Purpose
Purpose of this notice
This privacy notice describes how Moore Global Network Limited (“Moore”, “we”, “us” or “our”) collects and uses personal data in accordance with the General Data Protection Regulation (GDPR), the Data Protection Act and other applicable United Kingdom data protection legislation (together, “data protection law”).
This notice applies to personal data provided to us both by individuals themselves and by other people on their behalf. Personal data is any information relating to an identified or identifiable living individual. Capitalised terms (such as “Personal Data”), unless otherwise defined in this policy, have the same meaning given to them under data protection law.
If you do not agree with this privacy notice, you should not use Moore’s websites or provide us with information through them or in connection with their use.
Please note that this privacy notice applies only to access to our websites. If you are a member of the Network, this notice does not apply to your activities relating to the Network; instead, the processing of your personal data is governed by our internal privacy notice.
About us
Moore is made up of a global network of independent member firms providing accounting and consulting services (the “Network”). Because personal interaction is at the heart of what we do, we have developed this policy to ensure that personal data is processed lawfully, fairly and transparently.
Moore Global Network Limited is a company registered in England and Wales under company number 12139967. Moore is also registered with the UK Information Commissioner’s Office (ICO) as a data controller under registration number ZA764880.
Our role
Where we determine the purposes and means of processing personal data, we act as a data controller. This is generally the capacity in which we process personal data.
Personal data
Types of personal data we may collect
You do not need to provide personal data to access our websites. However, you may be asked to provide certain personal information in order to receive information or services offered by Moore.
We may collect the following categories of information:
- contact and personal details, including name, address, date of birth, employer name, a copy of your CV, job title, phone number, email address and other business contact details, which you may provide when requesting further information about our services, requesting to join our Network, or applying for a job;
- your communication and marketing preferences, which you may indicate when subscribing to newsletters, insights or other notifications through our websites;
- information you share with us, including details of your enquiries about our services or other general questions;
- photographs you may provide if you attend a conference or event and upload a photo to the relevant event platform;
- any information you may provide as part of your participation in an event, conference or webinar;
- information about dietary requirements or mobility restrictions that you may provide when registering for an event, conference or webinar;
- when you visit our website, we may automatically collect the following information:
- technical information, including the IP address used to connect your computer to the internet, login data, browser type and version, time zone settings, browser plug-in types and versions, operating system and platform;
- information about your visit, including the full URL clickstream to, through and from our site (including date and time); products and pages you viewed or searched for; page response times; download errors; the length of visits to certain pages; page interaction information such as scrolling, clicks and mouse-overs; and methods used to browse away from the page.
We may collect special categories of personal data if you provide information about dietary requirements that refer to religious beliefs and/or health conditions, or if you provide accessibility requirements that refer to a health condition. We only process such data with your consent.
Use of data
How we will use your personal data
We will process your personal data in accordance with applicable law solely for the following purposes:
- keeping internal records;
- personalising your interaction with us;
- creating records of events, webinars and conferences and providing access to them to individuals registered for the relevant events, webinars and conferences;
- enabling our advisors, suppliers and service providers to carry out certain functions on our behalf, including payment processing, data verification, and technical, logistical and other functions;
- ensuring the security of our organisation, including preventing and detecting fraud or misuse in the use of our websites;
- resolving disputes, including where you lawfully exercise your rights or challenge the use of a recording or other part of the services we offer;
- carrying out marketing campaigns and sending you personalised marketing communications, where you have consented to receive them, to inform you about our services that we believe may be of interest to you;
- developing and improving our services, for example by analysing visits to our website and its individual pages;
- complying with applicable law, for example in response to a request from a court or regulator made in accordance with the law.
Processing of data
Legal bases for processing
Set out below are the legal bases on which we process personal data. Please note that we may process personal data on the basis of more than one legal ground, depending on the specific purpose for which the information is used.
1. Legitimate interests
We may process personal data for the purposes of our legitimate interests in conducting our business effectively and lawfully, provided that such interests are not overridden by the interests, rights and freedoms of the data subject that require protection of the relevant personal data. Examples of such processing are set out above.
2. Compliance with a legal obligation
We are subject to legal, regulatory and professional obligations. We will process personal data to the extent necessary to comply with such obligations. We also retain certain records to demonstrate that our services are provided in accordance with legal, regulatory and professional requirements.
3. Consent
In certain limited cases, for example where a data subject has agreed to receive marketing communications from us, we may process personal data on the basis of consent. Where consent is the sole basis for processing personal data, the relevant data subject always has the right to withdraw their consent to processing for specific purposes. Our policy is to process personal data on the basis of consent only where no other lawful basis for processing is available.
Data retention
Retention of personal data
Your personal data will be retained for the period necessary to achieve the purposes set out in this Policy, unless a longer retention period is required by applicable law.
However, we will not retain your personal data for longer than necessary. The retention period for your personal data is subject to periodic review.
We may retain an anonymised form of your personal data, which no longer allows you to be identified, for statistical purposes without time limitation, where we have a legitimate interest in doing so.
Security
Data security
We take the security of all data held by us very seriously. We have implemented a system of policies, procedures and training covering data protection, privacy and security, and we regularly review the adequacy and appropriateness of the measures we take to protect data.
We have implemented appropriate security measures to prevent personal data from being accidentally lost, misused, accessed without authorisation, altered or disclosed.
We limit access to personal data to employees, agents, contractors and other third parties who need it in order to carry out their work duties. By default, our IT systems operate on the principle of least privilege.
Third parties may only process personal data in accordance with our instructions and are required to maintain confidentiality.
We have implemented procedures for responding to suspected data security breaches and will notify the affected data subject and the relevant regulator of a suspected breach where required to do so by law.
Data transfers
Transfer of personal data
We may transfer personal data to third parties where required by law, necessary to manage our relationships with clients and data subjects, or where we otherwise have a lawful basis for such a transfer.
As the Network is global, personal data may be transferred to member firms located outside the United Kingdom and the European Union (EU), including to countries whose laws do not provide the same level of protection for personal data.
All personal data will be afforded appropriate protection, and transfers of personal data outside the United Kingdom and the EU will be carried out lawfully.
Where personal data is transferred outside the United Kingdom or the EU to a country that has not been recognised by the European Commission as providing an adequate level of data protection, such transfer will be made under an agreement that incorporates the UK and/or EU requirements for the transfer of personal data outside the relevant territories, including standard contractual clauses approved by the European Commission, or another lawful data transfer mechanism recognised under UK law.
Where appropriate contractual arrangements and security safeguards are in place, we may transfer your data to:
- our employees and consultants;
- member firms of the Network, where necessary to provide services or respond to your request for further information about our services;
- third-party service providers who support us and help us provide our services, including: IT and cloud services and their operation and management; professional advisory services; administrative services; marketing services; banking services; event organisation services;
- another legal entity, on a temporary or permanent basis, in connection with a joint venture, collaboration, merger, sale, reorganisation, change of legal form, liquidation or similar event. In the event of a merger or sale, your personal data may be transferred to the successor entity;
- legal advisers, where they may need to advise us or handle claims or litigation on our behalf;
- any other third party, including third-party event sponsors, where you have given your consent to such disclosure.
All our third-party service providers are required to take commercially reasonable and appropriate security measures to protect personal data. We only permit third-party service providers to process personal data for specific purposes and strictly in accordance with our instructions.
Rights and obligations
1. The data subject’s obligation to notify us of changes
It is important that the personal data we hold about you is accurate and up to date. Each year we will take reasonable steps to contact data subjects to verify the accuracy of the information we hold. However, you may notify us at any time of changes to your personal data that we need to know about, by contacting us through your usual contact person or by one of the means set out at the end of this privacy notice.
2. Data subjects’ rights in relation to personal data
Under United Kingdom or European Union law, data subjects may have certain rights in relation to the personal data we hold about them. In particular, they may have the right to:
- request access to their personal data. This allows a data subject to receive details of the personal data we hold about them and to verify the lawfulness of our processing of it;
- request that we update the personal data we hold, or correct data that the data subject considers to be inaccurate or incomplete;
- request the deletion of their personal data. This allows a data subject to ask us to delete personal data where there is no good reason for us to continue processing it. Data subjects also have the right to ask us to delete their personal data after having exercised their right to object to processing;
- object to the processing of their personal data, where we are relying on a legitimate interest (of ours or of a third party) and there is something about their particular situation that makes them want to object to processing on this ground. Data subjects also have the right to object where we are processing their personal data for direct marketing purposes;
- request the restriction of the processing of their personal data. This allows a data subject to ask us to suspend the processing of their personal data, for example if they want us to establish its accuracy or the reason for processing it;
- request the transfer of their personal data to themselves or to another data controller, where processing is based on consent, carried out by automated means, and the transfer is technically feasible. Please note that, as at the date of this notice, we do not carry out any processing to which this right would apply;
- lodge a complaint with a supervisory authority. We encourage you to contact us with any questions or complaints regarding the processing of your personal data. However, you also have the right to contact the relevant supervisory authority directly.
To contact the United Kingdom Information Commissioner’s Office (ICO), you may use the ICO’s official website.
3. Withdrawal of consent
Where we process personal data on the basis of consent, individuals have the right to withdraw their consent at any time. However, as noted above, we do not generally process personal data solely on the basis of consent. To withdraw your consent to the processing of your personal data, please contact us by email. To stop receiving marketing communications, please use the unsubscribe link contained in the relevant email you received from us.
4. Contacting us to exercise your rights
If an individual wishes to exercise any of the rights set out above, they may contact us by email or by one of the means set out at the end of this privacy notice. We may charge a fee for a request for information about personal data, where permitted by law. We may refuse to comply with a request that is manifestly unfounded, repetitive or excessive.
Please note that our policy does not provide for copies of documents to be provided in response to a data subject’s access request. We will fulfil such requests in another way, typically by providing a specially prepared document listing the information we are required to provide under data protection law.
We may ask individuals contacting us to provide certain information to confirm their identity and to verify their right to access personal data or exercise other rights. This is a security measure to prevent personal data from being disclosed to persons who have no right to receive it. We may also contact an individual for further information in relation to their request, in order to speed up our response.
We aim to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if a request is particularly complex. In such cases, we will notify the relevant individual and keep them informed of the progress of their request.
Data subjects also have the right to lodge a complaint with the ICO, the United Kingdom’s supervisory authority for data protection matters.
Contact information
If you have any questions about this notice, wish to exercise any of your rights, or wish to contact us about the processing of your personal data, please contact us by email or by one of the means set out in this privacy notice.


