Privacy policy
GRANT THORNTON MAURITIUS is committed to respecting your privacy and protecting your personal data. In the interest of transparency, GRANT THORNTON MAURITIUS has adopted a “Personal Data Protection Policy” relating to the personal data collected by GRANT THORNTON MAURITIUS.
“GRANT THORNTON MAURITIUS” refers to the Grant Thornton entities in Mauritius, comprising Grant Thornton Services Ltd and Grant Thornton Audit (Mauritius) LLP both affiliated with GRANT THORNTON France, the French member firm of the Grant Thornton International Ltd network.
GRANT THORNTON MAURITIUS has updated its Personal Data Protection Policy in accordance with applicable regulations, including the Mauritius Data Protection Act 2017 (hereinafter referred to as the “DPA 2017”) and the guidelines issued by the Data Protection Commissioner.
This Policy aims to inform you of the commitments undertaken by GRANT THORNTON MAURITIUS to ensure the protection of your personal data.
GRANT THORNTON MAURITIUS is registered as a data controller with the Data Protection Commissioner in accordance with the DPA 2017.
1. DEFINITIONS
GRANT THORNTON MAURITIUS: refers to all statutory audit, accounting and advisory activities carried out by the affiliated legal entities forming part of the Grant Thornton group in Mauritius. GRANT THORNTON MAURITIUS is affiliated with GRANT THORNTON France, the French member firm of Grant Thornton International Ltd.
GRANT THORNTON ADVISORS: is a global integrated multidisciplinary professional services platform. It brings together several member firms of the international network (including France, Luxembourg, the United States, Ireland, the Netherlands, the UAE, Brazil, among others).
Supervisory Authority: the Data Protection Commissioner, responsible for the Data Protection Office established under Section 4 of the DPA 2017.
Consent: of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she agrees, through a statement or a clear affirmative action, to the processing of personal data relating to him or her.
Recipient: means a natural or legal person, public authority, agency or other body receiving disclosure of personal data, whether or not it is a third party.
Personal Data: means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more elements specific to their physical, physiological, genetic, psychological, economic, cultural or social identity.
Purpose: means the objective pursued by implementing the processing activity (e.g., recruitment, file management, invoicing).
Restriction of Processing: means the marking of stored personal data with the aim of limiting its future processing.
Data Controller: means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing and has decision-making authority regarding such processing.
Data Processor: means the natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.
Third Party: means a natural or legal person, public authority, agency or body other than the data subject, the data controller, the data processor and persons authorised to process personal data under the direct authority of the data controller or processor.
Processing: means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Personal Data Breach: means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
2. WHO IS THE DATA CONTROLLER?
The data controller is the firm. Your Personal Data is collected by GRANT THORNTON MAURITIUS, whose contact details are provided below:
Postal address:
GRANT THORNTON MAURITIUS
Level 11 & 12, Nexsky, Hotel Avenue Street, Cybercity, Ebene
For any questions, you may contact our Data Protection Officer by post at the following address:
GRANT THORNTON MAURITIUS
Data Protection Officer
Level 11 & 12, Nexsky, Hotel Avenue Street, Cybercity, Ebene
By email: Nitish.Nirsimloo@mus.gt.com
3. WHAT DATA IS COLLECTED?
This Policy applies to the personal data of identified or identifiable natural persons, including where such persons act as representatives, contacts or employees of corporate clients of GRANT THORNTON MAURITIUS. It does not apply to data relating exclusively to legal entities as such.
GRANT THORNTON MAURITIUS may collect the following data relating to you, both for its internal management purposes and for the performance of specific assignments entrusted to it by its clients (for example: payroll processing outsourcing):
Identification data: title, surname, first name;
Contact details: postal and email address, telephone number;
Information relating to education, professional activity and employment (for example: level of education, employment, position held (including whether the individual holds a political function), employer’s name, remuneration arrangements);
Data relating to interactions between the client and the firm: contact reports, our website, our social media pages, telephone interviews, emails, meetings and telephone conversations;
Data relating to the processing of emails and communications sent to you, such as the date and time emails are received and opened, as well as information relating to your interaction with the content provided.
In accordance with the principle of data minimisation, GRANT THORNTON MAURITIUS ensures that it only collects and processes data that is strictly necessary in relation to the purpose for which it is processed.
Certain data processed by GRANT THORNTON MAURITIUS may constitute special categories of personal data within the meaning of the DPA 2017, namely data relating to:
(a) racial or ethnic origin;
(b) political opinions or political affiliation;
(c) religious or philosophical beliefs;
(d) trade union membership;
(e) physical or mental health or medical condition;
(f) sexual orientation, sexual practices or preferences;
(g) genetic or biometric data enabling the unique identification of an individual;
(h) the commission or alleged commission of an offence;
(i) any proceedings relating to an offence committed or alleged to have been committed, the outcome of such proceedings or the sentence imposed; or
(j) any other personal data that the Commissioner may determine to constitute sensitive personal data.
The processing of such data is carried out strictly in accordance with the conditions set out in Sections 28 and 29 of the DPA 2017 and with appropriate safeguards.
4. HOW ARE THE COLLECTED DATA USED?
GRANT THORNTON MAURITIUS only processes your personal data on the basis of a legal obligation or in connection with the performance of its professional assignments.
In practice, GRANT THORNTON MAURITIUS primarily relies on the following legal bases: consent, the performance of a contractual relationship between you and GRANT THORNTON MAURITIUS and/or its legitimate interests relating to improving its services, client relationships and business development activities.
GRANT THORNTON MAURITIUS bears the burden of proof regarding the collection of your consent.
Any processing of your personal data is carried out for a legitimate, explicit and specific purpose.
Accordingly, GRANT THORNTON MAURITIUS collects and uses your data for several purposes:
- To communicate with you by email or postal mail in connection with the assignments entrusted to us;
- To send you newsletters, articles, thematic surveys, legal updates, information relating to training sessions, invitations linked to our services, legal or economic updates, and satisfaction surveys;
- To offer you meetings with our experts to address your specific needs;
- To manage your application for employment, collaboration opportunities or internships;
- To comply with legal or administrative obligations imposed by applicable legislation;
- Where necessary, for international cooperation purposes and service coordination, in order to provide high-quality professional services within a cross-border framework;
- If your personal data is processed for purposes other than those stated above, GRANT THORNTON MAURITIUS will inform you and, where required by law, obtain your prior consent.
In accordance with the DPA 2017, GRANT THORNTON MAURITIUS informs you, at the time your personal data is collected, of the following:
(a) the identity and contact details of the data controller and, where applicable, its representative and Data Protection Officer;
(b) the purpose of the collection;
(c) the intended recipients of the data;
(d) whether the provision of data is voluntary or mandatory;
(e) the existence of the right to withdraw consent at any time;
(f) the existence of the right to request access, rectification, restriction or erasure of your data, or to object to processing;
(g) the existence of automated decision-making, including profiling;
(h) the retention period of the data;
(i) the right to lodge a complaint with the Commissioner;
(j) where applicable, the intention to transfer data to another country and the level of protection provided; and
(k) any additional information necessary to ensure fair processing.
5. IN WHAT CONTEXT ARE YOUR PERSONAL DATA COLLECTED?
GRANT THORNTON MAURITIUS may collect your data mainly:
- Through the website www.grantthornton.mu: for submitting applications or subscribing to newsletters.
- For newsletter alerts: You may subscribe to our newsletters. If you no longer wish to receive them, you may unsubscribe by clicking on the link provided for this purpose in the body of the email.
- Through social media: Through buttons available on Facebook, Twitter and LinkedIn pages, you may follow and/or “like” GRANT THORNTON MAURITIUS posts. Information generated by these actions may potentially be used by the relevant social media platform. We invite you to consult the privacy policies of these networks to understand the possible consequences in detail.
- Through exchanges with our clients or prospects and the provision of documentation necessary for the performance of our work or the preparation of commercial proposals.
6. TRANSFER OF PERSONAL DATA
We do not transfer your personal data outside Mauritius without informing you beforehand and only where required for the processing of your file or where required by law.
If your personal data is transferred outside Mauritius, GRANT THORNTON MAURITIUS provides the Data Protection Commissioner with evidence of appropriate safeguards regarding the protection of personal data.
The transfer may also be based on your explicit consent, after informing you of the potential risks of the transfer in the absence of appropriate safeguards, or on other grounds provided under Section 36 of the DPA 2017.
GRANT THORNTON FRANCE is a member of the international network GRANT THORNTON International Ltd (“GTIL”), which brings together firms operating in more than 150 countries worldwide.
As part of the performance of cross-border assignments, service coordination, or cooperation requirements aimed at delivering high-quality services, GRANT THORNTON MAURITIUS may share your personal data with GRANT THORNTON FRANCE, other members of the international network, or GTIL.
To regulate such exchanges, a data transfer agreement has been entered into with the various member firms of the international network and with GTIL, providing safeguards compliant with Section 36 of the DPA 2017, as well as appropriate technical and organisational measures throughout the network.
GRANT THORNTON FRANCE has also joined the multinational platform GRANT THORNTON ADVISORS.
Within this framework, GRANT THORNTON MAURITIUS may share your personal data with member firms of the GRANT THORNTON ADVISORS multinational platform, where necessary, to facilitate internal cooperation, enhance services and provide access to a broader range of sector expertise and innovative solutions.
For this purpose, an inter-company data transfer and protection agreement has been entered into between GRANT THORNTON FRANCE and the firms that have joined the GRANT THORNTON ADVISORS platform.
The Data Protection Commissioner may, pursuant to Section 36(4) of the DPA 2017, require GRANT THORNTON MAURITIUS to demonstrate the effectiveness of the safeguards implemented or the existence of compelling legitimate interests, and may prohibit, suspend or subject the transfer to conditions determined by the Commissioner in order to protect the fundamental rights and freedoms of data subjects.
7. RETENTION PERIOD OF PERSONAL DATA
Personal data is retained in accordance with legal requirements for a period that does not exceed what is necessary for the purposes for which it is collected and processed, including:
7.1. Communication by email or postal mail in connection with entrusted assignments:
Duration of the contractual relationship.
7.2. Sending newsletters, legal updates and other information:
Duration of the commercial relationship.
7.3. Management of job applications:
12 months.
Once the purpose for which personal data has been retained has expired, GRANT THORNTON MAURITIUS will destroy the data within a reasonable timeframe and will notify any data processor holding such data so that they may also proceed with its destruction.
8. YOUR RIGHTS
You have the following rights:
- The right to access your personal data, exercised through a written request and free of charge;
- The right to rectification, erasure and restriction of processing;
- The right to object to processing;
- The right not to be subject to a decision based solely on automated processing.
GRANT THORNTON MAURITIUS will respond to any request within one month, which may be extended by an additional month in the event of a complex request or a large number of requests.
Where your personal data is processed for direct marketing purposes (including profiling related to such marketing), you have an absolute right to object, and your data will no longer be processed for this purpose. This right is expressly brought to your attention.
You may also, at any time, solely for processing activities based on your consent, withdraw your consent to the processing and use of your data with effect for the future. However, the withdrawal of your consent does not affect the lawfulness of processing carried out before such withdrawal.
For any questions regarding this matter or to exercise the rights mentioned above, you may submit a written request to our Data Protection Officer:
Your rights may also be exercised by:
- A parent or legal guardian (for minors);
- A guardian or legal administrator appointed by a court (for persons who are physically or mentally incapable);
- Any person duly authorised in writing.
You have the right to lodge a complaint with the Data Protection Commissioner.
Any person adversely affected by a decision of the Commissioner may, within 21 days, appeal before the ICT Appeal Tribunal.
Data Protection Office contact details:
Telephone: 460 0251
Email: dpo@govmu.org
Website: http://dataprotection.govmu.org
9. DISCLOSURE OF DATA TO THIRD PARTIES
GRANT THORNTON MAURITIUS does not disclose your personal data to third parties, except where required by legal or regulatory provisions, or where we have obtained your express authorisation. Any distribution or sale of your Personal Data is excluded.
However, as part of the management and monitoring of the client relationship, GRANT THORNTON MAURITIUS may engage a service provider (data processor) for the management of its client database.
Such processor acts solely on the instructions of GRANT THORNTON MAURITIUS under a written agreement.
The information communicated in this context includes:
First name; Last name; Email address; Company; Telephone number; Position; Title.
Similarly, and as indicated in Section 6 above, your personal data may be transferred to other member firms of the international network or the multinational GRANT THORNTON ADVISORS platform.
10. COOKIES
Your browsing experience on the GRANT THORNTON MAURITIUS website may involve the use of “Cookies.” Before placing non-essential cookies on your device, GRANT THORNTON MAURITIUS obtains your prior consent through an information banner displayed during your first visit.
Cookies consist of information files installed by your browser on your hard drive. Cookies allow us to obtain information about the characteristics of your visit to our website (such as browser type, etc.).
GRANT THORNTON MAURITIUS uses two types of Cookies:
– Session or preference Cookies
These are essential for navigation and the proper functioning of the website. These strictly necessary cookies are exempt from prior consent requirements.
– Audience measurement Cookies
These allow us to monitor your browsing activity on the website for statistical purposes and enable GRANT THORNTON MAURITIUS to better understand its audience in order to improve its services. These cookies are only placed after obtaining your explicit consent.
These cookies are intended to:
- Measure the number of users of our services, thereby making them easier to use and ensuring their ability to respond quickly to requests;
- Analyse data to enable GRANT THORNTON MAURITIUS to understand how users interact with its services in order to improve them.
If you refuse the use of certain cookies, please note that you may not be able to fully benefit from a significant part of the functions of the GRANT THORNTON MAURITIUS website.
You may withdraw your consent to the use of non-essential cookies at any time, modify your preferences or delete cookies already installed through your browser settings. The withdrawal of consent does not affect the lawfulness of processing based on consent given prior to withdrawal. Audience measurement cookies have a limited validity period strictly necessary for their purpose. Detailed information relating to each cookie used (name, content, purpose and validity period) is provided in the cookie banner displayed during your first visit to the GRANT THORNTON MAURITIUS website, as well as in the dedicated cookie notice accessible from the website.
GRANT THORNTON MAURITIUS does not use third-party cookies for behavioural advertising or cross-site tracking purposes. Should third-party cookies be used in the future, GRANT THORNTON MAURITIUS will inform you beforehand, identifying the relevant third parties and purposes, and will obtain your explicit consent before any such cookies are placed.
11. SECURITY
GRANT THORNTON MAURITIUS takes all appropriate precautions, as well as suitable technical and organisational measures, to ensure the security of your Personal Data and, in particular, to prevent unauthorised access, alteration, unauthorised disclosure, accidental loss and destruction of data under its control.
To determine appropriate security measures, GRANT THORNTON MAURITIUS takes into account:
(a) the state of available technological development;
(b) the cost of implementing security measures;
(c) the specific risks associated with the processing of data; and
(d) the nature of the data being processed.
In particular, the security measures implemented include:
- The pseudonymisation or encryption of personal data;
- The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- The ability to restore the availability of and access to personal data within appropriate timeframes in the event of a physical or technical incident;
- A process for regularly testing, analysing and evaluating the effectiveness of technical and organisational measures implemented to ensure processing security.
GRANT THORNTON MAURITIUS takes all reasonable measures to ensure that any person authorised to process personal data is informed of and complies with applicable security measures. For this purpose, mandatory data protection training is provided to relevant employees.
Where GRANT THORNTON MAURITIUS engages a processor, it selects a processor providing sufficient security guarantees and enters into a written agreement. If a processor processes data outside the instructions of GRANT THORNTON MAURITIUS, it will be considered the data controller for such processing. The Data Protection Commissioner may conduct a prior security assessment where the processing may present a specific risk to individuals’ privacy rights.
In the event of a personal data breach, GRANT THORNTON MAURITIUS will notify the Data Protection Commissioner without undue delay and, where possible, within 72 hours of becoming aware of the breach.
This notification will describe:
- The nature of the breach;
- The categories and approximate number of affected individuals;
- The likely consequences;
- The measures taken or proposed to address the breach.
Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, GRANT THORNTON MAURITIUS will communicate the breach to the affected individuals as soon as possible, unless appropriate protective measures have been implemented (particularly encryption), or the high risk is no longer likely to materialise.
12. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
Where processing activities are likely to result in a high risk to the rights and freedoms of data subjects, GRANT THORNTON MAURITIUS carries out a Data Protection Impact Assessment prior to the processing.
This assessment includes, in particular:
- A systematic description of the processing operations envisaged;
- An assessment of the necessity and proportionality of the processing;
- An assessment of the risks to the rights and freedoms of data subjects;
- The measures envisaged to address and mitigate such risks.
Furthermore, GRANT THORNTON MAURITIUS obtains prior authorisation from the Data Protection Office or consults with the Data Protection Office before carrying out processing where: The Data Protection Impact Assessment demonstrates that the processing operations present a high risk; or The Data Protection Office considers such consultation necessary.
13. LINKS TO OTHER WEBSITES
The websites of GRANT THORNTON MAURITIUS may provide links to third-party websites, including but not limited to:
Facebook; Twitter; LinkedIn; YouTube; Websites of members of the Grant Thornton International network.
GRANT THORNTON MAURITIUS has no control over the content of third-party websites or the personal data protection practices implemented by such third parties in relation to the personal data they may collect.
Consequently, GRANT THORNTON MAURITIUS accepts no responsibility for the processing of your Personal Data carried out by such third parties.