Privacy Notice

Privacy Notice

Dickinson Gleeson

Dickinson Gleeson (“Dickinson Gleeson”, “we”, “us” or “our”) is a Jersey law partnership providing legal services and is the data controller responsible for the personal data described in this privacy notice. We are registered with the Jersey Office of the Information Commissioner (JOIC) under registration number 19626.

This notice explains how we collect, use, share and protect personal data belonging to our clients, prospective clients, intermediaries, existing and prospective members of staff, and other third parties with whom we interact in the course of our business, together with any individual connected to those parties. It also explains the rights available to those individuals in respect of their personal data. This notice is issued in accordance with the Data Protection (Jersey) Law 2018 (the “DPJL 2018”).

The Data Protection Manager

We have appointed a Data Protection Manager to oversee our compliance with data protection law and to act as your point of contact for all data protection matters. You may contact our Data Protection Manager at any time using the details below.

Data Protection Manager:

dataprotection@dgadvocates.com

The Personal Data We Collect

We collect and process personal data about individuals who engage with us as clients, prospective clients, intermediaries, third parties connected with legal matters, and existing or prospective members of staff. The categories of personal data we may collect and process include the following.

Category of information

Examples

Identity and contact details

Full name, date of birth, residential and postal address, email address, telephone number, nationality and signature.

Client take-on and compliance documentation

Proof of identity, proof of address, beneficial ownership declarations, and source of funds and source of wealth documentation required for anti-money laundering purposes.

Know Your Client (KYC) and screening information

Politically Exposed Person (PEP) screening results, sanctions screening results, adverse media checks, and criminal background screening.

Financial information

Bank account details, payment-related information, details of financial transactions, asset information, tax status, and evidence of source of funds.

Information relating to legal matters

Details of your instructions, correspondence, documents, transaction details, professional relationships and background, disputes and court proceedings, and other information necessary to provide legal services.

Website enquiries

The content of any enquiry you submit through our website, and any other information you choose to provide to us.

Recruitment information

Details of past employment, professional qualifications and education, nationality and immigration or residential status, references and other opinions provided by third parties, and other information gathered during a recruitment process, where you apply for a position with us.

Data about connected individuals

Personal data about people connected to you by professional or other association, or by family relationship, which you or a third party may provide to us.

It is important that the personal data we hold about you is accurate and up to date. Please keep us informed if your personal data changes during the course of your relationship with us.

How Your Personal Data Is Collected

We collect personal data directly from you when you instruct us to provide legal services, when you contact us with an enquiry, or when you complete client take-on forms and compliance documentation. Personal data may also come from clients, intermediaries, other third parties connected to a data subject (for example, an employer or another service provider), or from publicly available sources.

We may also receive personal data about you from third parties, such as other legal representatives, financial institutions, or public registers, where this is necessary to carry out KYC checks, regulatory due diligence, or to verify information you have provided to us. Also, where it is required to comply with Anti Money Laundering (AML) and Client Due Diligence (CDD) obligations, Dickinson and Gleeson may obtain information from publicly available sources, including internet searches and/or adverse media screening tools.

Special Category Data

In some circumstances, the personal data we process may include special category data: information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data processed to uniquely identify a person, health data, data concerning a person’s sex life or sexual orientation, or data relating to criminal convictions or alleged criminal activity.

We only collect and use special category data where it is necessary to provide you with legal services, to comply with our legal or regulatory obligations, or where we have another specific lawful reason to do so – for example, information about your health where you are seeking advice on a personal injury claim, or information about criminal convictions or offences that is relevant to the matter on which we are advising you. Special category data is processed only on the basis of the conditions set out in paragraph 1 of Schedule 2 to the DPJL 2018 (ordinary personal data) and Part 2 of Schedule 2 to the DPJL 2018 (special category data), and access is limited to staff members who need it to provide services or comply with our legal obligations.

How We Use Your Personal Data: Purposes and Legal Basis

We process personal data for the purposes set out below, each supported by a lawful basis under Article 9 and Schedule 2 of the DPJL 2018:

  • to provide and improve our legal and other services, and to perform a contract we may have with you;
  • to comply with our legal and regulatory obligations, including anti-money laundering (AML), Know Your Client (KYC), sanctions and Politically Exposed Person (PEP) checks, beneficial ownership verification, tax obligations, professional conduct rules and court orders;
  • to conduct administrative and operational processes within our business, and to manage our client, intermediary and other business relationships;
  • to establish, exercise or defend our legal rights, or for the purposes of legal proceedings or obtaining legal advice;
  • to process and respond to requests, enquiries or complaints received from you or someone connected to you;
  • should you apply for a position with us, to review and process your application; and
  • for other legitimate business purposes, including assessing whether to accept you as a client, protecting ourselves against fraud, misuse or breach of professional duty, managing disputes, and ensuring the security of our systems and information.

The lawful bases we rely on for this processing include: performance of a contract to which you are a party, or steps taken at your request before entering into a contract; compliance with a legal obligation to which we are subject, including our professional and regulatory obligations; our legitimate interests, including providing our services efficiently, protecting our business, staff and systems, and internal know-how and training, provided these interests are not overridden by your interests or rights; the processing being necessary for legal proceedings, obtaining legal advice, or establishing, exercising or defending legal rights; and, in limited circumstances, your consent.

Typical scenarios are set out in the table below.

Purpose

Type of data we collect / process

Legal basis for processing

To provide and improve our services and perform a contract with you

Contact details; financial information such as professional background, assets, transactions and tax status; any other information you provide, including special category data

Performance of a contract; legitimate interest; consent

To comply with our legal and regulatory obligations, including anti-money laundering legislation

Contact details; financial information, including source of funds and source of wealth

Legitimate interest; legal obligation

To manage our client, intermediary and business relationships and conduct administrative processes

Contact details; financial information

Performance of a contract; legitimate interest

To process and respond to requests, enquiries or complaints

Contact details; financial information; any other information provided

Legitimate interest; consent

Should you apply for a position with us

Contact details; career information; any other information provided, including special category data

Legitimate interest; consent

Change of Purpose

We will use your personal data only for the purposes described in this notice unless we have a lawful reason to use it for a different purpose. If we intend to use your data for a purpose that is materially different from those set out above, we will provide you with information about the new purpose and its lawful basis and will obtain your consent where the law requires it, giving you the opportunity to object to the new use.

Automated Decision-Making and Artificial Intelligence

We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing, including profiling. This is consistent with Article 38 of the DPJL 2018.

We use artificial intelligence (AI) tools to help us provide our services efficiently and to a high standard. These tools may assist with drafting, reviewing, summarising and analysing documents and information, with legal and factual research, and with administrative processes. AI tools support our staff in their work; they do not replace human decision-making. Where we process personal data using AI tools, the legal basis is the same as the basis for the underlying purpose described in this notice, and we apply the following safeguards:

  • Closed, contractually protected tools. We use AI tools provided to us under commercial contracts that include data protection obligations. We do not enter your personal data into open or publicly accessible AI tools.
  • No training on your data. We do not permit our AI service providers to use your personal data to train their AI models.
  • Human oversight. AI-assisted work is reviewed by a suitably qualified member of our staff, and decisions that affect you are not made solely by automated means.
  • Security and data minimisation. AI processing is subject to the security measures described under Data Security below, and we limit the personal data processed through AI tools to what is necessary for the relevant purpose.
  • Due diligence. We carry out due diligence on our AI service providers and enter into appropriate data processing agreements with them.

Our principal AI-enabled system is our document management system, provided by NetDocuments, which processes personal data on our behalf as our processor and hosts it primarily in the United Kingdom. Within that system, we use AI features that assist with drafting, summarising, searching and analysing documents; on particular matters, and under our supervision, the system may send relevant content to external AI providers to carry out a specific task. The safeguards set out above apply to that processing. We keep our use of AI, and the AI providers and terms on which they operate, under review.

Who We Share Your Data With

We share personal data with processors and service providers who process data on our behalf or for specific purposes connected with the delivery of legal services, compliance, employment administration and facilities management. The table below sets out our principal processors.

Processor

Description of processing

Link to privacy notice

Computer Concepts Ltd

IT services and maintenance; PAT testing

Computer Concepts – Privacy

Kroll (Channel Islands) Limited

Regulatory assistance

Privacy Policy | Jersey Finance

Tiller

Customer due diligence and identity verification

Privacy Policy

Sonnic Cleaning

Confidential waste bins

Sonnic | Privacy

Worldcheck (LSEG)

Customer due diligence and PEP checks

Privacy Statement | LSEG

Microsoft (Office 365 / Azure)

Mailbox, productivity services and cloud hosting

Microsoft Privacy Statement – Microsoft privacy

NetDocuments

Document management system, including AI-assisted features

NetDocuments Privacy Notice

Lawman

Legal and compliance software services

Timeslice – Privacy Policy

We may also share personal data with other recipients where this is necessary for our business and legal services, including: counterparties to transactions or litigation, including law firms acting for other parties; other professional service providers, our own advisers such as auditors and accountants, and any external legal advisers we instruct; regulators, law enforcement agencies, governmental institutions, tribunals and courts, to the extent required by law, regulation or court order, or where compliance with a legal obligation such as our AML obligations requires disclosure; and, if you apply for a position with us, referees and others able to confirm details you have provided.

We do not rent or sell personal data to any other organisation or individual. Where we enter into an engagement with a third party under which personal data may be processed by that third party, we put in place a written agreement setting out each party’s respective obligations and satisfy ourselves that the third party has measures in place to protect data against unauthorised or accidental use, access, disclosure, damage, loss or destruction.

International Transfers of Personal Data

Personal data is hosted primarily in the United Kingdom by our IT and cloud service providers, principally Microsoft 365, Microsoft Azure and NetDocuments. Where we transfer personal data to a jurisdiction outside Jersey, we do so in accordance with Articles 66 and 67 of the DPJL 2018, and will ensure, before any such transfer, that the recipient meets the relevant data protection requirements applicable to the data being transferred. This may include being satisfied that the recipient has agreed by contract to protect the data to a standard consistent with the DPJL 2018, that the destination jurisdiction has data protection laws that provide comparable protection, or that we have obtained consent from the relevant data subjects to the transfer.

Where personal data is transferred to the United States of America, the transfer will be made to organisations participating in the EU-US Data Privacy Framework where possible; where that framework does not apply, we will put in place appropriate safeguards in accordance with the DPJL 2018, such as Standard Contractual Clauses or a Data Processing Agreement, to keep your personal data adequately protected.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law, in accordance with our data retention schedule. Our general policy is to retain data relating to a client matter for at least 11 years from the conclusion of that matter. This is subject to certain exceptions, including matters relating to wills and probate, property and conveyancing, and trusts, where records may be kept indefinitely, and instances where personal data remains relevant to a dispute after the closure of a matter, or cannot be deleted for legal, regulatory or technical reasons.

If you would like further information about our retention periods for specific data, or wish to request that data be destroyed, please contact our Data Protection Manager:dataprotection@dgadvocates.com

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, and against accidental loss, destruction, alteration or disclosure, taking account of the nature of the data and the risks involved, consistent with Article 21 of the DPJL 2018. These measures include:

  • encryption of personal data in transit and at rest;
  • access controls on a need-to-know basis, with multi-factor authentication;
  • network and endpoint security, including firewalls, malware protection, patching and monitoring;
  • physical security of our premises and records;
  • staff training and confidentiality obligations;
  • due diligence on, and written contracts with, the third parties and service providers that process data on our behalf; and
  • business continuity, disaster recovery and incident response plans.

Our processors and service providers are subject to contractual data protection obligations and are required to implement similar security standards. No method of transmission over the internet or storage is completely secure and we cannot guarantee absolute security of your data, but we keep our measures under review.

If you have concerns about the security of your personal data, or suspect a data breach, please contact our Data Protection Manager immediately using the details in this notice.

Personal Data Breaches

If a personal data breach occurs, we will assess it and, where the breach is likely to result in a risk to your rights, notify the Jersey Office of the Information Commissioner and, where required, notify you, in accordance with Article 20 of the DPJL 2018.

Your Rights as a Data Subject

Under the DPJL 2018, you have the following rights in relation to your personal data:

  • Right of access: you have the right to obtain confirmation of whether we hold your personal data and, if we do, to receive a copy of it.
  • Right to rectification: you have the right to request correction of personal data that is inaccurate or incomplete.
  • Right to erasure: you have the right to request deletion of your personal data in certain circumstances, for example where it is no longer necessary for the purpose it was collected, or where you withdraw consent.
  • Right to restriction of processing: you have the right to request that we restrict processing in certain circumstances, for example where you contest the accuracy of the data, or where processing is unlawful, but you do not wish us to delete it.
  • Right to data portability: you have the right to receive your personal data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted directly to another controller.
  • Right to object: you have the right to object to processing of your personal data on grounds relating to your situation, including the right to object to direct marketing.
  • Rights related to automated decision-making: you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you.

These rights are not absolute and may be restricted by law. For example, we may refuse a request for erasure if we are required by law to retain the data, or if the data is necessary to defend a legal claim.

If you choose not to provide personal data or exercise your rights in a way that limits our ability to process it, we may be unable to provide you with the relevant services. We will notify you if this is the case.

How to Exercise Your Rights

To exercise any of the rights listed above, please submit a request to our Data Protection Manager at the contact details below, providing as much detail as possible about the data concerned or the right you wish to exercise.

We will respond within four weeks of receipt, in accordance with Article 27 of the DPJL 2018. If your request is complex or you have made multiple requests, we may extend this period by a further eight weeks, and if we do so we will tell you within the original four-week period, together with our reasons. We may ask you for additional information to verify your identity or clarify your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act on it.

Right to Withdraw Consent

Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time, by contacting our Data Protection Manager using the details in this notice. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Changes to This Privacy Notice

We keep this privacy notice under review and may update it from time to time to reflect changes in our data processing activities, legal requirements, or other relevant factors. Updates will appear on our website at www.dgadvocates.com/privacy, and any significant changes will be communicated to you in advance where practicable or notified to you when you next interact with us.

Complaints

If you have concerns about how we have processed your personal data or believe we have breached data protection law, you may lodge a complaint with us in the first instance.

Dickinson Gleeson contact details:

Dickinson Gleeson, Le Gallais Building
6 Minden Place, St Helier, Jersey JE2 4WQ
Telephone: +44 (0) 1534 737757
Website: https://www.dgadvocates.com/about-us/

You also have the right to lodge a complaint with the supervisory authority responsible for data protection in Jersey:

Jersey Office of the Information Commissioner (JOIC)
2nd Floor, 5 Castle Street
St Helier, Jersey JE2 3BT, Telephone: +44 (0) 1534 716530
Email: enquiries@jerseyoic.je  Website: jerseyoic.org

Complaints to the JOIC may be made at any time. You do not have to complain to us first, although we would welcome the opportunity to resolve your concerns.