open navigation close navigation Menu

Further Information

The details below cover data processing activities that are common to all our services. We recommend reviewing these global practices alongside your service-specific notice for a complete picture of how we safeguard your personal data. 

toggle answer for Your Rights

UK & EU

  • Right to be Informed
  • Right of Access
  • Right to Rectification
  • Right to Erasure
  • Right to Restrict Processing
  • Right to Data Portability
  • Right to Object Automated Decision Making & Profiling

US

  • Right to be informed
  • Right to Access
  • Right to Correction / Rectification
  • Right to Deletion
  • Right to Appeal
  • Right to Non-Discrimination
  • Right to limit use and disclosure of Sensitive Personal Information
  • Right to Opt-Out - Sale, Share, Targeted Advertising & Profiling
  • Right to Data Portability

If you would like to exercise any of your rights please go to our Contact Us page.

toggle answer for Special Category Data

Data protection law classifies certain types of personal information as special category data due to their sensitive nature. We will only collect and use special category data where permitted by law and, where required, with your consent.

toggle answer for Keeping your personal data up to date

Please help us by reviewing the information we hold about you regularly and notifying us as soon as any details need to be updated or corrected.

toggle answer for Other people’s personal data

If you provide us with personal information about another person, you confirm that they are authorised to act on your behalf, that they consent to you providing their personal data to us and to our processing of it, and that you have informed them of our identity and the purposes for which their personal data will be processed, as set out in our Privacy Notices.

toggle answer for Sharing Information

We only share personal data where it is necessary to provide our products and services. This may include sharing information in the following situations:

  • With your permission – where you ask us to share your information, or where consent has been provided by you or a relevant third party.
  • To deliver our services – with other Equiniti companies and trusted partners such as agents, banks, printers, and insurers who help us provide our services.
  • For day to day operations – including IT support, fraud prevention, credit checks, and obtaining professional advice.
  • To meet legal requirements – with regulators, courts, law enforcement agencies, or other organisations where we are required to do so by law, including for debt recovery.
  • For financial and reporting purposes – such as tax compliance, financial reporting, or carrying out transactions.
  • During business changes – for example, if our business is sold, restructured, or becomes insolvent. In these cases, appropriate safeguards will always be in place to protect your information.
  • Data storage – your information is stored on secure, encrypted, cloud based servers located within the country or region where we provide our services to you.

toggle answer for Overseas Processing

Overseas Processing Statement

Some of our data processing occurs outside the country where the data originates. As a global organisation, Equiniti operates offices and processes data in multiple countries. We also work with third-party suppliers who may process data internationally.

When personal data is transferred across international borders, we implement robust safeguards to ensure compliance with applicable data protection laws. This includes using data transfer agreements, standard contractual clauses (SCCs), and conducting Transfer Risk Assessments (TRAs).

Examples of international data transfers include:

  • Sharing personal data with members of the Equiniti Group outside the UK, such as Equiniti India Private Limited, for purposes described in this Privacy Notice.
  • When you contact us by email or use our microsites, some of the service providers who support these services may be based outside the country where your data was originally collected.

Data Privacy Framework

For transfers to the US Equiniti complies with the EU-US Data Privacy Framework (EU-US DPF) and the UK Extension to the EU-US DPF, as set forth by the US Department of Commerce. Equiniti has certified to the US Department of Commerce that it adheres to the EU-US Data Privacy Framework Principles (EU-US DPF Principles) and the UK Extension to the EU-US DPF, with regard to the processing of Personal Information received from the European Union and the United Kingdom in reliance on the EU-US DPF and the UK Extension to the EU-US DPF. If there is any conflict between the terms in this Privacy Statement and the EU-US DPF Principles and the UK Extension to the EU-US DPF, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

The legal entities of Equiniti that are adhering to the EU-U.S. DPF Principles, including as applicable under the UK Extension to the EU-U.S. DPF, and are covered by the Equiniti Trust Company, LLC DPF submission include: Amor Holdco, Inc., Armor Intermediate Company LLC, Armor Holding II LLC, Canadian Stock Transfer Holdings LLC, Equiniti (US) Holdings, LLC, Equiniti (US) LLC, DF King & Co, Inc, DF King Acquisition LLC, DF King Holding LLC, EQ Fund Solutions, LLC, LINK Shareholder Services, LLC and EQ Private Company Solutions, Inc.

In compliance with the EU-US DPF and the UK Extension to the EU-US DPF, Equiniti commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) with regard to unresolved complaints concerning our handling of Personal Information received in reliance on the EU-US DPF and the UK Extension to the EU-US DPF.

Equiniti will arbitrate claims and follow the terms as set forth in the EU-U.S. DPF Principles and the UK Extension to the EU-US DPF, provided that an individual has invoked binding arbitration by delivering notice to Equiniti and following the procedures and subject to conditions set forth in Annex I of the EU-US DPF Principles and the UK Extension to the EU-US DPF. Under the EU-US Data Privacy Framework (EU-US DPF) and the UK Extension to the EU-US DPF Equiniti remains a liable party in cases of onward transfers to third parties if its supplier processes information in a manner that is inconsistent with the DPF principles, unless Equiniti proves that it is not responsible for the event giving rise to the damage. Equiniti is subject to the investigatory and enforcement powers of the US Federal Trade Commission (FTC) regarding personal data received or transferred pursuant to DPF.

If you would like any further details about transfers of your personal data, then please contact our Data Protection Office at DPO@equiniti.com

toggle answer for How we keep your personal data secure

We take the security of your personal data seriously. We use a range of strong technical and organisational measures to protect your information, including encryption, anonymisation, secure communications, and controlled data retention. Our information security practices align with ISO 27001 standards.

toggle answer for Children (16 years and under) and Vulnerable Adults

We are committed to protecting the privacy of children and vulnerable adults. We will only collect and use their personal data where the appropriate permissions are in place.

toggle answer for EQ's Use of Artificial Intelligence (AI)

At EQ, we use AI and more specifically use Generative Artificial Intelligence (GenAI) technologies to support our colleagues in delivering services, improving efficiency, enhancing quality and consistency, and assisting with information analysis and content generation.

We are committed to using GenAI responsibly, transparently and in accordance with applicable legal, regulatory and ethical requirements.

How we use GenAI

GenAI is used to support our work in performing tasks such as analysing information, identifying trends and patterns, generating content, summarising information, and supporting operational processes.

GenAI is designed to assist our colleagues, not replace them. Any outputs generated by AI are subject to appropriate human review and oversight before they are relied or acted upon. 

EQ does not use GenAI to make decisions about individuals solely through automated means where those decisions produce legal effects or similarly significant impacts on an individual.  Human involvement and judgement remain an essential part of our decision-making processes. Appropriately trained colleagues review AI generated outputs and retain responsibility for any decisions made.

If our use of AI were to change in a way that involved automated decision-making of this nature, we would implement the safeguards required by applicable data protection laws and provide clear information to you about those activities.

Governance and risk management

Before any GenAI capability is introduced into EQ it must undergo a formal assessment and approval process. This includes being reviewed by relevant key stakeholders, including Information Security, Legal, Data Protection, Environmental, Social and Governance (ESG), and Fraud teams, to ensure that the proposed use meets our requirements for security, privacy, legal compliance, ethical use, governance and risk management.

Approved AI solutions are deployed only within authorised enterprise environments and are subject to ongoing monitoring and review to ensure they remain secure, compliant and effective.

Use of personal data

Where GenAI systems process personal data, we ensure that:

  • only the personal data necessary for the specific purpose is used;
  • appropriate technical and organisational safeguards are applied;
  • access is restricted to authorised individuals with a legitimate business need; and
  • processing is carried out in accordance with applicable data protection laws.

We do not permit personal data, customer information or confidential business information to be used to train public, shared or third-party AI models.

Third-party AI providers

Some GenAI capabilities may be provided by carefully selected third-party suppliers acting on our behalf. Where this occurs, we implement appropriate contractual, security and data protection safeguards to protect information and ensure it is processed only for authorised purposes.

We require our providers to ensure that information processed on our behalf is not used to train AI models for the benefit of other customers or organisations.

Transparency and your rights

We are committed to being transparent about our use of GenAI and how personal data is processed. Where appropriate, we will provide additional information about the use of AI within specific services or processes.

Our customers continue to have rights in relation to their personal data under applicable data protection laws, including rights to access, rectify, object to certain processing activities and, where applicable, seek human intervention in relation to decisions affecting them.

Further information about how we process personal data and how you can exercise your rights can be found in our Privacy Notices.

share-xx