Privacy Statement

Summary

This Privacy Statement describes what personal data we gather about you, when we do so, how we use this personal data, and who we share such personal data with. We may use personal data provided to us for any of the purposes described in this Privacy Statement or as otherwise stated at the point of collection. This statement sets out your rights in relation to your personal data as well as who you can contact for more information or questions.

Introduction

PwC is strongly committed to protecting personal data. This Privacy Statement describes why and how we collect and use personal data and provides information about your rights. Each member firm in the PwC network is a separate legal entity, therefore a separate controller and/or processor depending on the processing activity. 

Personal data includes any information relating to an identified or identifiable living individual. PwC processes personal data for numerous purposes, and the means of collection, lawful bases of processing, use, disclosure, and retention periods for each purpose may differ. 

The Cyprus firm” refers to PricewaterhouseCoopers Limited, the limited liability company registered in the Republic of Cyprus under registration no. 143594 with registered address at PwC Central, 43 Demostheni Severi Avenue, 1080 Nicosia, Cyprus. This Privacy Statement encapsulates subsidiaries of the Cyprus firm (“PwC”, “us”, “our” or “we”) that: (1) are contracting parties for the purposes of providing or receiving services, (2) posted a position for which you are applying, or (3) you have a role or relationship with.

Collection of personal data

When collecting and using personal data, we believe in transparency. To find out more about collection of personal data in relation to our specific processing activities, please refer to the relevant sections below.

Our processing activities 

Collection​ ​of​ ​personal​ data

PwC processes personal data about contacts (existing and potential PwC clients and/or individuals associated with them). This includes name, employer name, contact title, phone, email and other business contact details. In addition, we may record information about our interactions with contacts.

Use​ ​of​ ​personal​ data

Personal data relating to business contacts may be visible to and used by PwC users to learn more about an account, client or opportunity they have an interest in, and may be used for the following purposes:

  • Administering, managing and developing our businesses and services

  • Providing information about us and our range of services

  • Making contact information available to PwC users

  • Identifying clients/contacts with similar needs

  • Describing the nature of a contact’s relationship with PwC

  • Performing analytics, including producing metrics for PwC leadership, such as on trends, relationship maps, sales intelligence and progress against account business goals

Lawful Basis: Legitimate interests 

The processing of the personal data relating to business contacts to administer, manage and develop our business and services, the processing of the personal data relating to business contacts when conducting corporate research and market analysis, as well as undertaking marketing activities in order to keep business contacts up to date with market developments and PwC’s products, services and events is in the legitimate interests of PwC Cyprus.

Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.

 

Collection of personal data

Our policy is to collect only the personal data necessary for agreed purposes. We ask our clients to only share personal data with us where it is strictly needed for those purposes. 

Where we need to process personal data to provide professional services, we ask our clients to provide the necessary information to the data subjects regarding the personal data’s use.  Our clients may use relevant sections of this privacy statement or refer data subjects to this privacy statement if they consider it appropriate to do so. 

We collect personal data directly from our clients or from third parties acting on the instructions of the relevant client when providing our professional services to the relevant client. 

The categories of personal data processed by us in relation to the services we provide are generally:

  • Personal details (e.g. name, age/date of birth, gender, marital status, country of residence);

  • Contact details (e.g. email address, contact number, postal address);

  • Financial details (e.g. salary and other income and investments, benefits, tax status); and

  • Job details (e.g. role, grade, experience and performance information). 

For certain services or activities, we may process special categories of personal data (such as in performing client checks and providing immigration and tax services, which involve us processing government identification documents that may contain biometric data or data revealing racial or ethnic origin or as part of an audit of an organization in the health sector).

Use of personal data

We use personal data for the following purposes:

  • Providing professional services

We provide a diverse range of professional services (https://www.pwc.com.cy/en/services.html).  Some of our services require us to process personal data in order to provide advice and deliverables.  For example, we will review payroll data as part of an audit and we often need to use personal data to provide global mobility and pensions services. 

Lawful Bases: Legitimate interests, legal obligation or consent

This processing is necessary for the purposes of our legitimate interests in providing professional services to our clients, and those of our clients in receiving our professional services in the course of their business activities. In some circumstances, we have a legal obligation to provide the services in a certain way (for example when providing statutory audit services to our clients). Where we are required to process special categories of personal data, we do so on the grounds of consent.

  • Administering, managing and developing our businesses and services. We process personal data in order to run our business, including:
    • managing our relationship with clients;
    • developing our businesses and services (such as identifying client needs and improvements in service delivery);
    • maintaining and using IT systems;
    • hosting or facilitating the hosting of events; and
    • administering and managing our website and systems and applications.

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to administer, manage and develop our business and services.

  • Security, quality and risk management activities

We have security measures in place to protect our and our clients’ information (including personal data), which involve detecting, investigating and resolving security threats.  Personal data may be processed as part of the security monitoring that we undertake; for example, automated scans to identify harmful emails.  We monitor the services provided to clients for quality purposes, which may involve processing personal data stored on the relevant client file.  We have policies and procedures in place to monitor the quality of our services and manage risks in relation to client engagements.  

We collect and hold personal data as part of our client engagement and acceptance procedures.  As part of those procedures we carry out searches using publicly available sources (such as internet searches and sanctions lists) to identify politically exposed persons and heightened risk individuals and organizations and check that there are no issues that would prevent us from working with a particular client (such as sanctions, criminal convictions, conduct or other reputational issues).  

Lawful Bases: Legal obligation or Legitimate interests

This processing is necessary to enable us to comply with our legal obligations or for the purposes of our legitimate interests in ensuring network and information security, managing risks to our business and checking the quality of our services.

  • Providing our clients with information about us and our range of services

Unless we are asked not to, we use client business contact details to provide information that we think will be of interest about us and our services.  For example, industry updates and insights, other services that may be relevant and invites to events. 

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of our legitimate interests promoting and growing our business and our range of professional services.

  • Complying with any requirement of law, regulation or a professional body of which we are a member

As with any provider of professional services, we are subject to legal, regulatory and professional obligations. We need to keep certain records to demonstrate that our services are provided in compliance with those obligations and those records may contain personal data. 

Lawful Bases: Legal obligation or legitimate interests

This processing is necessary for us to comply with a legal obligation, for example, when conducting customer due diligence checks to comply with anti-money laundering regulations. Where we do not have a legal obligation to conduct such processing, we have a legitimate interest to meet our regulatory or professional obligations.

Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.


We are continually looking for ways to help our clients and improve our business and services.  Where agreed with our clients, we may use information that we receive in the course of providing professional services for other lawful purposes, including analysis to better understand a particular issue, industry or sector, provide insights back to our clients, to improve our business, service delivery and offerings and to develop new PwC technologies and offerings. To the extent that the information we receive in the course of providing professional services contains personal data, we will de-identify the data prior to using the information for these purposes.

Collection of personal data

Our policy is to collect only the personal data necessary for agreed purposes and we ask our clients only to share personal data where it is strictly needed for those purposes.

Where we need to process personal data to provide our services, we ask our clients to provide the necessary information to other data subjects concerned, such as family members, regarding its use.

Given the diversity of the services we provide to personal clients (https://www.pwc.com.cy/en/services.html), we process many categories of personal data, including as appropriate for the services we are providing:

  • Contact details;

  • Business activities;

  • Family information;

  • Income, taxation  and other financial-related details; and

  • Investments and other financial interests.

For certain services or activities, and when required by law or with an individual's explicit consent, we may also collect special categories of personal data. Examples of special categories include race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health data, genetic data, biometric data, sexual life or sexual orientation and criminal records.

Generally, we collect personal data from our clients or from a third party acting on the instructions of the relevant client.  

Use of personal data

We use personal data for the following purposes:

  • Providing professional services

We provide a diverse range of professional services (https://www.pwc.com.cy/en/services.html). Some of our services require us to process personal data in order to provide advice and deliverables.  For example, we need to use personal data to provide individual tax advice, immigration services or pensions advice.

Lawful Basis: Performance of a contract, legitimate interests, legal obligation or consent

This processing is necessary for the performance of the engagement letter (contract) to which our personal client (the data subject) is a party and, where we process personal data about other individuals (such as family members) in order to provide our services, this processing is necessary for the purposes of the legitimate interests pursued by us in providing professional services and our client in receiving professional services. In some cases, we have a legal obligation to provide the services in a certain way and where we process special categories of personal data, we rely on consent.

  • Administering, managing and developing our businesses and services. We process personal data in order to run our business, including:
    • managing our relationship with clients;
    • developing our businesses and services (such as identifying client needs and improvements in service delivery);
    • maintaining and using IT systems;
    • hosting or facilitating the hosting of events; and
    • administering and managing our website and systems and applications.

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to administer, manage and develop our business and services.

  • Security, quality and risk management activities

We have security measures in place to protect our and our clients’ information (including personal data), which involve detecting, investigating and resolving security threats.  Personal data may be processed as part of the security monitoring that we undertake; for example, automated scans to identify harmful emails.

We monitor the services provided to clients for quality purposes and risk management in relation to client engagements, which may involve processing personal data stored on the relevant client file. 

We collect and hold personal data as part of our client engagement and acceptance procedures. As part of our client and engagement acceptance, we carry out searches using publicly available sources (such as internet searches and sanctions lists) to identify politically exposed persons and heightened risk individuals and organizations and check that there are no issues that would prevent us from working with a particular client (such as sanctions, criminal convictions , conduct or other reputational issues).  

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to ensure network and information security, manage risks to our business and check the quality of our services.

  • Providing our clients and prospective clients with information about us and our range of services

With consent or otherwise in accordance with applicable law, we use client contact details to provide information that we think will be of interest about us and our services. For example, industry updates and insights, other services that may be relevant and invites to events.  

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to promote our business and services.

  • Complying with any requirement of law, regulation or a professional body of which we are a member

As with any provider of professional services, we are subject to legal, regulatory and professional obligations.  We need to keep certain records to demonstrate that our services are provided in compliance with those obligations and those records may contain personal data.

Lawful Bases: Legal obligation or legitimate interests

This processing is necessary for us to comply with a legal obligation; for example, when conducting customer due diligence checks to comply with anti-money laundering regulations and, where we do not have a legal obligation, we have a legitimate interest in processing personal data as necessary to meet our regulatory or professional obligations. 

Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.


We are continually looking for ways to help our clients and improve our business and services.  Where agreed with our clients, we may use information that we receive in the course of providing professional services for other lawful purposes, including analysis to better understand a particular issue, industry or sector, provide insights back to our clients, to improve our business, service delivery and offerings and to develop new PwC technologies and offerings.  To the extent that the information that we receive in the course of providing professional services contains personal data, we will de-identify the data prior to using the information for these purposes. 

We provide external users access to various applications managed by us. Such applications will contain their own privacy statements explaining why and how personal data is collected and processed by those applications. We encourage individuals using our applications to refer to the privacy statements available on those applications.

Collection of personal data

Our policy is to collect only the personal data necessary for agreed purposes and we ask our clients only to share personal data where it is strictly needed for those purposes.

Where we need to process personal data to provide our services, we ask our clients to provide the necessary information to the data subjects concerned regarding its use.  

We collect and use contact details for our clients in order to manage and maintain our relationship with those individuals.  Please refer to the Business contacts section of this Privacy Statement for more information about our processing of this type of data.

Given the diversity of the services we provide to clients (https://www.pwc.com.cy/en/services.html), we process many categories of personal data, including:

  • Contact details;
  • Business activities;
  • Information about management and employees;
  • Payroll and other financial-related details; and
  • Investments and other financial interests.

Generally, we collect personal data from our clients or from a third party acting on the instructions of the relevant client.  For some of our services, for example, when undertaking a due diligence review of an acquisition target on behalf of a client, we may obtain personal data from that target’s management and employees or from a third party acting on the instructions of the target.

For certain services, we may process special categories of personal data (such as in performing client checks and providing immigration and tax services, which involve us processing government identification documents that may contain biometric data or data revealing racial or ethnic origin or as part of an audit of an organization in the health sector).

Use of personal data

We use personal data for the following purposes:

  • Providing professional services

We provide a diverse range of professional services (https://www.pwc.com.cy/en/services.html).  Some of our services require us to process personal data in order to provide advice and deliverables.  For example, we will review payroll data as part of an audit and we often need to use personal data to provide global mobility and pensions services.

Lawful Bases: Legitimate interests, legal obligation or consent

This processing of personal data by us is necessary for the purposes of the legitimate interests pursued by us in providing professional services and our client in receiving professional services as part of running their organization and, in some cases, we have a legal obligation to provide the services in a certain way (e.g. statutory audit). Where we process special categories of personal data, we rely on consent.

  • Administering, managing and developing our businesses and services

We process personal data in order to run our business, including:

  • managing our relationship with clients;

  • developing our businesses and services (such as identifying client needs and improvements in service delivery);

  • maintaining and using IT systems;

  • hosting or facilitating the hosting of events; and

  • administering and managing our website and systems and applications.

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to administer, manage and develop our business and services.

  • Security, quality and risk management activities

We have security measures in place to protect our and our clients’ information (including personal data), which involve detecting, investigating and resolving security threats.  Personal data may be processed as part of the security monitoring that we undertake; for example, automated scans to identify harmful emails.  We monitor the services provided to clients for quality purposes, which may involve processing personal data stored on the relevant client file.  We have policies and procedures in place to monitor the quality of our services and manage risks in relation to client engagements.  We collect and hold personal data as part of our client engagement and acceptance procedures.  As part of our client and engagement acceptance, we carry out searches using publicly available sources (such as internet searches and sanctions lists) to identify politically exposed persons and heightened risk individuals and organizations and check that there are no issues that would prevent us from working with a particular client (such as sanctions, criminal convictions, conduct or other reputational issues).   

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to ensure network and information security, manage risks to our business and check the quality of our services.

  • Complying with any requirement of law, regulation or a professional body of which we are a member

As with any provider of professional services, we are subject to legal, regulatory and professional obligations.  We need to keep certain records to demonstrate that our services are provided in compliance with those obligations and those records may contain personal data.

Lawful Bases: Legal obligation or legitimate interests

This processing is necessary for us to comply with a legal obligation; for example, when conducting customer due diligence checks to comply with anti-money laundering regulations and, where we do not have a legal obligation, we have a legitimate interest in processing personal data as necessary to meet our regulatory or professional obligations.

 Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.

 

We collect personal data when an individual gets in touch with us with a question, complaint, comment or feedback (such as name, contact details and contents of the communication).  In these cases, the individual is in control of the personal data shared with us and we will only use the data for the purpose of responding to the communication.

We collect personal data concerning our own personnel as part of the administration, management and promotion of our business activities.

Partners and staff should refer to the Employee Handbook for information on why and how personal data is collected and processed.

When applying online for a role at PwC via the PwC careers website, applicants should refer to the information made available when applying for a job for details about why and how personal data is collected and processed.  

Collection of personal data

We will collect personal data about you at various stages in the recruitment cycle, including:

  • Basic details (name, address, email, telephone number, right to work status);

  • CV, experience, education, academic and professional qualifications, and areas of interest;

  • Photographs and documents to verify your identity;

  • Recruitment platform login information;

  • Information provided as part of virtual campuses, interviews and assessments (including reasonable adjustments information);

  • Social mobility data (where you choose to provide this); and

  • Diversity and equal opportunities data (where you choose to provide this).

We also create personal data in the course of our recruitment activities with you, including:

  • Interview recordings and results, including from video interviews and video assessments;

  • Assessment results and feedback from online and face-to-face assessments/tests; and

  • Employment offer details.

We may collect your personal data from the following sources:

  • Directly from you: where you have directly applied for a position with PwC.

  • Publicly available sources: where you are a member of social media boards and/or job websites, including professional networking sites e.g. LinkedIn.

  • Third party sources: results of background, screening and reference checks.

If your application with us is successful, we will collect:

  • Additional information as part of our pre-employment screening process (proof of right to work, background checks, qualifications and professional status, employment history and referencing for example);

  • Information about your and your immediate family’s financial relationships for Independence regulatory compliance purposes; and

  • Bank account details, national insurance number (or similar) and tax status.

Use​ ​of​ ​personal​ data

Your personal data will be used for the following purposes:

  • To process and manage applications for roles at PwC, and evaluate you for open positions that match your interests and experience throughout the PwC network.

  • To manage your candidate profile, send you email notifications and other announcements, request additional information or otherwise contact you about your application.

  • To screen and select talent by evaluating your suitability for employment with PwC, including through face-to-face interviews, video interviews, and online and video assessments, and conducting appropriate background checks.

  • To hire and onboard talent by making offers of employment and carrying out pre-employment screening checks (which vary from role to role).

  • To conduct statistical analyses and create internal reports, for example regarding usage of our careers websites, demographic analysis of candidates, our recruitment activities, and analysis of candidate sourcing channels.

  • To administer and manage our careers websites, virtual campuses and other recruitment tools and solutions.

  • To communicate with you about careers at PwC.

  • Any other purposes stated when you provide your personal data information to us.

  • To send you, by email or post, welcome information or items once an offer is made.

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests to manage our recruitment process, including to assess and confirm suitability for employment.

We carry out criminal records checks for the following purposes: 

  • To comply with our legal obligations to ensure an individual is eligible to work in Cyprus and to report relevant information to the relevant public authorities as part of PwC sponsored visa applications.

  • For our legitimate interest or that of a third party to carry out pre-employment screening including a full background and criminal records check, depending on the role: (i) to establish whether an applicant has committed an unlawful act or been involved in dishonesty, malpractice or other seriously improper conduct; or (ii) to comply with government and public sector clearance requirements.

  • For reasons of substantial public interest, including complying with regulatory requirements relating to unlawful acts and dishonesty.

When and how we share personal data and locations of processing

In addition to the information set out in our general privacy statement, personal data processed by us in connection with our recruitment activities may also be transferred to:

  • Other PwC member firms

Your personal data will be provided to the PwC firm that has posted the position for which you are applying. It will also be provided to other PwC member firm(s) where (i) the role you are being considered for involves working with other PwC member firm(s) and (ii) it assists with their recruitment and employment activities (for example, if they are recruiting for a role that matches your interests and experience). For details of our member firm locations, please click here.

Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.We retain personal data processed in connection with our recruitment activities as follows:

  • If your application is successful, we retain relevant personal data as part of your personnel record.

  • If your application is unsuccessful, we will retain and use the information you provided to PwC as part of your application for as long as necessary to deal with any matter which may arise in connection with your application. In addition, we will use it to contact you (only insofar as you have provided explicit consent) about any other relevant employment opportunities that may arise.

Collection​ ​of​ ​personal​ data

We collect and process personal data about our suppliers (including subcontractors and individuals associated with our suppliers and subcontractors) in order to manage the relationship, contract, to receive services from our suppliers and, where relevant, to provide professional services to our clients. The personal data is generally business card data and will include name, employer name, phone, email and other business contact details.

 Use​ ​of​ ​personal​ data

We use personal data for the following purposes:

  • Receiving services

We process personal data in relation to our suppliers and their staff as necessary to receive the services. For example, where a supplier is providing us with facilities management or other outsourced services, we will process personal data about those individuals that are providing services to us.

Lawful Basis: Legitimate interests

This processing of personal data by us is necessary for the purposes of the legitimate interests pursued by us in receiving services.

  • Providing professional services to clients

Where a supplier is helping us to deliver professional services to our clients, we process personal data about the individuals involved in providing the services in order to administer and manage our relationship with the supplier and the relevant individuals and to provide such services to our clients (for example, where our supplier is providing people to work with us as part of a PwC team providing professional services to our clients).

Lawful Basis: Legitimate interests

This processing of personal data by us is necessary for the purposes of the legitimate interests pursued by us in providing professional services and our client in receiving professional services as part of running their organization.

  • Administering, managing and developing our businesses and services. We process personal data in order to run our business, including:
    • managing our relationship with suppliers;
    • developing our businesses and services (such as identifying client needs and improvements in service delivery);
    • maintaining and using IT systems;
    • hosting or facilitating the hosting of events; and
    • administering and managing our website and systems and applications.

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to administer, manage and develop our business and services.

  • Security, quality and risk management activities

We have security measures in place to protect our and our clients’ information (including personal data), which involve detecting, investigating and resolving security threats.  Personal data may be processed as part of the security monitoring that we undertake; for example, automated scans to identify harmful emails.  We have policies and procedures in place to monitor the quality of our services and manage risks in relation to our suppliers.  We collect and hold personal data as part of our supplier contracting procedures.  We monitor the services provided for quality purposes, which may involve processing personal data.

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to ensure network and information security, manage risks to our business and check the quality of the services.

  • Providing information about us and our range of services

Unless we are asked not to, we use business contact details to provide information that we think will be of interest about us and our services.  For example, industry updates and insights, other services that may be relevant and invites to events.

Lawful Basis: Legitimate interests

This processing is necessary for the purposes of the legitimate interests pursued by us to promote our business and services.

  • Complying with any requirement of law, regulation or a professional body of which we  are a member

As with any provider of professional services, we are subject to legal, regulatory and professional obligations.  We need to keep certain records to demonstrate that our services are provided in compliance with those obligations and those records may contain personal data.

Lawful Bases: Legitimate interests or legal obligation

This processing is necessary for us to comply with a legal obligation; for example, when conducting supplier due diligence checks and, where we do not have a legal obligation, we have a legitimate interest in processing personal data as necessary to meet our regulatory or professional obligations.

Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights. 

 

We have security measures in place at PwC offices, including CCTV and building access controls.

CCTV

We only perform CCTV monitoring where allowed by law. CCTV images captured are securely stored and only accessed on a need to know basis (e.g. to look into an incident). We use the CCTV images for the legitimate purposes of promoting security and safety of our personnel and members of the public, preventing and detecting crime and establishing, exercising and defending legal claims. We may disclose CCTV images to law enforcement bodies as requested and permitted by law.

CCTV recordings are typically automatically overwritten after a short period of time unless an issue is identified that requires investigation (such as a theft).

Visitor records

We require visitors to our offices to sign in at reception and we keep that record of visitors for a short period of time. Our visitor records are securely stored and only accessible on a need to know basis (e.g. to look into an incident).

Guest WIFI

We may monitor traffic on our guest WIFI networks using industry standard intrusion detection systems. This allows us to see limited information about a user’s network behaviors but will include being able to see at least the source and destination addresses the user is connecting from and to. We cannot inspect encrypted web pages and therefore do not have access to any information (personal or otherwise) that the user might share via these web pages.

Collection of personal data

Visitors to our websites are generally in control of the personal data shared with us.  We may capture limited personal data automatically via various webforms or the use of cookies on our website.

We receive personal data, such as name, title, company address, email address, and telephone and fax numbers, from website visitors; for example when an individual subscribes to updates from us.

Visitors are also able to send an email to us through the website. The messages will contain the user’s screen name and email address, as well as any additional information the user may wish to include in the message.    

We ask that you do not provide sensitive information to us when using our website; if you choose to provide sensitive information to us for any reason, the act of doing so constitutes your explicit consent for us to collect and use that information in the ways described in this privacy statement or as described at the point where you choose to disclose this information.

Cookies

We use small text files called ‘cookies’ which are placed on your hard drives to assist in personalizing and enriching your browsing experience by displaying content that is more likely to be relevant and of interest to you. If you are uncomfortable with the use of cookies, most browsers now permit users to opt-out of receiving them.  You need to accept cookies in order to register on our website. You may find other functionalities in the website impaired if you disable cookies. After termination of the visit to our site, you can always delete the cookies from your system if you wish.

You can find out more details regarding our use of cookies on our cookies page at https://www.pwc.com.cy/en/cookie-information.html

Use of personal data

When a visitor provides personal data to us, we will use it for the purposes for which it was provided to us as stated at point of collection (or as obvious from the context of the collection).  Typically, personal data is collected to:

  • register for certain areas of the site;

  • subscribe to updates;  

  • enquire for further information;

  • distribute requested reference materials;

  • submit curriculum vitae;

  • monitor and enforce compliance with our terms and conditions for use of our website;

  • administer and manage our website, including confirming and authenticating identity and preventing unauthorized access to restricted areas, premium content or other services limited to registered users; and

  • aggregate data for website analytics and improvements.

Should visitors subsequently choose to unsubscribe from mailing lists or any registrations, we will provide instructions on the appropriate webpage, in our communication to the individual, or the individual may contact us by email at cy_marketingcommunications@pwc.com

Our websites do not collect or compile personal data for the dissemination or sale to outside parties for consumer marketing purposes or host mailings on behalf of third parties. If there is an instance where such information may be shared with a party that is not a PwC member firm, the visitor will be asked for their consent beforehand.

Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.

 

Marketing communications 

Marketing includes any communications about PwC products and services. Where we are legally required to obtain your explicit consent to send you marketing materials, we will only provide you with such marketing materials if you have provided consent for us to do so.

We retain contact information (including name and email address) on our mailing lists until an individual unsubscribes from our mailing lists. If you unsubscribe from our mailings, we may retain limited information sufficient to identify you so that we can honor your opt out request.

PwC does not sell personal information to non-PwC parties for consumer marketing purposes.

How to unsubscribe from marketing communications

You can at any time contact us to request that we stop sending you email marketing communications. If you want to unsubscribe from mailing lists, you should look for and follow the instructions we have provided in the relevant communications to you.

If you wish to no longer receive only certain communications, please identify such communications in your request.

Events

Collection of personal data 

We collect and use your personal data in connection with our events.

Lawful Basis: Legitimate interests

Our lawful basis for this processing is our legitimate interests in offering and promoting client and associated services, and performance of a contract, in order to make sure that your requirements are met when attending our events. Where we process your special category data, we will do so only with your explicit consent.

Use of personal data

We process the following personal data fields provided by you in connection with your registration for and attendance at our events:

  • Name;

  • Job title and professional information;

  • Your organization or educational institution;

  • Contact information, including email address(es), work (and sometimes home) address, and telephone number(s);

  • Any dietary, accessibility or other requirements, where applicable;

  • Guest details; and

  • Other information specific to the event.

We will use your personal data to manage registration, attendance and participation at our events and to ensure that any special requirements that you request are communicated to any relevant third party providers, where required.

We may take photographs in public areas at our events and we may use these in our marketing materials.

When and how we share your personal data for the purposes of hosting events and locations of processing

We will only share personal data with others when we are legally permitted to do so. In connection with our events, we share your personal data with third party service providers within the EU that provide services to us and process your information on our behalf for the purpose of providing and managing our events. We put in place measures to protect the confidentiality and security of your personal data, and to comply with our data protection, confidentiality and security standards.

Data retention

We retain the personal data processed by us for as long as necessary for the purpose for which it was collected. Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.

 

Our role as Data Controller

PwC Cyprus is the data controller of any personal data collected from you. This means that PwC is responsible for deciding how this personal information is held and used. We will process such data in accordance with the provisions of applicable Data Protection law. 

If you have any question regarding this Privacy Statement or how and why we process your data, please contact us at:

Data Protection Officer

PricewaterhouseCoopers Ltd

PwC Central
43 Demostheni Severi Avenue
CY-1080 Nicosia, Cyprus 

Email: cy_dataprotection_office@pwc.com

Phone: +35722555000

Security

We have implemented a framework of policies and procedures relating to technology and operational security to protect personal data and information from loss, misuse, alteration, or destruction. We ensure that all appropriate confidentiality obligations and technical and organizational security measures are in place. We adhere to the Global PwC network information Security Policy (ISP).

We adhere to internationally recognised security standards and we are certified with ISO/IEC 27001.

When and how we share personal data and locations of processing

We only share personal data with other parties only when we are legally allowed to do so. We do not share personal data with unaffiliated third parties except as necessary for our legitimate professional and business needs, for the purpose of executing your instructions or requests and/or as required or permitted by applicable legislation, professional standards or any applicable agreement between us. When we share data with others, we set contractual arrangements in place to protect the data and to comply with our data protection, confidentiality, and security standards.

We are part of a global network of firms and in common with other professional service providers, we use third parties located in other countries to help us run our business.  As a result, personal data may be transferred outside the countries where we and our clients are located. This includes countries outside the European Union ("EU") and to countries that do not have laws that provide specific protection for personal data. 

We have taken steps to ensure all personal data is provided with adequate protection and that all transfers of personal data outside the EU are done lawfully. Where we transfer personal data outside of the EU to a country not determined by the European Commission as providing an adequate level of protection for personal data, the transfers are under an agreement covering the EU requirements for the transfer of personal data outside the EU, such as the European Commission approved standard contractual clauses. The European Commission approved standard contractual clauses are available here

Personal data held by us may be transferred to the following categories of persons:

Other PwC member firms

As we are part of a global network with member firms around the world, personal data submitted to us may be transferred to other member firms of the PricewaterhouseCoopers network when this is necessary to meet the purpose for which the personal data was submitted to us. For details of our member firm locations, please click here.

Third party organizations that provide applications/functionality, data processing or IT services to us

We use third parties to support us in providing our services and to help provide, run, and manage our internal IT systems. For example, providers of information technology, cloud-based software as service providers, identity management, website hosting and management, data analysis, data back-up, security, and storage services.  The servers powering and facilitating that cloud infrastructure are located in secure data centers around the world, and personal data may be stored in any one of them. Further details of these providers are included below.

Name

Role

Address

Google Ireland Limited

Business applications (such as email, documents and calendar)

Gordon House, Barrow Street, Dublin 4, Dublin, D04 E5W5

Data centres located in a number of locations around the world (EU, Chile, Singapore, Taiwan, USA)

 

Iron Mountain Cyprus Limited

Document storage

9 Kratirion street, Kokkinotrimithia,  2660, Cyprus

 

Microsoft Limited

Azure cloud services

Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, UK

 

Salesforce

Customer relationship management system

Salesforce.com EMEA, Village 9, Floor 26 Salesforce Tower, 110 Bishopsgate London, EC2N 4AY, UK  

Salesforce.com Sàrl, route de la Longeraie 9, 1110 Morges Switzerland

 

Evresis Services Limited

Call Center Service Provider

Vithleem 20, Strovolos 2033, Nicosia, Cyprus

 

Third party organizations that otherwise assist us in providing goods, services or information

On certain client engagements, we may engage or otherwise work with other providers to help us provide professional services to our clients.

Law enforcement, governmental or regulatory authorities or to other third parties as required by, and in accordance with, applicable law or regulation

We may also disclose personal data to respond to requests of the courts, governmental authorities or where it is necessary or prudent for compliance with applicable legislation, for criminal investigations or security purposes, and for purposes of establishing, exercising, or defending legal rights.


Individuals’ rights and how to exercise them

Individuals have certain rights over their personal data and data controllers are responsible for fulfilling these rights.  When we decide how and why personal data is processed, we are a data controller and include further information about the rights that individuals have .

In order to exercise the rights below, please submit a request to in relation to your personal data, or an enquiry if you have a question or complaint about the handling of your personal data.

Access to personal data

You have a right of access to personal data held by us as a data controller. We aim to respond to any requests for information promptly and in any event within the legally required time limits. Depending on the nature of the request, a charge may be imposed in accordance with applicable law.

Amending of personal data

When practically possible, once we are informed that any personal data processed by us is no longer accurate, we will make corrections where appropriate based on your updated information. 

Withdrawal of consent

Where we process personal data based on consent, individuals have a right to withdraw consent at any time.  We do not generally process personal data based on consent (as we can usually rely on another legal basis). Should visitors subsequently choose to unsubscribe from mailing lists or any registrations, we will provide instructions, on the appropriate webpage or in communications.

Additional Rights

You have the right to request the erasure of your personal data under the following circumstances and we shall endeavor to accommodate such request whenever feasible:            

  • Where your personal data is no longer necessary in relation to the specific purpose for which it was originally collected;

  • Where your consent is withdrawn (if such consent was used as a legal basis);

  • Where you object to the processing and there is no overriding legitimate interest for continuing the processing;

  • Where such erasure is necessary for compliance with a legal obligation.

You have the right to restrict processing. In the event that you choose to exercise this right, and provided that such request may not be overridden on legitimate grounds, we shall retain your data but restrict processing.

You have a right to data portability allowing you to obtain and reuse your personal data for your own purposes across different services.

Based on your right to object, you can object to processing based on legitimate interests or the performance of a task in the public interest and direct marketing.

 

Children

We understand the importance of protecting children's privacy, especially in an online environment. The websites and services covered by this Privacy Statement are not intentionally designed for or directed at children, and all users should be above the age of majority in their local country. We adhere to laws regarding marketing to children. We do not collect or maintain personal information about individuals under the age of 14, except as part of an engagement to provide professional services and only following the express consent of their legal guardian or parent.
 

Cookies

For further information on how we use cookies, please see our Cookie Policy.

Complaints

If you have any questions or complaints about this Privacy Statement or the manner in which we process your personal data or you would like to exercise one of your rights set out above, please contact us at cy_dataprotection_office@pwc.com

You have a right to lodge a complaint with the Data Protection Commissioner (the Cyprus relevant supervisory authority). For further information on your rights and how to complain please refer to this page.

Contact Us

For any other inquiries or questions, contact us. 

via email: cy_dataprotection_office@pwc.com

via phone: +35722555000

Changes to this Privacy Statement

We recognise that transparency is an ongoing responsibility, so we will keep this privacy statement under regular review.

This Privacy Statement has last been updated on 04/11/2024.

Follow us