Website Privacy Notice
DWP Dr. Werner and Partner
Last Updated: 14/02/2020
DWP Dr. Werner & Partner (hereinafter referred to as ‘DWP’ and/or ‘Service Provider’) is the brand under which the member firms of company DWP Malta Ltd. operate and provide professional services.
- Joerg Werner — Advocate & Legal Practitioner
- DWP Malta Ltd
Together, these firms form the DWP network. ‘DWP’ is often used to refer either to individual firms within the ‘DWP’ network or to several or all of them collectively.
Kindly note that for other services, such as VFA related services, Audit and Book Keeping, DWP works collaboratively with the following companies:
- DWP VFA Agent Ltd;
- Borg Galea Audit Ltd;
- Servox Ltd.
Kindly note that member firms of the Company have a data sharing agreement in place and data will be processed in line with your engagement depending on the scope of the engagement letter.
DWP is the Data Controller for the purposes of applicable data protection law.
The Company respects your privacy and is committed to protecting your personal data which it processes.
This Privacy Notice explains how the Company will comply with the applicable data protection legislation, including, the General Data Protection Regulation (EU) 2016/679 (hereinafter referred to as the ‘GDPR’), the Data Protection Act (Chapter 586 of the Laws of Malta, any subsidiary legislation and any other applicable laws relating to privacy and electronic communications, as may be amended from time to time.
It is important that you read this Privacy Notice so that you are aware of how and why we are using your information.
- DATA CONTROLLER
As the Data Controller, DWP is responsible for deciding how it holds and uses the personal information collected from you. The Company may, in certain circumstances, deliver services in partnership with another entity whereby the Company will be a Joint Controller with that entity.
DWP’s contact details:
Address: Phoenix Business Centre
Old Railway Track
Santa Venera, SVR9022
Tel: +356 21377700 from 09:00 to 17:00
For general contact, please send us an email on firstname.lastname@example.org.
The Company has a GDPR Compliance Team (hereinafter referred to as ‘the Team’) who is responsible for matters relating to privacy and data protection. The Team may be reached on email@example.com or by calling on +356 21377700.
- DATA PROTECTION PRINCIPLES
The Company is committed towards compliance. If we need to collect, use or store your Personal Data, we will abide by the following data protection principles:
- Lawfulness, fairness and transparency – the processing of personal data shall take place in a lawful, fair and transparent manner;
- Purpose limitation – the collection of personal data shall only be performed for specified, explicit and legitimate purposes and shall not be further processed in a manner which renders it incompatible with those purposes;
- Data minimisation – the collection of personal data shall be adequate, relevant and limited to what is necessary in relation to the purpose(s) for which they are processed;
- Accuracy – the personal data shall be accurate and where necessary kept up to date. Having regard to the purpose(s) for which personal data is processed, the Company shall take every reasonable step to ensure that inaccurate personal data are erased or rectified without undue delay;
- Storage limitation – personal data shall be kept in a form which permits identification of the data subject, for no longer than is necessary for the purpose(s) for which the personal data is processed;
- Integrity & Confidentiality - personal data shall be kept confidential and stored in a manner which ensures appropriate security. Personal data shall not be shared with third parties except when necessary and with a justifiable legal basis.
- PERSONAL DATA
Personal Data is any information relating to an identified or identifiable natural living person, also known as a ‘data subject’. A data subject can be described as an individual who can be directly or indirectly identified through the information collected and processed by the Company. Such information may include name, surname, identification number, location data, online identifier or any other data relating to their physical, physiological, genetic, mental, economic, cultural or social identity.
The definition of Personal Data excludes any data which has been rendered anonymous in such a manner that the data subject is no longer identifiable (‘anonymous data’).
Special category data includes data on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, health data, data concerning a natural person’s sex life or sexual orientation. The Company will only process special category data, also known as ‘sensitive data’, under strict conditions and with an appropriate legal basis.
We process personal data about the following categories of data subjects:
- THE PERSONAL DATA WE COLLECT & HOW WE USE IT
We collect and process personal data relating to you in connection with your use of this website and our relationship with you. This personal data may include:
|Personal Data||Purpose for Processing||Lawfulness|
|Response of Queries Provision of Feedback|
Commentary & Newsletter Subscriptions
To Take part in online discussions, surveys or promotions.
Bank Reference Letter
Professional Reference Letter
Proof of Address
Screenshots of a Person
|Legal Obligation Contractual Obligation|
|Proof of Authorisation to act on someone’s behalf such as Power of Attorney||Identification Purposes||Legal Obligation Contractual Obligation|
|Job Applicants Details||Recruitment Purposes|
For more information please refer to our Candidate Privacy Notice)
|Employee Details||Employment Purposes Payroll Purposes Performance Reviews|
Compliance with the applicable employment legislation
(For more information please refer to our Employee Privacy Notice which is provided to all employees at commencement of employment)
|Contractual Obligation Legal Obligation|
|Social Security Number|
Tax Identification Number
|Payroll Purposes||Legal Obligation|
Bank Reference Letter, Professional Reference Letter,
Proof of Address
Previous Employer Reference
Copies of Qualifications
|VFA Agent Services|
Conduct of Fit & Proper Assessment
|Contractual Obligation Legal Obligation|
|Personal Data relating to external consultants||To take steps to enter into a contract of Service||Contractual Obligation|
|Server Logfiles||Statistical Evaluation|
- FAILURE TO PROVIDE THE INFORMATION
In most cases, the provision of personal data arises either from statutory requirements or contractual provisions. Where applicable, failure of the provision of personal data will prevent the Company from complying with its legal or regulatory obligation, concluding contracts, and delivering the services requested.
- CHANGES TO YOUR PERSONAL DATA
It is important that the personal information we hold about you is current and accurate. Therefore, it is your responsibility to keep us informed should any of your personal information change.
Due to DWP’s obligations at law, you bind yourself to furnish us with recent suitable documentation for confirmation, on a regular basis, upon a mere verbal request to this effect from us. These may be required for KYC and due diligence purposes as well as to allow us to correctly perform the terms of our engagement, as per the internal operating procedures currently in force at the time.
Cookies are small text files placed on your computer by the websites you visit. They are widely used to make websites work more efficiently, as well as to provide information to the owners of the website.
- DISCLOSURE OF YOUR PERSONAL DATA
Except as described in this Privacy Notice, we will not intentionally disclose the personal data we collect or store to the third parties unless it is an imposed legal obligation on us to do so.
We will not share your information with any third parties for the purposes of direct marketing.
We use data processors who are third parties who provide elements of services for us. We have agreements in place with our data processors. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will hold it securely and retain it for the period we instruct.
In some circumstances we are legally obliged to share information. For example, under a court order or where we cooperate with other authorities. We might also share information with other regulatory bodies in order to further their, or our, objectives. In any scenario, we will ensure that we have a lawful basis on which to share the information.
We may disclose information to third parties in connection with the above-mentioned purposes, in the following circumstances:
|Recipients of Personal Data||Purpose||Legal Basis for Disclosure|
|Malta Business Registry||Company Service Provider||Contractual Obligations|
|Banks/ EMIs||Bank Account Openings||Contractual Obligations|
|FIAU||AML/CFT Regulations||AML/CFT Regulations|
|Identity Malta||Working Permits||Contractual Obligations|
|PayPal||Subscription and Payment Purposes||Contractual Obligations|
|Calendly||Consultation Booking||Contractual Obligations|
All our third-party service providers are required to take appropriate security measures to protect your personal data in line with our policies. Moreover, we only permit third parties to process your personal data for specified purposes and in accordance with our legally binding agreements.
- INTERNATIONAL TRANSFERS
The information provided to us may be shared with third parties situated in other European Economic Area (‘EEA’) Member States or in countries outside the EEA.
The Company will only transfer personal data outside the EEA after taking the necessary steps to ensure that your privacy rights continue to be protected, as outlined in this Privacy Notice and in accordance with applicable data protection laws.
For instance, we will transfer your personal data outside the EEA with your consent, to fulfil a legal obligation or to fulfil our contractual obligations.
- RETENTION OF PERSONAL DATA
The personal data that we process shall not be kept longer than is necessary. We retain your personal data for as long as we need it to comply with our obligations under applicable law, to enforce our contractual agreements, and if relevant, for the establishment, exercise and defence of legal claims.
We will actively review the personal data we handle, process and store, and will delete or anonymise it in a secure manner where there is no longer a legal, business or customer need for it to be retained.
For more information on the retention of your personal data, kindly contact us on firstname.lastname@example.org or on +356 21377700.
In circumstances where it is impossible for us to specify in advance the periods for which your personal data will be retained, we will determine the retention period on the following criteria:
- the purpose(s) was for which your personal data was collected;
- whether there are any statutory obligations, obliging us to continue to process your information;
- whether we have a legal basis in place to continue to process your information, including but not limited to consent;
- the value attached to your information;
- whether there are any industry practices stipulating how long the information should be retained;
- the risk, cost and liability attached to such retention; and
- any other relevant circumstances.
- DATA SUBJECT RIGHTS
As a data subject you have a number of rights in relation to your personal data. The Company respects your privacy rights and will endeavour to uphold such rights to the extent that they apply to the way in which we process your personal data.
Your principal rights are:
- the right to be informed;
- the right to access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to object to processing;
- the right to data portability;
- the right to know of the existence of automated decision-making;
- the right to lodge a complaint with the supervisory authority (IDPC) and/or seek judicial remedy in those cases where you believe that your data protection rights have been infringed following the processing of your personal data by a data controller; and
- the right to withdraw consent.
If you wish to exercise any of the above-mentioned rights, please send your request on email@example.com.
Any request made will be given appropriate consideration within the timescales required by data protection legislation. Generally, the Company will respond to such requests within one (1) month, with the possibility to extend this period to three (3) months for particularly complex requests, in accordance with applicable law. In any such event, we will inform you accordingly.
Prior to processing your request and where deemed reasonably necessary, you will be required to provide us with proof of your identity. This is intended to ensure that the personal data is not disclosed to unauthorised third parties. The Company may require additional information in relation to such requests in order to speed up our response procedure. We reserve the right to withhold your personal data if disclosing it would adversely affect the rights and freedoms of others.
Generally, when exercising your rights, no fees are applicable. However, if your request is clearly unfounded, repetitive or excessive, we may charge a reasonable fee.
The Company take appropriate security measures to protect your personal data against loss, misuse, unauthorised access, alteration, disclosure or destruction of your information.
We have taken steps to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services processing personal information and will restore the availability and access to information in a timely manner in the event of a physical or technical incident.
No method of electronic storage and no method of transmission over the internet, is 100% secure. The Company cannot warrant or ensure the security of any information transmitted to us, but this is done at your own risk. Moreover, we cannot guarantee that such information will not be accessed, disclosed, altered or destroyed by any breach of our physical, technical and/or organisational safeguards.
Regular training on information security practices is provided to all members of staff who process personal data.
The Company has put in place procedures to deal with any suspected personal data security breach and will notify the Regulator of any such breach where we are required to do so. We will also inform you, as the data subject, of the occurrence of a breach and the steps to take to safeguard your rights.
If you feel that your personal data has been compromised, please contact our Data Protection Officer on firstname.lastname@example.org or on +356 21377700.
- PRIVACY BY DESIGN & BY DEFAULT
When introducing new technologies, policies or processes, we will ensure that your privacy is considered at the ‘design’ stage. Where applicable and in line with Articles 35–36 of the GDPR, we will carry out a Data Protection Impact Assessment (‘DPIA’).
A DPIA will also be carried out where new technologies are used or where we consider there is a high risk to your rights and freedoms. Where an assessment identifies risks, which cannot be satisfactorily reduced, avoided or eliminated, we will seek advice from the Supervisory Authority (i.e. the Office of the Information and Data Protection Commissioner) prior to initiating the processing.
- LINKS TO OTHER WEBSITES
Where the Company provides links to websites belonging to other entities, this Privacy Notice does not in any way cover how that entity processes your personal data.
We encourage you to read the Privacy Notices on the other websites you visit.
- CHANGES TO THIS PRIVACY NOTICE
This Privacy Notice may change from time to time. If this Notice is changed in ways which affect how we use your personal information, we will advise you of the choices you may have as a result of such changes.
We will also post a notice that this Notice has changed.