Last revised: December 2024
1. What is the purpose of this document?
Deloitte Greece Entities (hereinafter referred to as “Data Controller” or “Deloitte” or “the Firm” or “we” or “us”) are committed to protect your privacy and process your data in a clear and transparent manner.
This privacy notice describes the processing of your personal data for the fulfilment of the Client Service Assessment initiative, in accordance with the General Data Protection Regulation (GDPR), national law 4624/2019, as in force, and all the applicable data protection laws and regulations. It provides information on the nature of the personal data - where personal data means any information relating to an identified or identifiable natural person (“Data Subject”) - collected by the Data Controller, the purposes of the processing and indicates your rights in relation to the data processed and who to contact for further information or to send any requests.
2. What is the identity and contact details of the Data Controller?
The Data Controller is each Greek Deloitte entity in relation to which you participate in the CSA initiative, and more specifically:
DELOITTE BUSINESS SOLUTIONS S.A., DELOITTE. and KBVL Law Firm are based in 3a Fragkokklisias & Granikou str., Marousi, Athens, P.O. 151 25. DACC S.A. is based in Pempti and Triti 6th Industrial Area Block of Technopolis Thessaloniki, Municipality of Pylaia Chortiatis, D.E. Pylaia, P.E. Thessaloniki.
3. What are the contact details of the Data Protection Officer?
The Data Protection Officer can always be contacted at the following e-mail address: DataPrivacyOfficer@deloitte.gr.
4. Which data do we collect about you and for which purposes?
We process the following personal information that you voluntarily submit: full name, e-mail address, phone number, company name, job title, work and/or home address. You are responsible for ensuring that any personal information submitted by you to Client Service Assessment is accurate, complete and up to date.
The personal data collected will be processed solely for the fulfilment of the Client Service Assessment initiative.
5. What is the legal basis on which we process your personal data?
The legal basis for the processing of your personal data is your consent provided to us (art. 6 par.1a GDPR), by voluntarily participating in the Client Service Assessment initiative.
You may revoke your consent at any time, by sending an email to our DPO at: DataPrivacyOfficer@deloitte.gr. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
6. Who has access to your personal data and to whom is it disclosed?
Your data may be communicated – for the purpose referred above in this privacy notice – to the following categories of recipients:
In all cases, we may be requested to disclose your personal data if required to do so by law, a regulator or during legal proceedings.
Your data will be communicated to these third parties after being appointed as data processors or recognized as autonomous data controllers and will be processed by collaborators and/or employees of Deloitte in the context of their respective functions and in accordance with the instructions given by Deloitte itself.
7. Are your data transferred abroad?
If necessary for the purposes stated above, the data collected may be transmitted or made accessible to other companies in the Deloitte Network, to entities that provide services to us and/or the Deloitte Network (e.g., vendors, suppliers), to competent authorities (e.g., courts, tax authorities, regulatory authorities) including those based in other countries, which may include countries outside the European Economic Area (EEA). Third parties to whom your personal data are transferred are bound by specific agreement and are required to keep your data securely.
In such cases, we guarantee that the transfer will take place in accordance with the provisions of Chapter V of the GDPR through the adoption of appropriate safeguards that ensure a level of data protection in accordance with the obligations to which we are legally bound, such as Standard Contractual Clauses, Binding Corporate Rules, other applicable legal basis or based on a statutory exemption (e.g. if you have given your consent to the transfer, if the transfer is directly connected with the conclusion or performance of a contract with you or if the transfer is necessary for the establishment, exercise or enforcement of legal claims before a foreign authority). For further information about the third parties, how we work with them and their processing of your personal data, or for information about the adequate safeguards installed by us in respect of data transfers please send an e-mail to the DataPrivacyOfficer@deloitte.gr.
8. What is the data retention period, or if not possible, the criteria used to determine it?
We will hold your personal data on our systems for a period of two (2) years, commencing from the provision of your personal information to us.
9. How do we protect and safeguard your personal data?
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, processed, or accessed in an unauthorized way, altered, or disclosed. These measures can include:
In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any incident that may lead to a security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so. Third parties will only process your personal data on our instructions and only where they have agreed to treat the data confidentially and to keep it secure in compliance with the applicable law.
10. What are your rights and how can you exercise them?
In relation to the processing of your personal data, you have specific rights according to Art. 15 - 22 of the GDPR:
To exercise these rights, you can contact us at DataPrivacyOfficer@deloitte.gr .
The time limit for Deloitte to address your request is 1 month, which may be extended up to 2 further months in cases of particular complexity.
We also inform you that you have the right to lodge a complaint with the Supervisory Authority for the protection of personal data, which in Greece is the Hellenic Data Protection Authority (HDPA), by following the instructions found on the HDPA’s website.
However, should you have a complaint or question, it is advisable to contact the Firm first, in order to try and solve the matter amicably.
11. Changes to this Privacy Notice
We may modify or amend this Privacy Notice from time to time at our discretion and we will promptly inform you through traditional channels of communication (e.g. by publishing the new information on our website). When we make changes to this notice, we will amend the revision date at the top of this page, and such modified or amended Privacy Notice will be effective from that revision date. We therefore invite you to regularly consult this Privacy Notice in order to stay up to date with any changes made since your last consultation.