Cross-Border Magazine (CBM)
Version: April 2026
Cross-Border Magazine ("Cross-Border Magazine", "CBM", "we", "us" or "our") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store and otherwise process your personal data when you visit www.cross-border-magazine.com (the "Website"), download our magazine, subscribe to our newsletter, or contact us through the Website.
This policy has been updated to reflect the requirements of Regulation (EU) 2016/679 (the "GDPR") and the supervisory guidance issued by the European Data Protection Board (EDPB) up to and including the 2026 coordinated enforcement action on transparency obligations under Articles 12-14 GDPR. It also takes into account the European Commission's Digital Omnibus proposals of November 2025, which may further amend the GDPR; we will update this policy if and when those proposals enter into force.
The Website is not intended for children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
The controller responsible for your personal data is:
We have appointed a data privacy manager who oversees compliance with this privacy policy. If you have any questions, complaints or requests in relation to this policy or the processing of your personal data, please contact us using the details above.
The categories of personal data we process, the purposes for which we use them, and the legal basis under Article 6 GDPR on which we rely, are summarised in the table below.
| Processing activity | Personal data | Purpose | Legal basis (Art. 6 GDPR) |
| Magazine download | Email address (mandatory); first name, company, country (optional, if requested in the form) | To deliver the magazine, send the requested issue and confirm the download. We may follow up once with a related issue or relevant content. | Performance of a contract / pre-contractual measures (Art. 6(1)(b)). |
| Newsletter subscription | Email address; subscription preferences; technical metadata (open/click events). | To send you our newsletter and related editorial content you have signed up for. | Consent (Art. 6(1)(a)). You can withdraw consent at any time via the unsubscribe link in every email. |
| Contact form / direct enquiries | Name, email address, company (if provided), the content of your message, and any attachments. | To respond to your question, request, partnership enquiry or complaint. | Performance of pre-contractual measures (Art. 6(1)(b)) and our legitimate interest in answering enquiries (Art. 6(1)(f)). |
| Website analytics | IP address (truncated where supported), device and browser information, referrer, pages viewed, time on page, approximate location. | To measure and improve Website performance, content quality and audience engagement, and to detect and prevent fraud or misuse. | Consent for non-essential analytics cookies (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive). Legitimate interest (Art. 6(1)(f)) for strictly necessary technical logs. |
| Cookie consent management | Your cookie choices, timestamp, version of the consent banner. | To demonstrate compliance with consent requirements and to honour your preferences. | Legal obligation (Art. 6(1)(c)). |
| Security and fraud prevention | Server logs, IP address, request metadata. | To protect the Website and its users against attacks, abuse and unauthorised access. | Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) where applicable. |
We do not process special categories of personal data (e.g. health, religion, ethnic origin, sexual orientation, biometric or genetic data) and we do not process personal data relating to criminal convictions or offences. We do not engage in solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
We share personal data only with the categories of recipients set out below, and only to the extent necessary for the purposes described in section 3:
We do not sell your personal data to third parties, and we do not share it with third parties for their own marketing purposes without your explicit prior consent.
Some of our service providers are established outside the European Economic Area (EEA), including in the United States. When we transfer personal data outside the EEA, we ensure an adequate level of protection by relying on one of the transfer mechanisms recognised under Chapter V of the GDPR, in particular:
You can request a copy of the safeguards in place by contacting us using the details in section 2.
We retain your personal data only for as long as necessary for the purposes for which it was collected, including any legal, accounting or reporting requirements. The retention periods we apply are, as a general rule:
We may retain anonymised data, which can no longer be associated with you, for statistical and editorial purposes for an indefinite period.
The Website uses cookies and similar technologies to function correctly, to remember your preferences and, with your consent, to measure how the Website is used and to improve our content.
Strictly necessary cookies (for example for session management, security and to remember your cookie choices) are placed without your consent, on the basis of Article 5(3) of the ePrivacy Directive.
Analytics, functional and marketing cookies, including Google Analytics and any social media or remarketing pixels, are placed only after you have given your specific, freely given, informed and unambiguous consent through our cookie banner. Refusing or withdrawing consent is as easy as giving it: you can do so at any time via the cookie settings link in the footer of the Website. The "Reject all" option in the banner is presented with equal prominence to the "Accept all" option, in line with EDPB guidance.
A detailed list of the cookies we use, their purpose, provider and retention period is available in our separate Cookie Policy at https://cross-border-magazine.com/cookie-policy/.
We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful loss, destruction, alteration, unauthorised disclosure or access, in line with Article 32 GDPR. These include encryption in transit (TLS), access controls based on the principle of least privilege, secure hosting in EU-located data centres where reasonably possible, logging and monitoring, regular back-ups, vendor due diligence, and staff awareness training.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we will also inform you without undue delay (Article 34 GDPR).
Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before fulfilling your request, in order to protect your data. We will respond to your request without undue delay and in any event within one month of receipt, although this period may be extended by a further two months where necessary, taking into account the complexity and number of requests, in which case we will inform you within one month of receipt.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for the controller is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), https://autoriteitpersoonsgegevens.nl. You may alternatively contact the supervisory authority of your usual place of residence or place of the alleged infringement.
We will only send you marketing emails (such as our newsletter or related editorial offers) on the basis of your prior consent or, where permitted, on the basis of an existing customer relationship for similar products and services in line with Article 13(3) of the ePrivacy Directive ("soft opt-in") and Dutch implementing law.
Every marketing email contains a clearly visible unsubscribe link. You can also opt out at any time by contacting us at [email protected]. Opting out of marketing communications does not affect transactional communications, such as a confirmation that you have downloaded the magazine.
The Website may contain links to third-party websites, plug-ins, advertisements and applications (for example to LinkedIn, X/Twitter, YouTube or partner websites). Clicking on these links or enabling these connections may allow third parties to collect or share data about you. We do not control these third-party websites and we are not responsible for their privacy or cookie practices. We encourage you to read the privacy policy of every website you visit.
We keep this privacy policy under regular review. Any updates will be published on this page with an updated version date at the top. Where the changes are material, we will notify you by a notice on the Website or, where appropriate, by email. We encourage you to review this policy periodically.
If you have any questions about this privacy policy, our privacy practices, or you wish to exercise any of your rights, please contact us:
By continuing to use the site, you agree to the use of cookies. more information
The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.