Legal
How we collect, use, share and protect personal data, and the rights you have under the UK GDPR.
Haynes Compliance Limited (trading as Haynes Compliance) ("we", "us", "our") provides outsourced compliance, Customer Due Diligence and regulatory advisory services. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for the personal data described in this notice.
If you have any question about this notice or about how we handle personal data, please contact us using the details above.
This notice explains how we handle personal data relating to visitors to this website, prospective and current clients, and individuals whose data we process in the course of providing our services. It also explains how we handle the personal data of third parties, such as beneficial owners and connected persons, whose details are provided to us by our clients.
Where we carry out due diligence or compliance work on behalf of a client, that client is generally the controller of the personal data concerned and we act as a processor on their instructions. Where we exercise our own professional judgement, keep our own records, or meet our own legal and regulatory obligations, we act as a controller in our own right.
Depending on our relationship with you, we may collect and process:
We obtain personal data directly from you; from our clients, where they instruct us in relation to their own customers or counterparties; from publicly available sources such as Companies House, court records, sanctions lists and news media; and from third-party screening, verification and credit reference providers.
Our work can involve information about criminal convictions and alleged offences, and occasionally special category data such as political affiliation where an individual is a politically exposed person. We process this data where it is necessary for reasons of substantial public interest (in particular the prevention and detection of money laundering, terrorist financing, fraud, bribery and other financial crime), as permitted by Schedule 1 of the Data Protection Act 2018, and we apply additional safeguards and restricted access to it.
We may share personal data with:
We do not sell personal data, and we do not share it for third-party marketing.
Our work frequently concerns cross-border matters, and some of our suppliers operate outside the United Kingdom. Where we transfer personal data outside the UK, we do so only where the destination is covered by UK adequacy regulations, or under an appropriate safeguard such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required.
We keep due diligence records for five years from the end of the business relationship or the completion of the transaction, as required by the Money Laundering Regulations 2017, and longer where a law enforcement authority or a regulator requires it. Client engagement files are generally retained for six years after the matter closes, to reflect statutory limitation periods. Enquiries that do not become engagements are deleted within twelve months. Website technical data is retained for a short period only.
We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including access controls on a need-to-know basis, encryption in transit and at rest, secure document exchange, staff confidentiality obligations and training, and due diligence on our own suppliers. We have procedures in place to detect, investigate and report personal data breaches to the Information Commissioner's Office and, where required, to affected individuals.
Subject to the conditions and exemptions in data protection law, you have the right to:
Important exemptions apply to anti-money laundering and financial crime work. Where disclosing information would prejudice the prevention or detection of crime, or would "tip off" a person about a suspicion or an investigation, we may be required to withhold information or decline a request. We will tell you where this is the case, to the extent that we are permitted to do so.
To exercise a right, please contact us at info@haynescompliance.com. We will respond within one month, and will tell you if we need to extend that period.
This website does not use advertising, analytics or tracking cookies. Web fonts on this site are served by Google Fonts, which means your IP address is disclosed to Google in order to deliver those fonts. Our hosting provider keeps standard server logs, including IP addresses, for security and diagnostic purposes.
We do not make decisions producing legal or similarly significant effects about individuals by automated means alone. Where screening tools generate a match or an alert, that output is always reviewed and assessed by a qualified professional before any conclusion is reached.
We may update this notice from time to time to reflect changes in our services, our systems, or the law. The date at the top of this page shows when it was last revised. Where a change is significant, we will take reasonable steps to bring it to the attention of our clients.
If you are unhappy with how we have handled your personal data, please contact us first so that we can try to resolve it. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint or on 0303 123 1113.