Legal

Privacy Policy

Privacy Policy


Control Risks Group Limited registered in England under registration number 01810707 and with a registered address at Cottons Centre, Cottons Lane, London SE1 2QG ("Control Risks") operates the website www.controlrisks.com (the “Site”) and organises its maintenance and the placing of its content. In this policy, “Control Risks” refers to Control Risks and its parent company: Control Risks International Limited and may refer to one or more of the members of that group each of which is a separate legal entity.   For a full list of such entities, please click here.

Control Risks is the controller of any personal data collected through the Site and will process such information in accordance with applicable data protection law including the EU General Data Protection Regulation ("GDPR") (in force from 25 May 2018). Any enquiries relating to data protection issues should be sent to our legal team at legal@controlrisks.com.

Control Risks understands that privacy is important to users of the Site and is committed to respecting your privacy and protecting your personal information. This policy sets out Control Risks’ approach to the collection, storage, usage and transfer or disclosure of collected information in connection with this Site. It also includes a description of your data protection rights which, in some instances, will include a right to object to the processing we carry out.  

To that end, please note that you have the right to object:

(a) at any time to Control Risks' use of your personal information for direct marketing purposes; and

(b) to Control Risks' processing of your personal information where it is based on our legitimate interests, unless we have compelling legitimate grounds to process the information, or we need to do so in relation to legal claims.

Further information on exercising these rights is set out in the Users' Rights section below. 

Information we collect
Control Risks collects, receives, stores and processes the following information: 

  • information that you provide when using the Site, including information you provide when registering to use certain portions of the Site;
  • information you provide when applying for a job with Control Risks which includes the information you provide within any CV submitted to Control Risks;  
  • any information you provide when subscribing to any marketing or mailing initiatives; and
  • information contained in, or relating to, any communications you send to us or send through the Site (including the communication content and meta data associated with the communication). 

Information supplied for the above purposes may include your name, address, telephone number, email address, data of birth, educational details and any other additional information that you may supply. These data collection forms use cookies (please see our Use of Cookies Policy).

Use of Data
Control Risks will use your personal information for various purposes which include:  

  • to provide our services to you; 
  • to administer the Site;
  • to maintain our business relationship, where you are a user of the Site, a client or a recruitment candidate; 
  • to provide you with information that you have specifically requested or that we have asked if you would like to receive including marketing and invitations to conferences and/or events;
  • to deal with enquiries and complaints made by or about you relating to us or the Site;
  • to keep the Site and systems secure and prevent fraud; 
  • where relevant, to meet legal, regulatory and compliance requirements;
  • where relevant, for the establishment, exercise or defence of legal claims;
  • to protect the rights, property, or safety of Control Risks, our clients, or others;
  • to understand your interests and preferences so we can tailor the content, offers and promotions we surface on the Site to better match your interests and preferences – see also our Cookie Policy; and
  • to compile anonymous statistical data about the use of the Site to improve its content and usability. 

Where required for the purpose for which the personal information was initially supplied by you, personal information may be shared with Control Risks' affiliates and associated companies as well as third party service providers who perform services or functions on our behalf, under the protections required under GDPR or other applicable law. In particular, if you supply personal information for marketing events or services operated by Travel Security Services Limited, the joint venture travel security company owned by Control Risks and International SOS, you should note that your personal information will be exchanged between the companies with all legally required data protection requirements being in place.

The Legal Basis for Processing your Personal Information
Under the GDPR, the main grounds that Control Risks relies upon in order to process your personal information are the following:

a) Necessary for entering into, or performing, a contract – in order to perform obligations that we undertake in providing service(s) to you, or in order to take steps at your request to enter into a contract with us, it will be necessary for us to process your personal data; 
b) Necessary for compliance with a legal obligation – we are subject to certain legal requirements which may require us to process your personal data.   We may also be obliged by law to disclose your personal data to a regulatory body or law enforcement agency;
c) Necessary for the purposes of legitimate interests -  either we, or a third party, will need to process your personal data for the purposes of our (or a third party's) legitimate interests, provided we have established that those interests are not overridden by your rights and freedoms, including your right to have your personal data protected.  Our legitimate interests include responding to requests and enquiries from you or a third party, optimising our website and customer experience, informing you about our services and ensuring that our operations are conducted in an appropriate and efficient manner;
d) Consent – in some circumstances, we may ask for your consent to process your personal data in a particular way. To the extent that we are processing your personal information based on your consent, you will have the right to withdraw your consent at any time. You can do this by contacting us using the details in the Contact section at the bottom of this page.   

Security
The security and protection of personal information supplied to you as a user of the Site is of the highest importance and concern to Control Risks. We have in place all generally accepted standards of technology and operational security in order to protect personal information submitted to the Site from loss, misuse, alteration or destruction and to ensure compliance with the requirements of all applicable data protection and privacy legislation. 

Notwithstanding the arrangements set out above, unfortunately the transmission of information via the internet is not completely secure. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

User's rights
You have certain rights in relation to personal information we hold about you. Details of these rights and how to exercise them are set out below.  We will require evidence of your identity before we are able to act on your request.

Right of Access
You have the right at any time to ask us for a copy of your personal information that we hold.  Where we have good reason, and if the GDPR permits, we can refuse your request for a copy of your personal information, or certain elements of the request (for example, if we would also be disclosing third party personal data). If we refuse your request or any element of it, we will provide you with our reasons for doing so.

Right of Correction or Completion
If personal information we hold about you is not accurate, out of date or incomplete, you have a right to have the data rectified, updated or completed.  Therefore, please advise us of any changes to your information. You can let us know by contacting us using the details in the Contacts section at the bottom of this page.

Right of Erasure
In certain circumstances, you have the right to request that personal information we hold about you is erased e.g. if the information is no longer necessary for the purposes for which it was collected or processed or our processing of the information is based on your consent (which you wish to withdraw) and there are no other legal grounds on which we may process the information.

Right to object to or restrict processing
In certain circumstances, you have the right to object to our processing of your personal information by contacting us using the details in the Contacts section at the bottom of this page.  For example, if we are processing your information on the basis of our legitimate interests and there are no compelling legitimate grounds for our processing which override your rights and interests.   You also have the right to object to use of your personal information for direct marketing purposes.

You may also have the right to restrict our use of your personal information, such as in circumstances where you have challenged the accuracy of the information and during the period where we are verifying its accuracy.

Right of Data Portability
In certain instances, you have a right to receive any personal information that we hold about you in a structured, commonly used and machine-readable format. 

You can ask us to transmit that information to you or directly to a third party organisation. 

The above right exists only in respect of personal information that:

  • you have provided to us previously; and
  • is processed by us using automated means.

While we are happy for such requests to be made, we are not able to guarantee technical compatibility with a third party organisation's systems. Also, we may be unable to comply with requests that relate to personal information of others without their consent.  

You can exercise any of the above rights by contacting us using any of the methods in the Contact section at the bottom of this page.

Most of the above rights are subject to limitations and exceptions.  We will provide reasons if we are unable to comply with any request for the exercise of your rights. 

Retention
Any personal information you submit to us will be retained for the period necessary to fulfil the purpose for which it was collected or, where the information is required for longer, in accordance with our data retention policies. However, you may always ask us to permanently erase your information and in certain circumstances you have a legal right to request such erasure (see above).

Children
Control Risks does not intend that children should visit the Site. Control Risks understands that children merit special protection and will never knowingly process their personal information.

Disclosure of Personal Information to Third Parties
Control Risks will not share any personal information collected on the Site with third parties unless required by law, required to enable the fulfilment of the purpose for which the personal information was originally supplied or as otherwise set out in this policy. Control Risks may transfer all or part of its business in the circumstances of a merger or sale of part or all of its business. In such circumstances personal information you supply may be transferred but this will be only in circumstances where the acquiring company has agreed to the same standards and terms of privacy as are set out in this policy.  Control Risks remains liable to you in respect of its obligations concerning your personal data in cases of onward transfers to third parties.

EU/US Privacy Shield
Control Risks complies with the European Union/United States Privacy Shield Framework regarding the collection, use and retention of personal information transferred from the European Union to the United States. Control Risks has certified to the U.S. Department of Commerce that it adheres to the Privacy Shield principles. To learn more about the Privacy Shield Program and to view Control Risks’ certification, please visit https://www.privacyshield.gov

Control Risks Group LLC, a subsidiary of Control Risks Group Holdings Limited, is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).  Under certain conditions, it is possible for any individual who wishes to do so to invoke binding arbitration in respect of the treatment of their personal data by Control Risks Group LLC. 

In compliance with the Privacy Shield Principles, Control Risks Group LLC commits to resolve complaints about our collection or use of your personal information.  EU individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Control Risks Group LLC at: legal@controlrisks.com.

Control Risks Group LLC has further committed to cooperate with the panel established by the EU data protection supervisory authorities with regard to unresolved Privacy Shield complaints concerning data transferred from the EU.

Complaints
If you are unhappy about our use of your personal information, you can contact us using the details in the Contact section at the bottom of this page. You are also entitled to lodge a complaint with the UK Information Commissioner's Office using any of the below contact methods:

Telephone: 0303 123 11113

Website: https://ico.org.uk/concerns/ 

Post: Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

If you live or work outside the UK or you have a complaint concerning our activities outside the UK, you may prefer to lodge a complaint with a different supervisory authority.  A list of relevant authorities in the EEA and the European Free Trade Area can be accessed here.

Data Processed During Provision of Services
This Privacy Policy primarily relates to personal data collected and processed as a result of your interaction with the Site.  However, in the course of providing due diligence services to clients, we may process personal data on individuals who are the subject of, or relevant to, those services.  

In accordance with GDPR, we do not provide fair processing notices to such individuals as to do so would seriously impair the achievement of the objectives of that processing.  We treat all such data in accordance with our obligations under GDPR.  We make this statement in compliance with our obligation under article 14(5)(b) GDPR to publicise that nature of the information that would otherwise be contained in any such fair processing notice.

Personal data obtained and processed in the course of providing client services will typically include a summary of the individual’s profile or reputation in the market. 

The data will be collected for the purpose of providing due diligence reports to our clients.  The lawful bases under GDPR for such data processing will vary depending on the nature of the data and the project, but will include:

a) necessary for the purpose of our or our client's legitimate interests.  These interests may include ensuring that the client does not take actions that could result in legal liability, reputational impact or other adverse effects;
b) necessary for the prevention or detection of an unlawful act;
c) necessary for the establishment, exercise or defence of a legal claim;
d) the data has been manifestly made public by the data subject.

The sources of the data include public record research, human source enquiries, interviews with subjects and associates / colleagues and information provided to us by our client.

Third parties with whom we may share such data include, other members of the Control Risks Group, our client who commissioned the work and its advisers who have, themselves, a lawful basis for processing the data, and our subcontractors who are involved in gathering the information.

Individuals whose data is processed during the course of our client services have the same rights as all other data subjects.  Please see above for details, and the Contact section below for details of how to exercise your rights. 

Changes to our Privacy Policy
This privacy policy can be changed by Control Risks at any time. If we change our privacy policy in the future, we will advise you of material changes or updates to our privacy policy by e-mail.

Contact 
If you have any enquires or if you would like to contact us about our processing of your personal information, including to exercise your rights as outlined above, please contact us by using one of the methods listed below.

When you contact us, we will ask you to verify your identity.

Contact name: Sally McNair Scott (Data Protection Officer)

Email: legal@controlrisks.com

Telephone: 020 7970 2200

Post: Cottons Centre, Cottons Lane, London SE1 2QG
  

Further information

Legal

Legal Notices

This website is operated by Control Risks Group Limited (“Control Risks”), a wholly owned subsidiary company of Control Risks Group Holdings Limited (“CRGH”). The website also contains content supplied by international subsidiaries of CRGH.

Legal

Use of Cookies

Control Risks Group Limited (“Control Risks”) operates the website www.controlrisks.com (the “Site”) and organises its maintenance and the placing of its content. Control Risks is strongly committed to issues of privacy. This page contains information about our use of cookies on the Site.