Navigate YOUR FINANCIAL FUTURE
The host of this website and all visitors to this website agree that the visitor to this website is the data user within the meaning set out in the Personal Data Protection Act 2010 ("Data Subject") and that the host of this website is the data user within the meaning set out in the Personal Data Protection Act 2010 ("Data User"). The Data User shall and shall procure its affiliates, contractors and/or sub-contractors to:
- Process personal data within the meaning set out in the Personal Data Protection Act 2010 ("Personal Data") only in accordance with instructions from the Data Subject (which may be specific instructions or instructions of a general nature as set out herein or as otherwise notified by the Data User to the Data Subject);
- utilise the Personal Data only to the extent, and in such manner, as is necessary for the provision of service as advertised or as is required by law or any regulatory bodies;
- implement appropriate technical and organisational measures to protect the Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration or disclosure. These measures shall be appropriate to the harm which might result from any unauthorised or unlawful Processing, accidental loss, destruction or damage to the Personal Data and having regard to the nature of the Personal Data which is to be protected;
- take reasonable steps to ensure the reliability of any of the Data User’s affiliates’ contractors’ and/or sub-contractors’ personnel and/or sub-contractors who have access to the Personal Data;
- obtain prior written consent from the Data Subject in order to transfer the Personal Data to any other of the Data User’s affiliates and/or sub-contractors for the provision of the Services save where delegation is expressly provided for herein;ensure that all the Data User’s affiliates and/or sub-contractors’ personnel required to access the Personal Data are informed of the confidential nature of the Personal Data and comply with the obligations set out in this Clause 6 (Protection of Personal Data);
- ensure that none of publish, disclose or divulge any of the Personal Data to any third party unless directed in writing to do so by the Data Subject;
- notify the Data Subject immediately if it receives:
- a request within the meaning set out in the Personal Data Protection Act 2010 to have access to that Data Subject's Personal Data; or
- a complaint or request relating to the Data Subject's obligations under the Personal Data Protection Act 2010 and all applicable laws and regulations, including guidance and codes of practice relating to Processing of personal data and privacy ("Data Protection Legislation");
- provide the Data Subject with full cooperation and assistance in relation to any complaint or request made, including by:
- providing the Data Subject with full details of the complaint or request;
- complying with a data access request within the relevant timescales set out in the Data Protection Legislation and in accordance with the Data Subject’s instructions;
- providing the Data Subject with any Personal Data it holds in relation to a Data Subject (within the timescales required by the Data User); and
- providing the Data Subject with any information requested by the Data Subject;
- permit the Data Subject’s audit team (“the Audit Team”) to inspect and audit, the Data User’s data Processing activities (and those of its related companies and/or sub-contractors) and comply with all reasonable requests or directions by the Audit Team to enable the Audit Team to verify and/or procure that the Data User is in full compliance with its obligations under this Agreement; and
- provide a written description of the technical and organisational methods employed by the Data User and its Affiliates for Processing Personal Data (within the timescales required by the Audit Team).
The Data User shall comply and shall procure its contractors and/or sub-contractor to comply at all times with the Data Protection Legislation and shall not perform its obligations under this Agreement in such a way as to cause the Data Subject any harm and/or a breach of any of the applicable obligations under the Data Protection Legislation.