8
accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we
limit access to your personal data to those employees, agents, contractors and other third parties
who have a business need to know. They will only process your personal data on our instructions
and they are subject to a duty of confidentiality.
17.2. We have put in place procedures to deal with any suspected personal data breach and will notify
you and any applicable regulator of a breach where we are legally required to do so.
18. Data retention
18.1. We will only retain your personal data for as long as reasonably necessary to fulfil the purposes
we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting
or reporting requirements. We may retain your personal data for a longer period in the event of
a complaint or if we reasonably believe there is a prospect of litigation in respect to our
relationship with you.
18.2. To determine the appropriate retention period for personal data, we consider the amount, nature
and sensitivity of the personal data, the potential risk of harm from unauthorised use or
disclosure of your personal data, the purposes for which we process your personal data and
whether we can achieve those purposes through other means, and the applicable legal,
regulatory, tax, accounting or other requirements.
18.3. In some circumstances we will anonymise your personal data (so that it can no longer be
associated with you) for research or statistical purposes, in which case we may use this
information indefinitely without further notice to you.
19. Your legal rights
19.1. Under certain circumstances, you have rights under data protection laws in relation to your
personal data.
19.2. You have right to request access to your personal data (commonly known as a "data subject
access request"). This enables you to receive a copy of the personal data we hold about you and
to check that we are lawfully processing it.
19.3. You have right to request correction of the personal data that we hold about you. This enables
you to have any incomplete or inaccurate data we hold about you corrected, though we may need
to verify the accuracy of the new data you provide to us.
19.4. You have the right to request erasure of your personal data. This enables you to ask us to delete
or remove personal data where there is no good reason for us continuing to process it. You also
have the right to ask us to delete or remove your personal data where you have successfully
exercised your right to object to processing, where we may have processed your information
unlawfully or where we are required to erase your personal data to comply with local law. Note,
however, that we may not always be able to comply with your request of erasure for specific legal
reasons which will be notified to you, if applicable, at the time of your request.
19.5. You have the right to object to processing of your personal data where we are relying on a
legitimate interest (or those of a third party) and there is something about your particular
situation which makes you want to object to processing on this ground as you feel it impacts on