Control Risks Group Limited registered in England under registration number 01810707 and with a registered address at Cottons Centre, Cottons Lane, London SE1 2QG ("Control Risks") operates the website (the "Site") and organises its maintenance and the placing of its content. In this policy, "Control Risks" refers to Control Risks and its parent company: Control Risks International Limited and may refer to one or more of the members of that group each of which is a separate legal entity. For a full list of such entities, please click here.

Control Risks is the controller of any personal data collected through the Site and will process such information in accordance with applicable data protection law including the EU General Data Protection Regulation 2016/679, as incorporated into UK legislation ("GDPR"). Any enquiries relating to data protection issues should be sent to our legal team at [email protected].

Control Risks understands that privacy is important and is committed to respecting your privacy and protecting your personal information. This policy sets out Control Risks’ approach to the collection, storage, usage and transfer or disclosure of information you provide to us and information we collect in the course of operating our business or in connection with this Site. It also includes a description of your data protection rights which, in some instances, will include a right to object to the processing we carry out.

To that end, please note that you have the right to object:

(a) at any time to Control Risks' use of your personal information for direct marketing purposes; and

(b) to Control Risks' processing of your personal information where it is based on our legitimate interests, unless we have compelling legitimate grounds to process the information, or we need to do so in relation to legal claims.

Further information on exercising these rights is set out in the Users' Rights section below. 

Information we collect

Control Risks collects, receives, stores and processes the following information: 

  • information that you provide when using the Site, including information you provide when registering to use certain portions of the Site;
  • information you provide when applying for a job with Control Risks which includes the information you provide within any CV submitted to Control Risks;  
  • any information you provide when subscribing to any marketing or mailing initiatives; and
  • information contained in, or relating to, any communications you send to us or send through the Site (including the communication content and meta data associated with the communication). 

Information supplied for the above purposes may include your name, address, telephone number, email address, date of birth, educational details and any other additional information that you may supply. These data collection forms use cookies (please see our Use of Cookies Policy).

Use of Data

Control Risks will use your personal information for various purposes which include:  

  • to provide our services to you; 
  • to administer the Site;
  • to maintain our business relationship, where you are a user of the Site, a client or a recruitment candidate; 
  • to provide you with information that you have specifically requested or that we have asked if you would like to receive including marketing and invitations to conferences and/or events;
  • to deal with enquiries and complaints made by or about you relating to us or the Site;
  • to keep the Site and systems secure and prevent fraud; 
  • where relevant, to meet legal, regulatory and compliance requirements;
  • where relevant, for the establishment, exercise or defence of legal claims;
  • to protect the rights, property, or safety of Control Risks, our clients, or others;
  • to understand your interests and preferences so we can tailor the content, offers and promotions we surface on the Site to better match your interests and preferences – see also our Cookie Policy; and
  • to compile anonymous statistical data about the use of the Site to improve its content and usability.  

Where required for the purpose for which the personal information was initially supplied by you, personal information may be shared with Control Risks' affiliates and associated companies as well as third party service providers who perform services or functions on our behalf, under the protections required under GDPR or other applicable law. 

We will not use your personal data for direct marketing purposes unless you have specifically consented to receive such communications.

The Legal Basis for Processing your Personal Information

Under the GDPR, and where applicable under analogous data protection laws, the main grounds that Control Risks relies upon in order to process your personal information are the following:  

a) Necessary for entering into, or performing, a contract – in order to perform obligations that we undertake in providing service(s) to you, or in order to take steps at your request to enter into a contract with us, it will be necessary for us to process your personal data;  
b) Necessary for compliance with a legal obligation – we are subject to certain legal requirements which may require us to process your personal data.   We may also be obliged by law or for national security reasons to disclose your personal data to a regulatory body, government agency, court of competent jurisdiction, regulatory body or law enforcement agency in response to a lawful request submitted by court order, subpoena, warrant, or similar legal mechanism that carries equal weight;
c) Necessary for the purposes of legitimate interests - either we, or a third party, will need to process your personal data for the purposes of our (or a third party's) legitimate interests, provided we have established that those interests are not overridden by your rights and freedoms, including your right to have your personal data protected.  Our legitimate interests include responding to requests and enquiries from you or a third party, optimizing our website and customer experience, informing you about our services and ensuring that our operations are conducted in an appropriate and efficient manner;
d) Consent – in some circumstances, we may ask for your consent to process your personal data in a particular way. To the extent that we are processing your personal information based on your consent, you will have the right to withdraw your consent at any time. You can do this by contacting us using the details in the Contact section at the bottom of this page. 


The security and protection of personal information supplied to you as a user of the Site is of the highest importance and concern to Control Risks. We have in place all generally accepted standards of technology and operational security in order to protect personal information submitted to the Site from loss, misuse, alteration or destruction and to ensure compliance with the requirements of all applicable data protection and privacy legislation. 

Notwithstanding the arrangements set out above, unfortunately the transmission of information via the internet is not completely secure. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.

User's rights

You have certain rights in relation to personal information we hold about you. Details of these rights and how to exercise them are set out below. We will require evidence of your identity before we are able to act on your request.

Right of Access

You have the right at any time to ask us for a copy of your personal information that we hold.  Where we have good reason, and if the GDPR or other applicable data protection law permits, we can refuse your request for a copy of your personal information, or certain elements of the request (for example, if we would also be disclosing third party personal data). If we refuse your request or any element of it, we will provide you with our reasons for doing so.

Right of Correction or Completion

If personal information we hold about you is not accurate, out of date or incomplete, you have a right to have the data rectified, updated or completed. Therefore, please advise us of any changes to your information. You can let us know by contacting us using the details in the Contacts section at the bottom of this page.

Right of Erasure

In certain circumstances, you have the right to request that personal information we hold about you is erased e.g. if the information is no longer necessary for the purposes for which it was collected or processed or our processing of the information is based on your consent (which you wish to withdraw) and there are no other legal grounds on which we may process the information.

Right to object to or restrict processing

In certain circumstances, you have the right to object to our processing of your personal information by contacting us using the details in the Contacts section at the bottom of this page. For example, if we are processing your information on the basis of our legitimate interests and there are no compelling legitimate grounds for our processing which override your rights and interests. You also have the right to object to use of your personal information for direct marketing purposes.

You may also have the right to restrict our use of your personal information, such as in circumstances where you have challenged the accuracy of the information and during the period where we are verifying its accuracy.

Right of Data Portability

In certain instances, you have a right to receive any personal information that we hold about you in a structured, commonly used and machine-readable format. 

You can ask us to transmit that information to you or directly to a third party organization. 

The above right exists only in respect of personal information that:

  • you have provided to us previously; and
  • is processed by us using automated means.

While we are happy for such requests to be made, we are not able to guarantee technical compatibility with a third party organization’s systems. Also, we may be unable to comply with requests that relate to personal information of others without their consent.  

You can exercise any of the above rights by contacting us using any of the methods in the Contact section at the bottom of this page.

Most of the above rights are subject to limitations and exceptions. We will provide reasons if we are unable to comply with any request for the exercise of your rights. 


Control Risks does not intend that children should visit the Site. Control Risks understands that children merit special protection and will never knowingly process their personal information.

Disclosure of Personal Information to Third Parties

Control Risks will not share any personal information collected on the Site with third parties unless required by law, required to enable the fulfilment of the purpose for which the personal information was originally supplied or as otherwise set out in this policy. Control Risks may transfer all or part of its business in the circumstances of a merger or sale of part or all of its business. In such circumstances personal information you supply may be transferred but this will be only in circumstances where the acquiring company has agreed to the same standards and terms of privacy as are set out in this policy. Control Risks remains liable to you in respect of its obligations concerning your personal data in cases of onward transfers to third parties.

EU-U.S. Privacy Shield + Swiss-U.S. Privacy Shield

Control Risks relies on the European Commission’s Standard Contractual Clauses to transfer personal data from the EU to the US and recognises that the EU-U.S. Privacy Shield Framework is no longer a valid data protection mechanism for such transfers.  

In addition, Control Risks complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use and retention of personal information transferred from the European Union and Switzerland to the United States. Control Risks has certified to the U.S. Department of Commerce that it adheres to the Privacy Shield principles. If there is a conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield Program and to view Control Risks’ certification, please visit

Control Risks Group LLC, a subsidiary of Control Risks Group Holdings Limited, is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). Under certain conditions, it is possible for any individual who wishes to do so to invoke binding arbitration in respect of the treatment of their personal data by Control Risks Group LLC. Control Risks Group LLC also commits to cooperate with the Swiss Federal Data Protection and Information Commissioner (FDPIC) and comply with the advice given by such authorities with regard to human resources data transferred from Switzerland in the context of the employment relationship.

In compliance with the Privacy Shield Principles, Control Risks Group LLC commits to resolve complaints about our collection or use of your personal information. EU individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Control Risks Group LLC at: [email protected].

Control Risks Group LLC has further committed to cooperate with the panel established by the EU data protection supervisory authorities with regard to unresolved Privacy Shield complaints concerning data transferred from the EU.


If you are unhappy about our use of your personal information, you can contact us using the details in the Contact section at the bottom of this page. You are also entitled to lodge a complaint with the UK Information Commissioner's Office using any of the below contact methods:

Telephone: 0303 123 11113


Post: Information Commissioner's Office
Wycliffe House
Water Lane

If you live or work outside the UK or you have a complaint concerning our activities outside the UK, you may prefer to lodge a complaint with a different supervisory authority. A list of relevant authorities in the EEA and the European Free Trade Area can be accessed here.

If you are dealing with Control Risks (Middle East) Ltd. (registered in the Dubai International Financial Centre with registration number 0093) or Control Risks (Middle East) Ltd is a controller of your personal data for other reasons, you have the right to lodge a complaint with the Dubai International Financial Centre Commissioner of Data Protection.

Data Processed During Provision of Services

This Privacy Policy primarily relates to personal data collected and processed as a result of operating our business or your interaction with the Site. However, in the course of providing due diligence services to clients, we may process personal data on individuals who are the subject of, or relevant to, those services.  

In accordance with GDPR or other applicable data protection laws, where we are a controller of the personal data in relation to due diligence services, we do not provide fair processing notices to such individuals as to do so would seriously impair the achievement of the objectives of that processing.  We treat all such data in accordance with our obligations under GDPR or other applicable data protection laws.  We make this statement in compliance with our obligation under article 14(5)(b) GDPR to publicize that nature of the information that would otherwise be contained in any such fair processing notice.

Personal data obtained and processed in the course of providing client services will typically include a summary of the individual’s profile or reputation in the market.  

The data will be collected for the purpose of providing due diligence reports to our clients.  The lawful bases under GDPR, or analogous data protection laws, for such data processing will vary depending on the nature of the data and the project, but will include:

a) necessary for the purpose of our or our client's legitimate interests.  These interests may include ensuring that the client does not take actions that could result in legal liability, reputational impact or other adverse effects;
b) necessary for the prevention or detection of an unlawful act;
c) necessary for the establishment, exercise or defence of a legal claim;
d) the data has been manifestly made public by the data subject.

We are a controller of personal data which is collected through source enquiries with suitable individuals. We are a processor of personal data which is collected through open-source research, which includes public record (such as press articles, corporate filings, court records, and the records of central and local government departments and statutory bodies), news aggregators, specialist databases, social media and deep-web research.

Third parties with whom we may share such data include, other members of the Control Risks Group, our client who commissioned the work and its advisers who have, themselves, a lawful basis for processing the data, and our subcontractors who are involved in gathering the information.

Individuals whose data is processed during the course of our client services have the same rights as all other data subjects. Please see above for details, and the Contact section below for details of how to exercise your rights. 


Personal data is stored according to our global data retention and data protection policies. Our policies establish that personal data is stored no longer than is necessary for the purposes for which it was processed.

Changes to our Privacy Policy

This privacy policy can be changed by Control Risks at any time. If we change our privacy policy in the future, we will advise you of material changes or updates to our privacy policy by e-mail.


If you have any enquires or if you would like to contact us about our processing of your personal information, including to exercise your rights as outlined above, please contact us by using one of the methods listed below.

When you contact us, we will ask you to verify your identity.

Contact name: Global General Counsel (Data Protection Officer)

Email: [email protected]

Telephone: 020 7970 2200

Post: Cottons Centre, Cottons Lane, London SE1 2QG