Privacy

Privacy Statement

Last revised: 14 August 2020

Privacy Statement Summary

This privacy statement explains what information we gather about you, what we use that information for, and who we give that information to. It also sets out your rights in relation to your information and who you can contact for more information or queries. Click on the links below to take you to the more detailed sections of this statement:

Who this privacy statement applies to and what it covers

Which personal data we collect

How we use personal data

The legal grounds we use for processing personal data

Sharing your personal data

Protection of your personal information

How long we keep your information for

Your rights

Sending you marketing information

Changes to this privacy statement

Who this privacy statement applies to and what it covers?

This privacy statement applies to Deloitte Malta and its related entities, being members of Deloitte Central Mediterranean S.r.l. with registered office address at Deloitte Place, Triq L-Intornjatur, Central Business District, CBD 3050 Malta (“Deloitte”, “we”, “us” or “our”).

We are committed to protecting your privacy and handling your information in an open and transparent manner, and at all times in compliance with the provisions of the General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC) and the Data Protection Act (Chapter 440 of the laws of Malta), and other relevant legislation and/or regulations and/or guidance as may be relevant (“Data Protection Legislation”).

This privacy statement sets out how we will collect, handle, store and protect information about you when:

  • providing services to you or our clients;
  • you use our Website; or
  • performing any other activities that form part of the operation of our business.

This privacy statement also contains information about when we share your personal data with other members of the Deloitte Network and other third parties (for example, our service providers).

In this privacy statement, your information is sometimes called “personal data”. We may also sometimes collectively refer to handling, collecting, protecting and storing your personal information as “processing” such personal information.

When we refer to “our Website” or “this Website” in this statement we mean the specific webpages of deloitte.com designated as “Malta” in the upper right hand corner and to specific webpages with a URL commencing ‘http://www.deloitte.com/mt'

Deloitte.com is comprised of various global, country, regional and practice specific websites, each of which is provided by Deloitte Touche Tohmatsu Limited (“DTTL”) or one of its independent member firms or their related entities (collectively, the “Deloitte Network”). Such websites, as well as other websites that may be linked to this Website, are not governed by this privacy statement. We encourage visitors to review the privacy statements on each of these other websites before disclosing any personal information. To learn more about DTTL, the member firms of DTTL and their related entities, please see About Deloitte.

This privacy statement also contains information about when we share your personal data with other members of the Deloitte Network and other third parties (for example, our service providers).

In this privacy statement, your information is sometimes called “personal data” or “personal information”. We may also sometimes collectively refer to handling, collecting, protecting and storing your personal information as “processing” such personal information.

Which personal data we collect?

We may collect, record and use your personal data in physical and electronic form, and will hold, use and otherwise process that data in line with the Data Protection Legislation and as set out in this statement.

When we provide services to you or our clients and perform due diligence checks in connection with our services (or discuss possible services we might provide), we will process personal data about you. We may also collect personal data from you when you use this Website.

We may process your data because:

  • you give it to us (for example, in a form on our Website such as the My Deloitte portal);
  • other people give it to us (for example, your employer or adviser, or third- party service providers that we use to help operate our business);
  • we are required to do so, by government or public authorities (for example, for contact tracing in Covid-19 pandemic); and
  • it is publicly available.

We may also collect or obtain personal data from you because we observe or infer that data about you from the way you interact with us. For example, to improve your experience when you use this Website and ensure that it is functioning effectively, we (or our service providers) may use cookies (small text files stored in a user’s browser) and web beacons which may collect personal data. Additional information on how we use cookies and other tracking technologies and how you can control these can be found in our cookie notice.

The personal data we process may include your:

  • name, gender, age and date of birth;
  • contact information, such as address, email, and mobile phone number;
  • country of residence;
  • family circumstances (for example, your marital status and dependents);
  • employment and education details (for example, the organisation you work for, your job title and your education details);
  • financial and tax-related information (for example your income, investments and tax residency);
  • postings or messages on any blogs, forums, platforms, wikis or social media applications and services that we provide (including with third parties);
  • IP address, browser type and language, your access times;
  • information in any complaints you make ;
  • details of how you use our products and services;
  • CCTV footage and other information we collect when you access our premises; and
  • details of how you like to interact with us, and other similar information relevant to our relationship.

The personal data we collect may also include so called ‘sensitive’ or ‘special categories’ of personal data, such as details about your:

  • dietary requirements (for example, when Deloitte would like to provide you with lunch during a meeting);
  • health (for example, so that we can make it easy for you to access our buildings, products and services); and
  • sexual orientation (for example, if you provide us with details of your spouse or partner).

We may also process personal data relating to ethnic or racial origin (for example, any multicultural networks you belong to), or about your political opinions (inferred from information you give us about political associations you belong to or have donated to, or from information that is publicly available).

If you choose not to provide, or object to us processing, the information we collect (see “Your rights” section below), we may not be able to process your instructions or continue to provide some or all of our services to you or our client.

We will, where necessary, obtain your explicit consent to collect and use such information.

We do not engage in the collection of personal information about your online activities across third-party websites or online services and we do not allow third parties to collect such personal information when you use the Website.

How we use your personal data

We process information about you and/or your business to enable us and other members of the Deloitte Network to provide our services to you or our clients, and to meet our legal or regulatory obligations.

Some of your personal data may be used for other business purposes. Below are some examples.

Use of personal data to provide services to our clients

We will use your personal data to provide you or our clients or other third parties with services, and this includes using your personal data in correspondence relating to those services. That correspondence may be with:

  • you;
  • other third parties or other members of the Deloitte Network;
  • our service providers; or
  • competent authorities.

We may also use your personal data to conduct due diligence checks relating to the services.

Because we provide a wide range of services to our clients or other third parties, the way we use personal data in relation to our services also varies. For example, we might use personal data about:

  • a client’s employees to help those employees manage their tax affairs when working overseas;
  • a client’s employees and customers in the course of conducting an audit (or similar activity) for a client; or
  • a client to help them complete a tax return.
Use of personal data for other activities that form part of the operation of our business

We may also use your personal data in connection with:

  • legal or regulatory requirements;
  • requests and communications from competent authorities;
  • client account opening and other administrative tasks;
  • financial accounting, invoicing and risk analysis;
  • relationship management, which may involve:
    (a) sending you thought leadership or details of our products and services;
    (b) contacting you for feedback on services;
    (c) sending you event invitations; and
    (d) other marketing or research purposes;
  • recruitment and business development, which may involve:
    (a) the use of testimonials from a client’s employees as part of our recruitment and business development materials (with that employee’s permission); and
    (b) the use of third-party data sources to help us verify and improve the information we hold about key business relationships with individuals;
  • services we receive from our professional advisors, such as lawyers, accountants and consultants;
  • investigating or preventing security incidents; or
  • protecting our rights and those of our clients.
Use of personal data collected via our Website

In addition to the above, we may also use your personal data collected via our Website:

  • to manage and improve our Website;
  • to tailor the content of our Website to give you a more personalized experience;
  • to draw your attention to information about our products and services that may be of interest to you; or
  • to manage and respond to any request you submit through our Website.

Your personal information may also be used to protect our rights or property and that of our users and, where appropriate, to comply with legal process.

The legal grounds we use for processing personal data

We are required by law to set out in this privacy statement the legal grounds on which we rely in order to process your personal data. We rely on one or more of the following lawful grounds:

  • you have explicitly agreed to us processing your information for a specific reason;
  • the processing is necessary to perform the agreement we have with you or to take steps to enter into an agreement with you;
  • the processing is necessary for compliance with a legal obligation we have such as keeping records for tax purposes or providing information to a public body or law enforcement agency; or
  • the processing is necessary for the purposes of a legitimate interest pursued by us or a third party, which might be:
    (a) to provide our services to you or our clients and other third parties and ensure that our client engagements are well-managed;
    (b) to prevent fraud;
    (c) to protect our business interests;
    (d) to ensure that complaints are investigated;
    (e) to evaluate, develop or improve our services or products; or
    (f) to keep you or our clients informed about relevant products and services and provide you with information, unless you have indicated at any time that you do not wish us to do so.

To the extent that we process any special categories of data relating to you for any of the purposes outlined above, we will do so because:

  • you have given us your explicit consent to process that data;
  • we are required by law to process that data in order to ensure we meet our ‘know your client’ and ‘anti-money laundering’ obligations (or other legal obligations imposed on us);
  • the processing is necessary to carry out our obligations under employment, social security or social protection law;
  • the processing is necessary for the establishment, exercise or defense of legal claims; or
  • you have made the data manifestly public.

Please note that in certain circumstances it may be still lawful for us to continue processing your information even where you have withdrawn your consent, if one of the other legal bases described above is applicable.

Sharing your personal data

In connection with one or more of the purposes outlined in the “How we use information about you?” section above, we may disclose details about you to:

  • other members of the Deloitte Network
  • third parties that provide services to us and/or the Deloitte Network
  • competent authorities (including courts and authorities regulating us or another member of the Deloitte Network)
  • other entities within the Deloitte Network and other third parties as part of a corporate transaction such as a sale, divestiture, reorganisation, merger or acquisition.
  • credit reference agencies or other organisations that help us make credit decisions and reduce the incidence of fraud.

Our Website hosts various blogs, forums, wikis and other social media applications or services that allow you to share content with other users (collectively “Social Media Applications”). Importantly, any personal information that you contribute to these Social Media Applications can be read, collected and used by other users of the application. We have little or no control over these other users and, therefore, we cannot guarantee that any information that you contribute to any Social Media Applications will be handled in accordance with this privacy statement.

Information we hold about you may be transferred to other countries (which may include countries outside the European Economic Area (“EEA”)):

  • where we do business;
  • which are linked to your engagement with us;
  • from which you regularly receive or transmit information; or
  • where our third parties conduct their activities.

Some of these countries may have less stringent privacy laws than we do, so any information they hold can become subject to their laws and disclosure requirements, including disclosure to governmental bodies, regulatory agencies and private persons. In addition, a number of countries have agreements under which information is exchanged with other countries for law enforcement, tax and other purposes.

When we, or our permitted third parties, transfer your personal data outside the EEA, we will impose contractual obligations on the recipients of that data to protect your personal data to the standard required in the EEA. We or they may also require the recipient to subscribe to international frameworks intended to enable secure data sharing.

We may also transfer your personal data when:

  • the transfer is to a country deemed to provide adequate protection of your personal data by the European Commission; or
  • where you have consented to the transfer.

In all cases, we may need to disclose your personal data if required to do so by law, a regulator or during legal proceedings.

Protection of your personal information

We use a range of physical, electronic and managerial measures to ensure that we keep your personal data secure, accurate and up to date. These measures include:

Education and training to relevant staff to ensure they are aware of our privacy obligations when handling personal data

  • Education and training to relevant staff to ensure they are aware of our privacy obligations when handling personal data
  • Administrative and technical controls to restrict access to personal data on a ‘need to know’ basis
  • Technological security measures, including fire walls, encryption and anti-virus software
  • Physical security measures, such as staff security passes to access our premises.

Although we use appropriate security measures once we have received your personal data, the transmission of data over the internet (including by e-mail) is never completely secure. We use appropriate measures to try to protect personal data, but we cannot guarantee the security of data transmitted to us or by us.

How long we keep your personal data for

We will hold your personal data on our systems for the longest of the following periods: (i) as long as is necessary for the relevant purpose of collection; (ii) any retention period that is required by law; (iii) the end of the period in which litigation or investigations might arise in respect of services provided to you.

Your rights

You have various rights in relation to your personal data. In particular, you have a right to:

  • Obtain confirmation that we are processing your personal data and request a copy of the personal data we hold about you;
  • Ask that we update the personal data we hold about you, or correct such personal data that you think is incorrect or incomplete;
  • Ask that we delete personal data that we hold about you, or restrict the way in which we use such personal data; withdraw consent to our processing of your personal data (to the extent such processing is based on consent);
  • Receive a copy of the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to transmit such personal data to another party (to the extent the processing is based on consent or a contract);
  • ask us to stop or start sending you marketing messages at any time by using the contact details below; and
  • Object to our processing of your personal data.

In order to exercise any of your personal data rights, or make a complaint to us relating to your privacy, or if you have any other questions about our use of your personal data, you should contact the Data Protection Officer of the Company at the address below:

Email dataprotectionofficer@deloitte.com.mt

Phone:+(356) 99915250

Post:

Deloitte Malta,
Deloitte Place,
Triq L-Intornjatur,
Central Business District,
CBD 3050,
Malta

Please note that your data subject rights may be limited in circumstances where, in order to comply with your request, we would need to unduly expose personal data about someone else, or where the data you ask us to delete or amend is required for us to perform our contractual obligations towards you, or if we require such data to comply with our legal obligations.

 

Sending you marketing information

We and other members of the Deloitte Network may use your information from time to time to inform you by letter, telephone, email and other electronic methods about products and services (including those of third parties) that may be of interest to you.

You may, at any time, ask us and/or other members of the Deloitte Network not to send marketing information to you by following the unsubscribe instructions in communications from us, or contacting us in the way described in section 8 above.

Changes to this privacy statement

We may modify or amend this privacy statement from time to time, at our discretion.

To let you know when we make changes to this privacy statement, we will amend the revision date at the top of this page. The new modified or amended privacy statement will apply from that revision date. Therefore, we encourage you to periodically review this statement to be informed about how we are protecting your information.

If at any time you do not agree with this Privacy Notice (as revised from time to time) you must terminate your use of this website and the included services.