mediator@mycdic.org
Official Youth Mediation Platform

Youth Mediation Programme within the MYCDIC Institutional Ecosystem

Privacy

Case data should be collected because it is necessary, not because it is available.

Youth Mediator separates general website interaction from case records and avoids unnecessary geolocation or invasive visitor profiling.

This Privacy Notice applies to the public Youth Mediator website, case intake, case tracking, Case Center, process complaints, mediator network applications, institutional enquiries and related operational records. Youth Mediator operates within the MYCDIC institutional ecosystem. Data-protection rights and obligations may vary according to the applicable law and the circumstances of a particular case.

Contact: mediator@mycdic.orgVersion: August 2026

1. Scope and responsibility

Youth Mediator processes information only for defined programme and case-management purposes. The programme is not designed as a public repository of disputes. Detailed case content is intended to remain within protected operational records and is not displayed through public case tracking.

Important: Do not send full confidential evidence through ordinary email unless specifically requested through an approved secure route. Use the case intake or authenticated Case Center for case material.

2. Information we may collect

Depending on the service used, we may collect:

  • Identity and contact information, such as name, email, phone, country, city and preferred language.
  • Organization, role or capacity information where a person acts for an association, company, institution, MYCDIC structure or other body.
  • Case information, including parties, chronology, communications, previous resolution attempts, requested outcomes, deadlines, safeguarding information and related proceedings.
  • Supporting documents and evidence voluntarily uploaded to the case record.
  • MDM verification information necessary to confirm whether an active card is eligible for operational priority. Raw card codes are not intended to become part of the public case record.
  • Case-access approvals, staff actions, audit events, authentication events and security logs necessary to protect the platform and establish accountability.
  • Complaint, feedback, network application and institutional enquiry information when those channels are used.
  • Email-verification records, electronic authorization records, typed signature names, drawn-signature files and limited technical integrity records used to evidence consent, reduce false submissions and protect the case workflow.

Please avoid providing irrelevant personal information about third parties. Where possible, submit only what is reasonably necessary to understand the matter.

3. Why information is used

Information may be used to:

  • verify identity, case references and secure access;
  • assess eligibility, urgency, safeguarding concerns and conflicts of interest;
  • understand the case, decide an appropriate route and communicate with the applicant;
  • assign authorized personnel and manage mediation, facilitation, referral, resolution and follow-up;
  • manage MDM priority verification where requested by the applicant;
  • investigate process complaints, quality concerns or suspected misuse;
  • maintain security, auditability, service integrity, prevent duplicate or abusive submissions, verify email ownership, and preserve records needed to evidence applicant authorizations and declarations;
  • comply with applicable legal obligations or respond to a valid request from a competent authority where required.

Where applicable law requires a specific legal basis for processing, that basis may include consent, steps requested before providing a service, legitimate operational interests, protection of vital interests, legal obligations, or another basis available under applicable data-protection law. The basis can depend on the type of information and the circumstances of the matter.

4. Internal access and external sharing

Purpose-limited internal access

Access is role-based. Staff members without approved sensitive access receive a masked operational view. Where the system requires additional approval, access can be granted for a limited period and recorded in the audit log.

External disclosure

Case information is not sold and is not made available to advertisers. Information may be disclosed only where reasonably necessary for the case process, an authorized institutional route, a service provider acting under appropriate safeguards, protection of a person, compliance with law, or a valid request from a competent authority. Youth Mediator may decline to disclose information where disclosure is not appropriate or permitted.

Submitting a case does not automatically authorize Youth Mediator to contact every person named in the submission. Contact decisions remain subject to eligibility, safety, conflict, legal and operational review.

5. MDM card verification and priority

An applicant may voluntarily enter an MDM card code to request verification. When a valid active card is confirmed, the case receives MDM operational priority. Priority affects queue ordering and does not change eligibility, neutrality, confidentiality standards, access controls or the merits of the case.

The system is designed to store a verification snapshot or masked card reference rather than exposing the raw card code in the case record. Information returned from the MDM registry should be limited to what is necessary for verification and prefill.

6. Retention and deletion

Records are kept only for as long as reasonably necessary for case administration, complaint handling, security, audit, governance, legal obligations and the defence or establishment of legitimate claims. Different categories of information may have different retention periods.

Deletion requests may be limited where records must be retained for security, legal, safeguarding, audit, dispute-resolution or evidentiary reasons. When information is no longer required, it should be deleted, anonymized or placed beyond routine operational use in accordance with the applicable retention rules.

7. Security and confidentiality controls

Technical and organizational measures are designed to reduce unauthorized access, disclosure, alteration or loss. These measures include private file storage, authentication controls, OTP access for Case Center, password hashing for staff accounts, CSRF protection, rate limiting, purpose-limited case access, audit logging and separation between public tracking and confidential case content.

No online system can guarantee absolute security. Users are responsible for protecting their email account, OTP codes, case references and devices, and should notify Youth Mediator promptly if they believe access information has been compromised.

8. Cookies and preference controls

Youth Mediator uses essential cookies that are necessary for security, protected forms, session continuity, case access and remembering privacy choices. Essential cookies cannot be disabled through the website because parts of the platform would not operate safely without them.

Optional analytics cookies are disabled by default and are activated only after the user gives consent through the cookie preference panel. Where analytics are enabled, they should be configured to collect proportionate aggregate usage information and should not be used to expose confidential case content, form narratives, uploaded evidence or Case Center information.

You can change your optional cookie choice at any time by selecting Cookie preferences in the website footer. A preference cookie is stored for a limited period so the website can remember the choice. Clearing browser cookies may cause the preference banner to appear again.

Case confidentiality: cookie consent does not authorize Youth Mediator to place confidential case content into analytics tools or advertising systems. The platform does not use advertising cookies.

9. Email verification, anti-abuse checks and electronic signatures

Case intake and selected Secretariat correspondence may require a one-time email code. The platform may also use rate limits, hidden anti-bot fields, minimum form-completion time, duplicate-submission fingerprints and other proportionate integrity checks to reduce spam, impersonation and automated abuse.

Where the case form requests an electronic authorization, Youth Mediator may retain the typed legal name, timestamp, drawn signature file, declaration version and limited hashed technical information connected to the signing event. These records are used to evidence consent and authorization within the platform record. A platform signature does not by itself create a power of attorney, legal representation or any authority beyond the scope stated in the authorization.

Technical integrity values are designed to support security and audit rather than public identification. They are not displayed in public case tracking.

10. Access, correction and other data rights

Subject to applicable law and legitimate restrictions, an individual may be able to request access to personal information, correction of inaccurate information, deletion, restriction, objection, portability or withdrawal of consent where consent is the relevant basis. Identity verification may be required before a request is processed.

Rights are not absolute. A request may be limited where disclosure would affect another person's rights, confidentiality of another case party, safeguarding, legal obligations, security, internal privileged material, or the integrity of an active dispute-resolution process.

Where applicable law provides a right to complain to a data-protection authority, that right remains available independently of the Youth Mediator complaint process.

11. Minors, vulnerable persons and sensitive information

Cases involving minors or vulnerable persons require additional care. The programme may request guardian, representative or safeguarding information, limit direct contact, refuse a proposed route, or refer a matter where another competent service is more appropriate. Applicants should identify relevant safeguarding concerns in the intake rather than withholding them from the eligibility review.

12. Privacy contact and updates

Privacy questions and data-rights requests can be sent to mediator@mycdic.org. For an active case, include the case reference but do not place detailed confidential evidence in the email subject line.

This notice may be updated when the service, legal requirements, hosting arrangements or case-management processes change. The version published on this page is the current public notice.

Case guidance

Choose the right route before sharing sensitive information.

Check eligibility, open a secure case, or contact the Secretariat for general institutional correspondence.