1. What is the purpose of this document?
Deloitte Greece Entities (hereinafter referred to as “Data Controller”, “Deloitte”, “we”, “us” or “the Firm”) are committed to protecting your privacy and processing your data in a clear and transparent manner.
This privacy notice describes the processing of your personal data in the context of our marketing and communication activities, in accordance with the General Data Protection Regulation (GDPR), national law 4624/2019, as in force, and all the applicable data protection laws and regulations. It provides information on the nature of the personal data - where personal data means any information relating to an identified or identifiable natural person (“Data Subject”) - collected by the Data Controller, the purposes of the processing and indicates your rights in relation to the data processed and who to contact for further information or to send any requests.
2. What is the identity and contact details of the Data Controller?
The Data Controller is each Greek Deloitte entity in relation to which a marketing and/or communication activity is conducted, and more specifically:
1. “Deloitte Business Solutions Societe Anonyme of Business Consultants” with the distinctive title “DELOITTE BUSINESS SOLUTIONS S.A.”,
2. “Deloitte Certified Public Accountants Societe Anonyme” with the distinctive title “DELOITTE.” and
3. “Deloitte Alexander Competence Center Single-Member Societe Anonyme of Business Consultants” with the distinctive title “DACC S.A.”.
DELOITTE BUSINESS SOLUTIONS S.A. and DELOITTE. are based in 3a Fragkokklisias & Granikou str., Marousi, Athens, P.O. 151 25. DACC S.A. is based in Pempti and Triti 6th Industrial Area Block of Technopolis Thessaloniki, Municipality of Pylaia Chortiatis, D.E. Pylaia, P.E. Thessaloniki, 555 35.
3. What are the contact details of the Data Protection Officer?
The Data Protection Officer can always be contacted at the following e-mail address: DataPrivacyOfficer@deloitte.gr.
4. Which data do we collect about you and for which purposes?
Deloitte, indicatively, processes the following personal information that you may voluntarily submit during one of our marketing activities or websites or have come to our possession through the performance of a relevant service in the near past, such as:
Also, Deloitte may process a footage of you (pictures and/or videos) taken during events. Deloitte may use the afore mentioned material for posts in our Social Media Accounts (Facebook, Instagram, LinkedIn, YouTube) and our Intranet site.
Kindly note that in case you do not wish to be filmed and/or photographed during any event, Deloitte will always provide a discrete space where you may choose to be seated. The provision of your personal data is not mandatory and if you do not consent to the processing there are not any negative consequences for you.
We do not collect and process special categories of personal data, such as data relating to your race or ethnic origin, religious conviction, criminal record, physical and mental health status or sexual orientation.
Your data are processed for the following purposes:
a) Conducting Deloitte’s marketing & communications activities. Related initiatives may include business insights, industry trends, reports, invitations to events we organise or sponsor, newsletters or other marketing communications related to the various services offered by Deloitte worldwide. Such communications could be shared by post, email, telephone, text messages or recorded calls.
b) We may process your personal data collected during events (pictures and/or videos of you) for the purpose of further promoting Deloitte events.
The processing of personal data for the above purposes is optional, and refusal to provide consent will not affect Deloitte’s provision of any services you may have requested.
5. What is the legal basis on which we process your personal data?
We will use your personal data for the purposes indicated above on the assumption of the following conditions of legitimacy (legal basis):
a) Your consent that you provided to us for the purpose of participating in Deloitte’s marketing & communications activities (art. 11 par.1, L. 3471/2006).
Your consent (article 6 par.1a GDPR) is the legal basis also for the processing of pictures and/or videos of you for the purpose of promoting Deloitte events.
In such case, you may revoke your consent at any time, by sending an email to the Firm’s DPO at: DataPrivacyOfficer@deloitte.gr. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
b) When personal data is already in our possession through the performance of a relevant service in the near past, the processing of your personal data for Deloitte’s marketing & communications activities (promoting our services) is carried out in accordance with article 11 par. 3 of Law 3471/2006, as in force. You have the right to object at any time to the processing of your personal data for such activities. Also, you may opt-out of receiving further communications at any time, by following the instructions included in the communications.
6. Who has access to your personal data and to whom is it disclosed?
Your data may be communicated – for the purposes referred above of this privacy notice – to the following categories of recipients:
Kindly note that your personal data collected during Deloitte events (pictures and/or videos) are processed only by authorized personnel through our Social Media Accounts (Facebook, Instagram, LinkedIn, YouTube) and our Intranet site.
In all cases, we may be requested to disclose your personal data if required to do so by law, a regulator or during legal proceedings.
Your data will be communicated to these third parties after being appointed as data processors or recognized as autonomous data controllers and will be processed by collaborators and/or employees of Deloitte in the context of their respective functions and in accordance with the instructions given by Deloitte itself.
7. Are your data transferred abroad?
If necessary for the purposes stated above, the data collected may be transmitted or made accessible to other companies in the Deloitte Network, to entities that provide services to us and/or the Deloitte Network (e.g., vendors, suppliers), to competent authorities (e.g., courts, tax authorities, regulatory authorities) including those based in other countries, which may include countries outside the European Economic Area (EEA). Third parties to whom your personal data are transferred are bound by specific agreement and are required to keep your data securely.
In such cases, we guarantee that the transfer will take place in accordance with the provisions of Chapter V of the GDPR through the adoption of appropriate safeguards that ensure a level of data protection in accordance with the obligations to which we are legally bound, such as Standard Contractual Clauses, Binding Corporate Rules, other applicable legal basis or based on a statutory exemption (e.g. if you have given your consent to the transfer, if the transfer is directly connected with the conclusion or performance of a contract with you or if the transfer is necessary for the establishment, exercise or enforcement of legal claims before a foreign authority). For further information about the third parties, how we work with them and their processing of your personal data, or for information about the adequate safeguards installed by us in respect of data transfers please send an e-mail to the DataPrivacyOfficer@deloitte.gr.
8. What is the data retention period, or if not possible, the criteria used to determine it?
We will retain your personal data for the abovementioned purposes until the consent is withdrawn or the right to object to processing for marketing purposes is exercised respectively. In any case, we will hold your personal data on our systems for a period of two (2) years, commencing either from the provision of your personal information to us or from the completion of a Marketing & Communications activity, where applicable.
9. How do we protect and safeguard your personal data?
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, processed, or accessed in an unauthorized way, altered, or disclosed. These measures can include:
In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any incident that may lead to a security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so. Third parties will only process your personal data on our instructions and only where they have agreed to treat the data confidentially and to keep it secure in compliance with the applicable law.
10. What are your rights and how can you exercise them?
In relation to the processing of your personal data, you have specific rights according to Art. 15- 22 of the GDPR:
To exercise these rights, you can contact us at DataPrivacyOfficer@deloitte.gr .
The time limit for Deloitte Greece to address your request is 1 month, which may be extended up to 2 further months in cases of particular complexity.
We also inform you that you have the right to lodge a complaint with the Supervisory Authority for the protection of personal data, which in Greece is the Hellenic Data Protection Authority (HDPA), by following the instructions found on the HDPA’s website.
However, should you have a complaint or question, it is advisable to contact theFirm first, in order to try and solve the matter amicably.
11. Changes to this Privacy Notice
We may modify or amend this Privacy Notice from time to time at our discretion and we will promptly inform you through traditional channels of communication (e.g. by publishing the new information on our website). When we make changes to this notice, we will amend the revision date at the top of this page, and such modified or amended Privacy Notice will be effective from that revision date. We therefore invite you to regularly consult this Privacy Notice in order to stay up to date with any changes made since your last consultation.
This document has been prepared by Deloitte Business Solutions Societe Anonyme of Business Consultants, Deloitte Certified Public Accountants Societe Anonyme and Deloitte Alexander CompetenceCenter Single Member Societe Anonyme of Business Consultants.
Deloitte Business Solutions Societe Anonyme of Business Consultants, a Greek company, registered in Greece with registered number 000665201000 and its registered office at Marousi Attica, 3a Fragkokklisias & Granikou str., 151 25, Deloitte Certified Public Accountants Societe Anonyme, a Greek company, registered in Greece with registered number 001223601000 and its registered office at Marousi, Attica, 3a Fragkokklisias & Granikou str., 151 25 and Deloitte Alexander Competence Center Single Member Societe Anonyme of Business Consultants, a Greek company, registered in Greece with registered number 144724504000 and its registered office at Thessaloniki, Municipality of Pylaia - Chortiatis of Thessaloniki, Vepe Technopolis Thessaloniki (5th and 3rd street), 555 35, are all companies of the Deloitte Central Mediterranean S.r.l. (“DCM”) geography. DCM, a company limited by guarantee registered in Italy with registered number 09599600963 and its registered office at Via Santa Sofia no. 28, 20122, Milan, Italy is one of the Deloitte NSE LLP geographies. Deloitte NSE LLP is a UK limited liability partnership and member firm of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee.
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms and their related entities (collectively, the “Deloitte organization”). DTTL (also referred to as “Deloitte Global”) and each of its member firms and related entities are legally separate and independent entities, which cannot obligate or bind each other in respect of third parties. DTTL and each DTTL member firm and related entity is liable only for its own acts and omissions, and not those of any of each other. DTTL does not provide services to clients.
Please see www.deloitte.com/ about to learn more.
DTTL, Deloitte NSE LLP and Deloitte Central Mediterranean S.r.l. do not provide services to clients. Please see www.deloitte.com/about to learn more about our global network of member firms.
Deloitte is a leading global provider of audit and assurance, consulting, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories serves four out of five Fortune Global 500® companies. Learn how Deloitte’s approximately 460,300 people make an impact that matters at www.deloitte.com.
This document and its contents are confidential and prepared solely for your use, and may not be reproduced, redistributed or passed on to any other person in whole or in part, unless otherwise expressly agreed with you. No other party is entitled to rely on this document for any purpose whatsoever and we accept no liability to any other party, who is provided with or obtains access or relies to this document.
© 2025 For more information contact Deloitte Central Mediterranean.