Privacy Policy


GP Strategies Government Solutions, Inc.  

Privacy Notice 



Effective Date: September 30, 2026
 

Personal Privacy Data Handling Information 

At GP Strategies Government Solutions, Inc., (“GP Gov”) our Data Privacy Policy (“Policy”) is a commitment to protecting the privacy data of employees, clients, business partners and web and social media site visitors.  The Policy guides our privacy data handling practices as described here in this Frequently Asked Questions (FAQ) format.  GP Gov makes every reasonable effort to protect the privacy of data collected, if any, when individuals visit our sites. However, GP Gov does not currently collect personal data via this site. 

GP Gov’s policy and practice is also guided by U.S. state and federal laws. For example, U.S. state and federal laws are our administrative thresholds, but we do adhere to more strict laws when applicable, such as the General Data Protection Regulation (GDPR) of the European Union (EU). GP Gov does not buy or sell consumer privacy data as defined in the CCPA and therefore while abiding by the law, we are not subject to all provisions of the CCPA.  For example, for CCPA compliance case, we are not required to have a separate landing page describing how GP Gov buys and sells consumer privacy data.  Therefore, there are limited needs for opt-out, opt-in and other CCPA specific disclosures. 

Children’s Privacy 

If you are under 18 years of age, we request you obtain parental consent before posting a comment on our blogs and sites.  Our websites do not publish content for or collect data that is directed at children. 

Contacting GP Gov and more Information about Data Privacy Practices 

Contact information is provided at the end of this page.   

As a GP Gov web site visitor, what information does GP Gov collect? 

GP Gov does not collect personal data via this website.  

As a GP Gov site visitor, does the “GDPR”, “CCPA”, and other similar data privacy requirements apply to my data? 

Companies within the EU and California, or who are externally located controllers and processors of the personal privacy data of EU and California residents in the context of collecting privacy data while soliciting and providing goods or services, must comply with the GDPR and CCPA.  GP Gov does NOT collect personal data, including business contact information, through our website. However, we do provide links to contact us through email and third-party social media providers which may separately collect or process privacy data for purposes of providing additional services. 

GP Gov may process personal information in the United States or other jurisdictions where GP Gov or its affiliates and authorized service providers operate. This may include situations in which personal information is shared among GP Gov affiliates or business partners to respond to inquiries, provide requested services, or support business operations.   

GP Gov has assessed its obligations under the GDPR and other applicable laws, including the CCPA, based in part on (1) the types of visitor data collected through this website and (2) the legal bases relied upon to protect that data.  We will exercise data privacy stewardship on all of our sites, where applicable. 

How will my personal information be used and shared by GP Gov for internal management of the sites? 

GP Gov does not collect visitors’ personal information via this website. 

Where does GP Gov store my privacy information? 

GP Gov stores personal information in secure systems operated by GP Gov and its authorized service providers. These systems may include FedRAMP authorized cloud environments, such as Microsoft GCC High and AWS GovCloud services, as well as various GP Gov owned or licensed business platforms used to support company operations. Access to personal information is restricted to authorized personnel with a legitimate business need, and GP Gov maintains safeguards designed to protect the confidentiality of personal information. Notwithstanding, GP Gov does not collect personal information via this website. 

What constitutes personal privacy data? 

Personal privacy data is information related to a natural person (called a ‘data subject’ by the GDPR, a “consumer” in the CCPA and as otherwise differentiated by other laws) that can be used to directly or indirectly identify the person when not encrypted and used individually or in combinations to create a profile. 

Personal privacy data is a very broad range of personal information and can be any information item that might be used to create a profile, to include basic business contact information of name, business address, and business phone and business title or business job.  Further personal privacy information would also be: an identifiable photo; identifiable voice recordings; fingerprints; biometric data; psychological profile, a personal email address, home phone number, home address; numbered identifiers – bank account, credit information and credit card, passport, country identification, driver’s license, pension and social security numbers; family member information; medical information; political opinions; sex, sexual preferences; computer IP address; data on children; travel profiles; trade union membership; criminal records.  Some countries differentiate some of these listed items as Sensitive Personal Identification Information (SPII). 

What is the difference between a data processor and a data controller? 

  • A controller is the entity that determines the purposes, conditions and means of the processing of personal data. A controller can be a processor.  A web site owner is a controller. 
  • A data processor is an entity which processes personal data, with instructions and IT security framework, on behalf of the controller. 
  • GP Gov may act as either a data controller or a data processor, depending on the nature of our business activities. 


Is GP Gov a data processor or data controller in regard to my personal data?
 

GP Gov acts as a data controller and in some cases is also a processor (or sub-processor) for personal data provided to GP Gov through our customers, by individuals and other third parties such as business partners. 

If a data subject (consumer) provides their personal data directly to GP Gov (such as a site visitor, a forum or conference attendee, a site browser, etc.), GP Gov acts as the data controller for that personal data.  Note, if GP Gov also processes that personal data in some fashion, GP Gov also qualifies as a data processor in regard to that personal data. 

Is GP Gov organized to manage the data processor obligations imposed by applicable data privacy laws and regulations? 

GP Gov has appointed Data Protection Officers (DPOs) to comply with applicable data privacy laws.   

GP Gov is committed to protecting the privacy and security of personal information entrusted to us by our website visitors, employees, customers, and business partners. We maintain administrative, technical, and physical safeguards designed to protect personal information, support compliance with applicable privacy and data protection requirements, and ensure that information security remains aligned with GP Gov’s business objectives and operational needs.  

When does GP Gov delete client data?  

GP Gov retains personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal, regulatory, contractual, and business requirements, resolve disputes, and enforce our agreements. Personal information is retained and securely deleted in accordance with GP Gov’s records retention and disposal practices. Retention periods vary depending on the type of information and applicable requirements and may range from a short period to several years. For additional information regarding our data retention practices, please contact us at dataprivacy@gpgov.us.  

What privacy rights do I have regarding my personal information? 

Depending on your location and applicable law, you may have certain rights regarding your personal information, including the right to request access to, correction of, deletion of, or restriction of the processing of your personal information. At this time, GP Gov does not collect personal information about visitors to this website.  Please note that GP Gov may retain certain information where necessary to comply with legal, regulatory, contractual, security, or legitimate business obligations. 

What are GP Gov site cookie practices? 

At this time, GP Gov does not use cookies or similar tracking technologies to collect information about visitors to this website. If GP Gov implements cookies or similar technologies in the future, this Policy will be updated to describe the technologies used, the information collected, and any choices available to website visitors regarding such technologies. 

How do you use Social Media Widgets? 

GP Gov websites can include links to third-party social media sites, such as LinkedIn.  These third-party sites may collect your IP address and/or collect which page on our site you clicked the social media link or button from and may set a cookie to enable such feature to function properly.   Your interactions with these features are governed by the privacy policy of the social media company providing it. 

How do you use Contact Forms and Email Links? 

Should you choose to contact us using an email link, the data you supply will be stored in our secure storage system or may be passed on to be processed by a third-party data processor(s) or may be sent to an internal affiliated subsidiary/organization for response.  We do retain information from data requests in our secure storage system. We do not sell personal information. 

How do you use information we provide to you? 

GP Gov seeks to collect only the personal information reasonably necessary to respond to inquiries, provide requested information or services, support recruiting and employment related activities, and meet legal, regulatory and contractual obligations. Personal information you voluntarily provide may include your name, email address, telephone number, company, job title, and any information you choose to include in communications with us. However, GP Gov does not collect personal information via this website. 

California Consumer Privacy Act (CCPA) 

What is considered “personal information” under the CCPA? 

Under California law, “Personal information” generally means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with any particular individual.” Examples may include identifiers such as a name, email address, postal address, telephone number, employment related information, or other information that can reasonably be linked to an individual.  

As a California citizen does GP Gov sell my data? 

No. GP Gov does not sell or buy Personal Information and has no intent to start.  GP Gov does not currently engage in activities that constitute the sale of personal information under applicable privacy laws.  

Does GP Gov honor the “rights” of consumers in the CCPA? 

By our Privacy Policy, GP Gov does honor the rights of California consumers as specified in the CCPA and the rights of citizens of other U.S. states where they may be more stringent. 

How will GP Gov notify me of changes to this Privacy Notice? 

GP Gov may update this Policy from time to time to reflect changes in our business practices, legal obligations, or website functionality. Any updates will be posted on this page and will become effective as of the revised Effective Date listed at the top of this Policy. 

Additional Information 

In compliance with the CCPA, among other U.S. state and federal laws (and the GDPR, where applicable), GP Gov commits to responding to inquiries about our collection or use of your personal information in accordance with applicable legal requirements. 

Individuals with inquiries regarding our Data Privacy Policy should contact us at: 

GP Strategies Government Solutions, Inc. 
9861 Broken Land Parkway, Suite 250 
Columbia, MD 21046 

Attn: Data Privacy Officer 

Or dataprivacy@gpgov.us