Purpose and Scope
This policy is the primary LMI instrument on publication-ethics confidentiality and on personal-data protection within the publishing workflow. It binds LMI, every journal operating under the LMI publishing framework, and every person granted access to confidential publishing information — editors, board members, staff, reviewers, contractors and service providers. It concerns the publishing process; general website privacy and cookie practices are addressed separately below.
Confidential Publishing Information
The following are confidential unless and until lawfully published or disclosed with proper authority: submitted and unpublished manuscripts and their data; reviewer identities (subject to the journal's declared peer-review model) and review reports; editorial deliberations and correspondence; complaint, allegation and investigation materials; and unpublished editorial decisions. Persons with access shall use such information only for the legitimate purpose for which access was granted, shall not use it for personal or competitive advantage, and shall not disclose it except as this policy permits.
Personal Data
LMI and its journals process personal data of authors, reviewers, editors, board members and complainants — names, contact details, affiliations, identifiers, declarations of interest, correspondence — and, within manuscripts, information about research participants. Such data shall be processed under these principles: purpose limitation (collected and used only for stated publishing purposes); data minimisation (no more than the purpose requires); accuracy; security proportionate to sensitivity; and limited retention (kept only as long as publishing, integrity, legal or assurance purposes require, then deleted or anonymised). Participant privacy within research content is further governed by D1; consent for identifiable material is a D1 requirement.
No Sale or Unrelated Commercial Profiling
LMI and its journals shall not sell personal data obtained through scholarly publishing and shall not use confidential publishing information for unrelated advertising, behavioural profiling or commercial targeting. Contact data may be used for legitimate journal communication and service administration only to the extent disclosed and permitted by applicable law.
Access, Systems and Service Providers
Access to confidential information shall be role-based and limited to what each role requires. LMI shall maintain reasonable technical and organisational security for the platforms it provides (A2), and each journal shall control access within its own workflow. Service providers processing confidential information shall be bound to confidentiality and security obligations no weaker than this policy, and shall process such information only on documented instructions. Where processing crosses borders — as is inherent in international publishing platforms — LMI shall ensure the protections of this policy travel with the data.
External Systems and Artificial Intelligence
Confidential publishing information — including manuscripts under review, review reports and investigation materials — shall not be entered into any external system, service or artificial-intelligence tool that is not under appropriate contractual and security control, because such entry may constitute disclosure and may place the material outside LMI's protection. The full framework governing AI use is C4; this confidentiality rule applies to it and prevails in any conflict.
Evidence Holds, Permitted Disclosure and Breach Handling
Where a matter enters complaint or investigation handling (A4, C5), relevant records shall be preserved and not destroyed, altered or placed beyond reach until the matter and any assurance requirements conclude (H2). Confidential information may be disclosed only: with proper authorisation; to persons who need it for legitimate handling of a matter; to institutions, regulators or ethics bodies where an integrity concern justifies cooperation under C5; or where law requires. Disclosure shall be the minimum necessary. Suspected breaches of confidentiality or data security shall be reported promptly to the journal and to LMI, contained, assessed for harm, remedied and recorded; affected persons shall be informed where the breach creates a real risk to them.
Access, Correction, Deletion and Record Integrity
Requests to access, correct, restrict or delete personal data shall be handled consistently with applicable law and legitimate publishing purposes. Incorrect contact or profile data should be corrected. A deletion request does not require erasure of information that must be retained to preserve authorship and attribution, the integrity of peer review, evidence in an unresolved case, legal obligations, or the scholarly record. Where full deletion is not appropriate, access restriction, minimisation, pseudonymisation or separation from active systems shall be considered.
Website Privacy — Separate Instrument
General website privacy, cookies, analytics and account matters for LMI and journal websites are corporate-operational subjects. LMI shall maintain a separate Website Privacy & Cookie Notice outside this policy framework, and this policy does not govern those matters except where website systems carry confidential publishing information.
Standards and Guidance
Informed by the ICMJE Recommendations on confidentiality in the review process, the COPE Core Practices, and internationally recognised data-protection principles including purpose limitation, minimisation and security.