Section 1: Introduction
This Privacy Notice is issued by NBC Global Finance Limited (“NBCGF”), Embassy House, Herbert Park Lane, Ballsbridge, Dublin 4 in its capacity as a Controller and applies to all potential job applicants and trading counterparties of NBCGF, to include the employees, contractors, agents, representatives, directors, beneficial owners and anyone else associated with such job applicants and trading counterparties (the “Data Subject”).
References in this Privacy Notice to “we”, “us” or “our” should be construed as references to NBCGF and references to “you” and “your” are references to you as the Data Subject.
NBCGF may amend this Privacy Notice from time to time to reflect regulatory or legislative changes, or changes to NBCGF’s internal procedures. In the event of a material amendment, NBCGF may send you written notice describing the relevant changes.
If you have any questions regarding this Privacy Notice, please contact the NBCGF Compliance Function at compliance.dublin@nbcgf.ie.
Section 2: Gathering and collecting personal data
NBCGF may gather, collect, use, store and process Personal Data of Data Subjects (as defined below). This is known as Processing Personal Data (and is defined further below). NBCGF ensures it has a legal basis for Processing the Personal Data of Data Subjects.
NBCGF collects the following personal data on data subjects
Contact, verification and validation information
May include Names, Addresses, Email Addresses, Telephone Numbers, Occupation, Dates of Birth, Passports, Drivers Licenses, National ID Validation Documentation, Proof of Address Documentation, Beneficial Ownership Information, Politically Exposed Persons and/or Relevant Close Associates Information, Negative News Information, Authorised Signatory Lists, Sanctions Verification Documentation, Communications including Telephone, Outlook, Bloomberg Communications and Information relating to data subject right requests.
Professional information
Curriculum vitae, and/or application form, previous employment background, references from previous employers, record of interview/interview notes, selection and verification records, educational details, professional and/or academic transcripts, professional certifications, special skills, language skills, memberships of committees or other bodies, financial and probative information.
NBCGF collects and gathers the personal data via the following methods
Direct Request
When we directly request you to provide us with the information and you provide such Personal Data either verbally or in writing.
Ordinary course of Business
When it is provided during the ordinary course of the business and/or contractual relationship
Third Party Service Providers
When we directly request information to be provided to us by third party service providers (e.g. client onboarding platforms, publicly accessible sources and law enforcement authorities).
Group Affiliates
When it is provided by one or more affiliates within the National Bank of Canada (“NBC”) group. Such affiliates may also be acting as a Controller or Processor (as defined below) in respect of the Personal Data.
NBCGF processes the Personal Data for following purposes and legal bases
Category of Personal Data: Contact, Verification and Validation Information
| Purpose | Legal bases |
|---|---|
To provide services as an investment firm authorised under the MiFID Regulations by the Central Bank of Ireland and to comply with the obligations arising thereunder |
Processing is necessary for compliance with a legal or regulatory obligation; and/or
Processing is necessary to pursue the legitimate interests of NBCGF (except if such interests are overridden by the interests or fundamental rights of the data subject)1 |
| Business and/or Contractual purposes: These will be identified and assessed on a case-by-case basis but may include: negotiation and storage of contracts and exchange of signing authority validations. | Processing is necessary to pursue the legitimate interests of NBCGF (except if such interests are overridden by the interests or fundamental rights of the data subject) |
| Administrative purposes: These may include but are not limited to onboarding validations, contact with Data Subjects, scheduling of interviews and meetings and associated internal filing. | Processing is necessary to pursue the legitimate interests of NBCGF (except if such interests are overridden by the interests or fundamental rights of the data subject) |
| To comply with Legislative and Regulatory purposes (e.g. Anti-Money Laundering and Counter Terrorist Financing legislation in addition to the legislative requirements of MiFID II, EMIR and all other applicable legislation and regulation) | Processing is necessary for compliance with a legal or regulatory obligation2 |
| Processing job applications | Processing is necessary for the performance of a contract to which you are subject or to take steps at your request prior to entering into such a contract. |
| In order to comply with NBCGF’s internal policies and procedures | Processing is necessary to pursue the legitimate interests of NBCGF (except if such interests are overridden by the interests or fundamental rights of the data subject) |
We may also be required to use your Personal Data for the purposes of establishing, exercising or defending legal proceedings. NBCGF will also lawfully process your Personal Data where it has received Consent (as defined below) from the Data Subject.
1 Legitimate Interests may include but are not limited to: the operation of our business in a commercially prudent manner, administration and management of personnel and in particular ensuring that company policies are being complied with, establishing, exercising and safeguarding NBCGF's legal rights; creating efficiencies in NBCGF's internal processes and preparing aggregated reports for use by NBCGF or external parties such as the Central Bank of Ireland
2 Please note that where legal or regulatory obligations are cited as a legal basis for processing Personal Data, examples of such legal obligations include, but are not limited to; our obligations under the Markets in Financial Instruments Directive II (“MiFID II”) which was transposed into Irish law by S.I. No. 375 of 2017 European Union (Markets in Financial Instruments) Regulation 2017 (“MiFID Regulations”) and EU Regulation 648/2012 on OTC Derivatives, Central Counterparties and Trade Repositories (“EMIR”)
Category of Personal Data: Professional information
| Purpose | Legal bases |
|---|---|
| Processing job applications | Processing is necessary for the performance of a contract to which you are subject or to take steps at your request prior to entering into such a contract. |
We may also be required to use your Personal Data for the purposes of establishing, exercising or defending legal proceedings. NBCGF will also lawfully process your Personal Data where it has received Consent (as defined below) from the Data Subject.
Section 3: Disclosure of personal data
NBCGF may disclose your Personal Data to other individuals and entities, for legitimate business purposes. This includes:
- Internally for business purposes;
- Internal transfers within the NBC group;
- Third Party Service Providers to NBCGF (e.g. auditors, external legal counsel and other outside professional advisors to NBCGF);
- Regulatory Authorities (e.g. Central Bank of Ireland);
- Governmental, regulatory or other law enforcement agencies (e.g. An Garda Siochana, the Revenue Commissioners).
We will take all reasonable steps, as required by law, to ensure the safety, privacy and integrity of such data and information and, where appropriate, enter into contracts with such third parties to protect the privacy and integrity of such data and any information supplied.
Section 4: Storage and retention
NBCGF securely stores your Personal Data for a period necessary to meet the purpose for which it was collected, including for the purposes of complying with anti-money laundering legislation and other measures in financial regulations such as the MiFID II as implemented in Ireland. Even when you cease to do business with us, we may further retain some of your Personal Data in case of queries or claims, for a period of 7 years.
Section 5: International transfers
Personal Data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Community ('EEA'). Due to the global nature of our business, your Personal Data may be disclosed to group companies outside of the EEA, including in particular to group entities in Canada, for purposes connected with your employment and/or contractual relationship with NBCGF.
These locations may not provide an adequate level of data protection. The European Commission has however partially recognised Canada (commercial organisations) as providing adequate protection. To obtain more information, please contact the NBCGF Compliance Function at compliance.dublin@nbcgf.ie.
Section 6: Data security
NBCGF uses a variety of security technologies and procedures to help protect your personal information from unauthorised access, use or disclosure. NBCGF also take steps to ensure that only persons with appropriate authorisation can access your personal information.
Section 7: Automated decision-making
We do not envisage that any decisions will be taken about you solely using automated means, however we will notify you in writing if this position changes.
Section 8: Data subject rights
Under the GDPR, you are afforded a number of rights with regards to your Personal Data:
- Right of access: You have the right to obtain from us confirmation as to whether or not Personal Data concerning you is being processed, and, where that is the case, to request access to the Personal Data, as well as certain information on how we are processing such data.
- Right to rectification: You have the right to obtain from us the rectification of inaccurate Personal Data concerning you. Considering the purpose of the processing, you may also, in some cases, be entitled to supplemental information regarding incomplete Personal Data.
- Right to erasure (right to be forgotten): You may, in certain circumstances, have your Personal Data deleted, for example if your personal information is no longer necessary in relation to the purpose for which it was collected, if you have objected to the processing of Personal Data and we do not have a legitimate interest which outweighs your interest, if the Personal Data has been processed unlawfully, or if the Personal Data must be deleted to comply with a legal obligation.
- Right to restriction of processing: You may require that we restrict the processing of your Personal Data in certain cases, for example where we no longer need your Personal Data but you need it to determine, enforce or defend legal claims or you have objected to processing based on our legitimate interest in order to enable us to check if our interest overrides your interest.
- Right to data portability: In some circumstances, you may be entitled to receive the Personal Data concerning you which you have provided to us in a structured, commonly used and machine-readable format and you have the right to transmit those Personal Data to another Controller.
- Right to object: You have the right to object to the processing of your Personal Data in certain circumstances, for example where the processing is based on our legitimate interest. If so, in order to continue processing, we must be able to show compelling legitimate grounds that override your interests, rights and freedoms.
You may also withdraw your Consent with respect to NBCGF processing your Personal Data, however this will not affect the lawfulness of the processing based on your Consent prior to the withdrawal. Your rights will in each case be subject to the restrictions set out in applicable data protection laws. If you have any concerns as to how your data is processed, or if you want to exercise any of your rights, please contact:
Conor Doyle
Chief Compliance Officer
conor.doyle@nbcgf.ie
+353 86 6071229
If you have any grievance, issue or problem in respect of our handling or processing of your Personal Data in any way, you have a right to lodge a complaint to the Data Protection Commission, whose contact details are available here.
Helpful definitions
Consent
Any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her.
Controller
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Personal Data
Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing
Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Processor
The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.