Privacy Notice
Dickinson Gleeson
Dickinson Gleeson (“Dickinson Gleeson”, “we”, “us” or “our”) is a Jersey law partnership providing legal services and is the data controller responsible for the personal data described in this privacy notice. We are registered with the Jersey Office of the Information Commissioner (JOIC) under registration number 19626.
This notice explains how we collect, use, share and protect personal data belonging to our clients, prospective clients, intermediaries, existing and prospective members of staff, and other third parties with whom we interact in the course of our business, together with any individual connected to those parties. It also explains the rights available to those individuals in respect of their personal data. This notice is issued in accordance with the Data Protection (Jersey) Law 2018 (the “DPJL 2018”).
We have appointed a Data Protection Manager to oversee our compliance with data protection law and to act as your point of contact for all data protection matters. You may contact our Data Protection Manager at any time using the details below.
Data Protection Manager:
dataprotection@dgadvocates.com
We collect and process personal data about individuals who engage with us as clients, prospective clients, intermediaries, third parties connected with legal matters, and existing or prospective members of staff. The categories of personal data we may collect and process include the following.
Category of information | Examples |
Identity and contact details | Full name, date of birth, residential and postal address, email address, telephone number, nationality and signature. |
Client take-on and compliance documentation | Proof of identity, proof of address, beneficial ownership declarations, and source of funds and source of wealth documentation required for anti-money laundering purposes. |
Know Your Client (KYC) and screening information | Politically Exposed Person (PEP) screening results, sanctions screening results, adverse media checks, and criminal background screening. |
Financial information | Bank account details, payment-related information, details of financial transactions, asset information, tax status, and evidence of source of funds. |
Information relating to legal matters | Details of your instructions, correspondence, documents, transaction details, professional relationships and background, disputes and court proceedings, and other information necessary to provide legal services. |
Website enquiries | The content of any enquiry you submit through our website, and any other information you choose to provide to us. |
Recruitment information | Details of past employment, professional qualifications and education, nationality and immigration or residential status, references and other opinions provided by third parties, and other information gathered during a recruitment process, where you apply for a position with us. |
Data about connected individuals | Personal data about people connected to you by professional or other association, or by family relationship, which you or a third party may provide to us. |
It is important that the personal data we hold about you is accurate and up to date. Please keep us informed if your personal data changes during the course of your relationship with us.
We collect personal data directly from you when you instruct us to provide legal services, when you contact us with an enquiry, or when you complete client take-on forms and compliance documentation. Personal data may also come from clients, intermediaries, other third parties connected to a data subject (for example, an employer or another service provider), or from publicly available sources.
We may also receive personal data about you from third parties, such as other legal representatives, financial institutions, or public registers, where this is necessary to carry out KYC checks, regulatory due diligence, or to verify information you have provided to us. Also, where it is required to comply with Anti Money Laundering (AML) and Client Due Diligence (CDD) obligations, Dickinson and Gleeson may obtain information from publicly available sources, including internet searches and/or adverse media screening tools.
In some circumstances, the personal data we process may include special category data: information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data processed to uniquely identify a person, health data, data concerning a person’s sex life or sexual orientation, or data relating to criminal convictions or alleged criminal activity.
We only collect and use special category data where it is necessary to provide you with legal services, to comply with our legal or regulatory obligations, or where we have another specific lawful reason to do so – for example, information about your health where you are seeking advice on a personal injury claim, or information about criminal convictions or offences that is relevant to the matter on which we are advising you. Special category data is processed only on the basis of the conditions set out in paragraph 1 of Schedule 2 to the DPJL 2018 (ordinary personal data) and Part 2 of Schedule 2 to the DPJL 2018 (special category data), and access is limited to staff members who need it to provide services or comply with our legal obligations.
How We Use Your Personal Data: Purposes and Legal Basis
We process personal data for the purposes set out below, each supported by a lawful basis under Article 9 and Schedule 2 of the DPJL 2018:
The lawful bases we rely on for this processing include: performance of a contract to which you are a party, or steps taken at your request before entering into a contract; compliance with a legal obligation to which we are subject, including our professional and regulatory obligations; our legitimate interests, including providing our services efficiently, protecting our business, staff and systems, and internal know-how and training, provided these interests are not overridden by your interests or rights; the processing being necessary for legal proceedings, obtaining legal advice, or establishing, exercising or defending legal rights; and, in limited circumstances, your consent.
Typical scenarios are set out in the table below.
Purpose | Type of data we collect / process | Legal basis for processing |
To provide and improve our services and perform a contract with you | Contact details; financial information such as professional background, assets, transactions and tax status; any other information you provide, including special category data | Performance of a contract; legitimate interest; consent |
To comply with our legal and regulatory obligations, including anti-money laundering legislation | Contact details; financial information, including source of funds and source of wealth | Legitimate interest; legal obligation |
To manage our client, intermediary and business relationships and conduct administrative processes | Contact details; financial information | Performance of a contract; legitimate interest |
To process and respond to requests, enquiries or complaints | Contact details; financial information; any other information provided | Legitimate interest; consent |
Should you apply for a position with us | Contact details; career information; any other information provided, including special category data | Legitimate interest; consent |
We will use your personal data only for the purposes described in this notice unless we have a lawful reason to use it for a different purpose. If we intend to use your data for a purpose that is materially different from those set out above, we will provide you with information about the new purpose and its lawful basis and will obtain your consent where the law requires it, giving you the opportunity to object to the new use.
We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing, including profiling. This is consistent with Article 38 of the DPJL 2018.
We use artificial intelligence (AI) tools to help us provide our services efficiently and to a high standard. These tools may assist with drafting, reviewing, summarising and analysing documents and information, with legal and factual research, and with administrative processes. AI tools support our staff in their work; they do not replace human decision-making. Where we process personal data using AI tools, the legal basis is the same as the basis for the underlying purpose described in this notice, and we apply the following safeguards:
Our principal AI-enabled system is our document management system, provided by NetDocuments, which processes personal data on our behalf as our processor and hosts it primarily in the United Kingdom. Within that system, we use AI features that assist with drafting, summarising, searching and analysing documents; on particular matters, and under our supervision, the system may send relevant content to external AI providers to carry out a specific task. The safeguards set out above apply to that processing. We keep our use of AI, and the AI providers and terms on which they operate, under review.
We share personal data with processors and service providers who process data on our behalf or for specific purposes connected with the delivery of legal services, compliance, employment administration and facilities management. The table below sets out our principal processors.
Processor | Description of processing | Link to privacy notice |
Computer Concepts Ltd | IT services and maintenance; PAT testing | |
Kroll (Channel Islands) Limited | Regulatory assistance | |
Tiller | Customer due diligence and identity verification | |
Sonnic Cleaning | Confidential waste bins | |
Worldcheck (LSEG) | Customer due diligence and PEP checks | |
Microsoft (Office 365 / Azure) | Mailbox, productivity services and cloud hosting | |
NetDocuments | Document management system, including AI-assisted features | |
Lawman | Legal and compliance software services |
We may also share personal data with other recipients where this is necessary for our business and legal services, including: counterparties to transactions or litigation, including law firms acting for other parties; other professional service providers, our own advisers such as auditors and accountants, and any external legal advisers we instruct; regulators, law enforcement agencies, governmental institutions, tribunals and courts, to the extent required by law, regulation or court order, or where compliance with a legal obligation such as our AML obligations requires disclosure; and, if you apply for a position with us, referees and others able to confirm details you have provided.
We do not rent or sell personal data to any other organisation or individual. Where we enter into an engagement with a third party under which personal data may be processed by that third party, we put in place a written agreement setting out each party’s respective obligations and satisfy ourselves that the third party has measures in place to protect data against unauthorised or accidental use, access, disclosure, damage, loss or destruction.
Personal data is hosted primarily in the United Kingdom by our IT and cloud service providers, principally Microsoft 365, Microsoft Azure and NetDocuments. Where we transfer personal data to a jurisdiction outside Jersey, we do so in accordance with Articles 66 and 67 of the DPJL 2018, and will ensure, before any such transfer, that the recipient meets the relevant data protection requirements applicable to the data being transferred. This may include being satisfied that the recipient has agreed by contract to protect the data to a standard consistent with the DPJL 2018, that the destination jurisdiction has data protection laws that provide comparable protection, or that we have obtained consent from the relevant data subjects to the transfer.
Where personal data is transferred to the United States of America, the transfer will be made to organisations participating in the EU-US Data Privacy Framework where possible; where that framework does not apply, we will put in place appropriate safeguards in accordance with the DPJL 2018, such as Standard Contractual Clauses or a Data Processing Agreement, to keep your personal data adequately protected.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law, in accordance with our data retention schedule. Our general policy is to retain data relating to a client matter for at least 11 years from the conclusion of that matter. This is subject to certain exceptions, including matters relating to wills and probate, property and conveyancing, and trusts, where records may be kept indefinitely, and instances where personal data remains relevant to a dispute after the closure of a matter, or cannot be deleted for legal, regulatory or technical reasons.
If you would like further information about our retention periods for specific data, or wish to request that data be destroyed, please contact our Data Protection Manager:dataprotection@dgadvocates.com
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, and against accidental loss, destruction, alteration or disclosure, taking account of the nature of the data and the risks involved, consistent with Article 21 of the DPJL 2018. These measures include:
Our processors and service providers are subject to contractual data protection obligations and are required to implement similar security standards. No method of transmission over the internet or storage is completely secure and we cannot guarantee absolute security of your data, but we keep our measures under review.
If you have concerns about the security of your personal data, or suspect a data breach, please contact our Data Protection Manager immediately using the details in this notice.
If a personal data breach occurs, we will assess it and, where the breach is likely to result in a risk to your rights, notify the Jersey Office of the Information Commissioner and, where required, notify you, in accordance with Article 20 of the DPJL 2018.
Under the DPJL 2018, you have the following rights in relation to your personal data:
These rights are not absolute and may be restricted by law. For example, we may refuse a request for erasure if we are required by law to retain the data, or if the data is necessary to defend a legal claim.
If you choose not to provide personal data or exercise your rights in a way that limits our ability to process it, we may be unable to provide you with the relevant services. We will notify you if this is the case.
To exercise any of the rights listed above, please submit a request to our Data Protection Manager at the contact details below, providing as much detail as possible about the data concerned or the right you wish to exercise.
We will respond within four weeks of receipt, in accordance with Article 27 of the DPJL 2018. If your request is complex or you have made multiple requests, we may extend this period by a further eight weeks, and if we do so we will tell you within the original four-week period, together with our reasons. We may ask you for additional information to verify your identity or clarify your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act on it.
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time, by contacting our Data Protection Manager using the details in this notice. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
We keep this privacy notice under review and may update it from time to time to reflect changes in our data processing activities, legal requirements, or other relevant factors. Updates will appear on our website at www.dgadvocates.com/privacy, and any significant changes will be communicated to you in advance where practicable or notified to you when you next interact with us.
If you have concerns about how we have processed your personal data or believe we have breached data protection law, you may lodge a complaint with us in the first instance.
Dickinson Gleeson contact details:
Dickinson Gleeson, Le Gallais Building
6 Minden Place, St Helier, Jersey JE2 4WQ
Telephone: +44 (0) 1534 737757
Website: https://www.dgadvocates.com/about-us/
You also have the right to lodge a complaint with the supervisory authority responsible for data protection in Jersey:
Jersey Office of the Information Commissioner (JOIC)
2nd Floor, 5 Castle Street
St Helier, Jersey JE2 3BT, Telephone: +44 (0) 1534 716530
Email: enquiries@jerseyoic.je Website: jerseyoic.org
Complaints to the JOIC may be made at any time. You do not have to complain to us first, although we would welcome the opportunity to resolve your concerns.