This privacy statement was last updated on 18 April 2024
PwC is strongly committed to protecting personal data. This privacy statement describes why and how we collect and use personal data and provides information about individuals’ rights in relation to personal data. It applies to personal data provided to us, both by individuals themselves or by others. We may use personal data provided to us for any of the purposes described in this privacy statement or as otherwise stated at the point of collection.
As used in this privacy statement, “PwC”, “us”, and “we” refer to the PwC network and/or one or more of its Member Firms that may process your personal information. Each Member Firm in the PwC network is a separate legal entity. The data controllers of your personal information are one or more of the Member Firms listed here. For further details, please see www.pwc.com/structure. See http://www.pwc.com/gx/en/about/office-locations.html for a list of countries and regions in which PwC Member Firms operate.
In this privacy statement, we refer to information about you or information that identifies you as “personal data” or “personal information”. We also sometimes collectively refer to handling, collecting, protecting or storing your personal information as “processing” such personal information.
PwC processes personal data for numerous purposes. Our policy is to be transparent about why and how we process personal data.
To find out more about our specific processing activities, go to our processing activities.
Your local law may require us to set out in this privacy statement the legal grounds on which we rely in order to process your personal information. In such cases, we rely on one or more of the following processing conditions:
Cross-border transfers
If we process your personal information, your personal information may be transferred to and stored outside the country where you are located. This includes countries that do not have adequate or appropriate laws and safeguards that provide specific protection for personal information. In this case, we will put in place the required organisational and technical measures before such transfer.
Transfer outside the EEA (where applicable) will be only:
to a recipient located in a country which provides an adequate level of protection for your personal information; and/or
under an agreement which satisfies EU requirements for the transfer of personal data to data processors or data controllers outside the EEA, such as standard contractual clauses approved by the European Commission.
Other PwC Member Firms
For details of PwC Member Firm locations, please see http://www.pwc.com/gx/en/about/office-locations.html.
We may share personal data with other PwC member firms where necessary in connection with the purposes described in this privacy statement. For example, when providing professional services to a client we may share personal information with PwC Member Firms in different territories that are involved in providing advice to that client.
Third Party Providers
We may transfer or disclose the personal data we collect to third party contractors, subcontractors, and/or their subsidiaries and affiliates. Third parties support the PwC Network in providing its services and help provide, run and manage IT systems. Examples of third party contractors we use are providers of identity management, website hosting and management, data analysis, data backup, security and cloud storage services. The servers powering and facilitating our IT infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them.
The third party providers may use their own third party subcontractors that have access to personal data (sub-processors). It is our policy to use only third party providers that are bound to maintain appropriate levels of security and confidentiality, to process personal information only as instructed by PwC, and to flow those same obligations down to their sub-processors.
Other disclosures
We may also disclose personal information under the following circumstances:
To find out more please go to the sections of this statement that are relevant to you.
We take the security of all the data we hold very seriously. We adhere to internationally recognised security standards and our Information Security Management System relating to client confidential data is independently certified as complying with the requirements of ISO/IEC 27001: 2013. We have a framework of policies, procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.
You may have certain rights under your local law in relation to the personal information we hold about you. In particular, you may have a legal right to:
We hope that you won't ever need to, but if you do want to complain about our use of your information, please reach out to us with the details of your complaint. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
This privacy statement was last updated on 09 January 2024
We may update this privacy statement at any time by publishing an updated version here. So you know when we make changes to this privacy statement, we will amend the revision date at the top of this page. The new modified or amended privacy statement will apply from that revision date. Therefore, we encourage you to review this privacy statement periodically to be informed about how we are protecting your information.
This privacy statement is in compliance with the requirements of the Data Protection Act, 2023.
You may also contact us at the following postal address:
PricewaterhouseCoopers
5B Water Corporation Road
Landmark Towers Victoria Island
Eti-Osa 101233
Lagos
Nigeria