AECOM Global – Website Cookie Policy L1-009-PL2
1. Purpose and Scope
a. This Policy explains how and why AECOM (collectively, “AECOM” or “the Company”) uses cookies, pixels, tags, SDKs, local storage, session replay, analytics scripts, advertising identifiers, and similar online tracking technologies (collectively, “Cookies and Other Trackers”) on AECOM websites and digital services, and the choices available to users.
b. This Policy applies globally and must be read with AECOM’s Privacy Notice and any applicable just-in-time notice, notice at collection, or cookie banner.
c. For California residents, this Policy is intended to satisfy the California Consumer Privacy Act / California Privacy Act (“CCPA/CPRA”) requirements for notice at collection and opt-out of sale/sharing as applied to online tracking.
d. For Europe / United Kingdom (EU/UK) users, non-essential cookies are used only with consent where required by the ePrivacy Directive, Privacy and Electronic Communications Regulations 2003 (PECR), EU General Data Protection Regulation (GDPR), and UK GDPR. For the purposes of EU GDPR and UK GDPR, the data controller is AECOM, unless a specific notice states otherwise.
e. For residents of other U.S. states with comprehensive privacy laws (including Colorado, Connecticut, Texas, Oregon, and Montana), AECOM honors recognized universal opt-out mechanisms, including the Global Privacy Control (GPC), as valid requests to opt out of targeted advertising, and applies the disclosure and choice framework described in this Policy to those users to the extent required by applicable law.
2. What are Cookies and other Trackers and Similar Technologies
a. A “Cookie” is a small text file that may be stored on, and accessed from, a user’s internet browsing device when they visit certain websites. The other tracking technologies such as JavaScript, local storage, log files, and other mechanisms work similarly to cookies in that they track a user’s website activity to enable the collection of information about how a user utilizes a website (“Usage Information”). A “Web Beacon,” also known as a pixel tag or clear GIF, is a clear graphic image delivered through a web browser or HTML e-mail. The web beacon operates as a tag recording an end user’s visit to a particular web page or viewing of a particular e-mail. It is also often used in conjunction with a web cookie and provided as part of a third-party tracking service. Web beacons provide an ability to produce specific profiles of user behavior in combination with web server logs. Common usage scenarios for web beacons include online ad impression counting, file download monitoring, and ad campaign performance management. Web beacons also can report to the sender about which emails are read by recipients. For the purposes of this Policy, all these tracking technologies are referred to as “cookies.” Cookies set by the AECOM website are known as “first-party cookies.” Cookies set by third parties, such as those who serve content or provide advertising or analytics services on their domains are known as “third-party cookies.”
b. AECOM uses only those cookies that are strictly necessary to operate the website before a user makes a choice. All functional, performance, analytics, session replay, advertising, targeting, remarketing, conversion, social media, and personalization cookies are non-essential and must not be placed, read, synced, or used to disclose Usage Information to third parties until the user has opted in where consent is required, or unless permitted by applicable law after a valid CCPA/CPRA opt-out has been honored. Session cookies expire when the browser is closed; persistent cookies remain on the device for the period stated in the cookie table and may not exceed the disclosed retention period unless legally required.
c. The cookie tables in Section 3.1 must identify each cookie or tracker by name, provider, purpose, category, duration, first-party or third-party status, whether the cookie results in a sale or sharing under CCPA/CPRA, and whether it is blocked by “Reject Non-Essential Cookies,” “Do Not Sell or Share My Personal Information,” and Global Privacy Control (GPC). AECOM must not publish this Policy until the Web/Legal team has confirmed the cookie inventory against live tag-scanning results and removed all placeholder language.
d. Privacy Notice Information collected through Cookies and Other Trackers may constitute “personal information” under the CCPA/CPRA and “personal data” under other privacy laws, including IP address, device identifiers, cookie IDs, advertising IDs, browsing activity, approximate or precise location, inferred interests, form-interaction metadata, session replay data, or other information linked or reasonably linkable to a consumer, household, browser, device, or pseudonymous profile. AECOM’s Privacy Notice provides additional information about categories of personal information, sources, purposes, disclosures, retention, and rights.
3. Advertising and Targeting
a. AECOM may work with third parties, such as advertising networks, analytics providers, tag-management providers, video-hosting providers, social media platforms, measurement services, and other technology partners (“third-party ad/analytics companies”) to measure website use, personalize content, measure campaigns, and deliver or assess advertising on AECOM websites and third-party sites, apps, and services. These activities are non-essential and may constitute a “sale” or “sharing” of personal information under the CCPA/CPRA even when AECOM does not receive money.
b. AECOM and third-party ad/analytics companies may collect or receive IP address, device identifiers, cookie identifiers, advertising IDs, browser and device information, page views, clickstream data, referring URLs, approximate location, interaction events, session replay data where enabled, and inferences. Where these activities are used for cross-context behavioral advertising, retargeting, ad measurement involving third parties, or identity synchronization, AECOM treats them as potential “sharing” or “sale” under the CCPA/CPRA and provides the opt-out methods described in this Policy.
c. Third-Party Analytics: AECOM may use third-party analytics tools, including Google Analytics and Microsoft Clarity, to understand website use and improve services, performance, campaigns, and user experiences. Analytics, heatmap, and session replay tools are non-essential and must be disabled unless the user has accepted the applicable cookie category, except to the extent a tool is configured to collect only aggregated, deidentified, or service-provider/contractor data that does not constitute a sale or sharing under the CCPA/CPRA. AECOM must maintain written service provider, contractor, or third-party terms required by the CCPA regulations for vendors that collect, receive, or process cookie-derived personal information.
i. please review the Google Privacy Policy at https://www.google.com/policies/privacy/partners/; and
ii. a user can also download the Google Analytics Opt-out Browser Add-on to prevent their data from being used by Google Analytics at https://tools.google.com/dlpage/gaoptout.
d. Opt-Out Enforcement Commitment: When a user selects “Reject All,” “Reject Non-Essential Cookies,” “Do Not Sell or Share My Personal Information,” or when AECOM receives a valid GPC or other recognized opt-out preference signal, AECOM will stop placing or reading non-essential cookies, stop disclosing Usage Information for targeted advertising, analytics, session replay, identity synchronization, or other sale/sharing purposes, and communicate the opt-out to downstream tags and partners where technically feasible. AECOM will honor the opt-out as soon as feasibly possible and no later than 15 business days and must not require the user to create an account, provide additional information, or complete verification to process a browser/device-level opt-out.
e. California Invasion of Privacy Act (CIPA) and Wiretap Risk Notice: California residents should be aware that, in addition to CCPA/CPRA rights, the California Invasion of Privacy Act (Cal. Penal Code §§ 630–638) may apply to third-party interception, recording, or disclosure of electronic communications, browsing activity, session replay, chat, or form-interaction data. AECOM does not authorize third-party ad/analytics companies to intercept or access communications, form inputs, or browsing data after a user rejects non-essential cookies or submits a sale/sharing opt-out. Session replay, chat, pixels, and analytics scripts must be configured to mask sensitive fields, exclude passwords/payment fields, and avoid collecting the content of user communications unless a separate, legally sufficient notice and consent mechanism is implemented.
3.1 Categories
This section outlines the specific categories of cookies and trackers AECOM may use. Non-essential cookies are subject to consent where required and, for California residents, must be covered by the CCPA/CPRA notice and opt-out framework described in this Policy.
3.1.1 Essential Cookies
Essential cookies are strictly necessary for the website to function, maintain security, remember privacy choices, load requested pages, balance traffic, prevent fraud, or enable a user-requested transaction. They cannot be switched off through AECOM’s cookie tool. Essential cookies must not be used for advertising, analytics, session replay, cross-context behavioral advertising, profiling, or any purpose unrelated to providing the website or service requested by the user. Essential cookies may still enable AECOM and certain third-party service providers (for example, security, traffic-management, and consent-management vendors) to collect user and device data, including IP addresses, device identifiers, and browsing activity, solely for the essential purposes described above. A user can set their browser to block or alert them about these cookies, but doing so may result in some parts of the AECOM website having reduced functionality.
Table 1. Essential Cookies
|
Cookie Name |
Purpose |
Duration |
Legal Basis |
CCPA Sale/Share & Opt-Out Status |
|
Cc setting |
This is essential for managing user consent preferences and ensuring our compliance with legal requirements. |
6 months |
(Art. 6(1)(f) legitimate interest/PECR strictly necessary exemption). |
Not sold or shared. Always active; cannot be disabled. |
|
Cookie Consent User Identity |
Manages user consent preferences. Essential for maintaining user consent settings. |
6 months |
Strictly Necessary (Art. 6(1)(f) legitimate interest / PECR strictly necessary exemption). |
Not sold or shared. Always active; cannot be disabled. |
|
AECOMInsights |
Tracks if consent options have previously been shown. |
6 months |
Strictly Necessary (Art. 6(1)(f) legitimate interest / PECR strictly necessary exemption). |
Not sold or shared. Always active; cannot be disabled. |
3.1.2 Non-essential – Functional Cookies
Functional cookies enable optional functionality, localization, embedded media, or personalization. These cookies are non-essential unless the user specifically requests the function during that session and the cookie is strictly necessary to provide that requested function. Functional cookies may be set by AECOM or by third-party providers, may disclose information to partners and must be blocked until the user accepts the functional category where consent is required. If a user does not allow these cookies, some or all of these services may not function properly.
Table 2. Functional Cookies
|
Cookie Name |
Purpose |
Duration |
More Information |
Legal Basis |
CCPA Sale/Share & Opt-Out Status |
|
translation.ISON |
Provides translations |
Session |
Translation for multilingual WordPress sites. |
Consent |
No sale/share. Blocked by "Reject Non-Essential Cookies"; withheld absent consent (EU/UK). |
|
Wistia |
Video Player Progress |
Session |
Video marketing provider. |
Consent |
No sale/share. Blocked by "Reject Non-Essential Cookies"; withheld absent consent (EU/UK). |
|
AECOMGEO AECOMInsights |
Geolocation |
Session |
Geolocation for localization. |
Consent |
No sale/share. Blocked by "Reject Non-Essential Cookies"; withheld absent consent (EU/UK). |
|
BROWSERID |
ID used to identify anonymous activity. |
12 months |
Unique browser instance identification. |
Consent |
No sale/share. Blocked by "Reject Non-Essential Cookies"; withheld absent consent (EU/UK). |
|
SESSIONID |
ID used to identify anonymous activity in one session. |
Session |
Unique session identification. |
Consent |
No sale/share. Blocked by "Reject Non-Essential Cookies"; withheld absent consent (EU/UK). |
3.1.3 Non-essential – Performance Cookies
a. Performance and analytics cookies allow AECOM and its analytics providers to count visits, understand traffic sources, measure campaign performance, generate heatmaps, conduct session replay where enabled, and improve website performance. These cookies are non-essential and may enable the disclosure of a user’s information to those analytics providers and other third parties. If a user rejects non-essential cookies or opts out of sale/sharing, AECOM must not use these cookies in a way that sells or shares personal information or discloses browsing activity to third parties for cross-context behavioral advertising, retargeting, or third-party analytics beyond permitted service provider/contractor processing.
b. Performance cookies help AECOM to know which pages are the most and least popular and to understand how visitors move around the AECOM website. If a user does not allow these cookies, AECOM will not know when a user has visited its website and will be unable to monitor its performance.
Table 3. Performance Cookies and Other Trackers
|
Cookie Name |
Purpose |
Duration |
More Information |
Legal Basis |
CCPA Sale/Share & Opt-Out Status |
|
_ga |
ID used to identify users. |
1 year |
Google Analytics |
Consent |
Service-provider analytics; no sale/share when configured per CCPA regs. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share opt-out, and GPC. |
|
_ga_123455 |
ID used to identify users. |
1 year |
Google Analytics |
Consent |
|
|
_ga_EBWMJ4FEME |
Google Analytics session/user identifier; tracks user behavior across pages to measure and improve website performance. Data is aggregated for analytics reporting only. |
1 year |
Google Analytics |
Consent |
Service-provider analytics; no sale/share when configured per CCPA regs. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share opt-out, and GPC. |
|
_ga_MZYL0YKBNK |
Google Analytics session/user identifier; tracks user behavior across pages to measure and improve website performance. Data is aggregated for analytics reporting only. |
1 year |
Google Analytics |
Consent |
Service-provider analytics; no sale/share when configured per CCPA regs. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share opt-out, and GPC. |
|
_ga_Y1G8KVG2ZL |
Google Analytics session/user identifier; tracks user behavior across pages to measure and improve website performance. Data is aggregated for analytics reporting only. |
1 year |
Google Analytics |
Consent |
Service-provider analytics; no sale/share when configured per CCPA regs. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share opt-out, and GPC. |
|
MUID |
Monitoring and performance |
1 year |
New Relic monitoring . |
Consent |
|
|
_clck |
Identifies unique visitors and records session behavior for Microsoft Clarity heatmaps and session replay. |
1 year |
Microsoft Clarity (.aecom.com – first-party). |
Consent |
Potential "share" (Bing identity sync). Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share opt-out, and GPC. |
|
_clsk |
Microsoft Clarity session cookie; consolidates page views into a single session recording. |
Session |
Microsoft Clarity (.aecom.com- first-party). |
Consent |
Potential "share" (Bing identity sync). Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share opt-out, and GPC. |
|
CLID |
Microsoft Clarity unique visitor identifier; links user behavior to a Clarity project. |
1 year |
Microsoft Clarity (www.clarity.ms — third-party). |
Consent |
Potential "share" (Bing identity sync). Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share opt-out, and GPC. |
3.1.4 Non-essential – Targeting and Advertising Cookies
Targeting and advertising cookies are used to build or augment profiles, identify browsers or devices, measure conversions, synchronize identifiers, retarget users, or show relevant advertising on AECOM or third-party sites, apps, or services. These cookies are non-essential, are treated as potential “sale” or “sharing” under the CCPA/CPRA, and must not be placed, read, synced, or used unless the user has opted in where required and has not opted out of sale/sharing through the Do Not Sell or Share link, Cookie Settings, GPC, or another recognized opt-out preference signal.
Table 4. Targeting and Advertising Cookies
|
Cookie Name |
Purpose |
Duration |
More Information |
Legal Basis |
CCPA Sale/Share & Opt-Out Status |
|
MUID |
Microsoft User Identifier; used to synchronize user identity across Bing and Clarity for advertising measurement and retargeting |
1 year |
Microsoft Bing |
Consent |
"Sale"/"Share" under CCPA/CPRA. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share link, and GPC. |
|
ANONCHK |
Bing/Clarity anonymous check; verifies whether the user is recognized without logging identifiable data directly |
Session |
Microsoft Bing (.c.clarity.ms — third-party). |
Consent |
"Sale"/"Share" under CCPA/CPRA. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share link, and GPC. |
|
MR |
Microsoft Bing remarketing cookie; tracks user activity to enable retargeted advertising on Bing and partner networks |
7 days |
Microsoft Bing (.c.bing.com — third-party). |
Consent |
"Sale"/"Share" under CCPA/CPRA. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share link, and GPC. |
|
SM |
Microsoft Clarity session marker; used to determine whether Clarity should record the current session |
Session |
Microsoft Clarity (.c.clarity.ms — third-party). |
Consent |
"Sale"/"Share" under CCPA/CPRA. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share link, and GPC. |
|
SRM_B |
Bing remarketing cookie; stores a unique user ID to track conversions and measure advertising campaign effectiveness |
1 year |
Microsoft Bing (.c.bing.com — third-party). |
Consent |
"Sale"/"Share" under CCPA/CPRA. Blocked by "Reject Non-Essential Cookies," the Do Not Sell or Share link, and GPC. |
|
request-ip |
Used for personalization of content |
1 year |
AECOM owned based on users first touch IP address. |
Consent |
First-party; no disclosure to third parties. Blocked by "Reject Non-Essential Cookies." |
|
visitor_id |
ID used to identify users for personalization |
1 year |
AECOM owned anonymous visitor ID. |
Consent |
First-party; no disclosure to third parties. Blocked by "Reject Non-Essential Cookies." |
4. Managing Cookies
a. Users may manage cookies through browser controls, the AECOM Cookie Settings link, the “Do Not Sell or Share My Personal Information” link and recognized opt-out preference signals such as GPC. Cookie controls and the sale/sharing opt-out must be easy to find, easy to use, symmetrical, and must not use dark patterns, manipulative wording, preselected non-essential toggles, confusing double negatives, unnecessary steps, or materially different visual prominence between acceptance and rejection choices.
b. Cookie preferences are browser- and device-specific unless AECOM can associate the preference with a known user account or profile. If a user deletes or blocks cookies, they may need to reset preferences. Similarly, if a user has enabled GPC and visits the AECOM website from a different browser or a different device, GPC must be enabled on that browser or device as well; opt-out preference signals apply on a per-browser, per-device basis unless AECOM can associate them with a known user. However, AECOM must not interpret the absence of a GPC signal after receiving one as consent to opt back in and must not ask a consumer to opt back into sale/sharing for at least 12 months after the consumer has opted out, unless legally permitted.
4.1 Controlling Cookies on the AECOM Website
A user may accept or reject non-essential cookies by using the Cookie Banner and Cookie Settings link. For California residents, the Cookie Banner alone is not the only method for exercising the CCPA/CPRA right to opt out of sale/sharing; AECOM must also provide a clear and conspicuous “Do Not Sell or Share My Personal Information” link or equivalent mechanism that addresses sale/sharing, not merely cookie collection.
Selecting “Reject Non-Essential Cookies” or submitting a sale/sharing opt-out will prevent AECOM from placing, reading, or disclosing non-essential cookie data for advertising, analytics, session replay, targeting, or identity-sync purposes, except for permitted service provider/contractor processing that is not a sale or sharing. Essential cookies will continue to operate.
Note: Disabling the Cookies Settings on the AECOM website shall not result in the deletion of any cookies already set. A user can delete those cookies at any time by accessing the browser settings on their device.
4.2 Controlling Cookies through the Browser
Users are always free to decline cookies if their browser permits, although doing so may interfere with their online experience, including the use of the AECOM website.
The following links may assist a user in managing their preferences, or a user can select the ‘Help’ option in their internet browser for more details.
|
· Google Chrome: |
http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95647 |
|
· Safari: |
|
|
· Microsoft Edge: |
https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge |
|
· Mozilla Firefox: |
5. Additional Privacy Rights of California Residents (CCPA/CPRA)
a. California Notice at Collection for Cookie-Derived Personal Information: AECOM may collect the following categories of personal information through Cookies and Other Trackers: identifiers; internet or other electronic network activity information; approximate geolocation; inferences; and only if enabled and expressly disclosed, sensitive personal information such as precise geolocation or contents of communications. AECOM uses this information to operate the website, remember privacy choices, secure the website, measure performance, improve user experience, deliver or measure advertising, and comply with law. AECOM may disclose these categories to service providers, contractors, analytics providers, advertising/marketing partners, social media platforms, tag-management providers, and other third parties identified in the cookie tables above and Privacy Notice. AECOM may sell or share identifiers, internet activity, approximate geolocation, and inferences when disclosed to advertising, analytics, measurement, retargeting, or identity-sync partners for cross-context behavioral advertising or their own purposes. AECOM does not use sensitive personal information collected through cookies to infer characteristics and does not use or disclose sensitive personal information beyond permitted purposes unless it provides a right to limit and honors that right.
b. Data Minimization and Purpose Limitation: AECOM will collect, use, retain, and disclose cookie-derived personal information only as reasonably necessary and proportionate to the disclosed purposes. AECOM must not collect form-field contents, sensitive personal information, or precise geolocation through non-essential trackers unless specifically approved by Legal, clearly disclosed, and consented to where required.
c. To opt out of sale or sharing of cookie-derived personal information, a user may use the “Do Not Sell or Share My Personal Information” link, adjust Cookie Settings on aecom.com, or activate GPC or another recognized opt-out preference signal. AECOM will process the opt-out without requiring verification, account creation, or additional information for browser/device-level opt-outs. For more information regarding the use of your personal data, see AECOM’s Privacy Notice.
d. Under the CCPA/CPRA, California residents have the rights to know/access, delete, correct, opt out of sale/sharing, limit use and disclosure of sensitive personal information where applicable, and not be discriminated or retaliated against for exercising rights. For cookie-derived data, these rights apply to personal information reasonably linkable to a consumer, household, browser, device, or pseudonymous profile. AECOM will not use cookie-derived profiles for automated decision-making that produces legal or similarly significant effects without providing legally required notices and opt-out rights.
e. Do Not Sell or Share My Personal Information: For purposes of this Policy, a "sale" or "sharing" of personal information includes disclosing or making available personal information (including browsing history and device information) to a third party for purposes of cross-context behavioral advertising or in exchange for monetary or other valuable consideration, whether or not money changes hands. California residents may exercise their right to opt out of sale/sharing by: (i) clicking the “Do Not Sell or Share My Personal Information” link; (ii) adjusting preferences through the Cookie Settings link on aecom.com; or (iii) activating GPC or another recognized opt-out preference signal. AECOM must treat a valid GPC signal as a request to opt out of sale/sharing for that browser or device and, where the user is known, for the associated account or profile. AECOM must display a clear confirmation that the opt-out preference signal has been recognized and processed, such as “Opt-Out Preference Signal Honored.
f. California Invasion of Privacy Act (CIPA): Separately from CCPA/CPRA, California residents should be aware that the California Invasion of Privacy Act (Cal. Penal Code §§ 630–638) may apply to the interception and disclosure of electronic communications and browsing data by third parties through cookies and tracking technologies. AECOM does not permit third-party ad companies or analytics providers to intercept or access user data on aecom.com after a user has rejected non-essential cookies. If you believe your “opt-out” has not been honored, contact privacyquestions@aecom.com immediately.
6. Do Not Track Signal
Some web browsers transmit “Do Not Track” signals, visit http://www.allaboutdnt.com. AECOM does not respond to legacy Do Not Track signals unless required by law. AECOM does recognize and honor GPC (see https://globalprivacycontrol.org) and other legally recognized opt-out preference signals as requests to opt out of sale/sharing under the CCPA/CPRA, as described in its Privacy Notice. AECOM also treats valid GPC signals as requests to opt out of targeted advertising under other applicable U.S. state privacy laws that require recognition of universal opt-out mechanisms. GPC must be processed without charging a fee, degrading service, requiring verification, or requiring the user to take additional steps.
7. Third Party Links
The AECOM website may contain links to third-party websites or applications such as Facebook, X (formerly Twitter), LinkedIn, or YouTube. AECOM is not responsible for those websites’ use of cookies, for their privacy practices, or the content of these other websites or applications. A user is to refer to the applicable policies and notices associated with those third-party websites and applications to understand how they collect and use Usage Information.
8. Data Retention
AECOM retains cookie-derived personal information only for as long as reasonably necessary and proportionate to the purposes disclosed in this Policy, the Privacy Notice, and the applicable notice at collection. Retention periods must be specific and tied to each cookie or tracker in the “Cookie tables” in Section 3.1. Session cookies expire at the end of the browser session. Persistent cookies must not exceed the stated duration unless a longer period is required by law. Cookie-derived data no longer required for disclosed purposes or compliance obligations must be deleted, aggregated, or deidentified in accordance with AECOM’s Records Retention Schedule and applicable deidentification requirements.
9. EU GDPR and UK GDPR Rights
a. Where AECOM processes personal data collected through cookies as a data controller subject to Regulation (EU) 2016/679 (EU GDPR) or the UK GDPR as retained in UK law, the following provisions apply.
b. Lawful Basis: Non-essential cookies (functional, performance, and targeting/advertising) are processed only on the basis of your freely given, specific, informed, and unambiguous consent (Article 6(1)(a) EU GDPR / UK GDPR). Essential cookies are placed on the basis of AECOM’s legitimate interest in ensuring the security and basic functionality of its website (Article 6(1)(f)), or where strictly necessary to provide a service you have requested. AECOM does not rely on legitimate interest as a lawful basis for any non-essential cookie that requires consent under the Privacy and Electronic Communications Regulations (PECR) or the ePrivacy Directive.
c. Withdrawal of Consent: Where processing is based on consent, you have the right to withdraw that consent at any time without detriment, by accessing the Cookie Settings link on AECOM.com. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to withdrawal (Article 7(3) EU GDPR / UK GDPR).
d. Data Subject Rights: Data subjects in the EU and UK have the right to: (a) request access to personal data AECOM holds about them (Article 15); (b) request rectification of inaccurate data (Article 16); (c) request erasure of their personal data where there is no compelling reason for its continued processing (Article 17); (d) object to processing based on legitimate interests (Article 21); (e) request restriction of processing in certain circumstances (Article 18); and (f) receive a copy of personal data processed on the basis of consent in a structured, machine-readable format where technically feasible (Article 20 — right to data portability). Requests may be submitted to privacyquestions@aecom.com.
e. International Transfers: AECOM uses certain third-party analytics and advertising services (including Google Analytics) that may transfer cookie-derived personal data to countries outside the European Economic Area (EEA) or the United Kingdom. Such transfers are subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) as approved by the European Commission or the UK International Data Transfer Agreement (IDTA), as applicable. Further details are set out in AECOM’s Privacy Notice and Transfer Impact Assessment documentation.
f. Right to Lodge a Complaint: If you believe AECOM has not complied with applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority. For EU residents, this is the data protection authority (DPA) in your EU member state of habitual residence. For UK residents, this is the Information Commissioner’s Office (ICO), which may be contacted at http://www.ico.org.uk or by telephone on 0303 123 1113. AECOM encourages users to contact us in the first instance at privacyquestions@aecom.com to seek resolution. For UK residents, the Data (Use and Access) Act 2025 also provides a right to complain to AECOM as the controller in the first instance; AECOM will facilitate such complaints, acknowledge receipt within 30 days, and respond without undue delay before any escalation to the ICO.
10. Changes to This Policy
The Company may update this Policy from time to time. Where changes are material — including changes to the categories of cookies used, the purposes for which data is processed, or the third parties with whom data is shared — AECOM will provide conspicuous notice on aecom.com before the change takes effect, in accordance with GDPR Art 13 and CPRA § 1798.130. The updated Policy will always be available at aecom.com and will state the date of the most recent revision.
11. Contact Us
If you have any questions about this Policy, please contact the AECOM Privacy Office at privacyquestions@aecom.com.
12. References
a. Global Privacy Notice – AECOM Global L1-007-PL5
b. Privacy Policy – aecom.com
f. “Do Not Track”
g. California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100 et seq
h. California Code of Regulations, title 11, §§ 7000–7304, including §§ 7012, 7025, 7026, 7050–7053.
i. CPPA Enforcement Advisory No. 2024-02, Avoiding Dark Patterns.
j. CPPA guidance on Opt-Out Preference Signals / Global Privacy Control.
k. Global Privacy Control – globalprivacycontrol.org
l. Website Terms of Use – aecom.com
13. Change Log
|
Rev # |
Change Date |
Description of Change |
Location of Change |
|
0 |
25-Jun-2025 |
Initial release as L1-009-PL2 |
All |
|
1 |
19-Jun-2026 |
2026 Review; update to reflect CCPA/CPRA regulatory updates. |
All |
|
2 |
16-Jul-2026 |
Incorporation of DLA Piper cookie banner and tool language review (17-Apr-2026): essential/functional category disclosures; plain-language sale/share definition; GPC device-portability caveat and link; U.S. state universal opt-out scope; sale/share and opt-out status column added to cookie tables; removal of internal scan flags and placeholder entries; legal basis, cross-reference, and typographical corrections. |
All |