This privacy notice describes how Moore Stephens Channel Islands (“MSCI”, “we”, “us” or “our”) collects and uses Personal Data in accordance with the General Data Protection Regulation 2016/679 (“GDPR”), the Data Protection (Jersey) Law 2018 (“DPJL”) and the Data Protection (Bailiwick of Guernsey) Law, 2017 (“DPGL”) (collectively “Data Protection Law”).
The Jersey data protection authority is the Jersey Office of the Information Commissioner (“JOIC”) and the Guernsey data protection authority is the Officer of the Data Protection Authority (“ODPA”).
This notice applies to all Personal Data provided to us. Personal Data is any information relating to an identified or identifiable living person. Words used with first letter capitalisation (e.g. Personal Data), unless otherwise defined in this policy, have the same definition and meaning as under Data Protection Law.
MSCI is comprised of Moore Stephens Guernsey (“MSG) and Moore Stephens Jersey (“MSJ”) and offers a range of financial services. Personal interactions are at the core of our business, so we have implemented this policy for reasons of lawfulness, fairness and transparency in relation to our use of Personal Data.
MSCI
MSG
MSG is comprised of:
MSJ
The Moore Stephens (Jersey) office, Moore Stephens (Jersey) Limited is a limited company, incorporated in Jersey with registration number 121337 and JOIC registration number 58434.
Our Role
Where we decide how and why Personal Data is processed, we are a Controller. This is generally the role under which we process Personal Data.
There may be limited circumstances where we solely process Personal Data on behalf of a Controller, and in these circumstances, we will be a Processor. Should this apply to you, we will inform you during the period of engagement and onboarding.
Types of Personal Data
Given the diversity of the services we provide to clients, we may process many categories of Personal Data such as:
For certain services or activities and when required by law or with an individual's consent, we may also collect Special Category Data such as:
Collection of Personal Data
We will only collect such Personal Data that is necessary for us to perform our services or where there has been an explicit selection to receive other information. We therefore ask our clients or website users to share such Personal Data as required for that purpose. Where we identify that a client has provided us with unnecessary Personal Data we will either return that information to its source or destroy it, taking into account our client’s preference wherever possible.
Generally, we collect Personal Data from our clients or from third parties acting on the instructions of the relevant client such as when:
Cookies
IP addresses of authorised users are not logged. The standard technology known as cookies is used on our website. Cookies are small text files placed on the authorised user's hard drive that allow the website to store tokens of information in connection with use of the website by allocation of an identifier to an authorised user while the site is in use.
Use of cookies enables us to analyse the operation of the website (such as to improve the service it provides) but cannot retrieve any other data from the hard drive of the authorised user's computer or capture the authorised user's e-mail address. It is therefore not intended to link Personal Data to information that may be contained in a cookie to determine or track the identity of any user of the site.
Google Analytics
We use Google Analytics to analyse our website usage and create reports for internal use only.
Google Analytics Cookies
Like many services, Google Analytics uses first-party cookies to track visitor interactions. These cookies are used to store information, such as what time the current visit occurred, whether the visitor has been to the site before and what website referred the visitor to the web page. Browsers do not share first-party cookies across domains. To find out more about how Google treats personal information, please see the Google Privacy Policy.
Use of Personal Data
Here we set out the basis upon which we process Personal Data. Please note that we may process Personal Data for more than one lawful basis, depending on the specific purpose for which we are using that information.
Performance of a Contract
We provide a diverse range of professional services, of which more information can be found here.
Many of our services require us to process Personal Data for purposes necessary for the performance of our contract with our clients. This may include processing Personal Data to provide requested bespoke fiduciary support to a private client or processing the Personal Data of a Data Subject who is the employee, subcontractor, supplier or customer of our client.
Legitimate Interests
We may process Personal Data for the purposes of our own legitimate interests in the delivery of information and services to our clients. We may also process Personal Data in the effective and lawful operation of our businesses, provided that those interests do not override the interests, rights and freedoms of a Data Subject which require that Personal Data to be protected.
Examples of such processing activities include:
Compliance with a Legal Obligation
As with any provider of professional services, we are subject to legal, regulatory and professional obligations. We will process Personal Data as necessary to comply with those obligations.
An example of such processing includes anti-money laundering activities such as carrying out searches to identify politically exposed and to check that there are no issues that would prevent us from working with a particular client (such as sanctions, criminal convictions, conduct or other reputational issues).
We are also required to keep certain records to demonstrate that our services are provided in compliance with our legal, regulatory and professional obligations.
Consent
In certain limited circumstances, such as where a Data Subject has agreed to receive marketing communications from us, we may process Personal Data by consent. Where consent is the only basis upon which Personal Data is processed the relevant Data Subject shall always have the right to withdraw their consent to processing for such specific purposes.
We understand the importance of protecting children’s privacy and data. Should we be required to process children’s data below the age of legal consent (13 for Jersey, Guernsey and EU purposes), we will request consent from persons with legal parental responsibility. Otherwise, consent will be obtained from the child where they are legally able to provide it.
It is our policy to only process Personal Data by consent where there is no other lawful basis for processing.
Data Retention
We retain the Personal Data processed by us for as long as is considered necessary for the purpose for which it was collected (including as required by applicable law or regulation). In the absence of specific legal, regulatory or contractual requirements, MSG’s standard retention period for records and other documentary evidence created in the provision of services is 6 years and MSJ’s is 10 years.
We continually review our data retention policies and reserve the right to amend the above retention periods without notice.
Other records, which are not required to be retained as part of our professional services, will have a retention period depending on:
We take the security of all the data we hold very seriously. We have a framework of policies, procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.
We have put in place appropriate security measures to prevent Personal Data from being accidentally lost, altered, disclosed or used or accessed in an unauthorised way. This is not only in accordance with our obligations under Data Protection Law but also in accordance with our regulatory obligations of confidentiality.
We limit access to Personal Data to those employees, agents, contractors and other third parties who have a business need to know and our IT systems operate on a “least privileged” basis by default. Third parties will only process Personal Data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and will notify any affected Data Subject and any applicable regulator of a suspected breach where we are legally required to do so.
In some circumstances, we may anonymise or pseudonymise Personal Data so that it can no longer be associated with the Data Subject, in which case we may use it without further notice.
We will share Personal Data with third parties where we are required by law, where it is necessary to administer our relationships between clients and Data Subjects or where we have another legitimate interest in doing so.
We are part of a global network of firms and accordingly Personal Data may be transferred to other member firms of the Moore Stephens International network. This may result in Personal Data being transferred outside the countries where we and our clients are located. This includes transfers to countries outside the European Union (“EU”) and to countries that do not have laws that provide specific protection for Personal Data. All Personal Data will be provided with adequate protection and all transfers of Personal Data outside the EU are undertaken lawfully. Where we transfer Personal Data outside of the EU to a country not determined by the European Commission as providing an adequate level of protection for Personal Data, the transfers will be under an agreement which covers the EU requirements for the transfer of personal data outside the EU, such as the European Commission approved standard contractual clauses.
Please also see here for a list of firms and countries in which member firms of the Moore Stephens International network operate. We may also share Personal Data with other entities within our group, subject to the safeguards mentioned above.
We may also share Personal Data with third-party service providers. For example, we use third parties to provide:
• our cloud services, and to operate and manage these services;
• professional advisory services (including our auditors);
• administration services;
• marketing services;
• banking services; and
• investment services
All our third-party service providers are required to take commercially reasonable and appropriate security measures to protect your Personal Data. We only permit our third-party service providers to process your Personal Data for specified purposes and in accordance with our instructions.
A Data Subject’s Duty to Inform Us of Changes
The Personal Data we hold must be accurate and current. Should your personal information change, please notify us of any changes of which we need to be made aware by contacting us, either through your usual contact or by using one of the means set out at the end of this privacy notice.
A Data Subject’s Rights in Connection with Personal Data
Data Subjects may have certain rights under Jersey, Guernsey or EU law in relation to the Personal Data held by us about them. These rights may include the right to:
Withdrawal of Consent
Where we process Personal Data based on consent, individuals have a right to withdraw consent at any time. However, as noted above, we do not generally process Personal Data based on consent. To withdraw consent to our processing of your Personal Data please e-mail the data protection teams at MSG or MSJ. To stop receiving an e-mail from a Moore Stephens marketing list, please click on the unsubscribe link in the relevant e-mail received from us.
Contacting Us to Exercise a Right
If any individual would like to exercise the above rights please e-mail the data protection teams at MSG or MSJ. We may charge for a request to access details of Personal Data, if permitted by law. If a request is clearly made in bad faith, we may refuse to comply with that request.
We may need to request specific information from those individuals who contact us to help us confirm their identity and ensure their right to access their Personal Data (or to exercise any of their other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact an individual to ask them for further information in relation to their request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if a request is particularly complex. In this case, we will notify the individual concerned and keep them updated.
Data Subjects also have the right to make a complaint to the JOIC or ODPA.
This note is reviewed regularly and updated where necessary.
If you have any queries about this notice, please e-mail our data protection teams at MSG or MSJ.