This privacy statement explains what information we gather about you, what we use that information for and who we give that information to. It also sets out your rights in relation to your information and who you can contact for more information or queries. We are committed to protecting your privacy and handling your information in an open and transparent manner. Click on the accordion labels below to take you to the more detailed sections of this statement.
This privacy statement applies to Deloitte Legal ehf. belonging to the Deloitte network (the Deloitte network being Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee („DTTL“), together with its member firms and their respective subsidiaries, affiliates and other firms with which in constitutes a network called the „DTTL network“), with registered office address at Dalvegur 30, Kópavogur, Iceland.
Deloitte Legal ehf., qualifies as data controller in relation to the processing of your personal data. This privacy statement sets out how we will collect, handle, store and protect information about you when:
When we refer to “our Website” or “this Website” in this statement we mean the specific webpages of deloitte.com designated as Iceland in the upper right hand corner.
Deloitte.com is comprised of various global, regional, country and practice specific websites, each of which is provided by DTTL or one of its independent member firms or their related entities (collectively, the “Deloitte Network”). To learn more about DTTL, the member firms of DTTL and their related entities, please see „About Deloitte“.
This privacy statement also contains information about when we share your personal data with other members of the Deloitte Network and other third parties (for example, our service providers).
In this privacy statement, your information is sometimes called “personal data” or “personal information”. We may also sometimes collectively refer to handling, collecting, protecting and storing your personal information as “processing” such personal information.
In the course of providing services to you or our clients and performing due diligence checks in connection with our services (or discussing possible services we might provide), we will collect or obtain personal data about you. We may also collect personal data from you when you use our Website.
We may collect or obtain such data because:
We may also collect or obtain personal data from you because we observe or infer that data about you from the way you interact with us or others. For example, to improve your experience when you use our Website and ensure that it is functioning effectively, we (or our service providers) may use cookies (small text files stored in a user’s browser) and Web beacons which may collect personal data. Additional information on how we use cookies and other tracking technologies and how you can control these can be found in our „cookie notice“.
The personal data that we collect or obtain may include:
The personal data we collect may also include so called ‘sensitive’ or ‘special categories’ of personal data, such as details about your: dietary requirements (for example, where Deloitte would like to provide you with lunch during a meeting), health (for example, so that we can make reasonable accommodations for you in our buildings, products and services) and sexual orientation (for example if you provide us with details of your spouse or partner).
The types of personal data and special categories of personal data that we collect may vary depending on the nature of the services that we provide to you or our client, or how you use our Website. In some rare circumstances, we might also gather other special categories of personal data about you because you volunteer that data to us or we are required to gather that data as a result of legal requirements imposed on us.
Where we are provided with personal data about you by our client or another third party, we take steps to ensure that they have complied with the privacy laws and regulations relevant to that information. This may include, for example, that the client or other third party has informed you of the processing, and has obtained any necessary permission for us to process that information as described in this privacy statement.
We will use your personal data to provide you or our client with the requested services. As part of this, we may also use your personal data in the course of correspondence relating to the services. Such correspondence may be with you, our client, other members of the Deloitte Network, our service providers or competent authorities.
We may also use your personal data to conduct due diligence checks relating to the services. Because we provide a wide range of services to our clients, the way we use personal data in relation to our services also varies. For example, we might use personal data:
We may also use your personal data for the purposes of, or in connection with:
We may also use your personal data regarding our client relationship management, which may involve:
In all above cases, we give you the opportunity to decline our offers and requests at any time in our communications.
In addition to the purposes connected to the operation of our business above, we may also use your personal data collected via our Website:
In respect of the use of personal data in connection with providing services to our clients and activities relating to our business we rely on one ore more of the following lawful grounds:
To the extent that we process any sensitive personal data relating to you for any of the purposes outlined above, we will do so because either: (a) you have given us your explicit consent to process that data; (b) we are required by law to process that data in order to ensure we meet our ‘know your client’ and ‘anti-money laundering’ obligations (or other legal obligations imposed on us); (c) the processing is necessary to carry out our obligations under employment, social security or social protection law; (d) the processing is necessary for the establishment, exercise or defence of legal claims or (e) you have made the data public.
In connection with one or more of the purposes outlined in the “How we use information about you?” section above, we may disclose details about you to: other members of the Deloitte Network; third parties that provide services to us and/or the Deloitte Network; competent authorities (including courts and authorities regulating us or another member of the Deloitte Network); your employer and/or their advisers; your advisers; organizations that help us reduce the incidence of fraud and other third parties that reasonably require access to personal data relating to you for one or more of the purposes outlined in the “How we use information about you?” section above.
Our Website hosts various blogs, forums, wikis and other social media applications or services that allow you to share content with other users (collectively “Social Media Applications”). Importantly, any personal information that you contribute to these Social Media Applications can be read, collected and used by other users of the application. We have little or no control over these other users and, therefore, we cannot guarantee that any information that you contribute to any Social Media Applications will be handled in accordance with this privacy statement.
Please note that some of the recipients of your personal data referenced above may be based in countries outside of the European Economic Area whose laws may not provide the same level of data protection. In such cases, Deloitte will ensure that there are adequate safeguards in place to protect your personal data that comply with our legal obligations. We may also need to disclose your personal data if required to do so by law, a regulator or during legal proceedings.
We may share non-personal, de-identified and aggregated information with third parties for several purposes, including data analytics, research, submissions, thought leadership and promotional purposes.
We use a range of physical, electronic and managerial measures to ensure that we keep your personal data secure, accurate and up to date. These measures include:
Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure. We endeavor to protect personal data, but we cannot guarantee the security of data transmitted to us or by us.
You have various rights in relation to your personal data. In particular, you have a right to:
To exercise any of your rights, or if you have any other questions about our use of your personal data, please email isprivacy@deloitte.com or write to us at the address below:
Deloitte Legal ehf. Att. Privacy
Dalvegur 30
201 Kópavogur, Iceland
You may also use these contact details if you wish to make a complaint to us relating to your privacy.
We may modify or amend this privacy statement from time to time.
When we make changes to this privacy statement, we will amend the revision date at the top of this page. The modified or amended privacy statement will apply from that date. We encourage you to review this statement periodically to remain informed about how we are protecting your information.