Effective Date: 6 December 2024
This Privacy Notice describes how Marsh LLC and its subsidiaries (collectively, “Marsh”), process personal information. We believe that it is important for you to understand what information we collect and how we use and share it. That is why we encourage you to take a moment to familiarize yourself with our privacy practices outlined below. In this Privacy Notice, we explain how we collect, use, share, retain, and transfer your personal information. We also explain what rights you may have regarding your personal information.
Please note that in some instances we also act on behalf of and under the instructions of financial institutions, merchants and other partners which act as data controllers, including for processing payment transactions. Please refer to their respective privacy policies for more information regarding the processing of your Personal Information in these contexts.
Though we strive to describe our practices and your rights fully below, each jurisdiction imposes obligations and grants rights to you depending on how you interact with us or the jurisdiction in which we are doing business with you.
“Personal Information” means any information relating to an identified or identifiable individual (either directly or indirectly). We may collect the following categories of personal information where appropriate to fulfil our intended business purposes:
| Category | Examples |
|---|---|
| Category | Examples |
| Biographical identifiers | name, date of birth, age, place of birth, gender; biometric data (such as fingerprints, voice, facial images); |
| Contact information | home address, telephone number, personal email address; |
| Identification information | social security number or other government issued identification number, driver’s license number, passport information, bank account details, income tax declaration, income tax number; |
| Professional or employment-related information | Employer or group, relationship to our company, job title, business contact details, employee ID, employment grade, employee performance, salary and remuneration arrangements and employment history, and/or your relationship to the policyholder, insured, beneficiary or claimant; |
| Sensitive demographic attributes | race, citizenship, ethnic origin, political or philosophical beliefs, religious beliefs, criminal record, biometric data, physical or mental (including psychological) health or disability, sex (including gender, gender identity, pregnancy or childbirth and related medical conditions), sexual orientation, union membership, veteran or military status (each only to the extent necessary to perform the services); |
| Financial Information | Payment card number and related bank account number and account details, income and other financial information; |
| Benefit and Pension Information | Benefit elections, pension entitlement information, date of retirement and any relevant matters impacting your benefits such as voluntary contributions, details of power of attorney; |
| Insurable Risk Information | Criminal records data, including driving offenses, vehicle information, health information, injury or disability information, relevant personal habits (e.g., smoking), medical history, psychometric test results, historical information about the insurance quotes and coverages obtained, education information, credit history, and claims information and history, each to the extent relevant to the risk being insured; |
| Internet or other similar network activity | browsing and search history, interaction with a website, application, or advertisement, data from cookies or web beacons, login credentials, domain names, and interactions with our emails, including when you read and respond to emails, ISP, browser details, other website activity, online identifiers (including IP address or device ID); |
| Any other voluntarily provided information | information regarding partners and dependents (including minor dependents); emergency contact details, disclosure statements, restrictive covenants, geolocation, marketing and communication preferences, information related to company-sponsored events that you have attended, and your feedback or survey responses where you choose to identify yourself. |
We may collect information from the following categories of sources:
If you supply us with personal information about other people (e.g., family members, beneficiaries, or dependents), you represent that you have the authority to provide this information and that you have shared this Privacy Notice where appropriate. We do not knowingly collect personal information directly from minors.
We use cookies and related tracking technologies (“Cookies”) on our company-owned websites. If available based on your jurisdiction, website users can opt-out of our use of certain Cookies using the Manage Cookies link at the bottom of the website. To find out more about how we use Cookies, please see our Cookie Notice.
If you conduct a transaction through us, a third party (e.g., a service provider or insurer) may collect and process credit card or other Personal Information about you, including through Cookies, in connection with such a transaction. In those instances, and for any other arrangement where we receive information from your employer, association or other third party, we encourage you to read the third party’s privacy policy to learn more about how your information will be used and disclosed by them.
We may use Personal Information we collect:
| Category | Use | Legal Basis |
|---|---|---|
| Category | Use | Legal Basis |
| To conduct our business | We use Personal Information as necessary to conduct our business, including to verify your identity, respond to your queries, communicate with you, process transactions, establish an online account, or carry out our contractual obligations. | Contract performance and, where applicable, legitimate interests (to enable us to perform our obligations and provide our services. |
| To provide you with marketing material where permissible under applicable law | We may use your contact details to send you information about products, services, and insights we think might be of interest to you. These communications may be sent by email, text, post, or phone in accordance with your marketing preferences and applicable global laws, including those relating to data protection and electronic communication. As a result, the basis on which we contact you will vary depending on who you are, our relationship with you, and where you are located. Regardless of the basis on which we share our marketing communications with you, we will comply with local law and provide an option for you to unsubscribe at any time in which case we will stop sending you our marketing communications. You can also change your marketing preferences by contacting us at privacy@mmc.com. Please note that, even if you opt-out of receiving marketing communications, we may still send you communications in connection with the services we provide to you. | Consent (which you can refuse or withdraw) and, where applicable, legitimate interest (to keep you updated with news in relation to our products and services). |
| For research, data analytics and development purposes | We may analyse Personal Information together with information from other clients to create insights, reports, and other analytics to better understand and improve the quality of our offering; market our advice, products, and services; and evaluate the effectiveness of our marketing activities, websites, and overall service. Please note that we may de-identify Personal Information such that it is not associated with any particular client or individual. | Where applicable, legitimate interests (to allow us to improve our services). |
| To monitor certain activities and maintain network security and performance, and protect against cyber attacks | We monitor queries and transactions to ensure service quality, compliance with procedures and to combat fraud. We also use Personal Information as necessary to maintain network security, monitor website performance, and protect our systems against cyber attacks. | Legal obligation, and, where applicable, legitimate interests (to ensure the quality and legality of our services). |
| To maintain our websites and ensure website content is relevant | We use Personal Information as necessary to maintain our websites and ensure that content from our websites is presented in the most effective manner for you and for your device. | Contract performance and, where applicable, legitimate interests (to allow us to provide you with content and services on the websites). |
| To reorganise or make changes to our business | As necessary if we: (i) are subject to negotiations for the sale of our business or part thereof to a third party; (ii) are sold to a third party; or (iii) undergo a re-organisation. | Legal obligation or legitimate interests (to allow us to change our business). |
| In connection with legal or regulatory obligations | We use Personal Information to comply with our regulatory disclosure requirements or as part of dialogue with our regulators as applicable. | Legal obligation, and where appropriate, legitimate interests (to cooperate with law enforcement and regulatory authorities). |
| For Fraud, Anti-Money Laundering and Sanctions Screenings | When establishing or maintaining client relationships for the provision of certain services we use Personal Information for the purposes of carrying out fraud, anti-money laundering or sanctions checks. | Legal obligations and, where appropriate, legitimate interests (to cooperate with law enforcement and regulatory authorities). |
We may also use the Personal Information we collect and receive as otherwise described to you at the point of collection.
We may also disclose de-identified information that is not reasonably likely to identify you for commercially legitimate and lawful business purposes. Where we have de-identified information, we will maintain and use it without attempting to re-identify the data other than as permitted under law. In de-identifying your information, we rely, where available, on your legitimate interests.
Our websites may include links to websites that are operated by organizations other than Marsh. If you access another organization’s website using a hyperlink on our website, the other organization may collect information from you. Marsh is not responsible for the content or privacy practices of linked websites or their use of your Personal Information. If you leave a Marsh website via such a link (you can tell where you are by checking the URL in the location bar on your browser), you should refer to that website’s privacy policies, terms of use, and other notices to determine how the other organization will handle any Personal Information they collect from you.
We may disclose Personal Information to the following categories of third parties:
| Categories of third parties | Purpose for Disclosure |
|---|---|
| Categories of third parties | Purpose for Disclosure |
| Insurers, third-party agents/brokers, and/or other third parties | Assist in providing the services |
| Your employer, association, group, or benefit program sponsor, when applicable (i.e., Marsh’s Client) | To provide services to our client |
| Marsh affiliates or other entities within the Marsh McLennan group of companies (MMC) | Enable them to provide services to you or contact you regarding additional products and services. |
| Agents or third-party service providers | Perform functions or services for us or on our behalf. Such third parties are contractually restricted from using Personal Information for purposes other than providing services for or on behalf of Marsh. |
| Marketing partners, including our affiliates and third parties engaged by us or our clients in connection with the services. | As permitted by law to provide you with information about our products, services or insights. |
| Potential partners or successor entities | In the context of mergers, acquisitions, bankruptcies, asset sales or other transactions where a third party assumes control of all or part of our assets. |
| Website analytics and advertising companies | Help us to personalize ads and content based on your interests, measure the performance of our ads and content, and derive insights about the audiences who see our ads and content. |
| Anti-fraud databases, supervisory or regulatory authorities, law enforcement and other third parties | As necessary to prevent fraud, communicate with supervisory or regulatory authorities, protect and defend the legal rights, safety, and security of Marsh, our affiliates and business partners, and users of any website, enforce the Terms of Use of a website; respond to claims of suspected or actual illegal activity; respond to an audit or investigate a complaint or security threat; or comply with applicable law, regulation, legal process, or governmental request. |
Our company strives to comply with all applicable cybersecurity and data protection laws. With these goals in mind, MMC has a dedicated Chief Information Security Officer (CISO) and a Global Chief Privacy Officer (GCPO). The CISO is responsible for managing a Global Information Security team and a comprehensive cybersecurity program. As part of our cybersecurity program, we have implemented commercially reasonable physical, administrative, and technical safeguards to protect Personal Information from unauthorized access, use, alteration, and deletion.
The GCPO leads and oversees a Privacy Center of Excellence and a Data Protection Officer Network responsible for implementing our comprehensive global privacy program. The Data Protection Officer Network connects our Data Protection Officers across the world and seeks to implement our privacy program consistently and thoroughly wherever we process data. You can obtain the name and contact information for the Data Protection Officer in your jurisdiction by contacting us at privacy@mmc.com.
In many cases, we handle Personal Information to provide our services to corporate clients, and you should contact them to exercise any rights you may have under applicable privacy laws. However, where we act as the controller or business that is primarily responsible for deciding how your information is processed, you may have some or all the rights listed below, depending on the jurisdiction and our reason for processing your information. Please note that we may need to use your Personal Information to verify your identity prior to responding to any of the below rights.
If you wish to exercise any of the above rights or request review of a decision or denial, please contact us using the applicable contact information:
Depending on your country, you may also have some or all the following rights:
Please note that some of these rights may be limited where we have an overriding legitimate interest or legal, regulatory, or contractual obligation to continue to process the Personal Information, or where the Personal Information may be exempt from disclosure or erasure under applicable law. Some of these rights can be exercised only in certain circumstances or may otherwise be limited by data protection legislation in your jurisdiction.
As a global company operating across more than 80 countries, there are circumstances in which we will have to transfer Personal Information out of the country, province, or territory in which it was collected for the purposes outlined in this Privacy Notice. Specifically, we may transfer data to offer, administer, and manage the Services provided to you, and to enhance the efficiency of our business operations. We will make every effort to ensure that these transfers adhere to all relevant data protection legislation, and that the rights and freedoms of individuals under such laws are appropriately safeguarded.
Where the need for such a transfer arises, we will take steps to ensure that there are appropriate safeguards in place to protect Personal Information such as an impact assessment, adequacy decision by the appropriate supervisory authority, the use of approved binding corporate rules or standard contractual clauses, or your consent.
For information regarding how MMC’s EU (European Union) Binding Corporate Rules (EU BCRs) operate, click here. For a list of entities that have agreed to be bound by the EU BCRs, click here.
For information regarding how MMC’s UK Binding Corporate Rules (UK BCRs) operate, click here. For a list of entities that have agreed to be bound by the UK BCRs, click here.
Our products, services, and regulatory obligations are complex, and thus our retention periods for Personal Information vary. We consider the following obligations when setting retention periods for Personal Information and the records we maintain:
Based on the factors above, we may retain Personal Information beyond the period for which we provide services to you. When we no longer need to retain Personal Information, our company policies require that we either de-identify or aggregate the information (in which case we may further retain and use the de-identified or aggregated information for analytics purposes) or securely destroy it.
To submit questions or requests regarding this Privacy Notice or Marsh’s privacy practices, please email us at privacy@mmc.com. If you would prefer to contact us by post or by phone, please contact your local Data Protection Officer. You can obtain the contact information for your local Data Protection Officer by contacting us at privacy@mmc.com.