ĢƵ Allen Global Privacy Statement
Last Updated: April 2025
1. Introduction and Definitions
This Privacy Statement broadly explains how and why ĢƵ Allen Hamilton collects and uses Personal Information (as defined below). It also describes the rights you have with respect to your Personal Information.
In this Privacy Statement, “ĢƵ Allen” refers to ĢƵ Allen Hamilton, Inc. and its subsidiaries and affiliates (collectively, “ĢƵ Allen,” “We” or “Company”). Personal Information (or “PI”) refers to information that can identify an individual, either on its own or when combined or associated with other information. PI includes Sensitive PI (or “SPI”) and Protected Health Information (or “PHI”).
SPI refers to certain categories of PI, such as:
- Social Security numbers
- government identification cards or numbers
- citizenship or immigration status associated with a particular individual
- financial information related to an individual’s financial account
- precise geolocation
- biometric or genetic data identifiable to an individual
- medical information identifiable to an individual
- criminal convictions or offenses identifiable to an individual
- racial or ethnic origin identifiable to an individual
- religious or philosophical beliefs identifiable to an individual
- union membership identifiable to an individual
- sex life or sexual orientation identifiable to an individual
PHI refers to individually identifiable health information created or received by a Covered Entity (for example, health plan, health care clearinghouse, or health care provider conducting electronic transactions) or Business Associate (for example, a service provider which must use, access, or create Protected Health Information to provide services to ĢƵ Allen).
ĢƵ Allen policies limit the collection, use, retention, and disclosure of PI to what is reasonably necessary and proportionate to achieve the purposes for which it was originally collected or processed. ĢƵ Allen policy also limits “secondary uses or disclosures” to that which is compatible with the original purpose of the PI collection.
2. Scope of this Global Privacy Statement
ĢƵ Allen collects and processes information, which sometimes includes Personal Information (or “PI”), in a variety of ways. Please click on the links below to see more detail about the information ĢƵ Allen collects, as well as the purposes for collecting such information:
C. Information About Individuals Who Communicate with ĢƵ Allen Through Email
D. Information in ĢƵ Allen's Customer Relationship Management (CRM) Systems
E. Information About Individuals Who Attend ĢƵ Allen Events
G. PI Collected and Used for ĢƵ Allen Research and Development
H. Information About Visitors to ĢƵ Allen Facilities
I. Information About Individuals Who Pose a Potential Threat or Risk to Others
3. Your Rights in Relation to Personal Information (or “PI") We Collect and Process About You
Depending on where you reside, you might have the following rights related to your PI:
- right to request access to your PI stored by ĢƵ Allen
- right to request that ĢƵ Allen amend, update or correct your PI
- right to request that ĢƵ Allen delete your PI
- right to receive a copy of your PI in a structured, commonly used and machine-readable format to transfer to another company
- right to request information about or to opt-out of automated decision-making
- right to opt-out of marketing communications from ĢƵ Allen at any time
- right to restrict or to object to the processing of your PI by ĢƵ Allen
- right to withdraw consent if you have voluntarily provided PI or have consented to provide your PI
- right to complain to a data protection authority
Note that these rights are not absolute. They are dependent upon, and subject to, certain conditions and exceptions under applicable laws and regulations. Please also note that evolving state laws impact your rights based on your residence. To exercise any of the above rights, please contact us at [email protected] or call 877-927-8278.
In your request, please include the following:
- the nature of the request – that is, the specific right you are asserting (see the Your Rights in Relation to the PI We Collect and Process About You section above)
- the specific PI you seek to access, amend, delete, restrict, transmit to another company, or withdraw your consent to process - or if you wish to exercise one or more of these rights with respect to all of your PI.
For your protection and to mitigate the risk of fraud, we must verify your identity, in accordance with applicable law(s) and regulation(s), before processing your request. Thus, we will only respond to your request if we have enough information about you to verify your identity and your relationship to ĢƵ Allen (e.g., employee, former employee, client).
We will comply with your request as soon as reasonably practicable and within the timeframe set forth in applicable law(s) and regulation(s).
Please also note that we may need to retain certain information to comply with legal or regulatory obligations or to complete any transactions that you began prior to submitting your request. Residual PI may also remain in backup copies. Such residual PI will not be removed until the applicable retention period ends, per ĢƵ Allen’s records retention policy, unless otherwise required by law.
A. California Specific Notice of Rights
1. Right of access and data portability: You may request that ĢƵ Allen disclose to you information about our collection and use of your Personal Information (or “PI”) PI and Sensitive Personal Information (or “SPI”) in the preceding 12 months, including:
- categories and specific pieces of PI and SPI that we collected about a California resident
- categories of sources from which we collect PI or SPI
- business or commercial purpose for which we collect PI or SPI
- categories of PI or SPI that we share and the categories of third parties with whom we share the PI or SPI
- business or commercial purpose for which we share PI or SPI
- categories of PI or SPI that we have disclosed for a business purpose
- length of time, or criteria for determining the length of time, that ĢƵ Allen intends to retain each category of PI and SPI
2. Right to request deletion of PI: You may request that ĢƵ Allen delete your PI or SPI. This request is subject to ĢƵ Allen’s right to maintain PI and SPI for purposes permitted under applicable law. If we cannot comply with your request, we will notify you.
3. Right to request correction of your PI and SPI: You may request that ĢƵ Allen correct inaccurate PI.
4. Right to opt-out of the sale or sharing of your PI for behavioral advertising purposes: You may request that your PI not be sold or shared for behavioral advertising purposes as indicated above. To make this request, click on the Do Not Sell or Share My Information link at the bottom of the Website.
5. Right to limit the use and disclosure of SPI: You may request to direct ĢƵ Allen to limit the use of your SPI to that which is necessary to perform the services or provide the goods as reasonably expected and to only use and disclose SPI as permitted by the CCPA. At this time, ĢƵ Allen only discloses SPI for purposes permitted by the CCPA. If this changes, ĢƵ Allen will notify you of the right to limit the use and disclosure of SPI.
6. Right to non-discrimination: You have the right to exercise any of your rights listed above and any other rights under the CCPA without discrimination by ĢƵ Allen. This includes the right of employees, applicants, and independent contractors not to be retaliated against for the exercise of their CCPA rights.
4. Information We Collect and for What Purposes
A. Information Related to Individuals Who Visit ĢƵAllen.com and Other ĢƵ Allen Websites
Information that Individuals Provide to ĢƵ Allen
We collect information that you voluntarily provide, such as when completing an online form, registering for a ĢƵ Allen sponsored event, subscribing to a ĢƵ Allen white paper or newsletter, or providing contact information to receive ĢƵ Allen communications, such as emails, or engaging with ĢƵ Allen social media posts.
ĢƵ Allen does not collect Sensitive Personal Information (or “SPI”) from our clients (organizations who engage ĢƵ Allen for services and organizations who purchase ĢƵ Allen products or packaged solutions), service providers, or Website visitors unless it is provided to us. We strongly encourage you not to share SPI in open text fields, emails, or other places. If you do, you consent to our collection and processing of such SPI. Likewise, if while visiting our Website(s), communicating with us or posting on a social media page related to ĢƵ Allen, you share any Personal Information (or “PI”) or SPI relating to other people, you represent that you have the authority to do so and to permit us to use such information in a manner consistent with this Privacy Statement.
If you elect to opt-out of receiving ĢƵ Allen publications and/or marketing communications, your name, email address, country, employer, and subscription status will be placed on our opt-out list.
Information you might choose to provide includes:
- name
- job title
- company/organization or employer
- email address
- contact information, including email address and business telephone number
- state and country
- communication preferences
- information relating to events captured through event-related forms, such as dietary restrictions, hotel and flight information, registration/participation status, previous event experience
- information related to providing services, products, or packaged solutions to our clients
- any other information that an individual, entity or organization chooses to provide to us
Information Collected Automatically from Our Website Visitors
If you visit a ĢƵ Allen Website, the Website server(s) might collect certain information automatically from your device. For example, the server(s) might collect:
- broad geographic location (e.g. country, city-level, or zip location)
- Internet Protocol (IP) address
- pixel identifier
- device type
- how the device interacts with the Website, including the pages viewed, time visited, current universal resource locator (URL), and any links you have clicked
Purposes for Which ĢƵ Allen Processes PI Related to Website Visitors
If you visit a ĢƵ Allen Website, here is why we might collect and process information about you or about your device:
- to administer and manage the Website
- to personalize and improve your browsing experience by displaying content and advertising that may be of particular interest to them
- to provide news or information that may interest you
- to analyze data related to Website traffic information and Website visits
- to determine the Website visitor’s employer or affiliation with an organization
- to develop our business strategy and service offerings
- to provide marketing communications and materials
- to monitor and enforce compliance with applicable Terms of Use/terms and conditions/license agreements
- to conduct quality and risk management reviews
- to maintain data and network security
- to provide for event and webinar registrations, management, and coordination
- to allow content downloads
- any other purpose for which Website visitors provide information to ĢƵ Allen
Note: If your internet browser’s “Do Not Track” setting or “Global Privacy Control” signal is enabled, marketing or targeting cookies will be disabled by default.
Legal Bases for Processing PI Related to Website Visitors
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
- ĢƵ Allen’s legal bases are:
- explicit consent of the Website visitor and/or
- ĢƵ Allen’s legitimate interests in:
- effectively delivering information and services to you;
- developing and improving our Websites and Website visitors’ experience;
- marketing our services to you or your employer
B. Information About Individuals Who Engage with ĢƵ Allen on Social Media Sites
ĢƵ Allen uses various social media platforms, such as X (formerly Twitter) and LinkedIn, for recruitment and marketing purposes. For example, we use these platforms to provide information about ĢƵ Allen job opportunities and events and to promote the ĢƵ Allen brand.
ĢƵ Allen is responsible for the content it publishes using social media platforms but does not have control over the social media platforms themselves, nor the way they are administered. When using social media platforms, you must adhere to the social media provider’s terms of use and their privacy policies apply, not ours. If you would like to invoke your rights with respect to the Personal Information (or “PI”)/ Sensitive Personal Information (or “SPI”) that a social media provider has collected about you, you should contact the social media platform provider.
Note also that some social media platform providers provide ĢƵ Allen with data collected from your engagement with our social media sites. This data is aggregated or combined with similar data from other visitors to our social media sites, such as the number of “likes” triggered by our content, the number of posts or visitors to the Websites, information downloaded from our Websites, or the links clicked.
Other Third-Party Software
Google Maps
Our Websites use the Google Maps service via an application programming interface (API). To allow you to use Google Maps, Google’s server(s) use different types of PI, such as an IP address or saved activities. ĢƵ Allen does not control Google’s collection of data. For more information, see Google’s privacy policy.
Legal Bases for Processing and Sharing PI Associated with Social Media Sites and Third-Party Software
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legal bases are:
- consent of the Website visitor; and/or
- ĢƵ Allen’s legitimate interests in:
- promoting ĢƵ Allen services and brands;
- attracting, identifying, and sourcing talent;
- improving Website visitors’ experiences
C. Information About Individuals Who Communicate with ĢƵ Allen Through Email
ĢƵ Allen uses various tools to protect the security of our information technology (IT) assets, including our email transmissions. Examples include:
- software that scans incoming emails for suspicious attachments and scans website domains/URLs to prevent malware attacks
- end-point threat detection tools that detect malicious attacks on system endpoint devices, such as laptops, computers, and mobile devices
- software that blocks certain content or websites
So, if you send emails to ĢƵ Allen, please be aware that your emails will be scanned, to maintain ĢƵ Allen’s IT network security. This means that ĢƵ Allen personnel, or its service providers’ personnel, might see the contents of your email even if those individuals are not the intended recipients of your email.
Legal Bases for Processing Personal Information (or “PI”) in Email Correspondence
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legal bases are:
- consent of the Website visitor; and/or
- ĢƵ Allen’s legitimate interests in:
- protecting its IT infrastructure and network against unauthorized attacks, malicious software and potential data leakage
- maintaining telecommunications connectivity within the company
D. Information in ĢƵ Allen’s Customer Relationship Management (CRM) Systems
ĢƵ Allen processes the following types of Personal Information (or “PI”) about its clients, prospective clients, industry partners, and alumni in its CRM systems:
- name, email address, country, phone
- name of employer or organization with whom the individual is associated
- industry
- data related to an individual’s direct marketing preferences, such as whether the individual has submitted an opt-out request and the individual’s email address
The PI collected in the CRM systems support ĢƵ Allen business development and marketing activities.
If you have opted out of receiving future marketing or promotional communications, your basic contact details (including your email address) will remain on our opt-out list.
Legal Bases for Processing PI in ĢƵ Allen’s CRM Systems
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legal bases are:
- consent of the individual;
- ĢƵ Allen’s legitimate interests in:
- managing and nurturing relationships with its business contacts;
- providing information about ĢƵ Allen and its services;
- thought leadership; organizing, promoting and offering events to clients and prospective clients;
- identifying talented job candidates/recruiting;
- processing job applications for ĢƵ Allen positions;
- hiring job candidates and onboarding new employees;
- carrying out pre-employment background screenings;
- complying with legal or regulatory requirements; and
- protecting the security of ĢƵ Allen personnel, buildings, and assets
E. Information About Individuals Who Attend ĢƵ Allen Events
ĢƵ Allen processes event registrations through ĢƵ Allen Websites and social media platforms. Please see the for details about Personal Information (or “PI”) collected and used in connection to ĢƵ Allen events.
Photographs and Video Recordings at ĢƵ Allen Events
Sometimes ĢƵ Allen takes photographs or records videos at ĢƵ Allen sponsored or co-sponsored events. During registration or at the event, participants are asked to sign a consent form allowing ĢƵ Allen to use their photographs or videos for commercial purposes. ĢƵ Allen will only use photographs or videos when participants have consented to the use of their images for such purposes.
In some circumstances, ĢƵ Allen might not be able to obtain prior written or electronic consent for photographs and video recordings taken at an event. In such circumstances, if photographs or videos are taken at the event, ĢƵ Allen will not use these images for commercial purposes nor publicly post them, unless the persons depicted in the photographs or videos have provided prior written or electronic consent to use them for such purposes.
If you have previously consented and now would like to withdraw your consent, you can contact ĢƵ Allen at the phone number and email provided above in Section 3, Your Rights in Relation to Personal Information (PI) We Collect and Process About You.
Legal Bases for Processing PI About Individuals Who Attend ĢƵ Allen Events
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legal bases are:
- consent of the individual when images, videos and PI are used for commercial or marketing purposes); and
- ĢƵ Allen’s legitimate interests in taking photographs and video recordings related to operating its business (for non-commercial purposes)
F. Information About ĢƵ Allen Clients and Individuals Whose Personal Information (PI) We Process in Providing Services
Information About Clients
When an individual or entity interacts with ĢƵ Allen to obtain ĢƵ Allen services or products, ĢƵ Allen collects and processes PI in connection with providing those products and services.
ĢƵ Allen processes PI voluntarily provided by our clients and potential clients. This PI may include:
- names of client employees or other personnel
- work-related contact Information, including work addresses, email addresses, and telephone numbers of employees and other personnel
- entity name and positions/job roles of employees/personnel
- any other information provided to ĢƵ Allen so that ĢƵ Allen can provide services or packaged solutions to its clients
Information About Individuals (Other than Clients) Whose PI We Process in Providing Services to Clients
In connection with certain client engagements, ĢƵ Allen collects or obtains PI of individuals on behalf of its clients. In those situations, ĢƵ Allen might process the PI of individuals with whom ĢƵ Allen does not have a direct relationship (contractual or otherwise). For example, ĢƵ Allen may conduct a research project on behalf of a client which requires ĢƵ Allen employees to interact directly with individuals and collect their PI, or a client might engage ĢƵ Allen to perform data analytics, cybersecurity assessments, or other services. In doing this latter type of work, ĢƵ Allen might have access to the PI it collects, but which is maintained in its client’s systems.
United States Government Clients
ĢƵ Allen contracts with U.S. and foreign government entities at the national, state/territorial and local level. In providing services to the government, ĢƵ Allen must comply with various privacy and data security laws, regulations, guidance, and policies that apply to any PI maintained in government systems. For example, if ĢƵ Allen conducts a clinical research project, ĢƵ Allen might need to comply with the consent requirements under the Federal Protection of Human Subjects and the Health Insurance Portability and Accountability Act. If ĢƵ Allen obtains PI from or provides PI to the government, it complies with U.S. privacy laws applicable to such PI, as well as the contractual, statutory, and regulatory requirements applicable to ĢƵ Allen’s services.
Commercial Clients
In providing services to commercial (business) clients which involve collecting or processing PI, ĢƵ Allen seeks contractual assurances from them that they have the appropriate legal authority and permissions to provide such PI to ĢƵ Allen. Likewise, ĢƵ Allen typically provides contractual assurances that it will process the PI in a legally compliant manner and accommodate the rights of the individuals whose PI we process, as applicable.
Since ĢƵ Allen provides many types of services to both government and commercial clients, it sometimes processes PI and SPI related to those services, including, but not limited to:
- names
- basic demographic data about an individual, such as date of birth, age, marital status, country of residence, or citizenship
- contact information, such as phone numbers, postal addresses, and email addresses
- employment-related data, such as employer name, role or rank, experience, and prior performance
- health data, such as an individual’s medical diagnosis, treatment, and insurance information
- financial data, such as financial account numbers, salary, benefits, and tax-related information
- biometric data, such as facial images and voiceprints
- religion, race, ethnicity, sexual orientation, gender
- membership in a trade union or other type of worker membership organization
Legal Bases for Processing PI Related to ĢƵ Allen Relationships with Clients
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legal bases are:
- consent of the individual, when required by law
- ĢƵ Allen’s legitimate interests in:
- providing services to our clients and products and packaged solutions to our clients;
- administering contracts with our clients and managing associated services, programs and projects;
- complying with accounting and tax-related requirements;
- marketing its services;
- business development;
- complying with legal and regulatory requirements;
- establishing, exercising, or defending its legal rights; and
- protecting its employees and other personnel, building visitors, facilities, and assets
G. Personal Information (PI) and Anonymized Information Used for Research and Development
ĢƵ Allen collects, receives, and processes PI to develop and improve its products and services. ĢƵ Allen also obtains data sets, which might include PI or de-identified or anonymized PI, for purposes of conducting research and developing new software, systems, technologies and services, including systems or technologies that can perform tasks typically requiring human intelligence. These tasks include, but are not limited to, understanding natural language, recognizing patterns, solving problems, making decisions, and learning from experience (“Artificial Intelligence”).
ĢƵ Allen might also obtain or process “limited data sets” where the data set only has “indirect” identifiers, or “pseudonymized” data sets, where the data set is de-identified, but may be re-identified.
The types of PI that ĢƵ Allen might obtain include, but are not limited to:
- mobile device identifiers
- photographs
- audio or video recordings
- health-related data
- videos o biometric data
- employment-related information
Legal Bases for Processing PI for Research and Development
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legal bases are:
- consent, when required by applicable law and when ĢƵ Allen collects the PI directly from individuals or obtains it from a third party
- ĢƵ Allen’s legitimate interests in:
- conducting its own research and development activities;
- growing ĢƵ Allen’s business;
- offering new services or enhancing existing services;
- enhancing efficiency by streamlining operations and automating repetitive tasks;
- improving decision-making by utilizing data-driven insights; and
- fostering innovation through new Artificial Intelligence-driven products and services.
H. Information About Visitors to ĢƵ Allen Facilities
We collect and process the following categories of Personal Information (or “PI”) about visitors to ĢƵ Allen facilities:
Visitor Records and Access Badges
Before entering a ĢƵ Allen facility, visitors must provide name, contact information, country of residence, and date of birth through an online pre-registration portal or at the door. Visitors must also show a passport or driver’s license to verify the information they have provided.
As explained in the “Legal Bases” subsection below, ĢƵ Allen collects this information to comply with its legal obligation to confirm that the visitor is not on a restricted “watchlist” and to protect ĢƵ Allen personnel, facilities, and assets.
Visitor information is also used to investigate security incidents and for emergency purposes, such as an emergency at the facility requiring identification of all individuals on the premises.
Wi-Fi and ĢƵ Allen Information Assets
ĢƵ Allen monitors and logs traffic on our Wi-Fi networks. Thus, if a visitor is provided with ĢƵ Allen Wi-Fi connectivity or access to its network/information systems, ĢƵ Allen can see information about the visitor’s network behavior, as well as the source and destination addresses to which the individual connects.
Closed Circuit Television (CCTV)
ĢƵ Allen uses CCTV monitoring on facilities where permitted by law. CCTV images are securely stored and used as necessary for security purposes.
Legal Bases for Processing PI About Visitors to ĢƵ Allen Facilities
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legitimate interests in:
- protecting its employees and other personnel, facilities, and assets; and
- complying with laws and regulations related to individuals on a restricted watchlist
I. Information About Individuals Who Pose a Potential Threat or Risk
ĢƵ Allen collects and processes the Personal Information (or “PI”) of individuals who present a potential security threat to ĢƵ Allen people, facilities, assets, business, or reputation.
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
Legal Bases for Processing PI About Individuals Who Pose a Potential Threat or Risk
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data.
ĢƵ Allen’s legitimate interests in:
- protecting personnel, facilities, businesses, and assets;
- preventing and detecting crimes; and
- establishing, exercising, and defending legal claims
J. Information About Suppliers
ĢƵ Allen collects and processes Personal Information (or “PI”) about employees and other personnel who perform work for suppliers, service providers, vendors, and subcontractors (collectively, “Supplier Personnel”). ĢƵ Allen processes this PI to manage its contractual relationships with them and to enable them to provide services.
The PI ĢƵ Allen collects and processes about Suppliers and Supplier Personnel generally includes:
- supplier name
- names of Supplier Personnel
- contact information (business phone and email address) of Supplier Personnel
- all information, which might include PI, in emails, phone calls, video meetings and any other communications between the Supplier and ĢƵ Allen; and
- financial information related to payment of services
As required by applicable laws and regulations, such as those related to fraud and corruption and international trade compliance, ĢƵ Allen also collects PI to check for conflicts of interest and to conduct background checks.
ĢƵ Allen might also collect PI in doing due diligence prior to engaging a Supplier.
Legal Bases for Processing Personal Information (PI) About Suppliers
Under the European Union (EU) and United Kingdom (UK) General Data Protection Regulation (GDPR), personal data about an individual can only be processed if there is a “legal basis” for processing personal data. ĢƵ Allen’s legal bases are:
- performing its contractual obligations
- ĢƵ Allen’s legitimate interests in
- complying with its legal or regulatory obligations;
- managing payments, fees, and charges related to the contract for services;
- identifying any potential conflicts of interest;
- protecting ĢƵ Allen personnel, facilities, assets, and/or reputation; and
- preventing our association with others’ criminal or fraudulent activities
K. Minors
ĢƵ Allen Websites are not directed to individuals under the age of eighteen (18), and we do not knowingly collect, process, disclose, or share the Personal Information (or “PI”) of minors. If you are a minor and believe that you have provided PI, please ask your parent(s) or legal guardian(s) to notify us, and we will delete your PI.
5. Retention of Personal Information (or “PI”)
ĢƵ Allen retains PI for only as long as needed for the reason for which it was collected and based on business and legal requirements, including the need to exercise and defend our legal rights. ĢƵ Allen also maintains records for archiving and historical purposes in compliance with applicable laws.
6. How ĢƵ Allen Protects Personal Information (or “PI”)
ĢƵ Allen uses commercially reasonable organizational, technical, and administrative measures to protect the confidentiality, integrity, and availability of the PI that ĢƵ Allen collects, maintains, and processes. For example, ĢƵ Allen limits access to PI to those with a “need to know” to do their jobs. ĢƵ Allen also has robust policies, procedures, and technical controls to safeguard PI from unauthorized access, loss, misuse, and improper disclosure.
If you have reason to believe that your PI is no longer secure, please immediately notify us at [email protected]. Because email communications are not always secure, please do not include sensitive information in your emails to us.
7. De-Identified Data
To the extent ĢƵ Allen intends to create de-identified data as defined by applicable law for the purposes of using the data in de-identified form, ĢƵ Allen policy requires that the data not be re-identified, except as permitted by applicable law.
8. Transfers of Personal Information (or “PI”) Between ĢƵ Allen Entities
ĢƵ Allen operates globally in several countries. If you would like a list of ĢƵ Allen affiliates and where they operate, please contact ĢƵ Allen at [email protected].
ĢƵ Allen centralizes various internal operations, including IT services, human resources and finance/accounting functions in the United States. Client engagements in jurisdictions outside the United States often involve transfers of PI outside of the client’s or client’s jurisdiction. These transfers occur due to:
- the need to access PI by ĢƵ Allen’s internal operations in the United States
- the location of ĢƵ Allen employees working on the client engagement outside the client’s jurisdiction
- the location of ĢƵ Allen vendors or subcontractors who are located outside of the client’s jurisdiction
This means that your PI may be transferred and processed outside of the country where you may be located. This includes transfers of PI from the European Economic Area (EEA) or United Kingdom (UK) to countries with laws that the EEA, UK, or other jurisdictions have not deemed to provide an adequate level of protection for the processing of personal data.
ĢƵ Allen uses appropriate safeguards to protect the confidentiality, integrity, and availability of the PI transferred among ĢƵ Allen entities. For example, where PI is collected or obtained from individuals in the United Kingdom (UK) or European Economic Area (EEA), ĢƵ Allen has executed data transfer agreements that allow for global transfers within the ĢƵ Allen group of entities.
9. Disclosures of Personal Information (or “PI”) to Suppliers
ĢƵ Allen engages service providers to support our internal operations, including client contracts. We may disclose, and in some cases, transfer PI to our service providers and their affiliates and sub-processors (collectively, “Suppliers”). In other cases, Suppliers may collect and transfer PI on our behalf. For example, Suppliers may provide:
- IT functions, such as information security, data storage, data analytics, business applications, and voicemail
- general operational support, such as enterprise management software, CRM software, archiving, and event management
- accounting, finance, and billing support
- compliance risk reviews and assessments, legal hold services, and legal case management
- subcontractor services when we are engaged by a client
When Suppliers provide services to ĢƵ Allen, they sometimes require access to PI. Thus, when engaging Suppliers, ĢƵ Allen requires them to contractually agree to comply with applicable privacy and data protection laws, including those related to information security and to the transfer of PI outside the jurisdiction from which it was collected. If you would like to know more about the Suppliers ĢƵ Allen engages, please contact ĢƵ Allen at [email protected].
10. Other Disclosures of Personal Information (or “PI”)
In addition to the other reasons set forth in this Privacy Statement, ĢƵ Allen might disclose PI about an individual:
- when directed to do so by the relevant individual or with the individual’s consent
- when the disclosure is consistent with the purposes described in this Privacy Statement
- if and when required by applicable law, including applicable law outside the country where the PI was initially collected and/or where the individual resides
- in connection with a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of ĢƵ Allen’s business assets or stock (including in connection with any bankruptcy or similar proceeding)
- to protect, exercise, and defend ĢƵ Allen’s legal claims, safety, or property
- to comply with a regulatory or government inquiry, court order, or other legal obligation, including in a country different from where the PI was collected
- to cooperate with a law enforcement inquiry or investigation
Note also that ĢƵ Allen is obligated to report certain activities or suspected criminal activity to relevant regulatory authorities and law enforcement entities. In these cases, recipients of the PI might include, for example:
- law firms, tax advisors, or auditors
- insurers
- audit regulators
- tax and customs, and excise authorities
- regulatory bodies
- credit reference/reporting agencies
- courts, police, and law enforcement agencies
- government departments and agencies
- ĢƵ Allen suppliers
ĢƵ Allen is sometimes legally prohibited from informing an individual about the disclosure either: 1) before the disclosure happens or 2) at any time.
11. Contact Us or a Relevant Government Agency
To ask a question, report an alleged violation of a privacy law or regulation, or compliment us, please contact us at [email protected]. You can also reach out to the privacy team at Office of the General Counsel, ĢƵ Allen Hamilton Inc., 8283 Greensboro Drive, McLean, Virginia 22102. Depending on where you live, you might also have the right to submit a complaint to a national or state government agency, such as a Data Protection Authority or relevant Supervisory Authority in your country or your state Attorney General. For example, if you are in the European Economic Area (EEA), you may lodge a complaint with a Data Protection Authority for your country or region, or where an alleged infringement of applicable data protection law occurs.
12. Revisions to This Privacy Statement
We may change this Privacy Statement to reflect changes in our data collection and processing practices and/or applicable laws. Changes will become effective when we post the revised version on this Website. Thus, we recommend checking here from time to time
Revisions to the Privacy Statement
We may change this Privacy Statement to reflect changes in our practices and services. The “Last Updated” legend at the top of this page indicates when this Privacy Statement was last revised. Any changes will become effective when we post the revised notice on this website. We recommend checking this Statement from time to time to inform yourself of any changes based on the last updated date.