Updated 20 March 2024

ERM is committed to protecting the privacy of personal data and maintaining the principles of integrity and trust in the course of ERM’s business.

This privacy notice aims to give you information on how ERM collects and processes your personal data through your use of this website, and through interactions with its clients, suppliers, and other third parties.

The data we may collect about you
How we use your personal data
Purposes for which we will process your personal data
Cookies
Disclosures of your personal data
Direct Marketing
International transfers
Data Security
How long will you use my personal data for?
Your legal rights
Information about the data controller
Contact us
To contact your data protection supervisory authority
Changes to this privacy policy and informing us of changes

The data we may collect about you

“Personal data” means any information about a person that can be used to identify that person. It does not include data where the identity has been removed (anonymous data). We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:

Back to top

How is your personal data collected?

We use different methods to collect personal data from and about you. You may give us your personal data by filling in forms or by corresponding with us by post, phone, email or otherwise. We may also receive personal data about you from various third parties (such as our clients and suppliers, particularly if they are your employer) and public sources, such as identity and contact data from publicly availably sources (see “Public Data” above) and reports from external professionals.

Back to top

How we use your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Back to top

Purposes for which we will process your personal data

The table below sets out the purposes for which ERM may process your personal data, and the lawful grounds for that processing. Depending on the purpose/s for which we are processing your data, we may do so under more than one lawful grounds.

Purpose/Activity

 Lawful grounds for processing

To communicate with you and to process and respond to correspondence from you 

To comply with law
To help us meet our contractual obligations to you
To contact you where we need to, when it is within our legitimate interests to do so

To register you as a new client or supplier 

To help us meet our contractual obligations to you

To manage our relationship with you 

To help us meet our contractual obligations to you
To keep our records updated and to provide our services, when it is within our legitimate interests to do so

To help ensure the quality of our services (including processing Service Data) 

To maintain the quality of our services, when it is within our legitimate interests to do so

To understand the performance of our business 

To understand the performance of our business, when it is within our legitimate interests to do so

To meet regulatory requirements by producing management information and reports to help us identify potential problems 

To comply with law
To help us demonstrate that we manage our risk appropriately, within our legitimate interests

To administer and protect our business and this website 

To run our business, provide of administrative and IT services, network security and when it is within our legitimate interests to do so
To comply with law

To undertake sanctions list checks 

To comply with law

To conduct direct marketing about our services, events to attend or industry updates or articles that may be of interest to you 

Consent where it has been given (note that you can opt out at any time)

To use data analytics to improve our website, marketing, client relationships and experiences 

To keep our website updated and relevant, to develop our business and to inform our marketing strategy, when it is within our legitimate interests to do so

Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out.

Back to top

Cookies

ERM uses cookies. A cookie is a small piece of information that a website stores on the web browser on your device and can later retrieve. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. Our Cookie Notice will illustrate the cookies we use.

Back to top

Disclosures of your personal data

We may need to share your personal data within the ERM Group in order to provide you with our services or manage our business.

We may also employ the services of third party service providers who provide services to us. These service providers have agreed to confidentiality restrictions and will use any personal data we share with them (or which they collect on our behalf) solely for the purpose of providing those services. We take appropriate steps to ensure that such third parties treat your personal data with the same care that we do. Where third party service providers receive your information we remain responsible for the use of your personal data.

We may be required to disclose your personal data to law enforcement bodies, regulators, agencies or other third parties under a legal requirement or court order. We act responsibly and take account of your interests when responding to any such requests.

Back to top

Direct Marketing

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. If you have given us your consent to send you marketing material by email or post, you have the right to opt out of receiving that material. We will also get your express opt-in consent before we share your personal data with any company outside the ERM Group for marketing purposes. You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you, or you can contact us at any time.

Back to top

International transfers

ERM is an international organisation, with businesses inside and outside the European Economic Area ("EEA"). Third party service providers who handle data on our behalf may be based in locations around the world. For these reasons, your personal data may be transferred to other countries both inside and outside of the EEA. Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

Additional information for individuals in Mainland of the People’s Republic of China (PRC)

Where you are located in the PRC and when data protection laws of the PRC apply, our PRC entity ERM (Shanghai) Limited will transfer your personal data it collected to jurisdictions/regions outside the PRC via the Internet and/or our intranet connecting our information systems.

If you are a client contact in the PRC, we will transfer the following personal data of yours (no sensitive personal data involved):

If you are a sub-contractor or a supplier contact in the PRC, we will transfer the following personal data of yours (no sensitive personal data involved):

The overseas recipient is The ERM International Group Limited, a company registered in the UK with the contact address at 2nd Floor Exchequer Court, 33 St. Mary Axe, London, England, EC3A 8AA. The overseas recipient in the UK may use information systems deployed on servers in other jurisdictions/regions (including Ireland, United States, and Germany) to receive personal data that we transfer and conduct the further processing.

When we store or transfer your personal data outside the PRC, we will take all reasonable steps to ensure that your personal data is treated as safely and securely as it would be within the PRC and under the Personal Information Protection Law (PIPL) of the PRC.

Your acceptance of this privacy policy shall be your separate consent permitting us to transfer and store your personal data outside the PRC if it is necessary for us to do so.

In addition, we will take necessary measures required by the PIPL including entering into Standard Contract with the overseas recipient to stipulate the rights and obligations between us and will ensure that the overseas recipient provides adequate protection for your personal data under applicable laws.

We will only transfer your personal data (including sensitive personal data) to the extent necessary and will work with the overseas recipient to process it in a secure manner to protect your legitimate interests and to avoid causing harms to you. We and the overseas recipient will only retain your personal data for the minimum necessary retention period unless otherwise required by applicable laws.

You have the right to exercise your personal data rights over the overseas recipient by sending an email request to data.protection@erm.com. Under our Standard Contract for the cross-border transfer of personal data with the overseas recipient, you could be considered as a third-party beneficiary and can be entitled to exercise the third-party beneficiary rights if you do not expressly refuse within 30 days upon your acceptance of this privacy policy. According to applicable laws and the Standard Contract (if applicable), you may have the right to demand us to provide a copy or a summary of the relevant contract content.

Back to top

Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Back to top

How long will you use my personal data for?

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

Back to top

Your legal rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data.

Your rights

Further details

Rectification

You can correct any personal data that we hold about you that is incorrect.

Erasure

You can request that personal data that we hold about you be deleted when it is no longer necessary for us to hold, you have withdrawn consent, or we no longer have a legitimate interest to process your personal data.

Access

You can request access to your personal data that is held by us, including the purpose of our processing, the types of personal data held and any recipients of your personal data.

Restriction of processing

You can request that we restrict processing your personal data when we no longer need to process your personal data, or you object to us processing your personal data.

Portability

You can request the personal data that we hold about you to be provide in a commonly used format if you wish to provide that information to another party.

Object

You have the right to object to the use of your personal data where we process it in our legitimate interests.

Withdrawal of consent

You can withdraw your consent for any processing that we undertake on the basis of your consent.


Although you are encouraged to contact us if you would like to exercise your rights, some of these rights are only available in certain circumstances and so we may not be required to comply with every request.

Back to top

Information about the data controller

This privacy policy is issued on behalf of The ERM International Group (i.e. The ERM International Group Limited and its group companies), so when we mention ERM "we", "us" or "our" in this privacy policy, we are referring to the relevant company in The ERM International Group responsible for processing your data. In the majority of circumstances, and in relation to data collected via this website, your data controller will be The ERM International Group Limited. However, if your data controller is another member of The ERM International Group, we will make that information clear to you at the time your personal data is collected.

Back to top

Contact us

The primary point of contact for all issues arising from this privacy policy is the ERM Data Protection Team. If you have any complaints or queries relating to the processing of your personal data by any member of ERM Group, or to exercise any rights in respect of your personal data, you should contact us.

We will investigate and attempt to resolve complaints and disputes and will make every reasonable effort to honour your wish to exercise your rights.

Back to top

To contact your data protection supervisory authority

You have a right to lodge a complaint with your local data protection supervisory authority at any time. In the UK, this is the Information Commissioner's Office (www.ico.org.uk).

Should you have a complaint, we hope that you can approach us first so that we can try to resolve your concern.

Back to top

Changes to this privacy policy and informing us of changes

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

Back to top