information for this processing activity is not required.  Failure to provide personal information could result in signing software failure because it could not provided a credential for signing software.
Who are the recipients of the personal data in this activity? The recipients of personal information in this activity are the PKI Operators at Carillon Information Security Inc.
In what countries will the personal data be processed? The personal information will be used by business processes based in Canada.

The personal information will only be stored in Canada.

How long will the personal data be retained by this activity? The data will be retained for 10y 6mo or as determined by relevant regulation.
What specific privacy rights may the individuals whose personal data is processed by this activity have, and how can they be exercised? Anyone may have the right to lodge a complaint with a supervisory authority (https://boeing.com/privacy/authorities.html).

Depending upon the jurisdiction(s) in which you live or work, you may have the following additional rights:

  • to request access to and rectification or erasure of personal data or restriction of processing
  • to object to processing
  • to data portability
  • to not be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly affects you

If not offered as a self-service capability within the "Carillon PKI" data processing activity or otherwise addressed in another answer above, any applicable privacy rights may be exercised using https://boeing.com/privacy/rightsexerciseportal.

If you have questions or concerns about privacy issues associated with our "Carillon PKI" data processing activity, you may contact the Boeing Global Privacy Office by:

Boeing Global Privacy Office

Email

Telephone

Mail

globalprivacy@boeing.com

+1-206-544-2406
+1-877-544-2407

Boeing Global Privacy Office
Mail Code 11-503
7755 East Marginal Way S.
Seattle, WA 98108

 

You may use https://boeing.com/privacy/rightsexerciseportal to exercise any applicable privacy rights for which a self-service capability has not been offered within the "Carillon PKI" data processing activity or for which other specific instructions do not appear above.

For customers and visitors to our web sites: This notice supplements the Boeing Privacy and Cookie Statement.

For employees, contract labor, retirees, and subsidiary employees: This notice supplements the Boeing Employee Privacy Notice.
 

 


Boeing will periodically review and update the content of this notice at its discretion.
It was last updated 2024-01-12 17:11:37 (UTC).

 

Copyright 2025 The Boeing Company - All Rights Reserved