In this notice, “we”, “us” and “our” means the Brevan Howard entity listed below employing or proposing to employ you on the date that you receive this document:
Brevan Howard Asset Management Services Limited – a company registered in the UK with registered address at 4th Floor, Phoenix House, 1 Station Hill, Reading, Berkshire RG1 1NB and company registration number 11117501.
Brevan Howard Employment Services Limited – a company registered in the Cayman Islands with registered address at c/o Walkers Corporate Limited,190 Elgin Avenue, George Town, Grand Cayman KY1-9008, Cayman Islands and company registration number MC122759.
Brevan Howard US Investment Management LP – with its principal place of business at 1345 Avenue of the Americas, 20th Floor, New York, NY 10105, United States with company registration number 5147304.
Brevan Howard US LLC – registered in Delaware with its c/o The Corporation Trust Company, Corporation Trust Center, 1209 Orange Street, Wilmington, New Castle County, Delaware 19801 with company registration number 4555714.
Brevan Howard Inc – registered in Delaware with its c/o The Corporation Trust Company, Corporation Trust Center, 1209 Orange Street, Wilmington, New Castle County, Delaware 19801 with company registration number 3882407.
Brevan Howard Investment Products Limited St Helier (Jersey) Geneva Branch – a Brevan Howard Investment Products Limited branch registered in Geneva with registered address at Rue du Rhône 7, 1204 Geneva, Switzerland and registration number CHE-115.572.412.
Brevan Howard Investment Products Limited, ADGM branch – a company registered in the Abu Dhabi Global Markets with registered office address at Floor 17, Al Sarab Tower, Abu Dhabi Global Market Square, Al Maryah Island, Abu Dhabi, PO Box 6684 and company registration number 000009185.
Brevan Howard Investment Products Limited, DIFC Branch – a company registered in the Dubai International Financial Centre with registered office address at Unit 615, Level 6, Index Tower, DIFC, Dubai and company registration number 6200.
Brevan Howard (Tel Aviv) Limited – a company registered in Israel with registered office address at 17 Yitzhak Sadeh Street, Tel Aviv, Israel and company registration number 516538105.
Brevan Howard Cayman SEZC Limited - whose registered office c/o Walkers Corporate Limited, 190 Elgin Avenue, George Town, Grand Cayman KY1-9008, Cayman Islands and company registration number 381388.
Brevan Howard India Private Limited – a company whose registered office is at 7th Floor, Campus 32, RMZ Ecoworld, Bellandur, Bangalore South, Bangalore 560103, Karnataka and company registration number 202396.
About this privacy notice
We are a data controller in respect of your personal data for the purposes of applicable data protection laws, such as the European Union’s General Data Protection Regulation 2016/679 and national implementing legislation, the UK GDPR (which is the EU GDPR as transposed into the laws of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018), the UK Data Protection Act 2018, the Swiss Data Protection Act of September 25, 2020 and its federal implementing ordinance, the Cayman Islands Data Protection Act (As Revised), the Data Protection (Jersey) Law 2018, Dubai International Financial Centre (“ DIFC ”) Data Protection Law No.5 of 2020 and Abu Dhabi Global Market (“ ADGM ”) Data Protection Regulations 2021, the Personal Data Protection Act 2012 of Singapore (in which case, we are an ‘organisation’ for purposes of such law), Israeli Protection of Privacy Law 1981 and the Information Technology Act, 2000 together with all laws and regulations supplementing, amending or replacing the same. We are responsible for ensuring that we use your personal data in compliance with data protection law.
This privacy notice applies if you are an employee, member, worker or contractor or a prospective employee, member, worker or contractor of our organisation. The privacy notice sets out the basis on which any personal data about you will be processed by us. Please take the time to read and understand this privacy notice.
This privacy notice does not have contractual force or effect. We may revise it at any time by amending this page. You are expected to check this page from time to time to take note of any changes we make, as they are binding on you.
In this privacy notice, “personal data” or “personal information” is any data or information in whatever form that can be used to identify you or that we can link to you and which we have in our possession or control.
Personal data that we collect about you
We will collect and process the following personal data about you:
• information that you provide to us or one of our affiliates. This includes information about you that you give to us by filling in forms or by communicating with us, whether face-to-face, by phone, e-mail or otherwise through the recruitment process and during your employment, engagement or membership with us. This information may include:
• your full name, date of birth, nationality, CV, education and qualification details, marital status, home address and home telephone number, mobile telephone number, personal email address, next of kin, emergency contact and dependent details (including contact information, date of birth and nationality), bank account details for the transfer of your salary and other benefits (or payment), tax details and your date of hire; and
Information we collect or generate about you. This includes:
• work-related details such as your job position, contact details, performance at work, absences, pay and benefits information, turnstile data, service history, a copy of your employment agreement, allocation agreement or contract, passport and right to work details, photograph, health information, pregnancy and/or disability status, proof of address, disciplinary and grievance information;
• personal data that we collect through our use of CCTV and other security measures implemented within our premises and IT systems (e.g. by means of monitoring mechanisms on our IT systems, as further described below), swipe card records, computer and network logins, turnstile data, internet usage, and telephone, text, and email communications and your use of our assets and information and communications systems (including but not limited to your full name, email address, the content, date and time of your professional correspondence, IP addresses and logs);
• information obtained through an exit interview with you (upon your departure from our organisation), including your reasons for leaving; and
Information we obtain from other sources, such as employment agencies or our background check provider. This may include:
• publicly available information
• education and qualification details, confirmation of address, debt collection history, legal situation and probity, online public presence, good reputation, credit and criminal record checks for background screening purposes (collectively, “Background Check Information”).
Uses of your personal data
Your personal data may be stored and processed by us for the purpose of determining your suitability for employment and/or contractual duties and to the extent necessary in connection with performance of the contract between us, which include processing in the following ways and for the following purposes:
• to enter into, manage or terminate the employment relationship with you;
• to meet our legal obligations as an employer, and perform our obligations and exercise our rights under your contract of employment or engagement or allocation agreement with us. For example, we use your personal data to pay you, to evaluate your individual performance, and if applicable provide benefits in connection with your employment or membership with us;
• to conduct (and regularly renew) background checks in order to verify your application and suitability for the position and to carry out internal investigations;
• we will use the private contact details relating to you and your next of kin (and that you have provided to us for emergency purposes) only in connection with an emergency;
• we will process personal data related to our monitoring of your business and personal use of our assets and information and communication systems in order to enable the effective operation of the respective system and ensure that it is used in accordance with our policies and procedures, to ensure the security, integrity and confidentiality of our premises, infrastructure and data, as well as that of our personnel and resources, including access controls and the security and operation of our IT systems, to maintain proof of business transactions and for recordkeeping purposes, to safeguard confidential information and intellectual property in our custody and control, and for other legitimate purposes permitted under applicable law;
• we will use personal data collected via CCTV for security purposes; and
• we will process turnstile data relating to you to monitor compliance with our policies relating to time that is required to be spent in the office.
Monitoring use of systems
We monitor our premises, assets and information technology (IT) and communications systems including, without limitation, professional laptops, email and text messaging services, telephonic devices, scanners, printers, and similar mobile devices. We may monitor your professional use of these devices and services through computer and network logins, swipe card records, turnstile data, internet usage, CCTV and telephone, text, and email communications and may access employee communications for monitoring purposes, as further described below. We may also monitor non-electronic communications (such as letters) which you generate, send or receive in connection with your employment.
Our monitoring activities are generally continuous and ongoing on an automatic and aggregate basis with no specific targeting of individuals, unless in case of trigger events leading to the collection of alerts by our authorised monitoring team. Upon collection of alerts, we carry out limited and selective checks in a proportionate way to the extent suitable and necessary in order to achieve legitimate business purposes, and comply with any applicable data protection laws. In particular, our monitoring activities never aim at monitoring your behaviour as such but rather support us in satisfying our legal obligations, ensuring the security, integrity and confidentiality of our premises, infrastructure and data, as well as that of our personnel and resources (including access controls and the security and operation of IT systems), verifying your compliance with your professional duties and our policies, reviewing and controlling your work performance, investigating concrete and serious suspicion of misuse of business communications or our other resources and/or claim, establish or defend our rights in disputes or legal proceedings.
We have no intention of and take appropriate measures to avoid monitoring or otherwise accessing your private, personal and/or non-work related communications and personal data. In case of use of Brevan Howard-issued devices for non-work related purposes, or in case of use of personal devices for work-related purposes, you understand and acknowledge that, in the event of an internal or regulatory investigation, non-work related communications and/or your personal devices may be technically made accessible to us and risk being subject to business communications monitoring, as described herein, unless their private or personal content can obviously be deduced or is appropriately marked accordingly.
Unless otherwise necessary to carry out the processing purposes described herein, only management and limited authorised personnel from our monitoring team will be granted access to personal data as part of our monitoring activities on a need to know basis.
Legal bases for processing your personal data
We are entitled to use your personal data in these ways because:
• we need to in order to enter into, manage, or terminate the employment relationship with you and/or perform our obligations and exercise our rights in connection with your employment contract, contract of engagement or allocation agreement with us;
• we have legal and regulatory obligations that we have to discharge;
• we may need to in order to establish, exercise or defend our legal rights or for the purpose of legal proceedings; or
• the use of your personal data as described may be necessary for our legitimate business interests (or the legitimate interests of one or more of our affiliates), and your interests and fundamental rights do not override those interests such as:
• allowing us to effectively and efficiently administer and manage the operation of our business;
• ensuring a consistent approach to the management of our corporate group, employees and the employees of our affiliate companies worldwide;
• maintaining compliance with internal policies and procedures; or
• being able to contact you or your family in the event of an emergency; or
• you have given your consent for us to process your personal information.
The data protection laws in jurisdictions such as Israel do not recognise all of the above legal grounds to process personal data and for these jurisdictions, we process your personal data based on your consent or as may be required by applicable laws. In the United States, we will only process Background Check Information with your consent. Where we do rely on consent in a jurisdiction, this will be made clear to you.
You are not required by law to provide your personal data, or to agree to all the terms of this privacy notice. Where we need to collect your personal data by law, under the terms of a contract we have with you or based on our legitimate interest, and you choose not to give us the personal data, it may delay or prevent us from meeting our obligations and providing our services to you.
Processing of sensitive personal data
Special categories of particularly sensitive personal data, such as information about your health, your private life, racial or ethnic origin, sexual orientation, administrative and/or criminal sanctions or history and information about your religious, philosophical, political or trade union views or activities, or any other information classified as ‘sensitive personal data or information’ under applicable law, require higher levels of protection. We need to have further justification for collecting, storing, sharing and using this type of personal data.
In general, we will not process sensitive personal data about you unless it is necessary for performing or exercising obligations or rights in connection with employment or for the assessment of your ability to fulfil your position and/or engagement with us. On rare occasions, there may be other reasons for processing, such as it is in the public interest to do so. The situations in which we will process your sensitive personal data are listed below.
• We will collect and use sensitive personal data about you to:
• process payroll, provide insurance benefits and other employment benefits;
• ensure your health and safety in the workplace;
• assess your fitness to work (including by carrying out appropriate background checks);
• make reasonable adjustments to the recruitment process;
• provide appropriate workplace adjustments;
• monitor and manage sickness absence; and
• ensure adequate insurance coverage and administer benefits including statutory maternity pay and statutory sick pay.
We need to process this information to exercise rights and perform obligations in connection with your employment and will retain this information only as permitted by our Global Data Retention Policy (see further below under “Retention of personal data”).
• If we reasonably believe that you or another person are at risk of harm and the processing is necessary to protect you or them from physical, mental or emotional harm or to protect physical, mental or emotional well-being.
• We may also collect and use sensitive personal data about you to ensure meaningful equal opportunity monitoring and reporting.
In limited circumstances, we may approach you for your written consent to allow us to process certain particularly sensitive personal data. If we do so, we will provide you with full details of the information that we would like and the reason we need it, so that you can carefully consider whether you wish to consent. You should be aware that it is not a condition of your contract with us that you agree to any request for consent from us.
Information about criminal convictions
We will collect information about criminal convictions as part of the recruitment process (and performance of background checks) or you may tell us about criminal convictions in the course of you working for us. We are allowed to use your personal data in this way to carry out our legal and regulatory obligations and for the assessment of your ability to fulfil your position and/or engagement with us.
Disclosure of your information to third parties
We may disclose your personal data to our affiliates for the purposes of:
• the management and administration of our business and our affiliates’ business;
• intra-group secondment arrangements;
• complying with the functions that each of them may perform relating to regional or global HR decisions;
• benchmarking salaries and benefits with similar organisations;
• assessing compliance with applicable laws, rules and regulations, and internal policies and procedures across our business and our affiliates’ businesses;
• where your personal data are held as part of an internal directory, enabling adequate communication with you for the performance of employment or membership duties or for emergency reasons;
• the administration and maintenance of the databases storing personal data relating to our employees, contractors, consultants or members or to employees, contractors, consultants or members of our affiliates; and
• providing references sought to confirm current and previous employees employment, details of engagement or membership with any financially regulated firms.
We will take steps to ensure that the personal data is accessed only by employees of our affiliates that have a need to do so for the purposes described in this notice.
We may also share your personal data to third parties outside of our corporate group for the following purposes:
• if in your role you are connected to the administration or facilitation of investment in a fund managed by us or one of our affiliates, in which case we may disclose your personal data for the purposes of “know-your-client” or due diligence to a service provider to the funds or an investor or potential investor in the funds;
• if we sell any of our business or assets, in which case we may disclose your personal data to the prospective buyer for due diligence purposes;
• if we are acquired by a third party, in which case personal data held by us about you will be disclosed to the third party buyer;
• to third party agents and contractors for the purposes of providing services to us, including but not limited to payroll, benefits, HR Workday system, trading platform service providers, insurance, IT and hosting, background screening, recruitment services, and communications providers, immigration services, relocation providers, law firms, benefits and insurance brokers, accountants and auditors, as well as banking and financial institutions. In addition, we may be required by law or regulation to share your data with third parties or with regulatory and/or government authorities. These third parties will be subject to confidentiality requirements and they will only use your personal data as described in this privacy notice to the extent they only process your personal data on our behalf and instructions; and
• to a regulator, government agency (such as tax authorities) or to the extent required by law, for example if we are under a duty to disclose your personal data in order to comply with any legal obligation, establish, exercise or defend our legal rights.
International transfers of personal data
Given the global nature of our activities, the personal data that we collect from you may be transferred to, and stored at, a destination outside of the jurisdiction in which it was originally collected (“ Relevant Location ”). It may also be stored and processed by other companies and/or third parties in other countries, which may include destinations outside of the Relevant Location, such as the UK, Channel Islands, Switzerland, the USA, Hong Kong, Singapore and the UAE.
Where we transfer your personal data outside of the Relevant Location, we will implement appropriate guarantees in order to ensure that it is protected in a manner that is consistent with how your personal data will be protected by us in the Relevant Location. This can be done in a number of ways, for instance:
• the country which the data recipient is located and that we send the data to is approved by the data protection authority in the Relevant Location as offering an adequate level of protection of your personal data;
• the data recipient located in a country not providing an adequate level of data protection according to applicable laws (e.g. the USA – if the data recipient is not certified under the Data Privacy Framework – Singapore, Hong Kong and/or the UAE) has signed up to a contract based on “standard contractual clauses” approved by the data protection authority in the Relevant Location, obliging them to protect your personal data; or
• where the data recipient is located in the USA, it might be a certified member of the EU-US Data Privacy Framework and the Swiss and/or UK extension to that framework.
In other circumstances the law may permit us to otherwise transfer your personal data outside the Relevant Location based on statutory guarantees or derogations. In all cases, however, we will ensure that any transfer of your personal data is compliant with data protection law.
You can obtain more details about the protection given to your personal data when it is transferred outside the Relevant Location (including a copy of the standard contractual clauses which we have entered into with recipients of your personal data, as the case may be) by contacting us in accordance with the “Contacting us” section below.
Retention and Security of personal data
How long we hold your personal data for will vary. The retention period will be determined by the following criteria:
• the purpose for which we are using your personal data – we will need to keep the data for as long as is necessary for that purpose; and
• legal obligations – laws or regulation may set a minimum period for which we have to keep your personal data.
Further details of retention periods are available in our Global Data Retention Policy.
We take all appropriate technical and organisational measures to guarantee the security, confidentiality, integrity, availability and traceability of your personal data in order to protect against data breach resulting in unauthorised access to, or unauthorised alteration, loss, disclosure, deletion or destruction of personal data. Such measures include but are not limited to the following:
• We protect our systems and networks from the Internet with Firewall systems.
• We employ intrusion detection software and monitor for unauthorised access.
• We maintain and selectively review activity logs, to prevent unauthorized activities from occurring within our computing environment.
• We build information security into our systems and networks by following our information security policies, procedures and standards. These documents are based on internationally respected security standards, applicable laws and regulations, and industry-based 'best practices'
• We provide information security awareness courses and materials to employees to ensure they apply our information security standards in the course of their work.
Automated decision-making
You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.
We do not envisage that any decisions will be taken about you using automated means. However, we will notify you in writing if this position changes.
Your rights
You have a number of legal rights in relation to the personal data that we hold about you. As and to the extent provided under applicable laws, these rights may (depending on in particular where your personal data is located and on the Relevant Location) include:
• the right to obtain information regarding the processing of your personal data and access to the personal data which we hold about you;
• the right to withdraw your consent to our processing of your personal data at any time. Please note, however, that we may still be entitled to process your personal data if we have another legitimate reason (other than consent) for doing so.
• in some circumstances, the right to receive some personal data in a structured, commonly used and machine-readable format and/or request that we transmit those data to another controller where this is technically feasible. Please note that this right only applies to personal data which you have provided to us;
• the right to request that we rectify your personal data if it is inaccurate or incomplete;
• the right to request that we erase your personal data in certain circumstances. Please note that there may be circumstances where you ask us to erase your personal data but we are legally entitled to retain it;
• the right to object to, and the right to request that we restrict, our processing of your personal data in certain circumstances. Again, there may be circumstances where you object to, or ask us to restrict, our processing of your personal data but we are legally entitled to continue processing your personal data and / or to refuse that request;
• the right to object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you;
• the right not to be discriminated against by us when exercising your rights;
• the right to lodge a complaint with the relevant data protection regulator (details of which are provided below) if you think that any of your rights have been infringed by us; and
• we can, on request, tell you which data protection authority is relevant to the processing of your personal data.
You can exercise your rights in line with applicable law in the Relevant Location by contacting us using the details set out in the “Contacting us” section below. However, please note that these rights are conditional under applicable laws and are not always absolute rights.
Please also note that U.S. law does not grant U.S. residents the personal data rights set forth above.
Contacting us
If you would like further information on the collection, use, disclosure, transfer or processing of your personal data or the exercise of any of the rights listed above, please address questions, comments and requests to [email protected] or, where relevant in your jurisdiction, by contacting your relevant employee representative.
You can find out more information about your rights using the following contact details:
UK: by contacting the Information Commissioner’s Office at www.ico.org.uk.
EU: by contacting the relevant data protection authority in the applicable EU Member State. For more information, please search the website at edpb.europa.eu.
Cayman Islands: by contacting the Cayman Islands’ Ombudsman. For more information, please search their website at ombudsman.ky.
Jersey: by contacting the Jersey Office of the Information Commissioner. For more information, please search their website at www.jerseyoic.org.
DIFC: by contacting the DIFC Commissioner of Data Protection. For more information, please search their website at www.difc.ae/business/registrars-and-commissioners/commissioner-of-data-protection.
ADGM: by contacting the ADGM Office of Data Protection. For more information, please search their website at www.adgm.com/operating-in-adgm/office-of-data-protection.
Singapore: by contacting the Personal Data Protection Commission. For more information, please search their website at https://www.pdpc.gov.sg/.
Hong Kong: by contacting the Office of the Privacy Commissioner for Personal Data, Hong Kong, or by searching their website at https://www.pcpd.org.hk.
Switzerland: by contacting the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch/edoeb/en/home.
Israel: by contacting the Israeli Protection of Privacy Authority. For information, please search their website at www.gov.il/he/departments/the_privacy_protection_authority/govil-landing-page.
India: by contacting the Ministry of Electronics & Information Technology. For information, please search their website at https://www.meity.gov.in/home.