World-Check - GDPR Product Information May 2022

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

Product Information The Financial and Risk

business of Thomson
Reuters is now Refinitiv

World-Check
(including Screening Online and Screening Deployed)

This overview answers common questions about how personal data in


World-Check (including in Screening Online and Screening Deployed) is
handled, stored and protected.

negative allegations, it should be assumed that


What is World-Check? the allegations are denied.

World-Check holds information that helps financial In order to safeguard individuals’ privacy, and the
institutions, corporates, professional service firms, integrity of the World-Check database, WC
governments, law enforcement agencies, regulators Customers are not able to amend personal data on
and other World-Check customers (“WC the World-Check database.
Customers” or “You/Your Staff”) to perform due
diligence and other screening activities in More detailed information about how personal data
accordance with their legal or regulatory obligations is used in World-Check (and on the types of
and risk management procedures which are carried information held in World-Check) can be found in
out in the public interest (“Checks”). the World-Check Privacy Statement available
online: https://www.refinitiv.com/en/products/world-
How is personal data used in check-kyc-screening/privacy-statement

World-Check? Is Refinitiv a controller or


World-Check researchers gather data from public processor of data?
sources (such as official records and news sources)
and carry out standard checks of the information For the purposes of EU data protection laws,
entered into World-Check. Refinitiv Limited acts as controller of personal data
in the World-Check database. The only exception to
Researchers will only include information about an this is the Ongoing Screening and Watchlist
individual within the World-Check database if public functions in World-Check. The Ongoing Screening
domain data suggests that there is information function enables WC Customers to receive updates
about him/her that institutions ought to be aware of to Checks to reflect any changes to the information
for the purposes of the Checks. on individuals in World-Check. Watchlist allows WC
Inclusion of an individual within the World- Customers to store the names of individuals of
Check database does not by itself demonstrate interest on the World-Check platform so as to
criminality or wrongdoing of any sort. Some conduct Checks against them. Refinitiv will host the
individuals are only included in World-Check names of these individuals and details of the
because they have, for example, held public office Checks conducted against them as processor in
and guidelines such as those of the Financial Action accordance with the WC Customer’s instructions.
Task Force require financial institutions to be able
to identify these types of individuals. Separately, WC Customers (as data controllers) are
responsible for any personal data they record as a
WC Customers can search the World-Check result of, or in connection with, the use of World-
database to check if an individual is included in it. Check (including the use of Ongoing Screening and
However, this information is intended to be only part Watchlist). WC Customers’ processing of that
– and not all – of any WC Customer’s Checks. personal data for these purposes is separate and
World-Check flags issues for investigation: it distinct from the processing of Refinitiv as a
does not provide any conclusions about controller. Therefore, Refinitiv should neither be
individuals and where World-Check contains considered a joint controller nor a controller in

September 2020 Page 1


PRODUCT INFORMATION WORLD-CHECK

common of any personal data. WC Customers are compliance processes to assist You with
solely responsible for ensuring their compliance performing due diligence and other screening
with data protection laws. activities that are necessary for reasons of
substantial public interest on the basis of, or as
authorized by EU Law/applicable law, for
How can customers use World- example in connection with Your legal or
regulatory obligations connected to preventing
Check? or detecting unlawful acts (such as money
laundering, terrorist financing or fraud)
Some of the personal data contained in World-
Check is special category data that attracts extra  not to use World-Check to make automated
protection under EU data protection laws. For decisions about an individual or his/her
example, World-Check holds public domain data business
about actual or alleged financial crime.
 not to allow Your Staff who have not reviewed
World-Check User Training made available to
Therefore, all WC customers must respect the You by Refinitiv to use World-Check
following commitments and restrictions when
using World-Check.  not to use the Watchlist function to upload
or compile a list of individuals, entities or other
persons that You do not wish to do business
Commitments with

✓ to bring the World-Check Privacy Statement to Where are the data centers for
the attention of individuals that You search
against on World-Check so they are aware that World-Check located?
You use World-Check and understand how we
handle their personal data. The World-Check The primary data centers for World-Check are
Privacy Statement can be found at: located in the United Kingdom and data is also held
in the Amazon Web Services Cloud, with a primary
https://www.refinitiv.com/en/products/world- data center in Ireland, and secondary location in the
check-kyc-screening/privacy-statement United Kingdom.

✓ to carry out Your own investigation into any Can personal data be accessed
circumstances flagged by World-Check
✓ to assume that individuals deny any allegations
from outside of the EEA?
made about them World-Check is a global service and Refinitiv is a
✓ if You have purchased the World-Check data global organization that provides 24/7 solutions to
file, datafeed or API to implement any updates customers around the world. In order to do this, it
(including deletions) we send to you uses a global team to provide services, support and
promptly – this helps to keep data accurate and maintenance.
to stop it being retained for excessive periods
This means that personal data on World-Check may
✓ to keep access to World-Check, and the World- be accessed from countries outside of the
Check database (if you have a copy), secure –
European Economic Area (“EEA”) in accordance
you should take advice from Your information
technology security team on how to do this with applicable laws. For more information on these
countries, please see the World-Check Privacy
✓ if you have purchased the World-Check data Statement:
file, datafeed or API, identify to us a named
person who is responsible for the security of https://www.refinitiv.com/en/products/world-check-
World-Check data kyc-screening/privacy-statement
✓ complete and return any questionnaires we When we transfer personal data from the EEA to
send to you about the use of World-Check
other countries whose laws do not offer the same
promptly – this helps us to check that World-
level of data protection, we will ensure that there
Check is being used in a way that provides
adequate protection for individuals’ personal are adequate safeguards in place to protect the
data personal data that comply with our legal obligations.

WC Customers (as data controllers) are solely


Restrictions responsible for complying with data protection laws
when they transfer personal data outside of the
EEA as a result of or in connection with their use of
 not to use World-Check for any purposes
World-Check.
other than as part of your own internal

2
September 2020
PRODUCT INFORMATION WORLD-CHECK

• administrative and technical controls to restrict


staff access to the personal data in World-
Check
How long is data retained for? • a business continuity and disaster recovery
strategy that applies to World-Check and
The personal data in World-Check is retained by
which is designed to safeguard the continuity
Refinitiv for so long as required in order to inform
of access to, and security of, World-Check;
current and future Checks conducted by WC
Customers. In determining this length of time, • physical security measures, such as staff
Refinitiv takes into consideration local laws, the security passes and strict controls on access
reasonable requirements of WC Customers, the to locations of World-Check servers
rights of individuals and the continuing relevance of • monitoring compliance with our policies,
the personal data (which is assessed through procedures and controls;
ongoing relevancy checks). We also carry out • regular penetration testing by an independent
ongoing checks to ensure that personal data in third party company; and
World-Check remains relevant even before it • regularly scanning of code and infrastructure
reaches the end of its retention period. using third party capabilities

When personal data reaches the end of its retention We do not agree bespoke security and data
period or Refinitiv otherwise identifies that it is no protection specifications for customers as the
longer relevant - Refinitiv securely deletes or stability and integrity of the World-Check solution
destroys it from the World-Check database. rely on the standardization of our security and data
protection methodologies.
Where WC Customers have purchased the World-
Check data file, data feed or API, Refinitiv provides Annual privacy assurance and
them with daily updates and deletions of data in the
World-Check database. This is to ensure that the WC Customer training
World-Check data held by such WC Customers
continues to reflect the World-Check database Refinitiv conducts annual privacy assurances with
maintained by Refinitiv. If You hold a copy of the its WC Customers to check that World-Check is
World-Check database on Your own systems, You being used by WC Customers in accordance with
must implement all updates and deletions promptly. the terms and conditions applying to it. This will
include obtaining an acknowledgment that the WC
Customer and its users are only using World-Check
How is personal data secured? for the limited purposes permitted by Refinitiv and
Securing personal data is a priority at Refinitiv and demonstrating that Your Staff understand such
a key aspect of protecting privacy. Our security purposes and have been provided with appropriate
organization applies policies, standards and privacy guidance and/or completed any privacy
supporting security controls at the level appropriate training applying to World-Check.
to the risk level and the service provided. In You agree that Your Staff will complete any such
addition, appropriate security controls are privacy training and that on request by Refinitiv,
communicated to application owners and You will complete the World-Check annual privacy
technology teams across the business to support assurance (including, where You purchase the
secure development of products and a secure
World-Check data file, providing evidence of the
operating environment. World-Check is also subject
acknowledgements outlined in the paragraph
to an ongoing audit and assessment programme
above). Where You purchase a hosted version of
and has received independent assurance against
World-Check, Refinitiv will obtain these
the ISAE 3000, Type II standard.
acknowledgments bi-annually from Your staff when
We pay specific attention to the protection of they log in to World-Check.
personal data and the risks associated with
processing this data in World-Check. In particular, Security of World-Check data file
the security infrastructure applying to World-Check
includes:
Refinitiv requires WC Customers that purchase the
• robust controls around the inclusion and World-Check data file to establish and maintain an
maintenance of information in World-Check adequate accreditation e.g. ISO 27001 or
which are designed to ensure the accuracy equivalent, that is acceptable to Refinitiv) for the
and relevance of information in World-Check people, processes and IT systems that they use to
• education and training to relevant Refinitiv process World-Check data.
staff on the proper handling of personal data;

3
September 2020
PRODUCT INFORMATION WORLD-CHECK

If You purchase the World-Check data file, You


agree to meet the requirements outlined in the
paragraph above at Your own cost and to provide a
copy of your accreditation report to Refinitiv upon
request. Refinitiv will be able to determine whether
You are maintaining the necessary accreditation on
the basis of the report.

Personal Data Breaches


Refinitiv implements appropriate measures
designed to prevent personal data breaches. These
measures include:

• strict controls on access to World-Check and


World-Check’s physical infrastructure;
• regular scanning and penetration testing to
identify potential security vulnerabilities;
• use of encryption (where appropriate); and
• contractual obligations on Refinitiv third party
service providers to comply with our IT
security policies.

The measures we use are also reviewed and


updated as necessary to meet changes in
regulatory requirements.

WC Customers must also implement such


measures and You agree that You will do so and
also notify TR promptly of any actual or suspected
personal data breach affecting World-Check.

Individual rights
Under data protection laws, individuals may have
certain rights in relation to information held about
them (e.g. a right to request a copy of their personal
data or to request inaccuracies in such data to be
corrected). If You receive a request from an
individual seeking to exercise a right in relation to
information about them in World-Check, You agree
to promptly forward this request to Refinitiv as data
controller. Refinitiv shall respond to this request,
unless we expressly agree otherwise. You agree to
provide reasonable cooperation to enable us to
formulate that response.

For more information


If You would like to know more about our approach
to processing and protecting personal data as part
of World-Check, please contact Your account
manager.

For general questions on how Refinitiv deals with


personal data, please contact us at:
privacy.enquiries@refinitiv.com

4
September 2020

You might also like