No results found
Deloitte LLP (hereinafter referred to as “Data Controller” or “we” “our” or “us”) is committed to protecting your privacy and processing your data in a clear and transparent manner, using appropriate technical, administrative and physical security measures.
We are the UK affiliate of Deloitte NSE LLP, a member firm of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”).
DTTL and each of its member firms are legally separate and independent entities. DTTL and Deloitte NSE LLP do not provide services to clients.
This privacy notice describes how we process personal data, in accordance with applicable data protection legislation, including the UK General Data Protection Regulation.
This privacy notice provides details of the nature of the personal data collected by us, together with the purposes of the processing. It also indicates your rights in relation to the data processed and who to contact for further information or requests. In this privacy notice your “personal data” is sometimes referred to as your “information”.
In particular, this privacy notice sets out how we will collect, process, store and protect information about you when:
a) Providing services to you or our clients;
b) You use our Website; or
c) Performing any other activities that form part of the operation of our business, as described in further detail below.
When we refer to “our Website” or “this Website”, we mean the specific webpages of deloitte.com designated as United Kingdom in the upper-right-hand corner and any other website which links to this privacy statement.
As you read this privacy notice, please note that “process” means any operation performed on information about you, including to collect, record, organise, structure, store, alter, use, transfer, destroy or otherwise make available.
On occasion, we will prepare a specific standalone privacy notice, in relation to certain services or in the context of ad-hoc personal data collection forms (e.g., when participating in a survey). Where this occurs, we will advise you at the point at which we collect your personal data.
If you or an entity relevant to you uses Deloitte for any of the services below, you can click on the links for details about how we handle information about you in the relevant service area:
• Audit
• Actuarial Insurance & Banking Solutions
• Deloitte Commercial Database Analysis
If there do not apply to you, please consult the information in the statement below.
This privacy statement applies to Deloitte LLP with its registered office at 1 New Street Square, London, EC4A 3HQ and the entities we own or control.
Our Data Protection Officer can be contacted at Deloitte LLP, 1 New Street Square, London, EC4A 3HQ or the following e-mail address: dpo@deloitte.co.uk.
In the course of providing services to you or our client, performing due diligence checks in connection with our services (or communicating with you regarding possible services we might provide), we may collect or obtain personal data about you in physical and electronic form. We may also collect personal data from you when you use our Website.
We may collect or obtain such data because: (i) you give it to us (for example in a form on our Website), (ii) other people give that data to us (for example your employer or adviser, or third party service providers that we use to help operate our business), or (iii) it is publicly available.
We may also collect or obtain personal data from you because we observe or infer that data about you from the way you interact with us or others. For example, to improve your experience when you use our Website and ensure that it is functioning effectively, we (or our service providers) may use cookies (small text files stored in a user’s browser) and Web beacons which may collect personal data. Additional information on how we use cookies and other tracking technologies and how you can control these can be found in our cookie notice on our Website: Cookies (deloitte.com)
The personal data that we may process may include (but is not limited to):
a) your name, gender, age and date of birth;
b) your contact information, such as your address and contact details (including your email and mobile telephone number), and country of residence;
c) family circumstances (e.g., your marital status and dependents);
d) employment and education details (e.g., the organisation you work for, your job title and your education details);
e) Government identifiers (e.g., your National Insurance number, passport number, driver’s licence);
f) your postings on any blogs, forums, wikis and any other social media applications and services that we provide;
g) your IP address, your browser type and language, your access times, complaint details;
h) details of how you use our products and services;
i) Background information regarding company management, such as beneficial ownership/persons of significant control, the educational and career histories of company principals;
j) Business compliance information from public source government and professional records, media and business publications; and
k) Newspaper and media reports of criminal convictions.
The personal data we collect may also include so called ‘sensitive’ or ‘special categories’ of personal data, such as details about your: dietary requirements (for example, where Deloitte would like to provide you with lunch during a meeting); health (for example, so that we can make reasonable accommodations for you in our buildings or at our events) and sexual orientation (for example, if you provide us with details of your spouse or partner). We may also collect and process personal data relating to ethnic or racial origin e.g. multicultural networks.
If you choose not to provide us with this information, or you object to us processing such information, we may be prevented from processing your instructions or continuing to provide all or some of our services to you or our client.
Use of personal data to provide services to our clients:
a) We will use your personal data to provide you or our clients or other third parties with services. As part of this, we may use your personal data in the course of correspondence relating to the services. Such correspondence may be with you, other third parties, other members of the Deloitte Network, our service providers or competent authorities.
b) We may also use your personal data to conduct due diligence or sanctions screening (where relevant) relating to the services.
i. Because we provide a wide range of services to our clients or other third parties, the way we use personal data in relation to our services also varies. For example, we might use personal data about;
ii. a client's employees to help those employees manage their tax affairs when working overseas;
iii. a client's employees and customers in the course of conducting an audit (or similar activity) for a client; or
iv. a client to help him/her complete a tax return.
Use of personal data for other activities that form part of the operation of our business:
a) We may also use your personal data for the purposes of, or in connection with:
i. applicable legal, regulatory or professional requirements;
ii. requests and communications from competent authorities;
iii. client account opening and other administrative purposes;
iv. financial accounting, invoicing and risk analysis purposes; or
v. protecting our rights and those of our client.
Use of personal data for marketing and business development purposes:
a) We may use your personal data for client and prospect relationship purposes, which may involve;
i. sending you insights, opinions, updates, reports on topical issues or details of our products and services that we think might be of interest to you. contacting you to receive feedback on services;
ii. contacting you to invite you to events, seminars, briefings; or
iii. recruitment and business development purposes (for example testimonials from a client's employees may be used as part of our recruitment and business development materials with that employee's permission).
These communications may come from our Deloitte Alumni Network or be general Deloitte communications. (See paragraph 14 below)
Use of personal data collected via our Website:
a) to enable the navigation of this Website;
b) to manage and improve our Website;
c) to tailor the content of our Website to provide you with a more personalised experience and draw your attention to information about our products and services that may be of interest to you;
d) to send targeted advertising from third parties through advertising and targeting cookies, should you consent to the use of same via our privacy preference centre.
e) to manage and respond to any request you submit through our Website.
In respect of the use of personal data in connection with providing services to our clients and activities relating our business (as set out at paragraphs 6.1 and 6.2 above) we rely on one or more of the following lawful grounds:
a) the processing is necessary to perform the agreement we have with you or to take steps to enter into an agreement with you;
b) the processing is necessary for compliance with a legal obligation we have such as keeping records for tax purposes or providing information to a public body or law enforcement agency; or
c) the processing is necessary for the purposes of a legitimate interest pursued by us, which might be:
i. to provide our services to you or our clients and other third parties and ensure that our client engagements are well-managed;
ii. to prevent fraud;
iii. to protect our business interests;
iv. to ensure that complaints are investigated; or
v. you have explicitly agreed to us processing your information for a specific reason.
In respect of use of personal data for marketing and business development purposes and personal data collected via our Website (as set out in paragraphs 6.3 to 6.6 above), we rely on legitimate interest or you have given us your explicit consent to process that data, for the following purposes:
a) to develop our business and maintain business relationships with clients and business contacts;
b) to evaluate, develop or improve our services or products; or
c) to keep you or our clients informed about relevant products and services and provide you with information, unless you have indicated at any time that you do not wish us to do so.
To the extent that we process any special categories of data relating to you for any of the purposes outlined above, we will do so because either:
a) you have given us your explicit consent to process that data;
b) we are required by law to process that data in order to ensure we meet our 'know your client' and 'anti-money laundering' obligations (or other legal obligations imposed on us);
c) the processing is necessary to carry out our obligations under employment, social security or social protection law;
d) the processing is necessary for the establishment, exercise or defence of legal claims or
e) you have made the data manifestly public.
Please note that in certain circumstances it may be still lawful for us to continue processing your information even where you have withdrawn your consent, if one of the other legal bases described above is applicable.
In connection with one or more of the purposes outlined in the "How we use information about you" section above, we may disclose details about you to the following recipients, or categories of recipients:
a) other members of the Deloitte Network; third parties that provide services to us and/or the Deloitte Network;
b) competent authorities (including courts and authorities regulating us or another member of the Deloitte Network);
c) your employer and/or their advisers;
d) your advisers;
e) any other person or organisation after a restructure, sale or acquisition of any member of the Deloitte Network, as long as that person uses your information for the same purposes as it was originally given to us or used by us (or both);
f) credit reference agencies or other organisations that help us make credit decisions and reduce the incidence of fraud;
g) and other third parties that reasonably require access to personal data relating to you for one or more of the purposes outlined in the "How we use information about you" section above..
Our Website hosts various blogs, forums, wikis and other social media applications or services that allow you to share content with other users (collectively "Social Media Applications"). Importantly, any personal data that you contribute to these Social Media Applications can be read, collected and used by other users of the application. We have little or no control over these other users and, therefore, we cannot guarantee that any information that you contribute to any Social Media Applications will be processed in accordance with this privacy notice.
Information about you in our possession may be transferred to other countries (which may include countries outside the European Economic Area ("EEA"), such as jurisdictions where we do business; jurisdictions linked to your engagement with us; jurisdictions from which you regularly receive or transmit information; or jurisdictions where our third parties conduct their activities.
These countries may have differing (and potentially less stringent) laws relating to the degree of confidentiality afforded to the information it holds and that such information can become subject to the laws and disclosure requirements of such countries, including disclosure to governmental bodies, regulatory agencies and private persons, as a result of applicable governmental or regulatory inquiry, court order or other similar process. In addition, a number of countries have agreements with other countries providing for exchange of information for law enforcement, tax and other purposes.
When we, or our permitted third parties, transfer your personal data outside the UK or EEA, we or they will impose contractual obligations on the recipients of that data to protect your personal data to the standard required in the EEA. We or they may also require the recipient to subscribe to international frameworks intended to enable secure data sharing. We or they may also transfer your personal data where:
a) the transfer is to a country deemed to provide adequate protection of your personal data by the UK government; or
b) where you have consented to the transfer.
If we transfer your personal data outside the EEA or UK in other circumstances (for example because we have to provide such information by law), we will put in place appropriate safeguards to ensure that your personal data remains adequately protected.
We may share non-personal, de-identified and aggregated information with third parties for several purposes, including data analytics, research, submissions, thought leadership and promotional purposes.
The information systems and computer programs used by us are configured in such a way as to minimise the use of personal data.
We keep your personal data for the longest of the following periods:
a) as long as is necessary for the relevant activity or services;
b) any retention period that is required by law; or
c) the end of the period in which litigation or investigations might arise in respect of the services.
We maintain retention schedules relating to the processing of personal data.
We use a range of measures to ensure that we keep your personal data secure, accurate and up to date. These include:
a) education and training to relevant staff to ensure they are aware of our data protection obligations when processing personal data;
b) administrative and technical controls to restrict access to personal data to a 'need to know' basis;
c) technological security measures, including fire walls, encryption and anti-virus software; and
d) physical security measures, such as staff security passes to access our premises.
Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure. We endeavour to protect personal data, but we cannot guarantee the security of data transmitted to us or by us.
You have various rights in relation to your personal data. In particular you have a right to:
a) obtain confirmation that we are processing your personal data and request a copy of the personal data we hold about you;
b) be informed about the processing of your personal data (i.e. for what purposes, what types, to what recipients it is disclosed, storage periods, any third-party sources from where it was obtained, confirmation of whether we undertake automated decision-making, including profiling, and the logic, significance and envisaged consequences);
c) ask that we update the personal data we hold about you, or correct such personal data that you think is incorrect or incomplete;
d) ask that we delete personal data that we hold about you, or restrict the way in which we use such personal data; withdraw consent to our processing of your personal data (to the extent such processing is based on previously obtained consent);
e) receive a copy of the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit such personal data to another party (to the extent the processing is based on consent or a contract);
f) ask us to stop or start sending you marketing messages at any time by using the contact details set out in this Privacy Notice; and
g) object to our processing of your personal data.
Should you request access or wish to see a copy of your personal data, we will endeavour to respond within a reasonable period and in any event within one month in compliance with Data Protection Legislation. We will comply with our legal obligations as regards your rights as a data subject.
We aim to ensure that the information we hold about you is accurate at all times. To assist us in ensuring that your information is up to date, do let us know if any of your personal details change using the contact details set out in this Privacy Notice.
You may also use the contact details in this Privacy Notice if you wish to make a complaint to us relating to your privacy.
If we believe you are a client or business contact who may be interested in our thought leadership or marketing campaigns, we may use your information from time to time to inform you by letter, telephone, email and other electronic methods, about similar products and services (including those of third parties) which may be of interest to you.
If you have indicated that you wish to be part of the Deloitte Alumni Network, we may use your information to provide you with our newsletter and other communications which will inform you about network events, our diversity network activities, career opportunities at Deloitte, our talent scout referral rewards scheme, webinars and other thought leadership.
You may, at any time, withdraw your consent or request a change to your marketing preferences by following the instructions in communications from us or contacting us in the way described in this Privacy Notice.
If you wish to exercise any of the rights relating to your information set out at paragraph 12 above, or if you have any questions or comments about privacy issues, or you wish to raise a complaint about how we are using your information you can contact us in the following ways:
a) Write to our Data Protection Officer at 1 New Street Square, London, EC4A 3HQ.
b) send an email to dpo@deloitte.co.uk
If you have any concerns about our use of your information, you also have the right to make a complaint to the Information Commissioners Office who can be contacted in the following ways;
a) Write to the Information Commissioner at The Office of the Information Commissioner, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF;
b) Via the Information Commissioners data protection complaints tool which can be found at https://ico.org.uk/make-a-complaint/data-protection-complaints/data-protection-complaints/
We may modify or amend this Privacy Notice from time to time. When we make changes to this notice, we will amend the revision date at the top of this page, and such modified or amended Privacy Notice will be effective from that revision date. We therefore invite you to regularly consult this notice to stay up to date with any changes made since your last consultation.
If you are submitting a Personal data request on behalf of someone other than yourself, please contact us by using the contact details in this Privacy Notice and include proof that you are authorised to make the request. This may be in the form of a written authorisation signed by the person whom you are acting on behalf of or a valid power of attorney.