No results found
This privacy statement applies to Deloitte Malta and its related entities, being members of Deloitte Central Mediterranean S.r.l. with registered office address at Deloitte Place, Triq L-Intornjatur, Central Business District, CBD 3050 Malta (“Deloitte”, “we”, “us” or “our”).
We are committed to protecting your privacy and handling your information in an open and transparent manner, and at all times in compliance with the provisions of the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC) and the Data Protection Act (Chapter 586 of the laws of Malta) its subsidiary legislation, and other relevant legislation and/or regulations and/or guidance as may be relevant (“Data Protection Legislation”).
This privacy statement sets out how we will collect, handle, store and protect information about you when:
This privacy statement also contains information about when we share your personal data with other members of the Deloitte Network and other third parties (for example, our service providers).
When we refer to “our Website” or “this Website” in this statement we mean the specific webpages of deloitte.com designated as “Malta” in the upper right hand corner and to specific webpages with a URL commencing ‘http://www.deloitte.com/mt'.
Deloitte.com is comprised of various global, country, regional and practice specific websites, each of which is provided by Deloitte Touche Tohmatsu Limited (“DTTL”) or one of its independent member firms or their related entities (collectively, the “Deloitte Network”). Such websites, as well as other websites that may be linked to this Website, are not governed by this privacy statement. We encourage visitors to review the privacy statements on each of these other websites before disclosing any personal information. To learn more about DTTL, the member firms of DTTL and their related entities, please see About Deloitte.
In this privacy statement, your information is sometimes called “personal data” or “personal information”. We may also sometimes collectively refer to handling, collecting, protecting and storing your personal information as “processing” such personal information.
We may collect, record and use your personal data in physical and electronic form, and will hold, use and otherwise process that data in line with the Data Protection Legislation and as set out in this statement.
When we provide services to you or our clients and perform due diligence checks in connection with our services (or discuss possible services we might provide), we will process personal data about you. We may also collect personal data from you when you use this Website.
We may process your data because:
We may also collect or obtain personal data from you because we observe or infer that data about you from the way you interact with us. For example, to improve your experience when you use this Website and ensure that it is functioning effectively, we (or our service providers) may use cookies (small text files stored in a user’s browser) and web beacons which may collect personal data. Additional information on how we use cookies and other tracking technologies and how you can control these can be found in our cookie notice.
The personal data we process may include your:
The personal data we collect may also include so called ‘sensitive’ or ‘special categories’ of personal data, such as details about your:
We may also process personal data relating to ethnic or racial origin (for example, any multicultural networks you belong to), or about your political opinions (inferred from information you give us about political associations you belong to or have donated to, or from information that is publicly available).
If you choose not to provide, or object to us processing, the information we collect (see “Your rights” section below), we may not be able to process your instructions or continue to provide some or all of our services to you or our client.
We will, where necessary, obtain your explicit consent to collect and use such information.
We do not engage in the collection of personal information about your online activities across third-party websites or online services and we do not allow third parties to collect such personal information when you use the Website.
We process information about you and/or your business to enable us and other members of the Deloitte Network to provide our services to you or our clients, and to meet our legal or regulatory obligations.
Some of your personal data may be used for other business purposes. Below are some examples.
We will use your personal data to provide you or our clients or other third parties with services, and this includes using your personal data in correspondence relating to those services. That correspondence may be with:
We may also use your personal data to conduct due diligence checks relating to the services.
Because we provide a wide range of services to our clients or other third parties, the way we use personal data in relation to our services also varies. For example, we might use personal data about:
We may also use your personal data in connection with:
In addition to the above, we may also use your personal data collected via our Website:
Your personal information may also be used to protect our rights or property and that of our users and, where appropriate, to comply with legal process.
Deloitte organises several events, seminars and conferences from time to time to update, educate and provoke discussion amongst its clients, potential clients and key players within the industry. This section of our Policy explains how we utilise your personal data when you show interest in, register for, or attend any events organised by Deloitte.
When showing an interest in, registering for or attending any events, the information you provide us with will include:
Deloitte may photograph and film events which will be used to market our services and to possibly promote future events. We will therefore process your image. You will be notified if we intend to photograph or film at any event we organise, with said notification generally found in the invitation or on signs at the event location. Should you wish not to be filmed or photographed at any of our events, please contact us. Where possible, we will consider photo-free zones for those who do not want their picture taken.
We will process personal data relating to events for the following reasons:
We may only process your personal data when we have a valid reason to do so. We rely on one or more of these lawful grounds depending on the processing activity:
To the extent that we process any special categories of data relating to you for any of the purposes outlined above, we will do so because:
Please note that in certain circumstances it may be still lawful for us to continue processing your information even where you have withdrawn your consent, if one of the other legal bases described above is applicable.
In connection with one or more of the purposes outlined in the “How we use your personal data” section above, we may disclose details about you to:
Our Website hosts various blogs, forums, wikis and other social media applications or services that allow you to share content with other users (collectively “Social Media Applications”). Importantly, any personal information that you contribute to these Social Media Applications can be read, collected and used by other users of the application. We have little or no control over these other users and, therefore, we cannot guarantee that any information that you contribute to any Social Media Applications will be handled in accordance with this privacy statement.
Information we hold about you may be transferred to other countries (which may include countries outside the European Economic Area (“EEA”)):
Some of these countries may have less stringent privacy laws than we do, so any information they hold can become subject to their laws and disclosure requirements, including disclosure to governmental bodies, regulatory agencies and private persons. In addition, a number of countries have agreements under which information is exchanged with other countries for law enforcement, taxation and other purposes.
When we, or our permitted third parties, transfer your personal data outside the EEA, we will impose contractual obligations on the recipients of that data to protect your personal data to the standard required in the EEA. We or they may also require the recipient to subscribe to international frameworks intended to enable secure data sharing when necessary.
We may also transfer your personal data when:
In all cases, we may need to disclose your personal data if required to do so by law, a regulator or during legal proceedings.
We use a range of physical, electronic and managerial measures to ensure that we keep your personal data secure, accurate and up to date. These measures include:
Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure. We use appropriate measures to try to protect personal data, but we cannot guarantee the security of data transmitted to us or by us.
We will hold your personal data on our systems for the longest of the following periods:
(i) as long as is necessary for the relevant purpose of collection;
(ii) any retention period that is required by law;
(iii) the end of the period in which litigation or investigations might or may arise in respect of our relationship with you or any services provided to you
You have various rights in relation to your personal data. In particular, you have a right to:
In order to exercise any of your personal data rights, or make a complaint or suggestions to us relating to your privacy, or if you have any other questions about our use of your personal data, you should contact our Data Protection Officer of the Company at the address below:
Email: dataprotectionofficer@deloitte.com.mt
Phone:+(356) 2343 2000
Post:
Deloitte Malta,
Deloitte Place,
Triq L-Intornjatur, Zone 3,
Central Business District,
Birkirkara CBD 3050,
Malta
Please note that your data subject rights may be limited in circumstances where, in order to comply with your request, we would need to unduly expose personal data about someone else, or where the data you ask us to delete or amend is required for us to perform our contractual obligations towards you, or if we require such data to comply with our legal obligations, or if it is in our legitimate interest to continue processing said data in order to abide by our internal procedures and policies..
We and other members of the Deloitte Network may use your information from time to time to inform you by letter, telephone, email and other electronic methods about products and services (including those of third parties) that may be of interest to you.You may, at any time, ask us and/or other members of the Deloitte Network not to send marketing information to you by following the unsubscribe instructions in communications from us, or contacting us in the way described in section 8 above.
We may modify or amend this privacy statement from time to time, at our discretion.
To let you know when we make changes to this privacy statement, we will amend the revision date at the top of this page. The new modified or amended privacy statement will apply from that revision date. Therefore, we encourage you to periodically review this statement to be informed about how we are protecting your information.
If at any time you do not agree with this Privacy Notice (as revised from time to time) you must terminate your use of this website and the included services.
Information on sub-processors
Pursuant to art. 28 paragraph 4 of the General European Data Protection Regulation no. 679/2016 (hereinafter also "GDPR"), "Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor […], in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations."
Deloitte uses different types of sub-processors to perform its services and has implemented a third-party selection process aimed at assessing the adequacy of their guarantees in terms of security, privacy and confidentiality.
The following list contains the main sub-processors used for the provision of services and products offered by one or more of the Legal Entities of the Maltese Deloitte Network, when these are hired as data processors pursuant to art. 28 GDPR.