Updated 4 September 2025
ERM is committed to protecting the privacy of personal data and maintaining the principles of integrity and trust in the course of ERM’s business.
This privacy notice aims to give you information on how ERM collects and processes your personal data through your use of this website, and through interactions with its clients, suppliers, and other third parties.
The data we may collect about you
“Personal data” means any information about a person that can be used to identify that person. It does not include data where the identity has been removed (anonymous data or pseudonymised data where we do not hold the key). We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:
- Identity Dataincludes first name, last name, username or similar identifier, title, date of birth and gender, job title and employer; photograph / identity documents (where necessary for identification when attending ERM functions).
- Contact Dataincludes postal address, email address and telephone numbers and corporate contact details (including business "direct dial" or office address).
- Public Dataincludes information we collect when providing our services to our clients, which may include data that is public or is contained on public data sites (such as LinkedIn, company registrar websites and our clients’ own websites), including information about whether you may be or be connected with a person listed on government sanctions lists.
- Service Dataincludes information we collect when providing our services to our clients, which includes personal data collected as part of surveys carried out by ERM in the course of performing its services (including Identity Data, Contact Data, Public Data and information such as occupation and income).
- Correspondence Dataincludes personal data we obtain as a result of our correspondence, including personal data contained in feedback and complaints, the progress of complaint resolution, and the outcome of complaints.
- Financial Dataincludes bank account and payment card details (where necessary to conclude or perform service contracts with you).
- Marketing and Communications Dataincludes your preferences in receiving marketing materials from us and our third parties and your communication preferences.
- Technical Dataincludes internet protocol (IP) address, your login data for our websites and other online services, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website and information about how you use our website.
How is your personal data collected?
We use different methods to collect personal data from and about you. You may give us your personal data by filling in forms or by corresponding with us by post, phone, email or otherwise. We may also receive personal data about you from various third parties (such as our clients and suppliers, particularly if they are your employer) and public sources, such as identity and contact data from publicly availably sources (see “Public Data” above) and reports from external professionals.
How is your personal data collected?
We use different methods to collect personal data from and about you. You may give us your personal data by filling in forms or by corresponding with us by post, phone, email or otherwise. We may also receive personal data about you from various third parties (such as our clients and suppliers, particularly if they are your employer) and public sources, such as identity and contact data from publicly availably sources (see “Public Data” above) and reports from external professionals.
Purposes for which we will process your personal data
The table below sets out the purposes for which ERM may process your personal data, and the lawful grounds for that processing. Depending on the purpose/s for which we are processing your data, we may do so under more than one lawful grounds.
Purpose/Activity |
Lawful grounds for processing |
To communicate with you and to process and respond to correspondence from you |
To comply with law |
To register you as a new client or supplier |
To help us meet our contractual obligations to you |
To manage our relationship with you |
To help us meet our contractual obligations to you |
To help ensure the quality of our services (including processing Service Data) |
To maintain the quality of our services, when it is within our legitimate interests to do so |
To understand the performance of our business |
To understand the performance of our business, when it is within our legitimate interests to do so |
To meet regulatory requirements by producing management information and reports to help us identify potential problems |
To comply with law |
To administer and protect our business and this website |
To run our business, provide of administrative and IT services, network security and when it is within our legitimate interests to do so |
To undertake sanctions list checks |
To comply with law |
To conduct direct marketing about our services, events to attend or industry updates or articles that may be of interest to you |
Consent where it has been given (note that you can opt out at any time) |
To use data analytics to improve our website, marketing, client relationships and experiences |
To keep our website updated and relevant, to develop our business and to inform our marketing strategy, when it is within our legitimate interests to do so |
Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out.
Cookies
ERM uses cookies. A cookie is a small piece of information that a website stores on the web browser on your device and can later retrieve. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. Our Cookie Notice will illustrate the cookies we use.
Disclosures of your personal data
We may need to share your personal data within the ERM Group in order to provide you with our services or manage our business.
We may also employ the services of third party service providers who provide services to us. These service providers have agreed to confidentiality restrictions and will use any personal data we share with them (or which they collect on our behalf) solely for the purpose of providing those services. We take appropriate steps to ensure that such third parties treat your personal data with the same care that we do. Where third party service providers receive your information we remain responsible for the use of your personal data.
We may be required to disclose your personal data to law enforcement bodies, regulators, agencies or other third parties under a legal requirement or court order. We act responsibly and take account of your interests when responding to any such requests.
Direct Marketing
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. If you have given us your consent to send you marketing material by email or post, you have the right to opt out of receiving that material. We will also get your express opt-in consent before we share your personal data with any company outside the ERM Group for marketing purposes. You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you, or you can contact us at any time.
International transfers
ERM is an international organisation, with businesses inside and outside the European Economic Area ("EEA"). Third party service providers who handle data on our behalf may be based in locations around the world. For these reasons, your personal data may be transferred to other countries both inside and outside of the EEA. Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;
- Where we use certain service providers, we may use specific contracts approved by relevant authorities which give personal data the same protection it has in UK or Europe; and/ or
- Where we use third party providers based in the US, we may transfer data to them if they have adequate measure in place, which requires them to provide similar protection to personal data shared between the UK, Europe and the US.
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data.
Additional information for individuals in Mainland of the People’s Republic of China (PRC)
Where you are located in the PRC and when data protection laws of the PRC apply, our PRC entity ERM (Shanghai) Limited will transfer your personal data it collected to jurisdictions/regions outside the PRC via the Internet and/or our intranet connecting our information systems.
If you are a client contact in the PRC, we will transfer the following personal data of yours (no sensitive personal data involved):
- Personal basic profile including name, phone number, e-mail address, location.
- Personal education and work information including position, company information.
If you are a sub-contractor or a supplier contact in the PRC, we will transfer the following personal data of yours (no sensitive personal data involved):
- Personal basic profile including name, phone number, e-mail address.
- Personal education and work information including company information.
The overseas recipient is The ERM International Group Limited, a company registered in the UK with the contact address at 2nd Floor Exchequer Court, 33 St. Mary Axe, London, England, EC3A 8AA. The overseas recipient in the UK may use information systems deployed on servers in other jurisdictions/regions (including Ireland, United States, and Germany) to receive personal data that we transfer and conduct the further processing.
When we store or transfer your personal data outside the PRC, we will take all reasonable steps to ensure that your personal data is treated as safely and securely as it would be within the PRC and under the Personal Information Protection Law (PIPL) of the PRC.
Your acceptance of this privacy policy shall be your separate consent permitting us to transfer and store your personal data outside the PRC if it is necessary for us to do so.
In addition, we will take necessary measures required by the PIPL including entering into Standard Contract with the overseas recipient to stipulate the rights and obligations between us and will ensure that the overseas recipient provides adequate protection for your personal data under applicable laws.
We will only transfer your personal data (including sensitive personal data) to the extent necessary and will work with the overseas recipient to process it in a secure manner to protect your legitimate interests and to avoid causing harms to you. We and the overseas recipient will only retain your personal data for the minimum necessary retention period unless otherwise required by applicable laws.
You have the right to exercise your personal data rights over the overseas recipient by sending an email request to data.protection@erm.com. Under our Standard Contract for the cross-border transfer of personal data with the overseas recipient, you could be considered as a third-party beneficiary and can be entitled to exercise the third-party beneficiary rights if you do not expressly refuse within 30 days upon your acceptance of this privacy policy. According to applicable laws and the Standard Contract (if applicable), you may have the right to demand us to provide a copy or a summary of the relevant contract content.
Additional information for individuals in Mainland of the People’s Republic of China (PRC)
Where you are located in the PRC and when data protection laws of the PRC apply, our PRC entity ERM (Shanghai) Limited will transfer your personal data it collected to jurisdictions/regions outside the PRC via the Internet and/or our intranet connecting our information systems.
If you are a client contact in the PRC, we will transfer the following personal data of yours (no sensitive personal data involved):
- Personal basic profile including name, phone number, e-mail address, location.
- Personal education and work information including position, company information.
If you are a sub-contractor or a supplier contact in the PRC, we will transfer the following personal data of yours (no sensitive personal data involved):
- Personal basic profile including name, phone number, e-mail address.
- Personal education and work information including company information.
The overseas recipient is The ERM International Group Limited, a company registered in the UK with the contact address at 2nd Floor Exchequer Court, 33 St. Mary Axe, London, England, EC3A 8AA. The overseas recipient in the UK may use information systems deployed on servers in other jurisdictions/regions (including Ireland, United States, and Germany) to receive personal data that we transfer and conduct the further processing.
When we store or transfer your personal data outside the PRC, we will take all reasonable steps to ensure that your personal data is treated as safely and securely as it would be within the PRC and under the Personal Information Protection Law (PIPL) of the PRC.
Your acceptance of this privacy policy shall be your separate consent permitting us to transfer and store your personal data outside the PRC if it is necessary for us to do so.
In addition, we will take necessary measures required by the PIPL including entering into Standard Contract with the overseas recipient to stipulate the rights and obligations between us and will ensure that the overseas recipient provides adequate protection for your personal data under applicable laws.
We will only transfer your personal data (including sensitive personal data) to the extent necessary and will work with the overseas recipient to process it in a secure manner to protect your legitimate interests and to avoid causing harms to you. We and the overseas recipient will only retain your personal data for the minimum necessary retention period unless otherwise required by applicable laws.
You have the right to exercise your personal data rights over the overseas recipient by sending an email request to data.protection@erm.com. Under our Standard Contract for the cross-border transfer of personal data with the overseas recipient, you could be considered as a third-party beneficiary and can be entitled to exercise the third-party beneficiary rights if you do not expressly refuse within 30 days upon your acceptance of this privacy policy. According to applicable laws and the Standard Contract (if applicable), you may have the right to demand us to provide a copy or a summary of the relevant contract content.
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
How long will you use my personal data for?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Your legal rights
You have and retain all rights under the relevant data protection laws where you reside.
In respect of receiving communications from ERM and other content, you will be asked for your consent as well as your preferences. You can withdraw your consent at any time.
You can contact dataprivacy@erm.com,or your regular contact at ERM, if you would like to exercise your rights.
Alternatively, ERM has appointed Bird & Bird DPO Services SRL as a Data Protection Officer (DPO), and the DPO may be reached:
- by using the following email: DPO.ERM@twobirds.com or dataprivacy.erm.com
- by mail at the following address: Bird & Bird DPO Services SRL, Avenue Louise 235 b 1, 1050 Brussels, Belgium
Information about the data controller
This privacy policy is issued on behalf of The ERM International Group (i.e. The ERM International Group Limited and its group companies), so when we mention ERM "we", "us" or "our" in this privacy policy, we are referring to the relevant company in The ERM International Group responsible for processing your data. In the majority of circumstances, and in relation to data collected via this website, your data controller will be The ERM International Group Limited. However, if your data controller is another member of The ERM International Group, we will make that information clear to you at the time your personal data is collected.
Contact us
The primary point of contact for all issues arising from this privacy policy is the ERM Data Protection Team. If you have any complaints or queries relating to the processing of your personal data by any member of ERM Group, or to exercise any rights in respect of your personal data, you can contact us at dataprivacy@erm.com.
We will investigate and attempt to resolve complaints and disputes and will make every reasonable effort to honour your wish to exercise your rights.
To contact your data protection supervisory authority
You have a right to lodge a complaint with your local data protection supervisory authority at any time.
Should you have a complaint, we hope that you can approach us first so that we can try to resolve your concern.
Changes to this privacy policy and informing us of changes
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.