Privacy notice
Comply Limited | Last updated 9 September 2026
1. Who we are and definitions
1.1 Comply Limited is a company incorporated in Jersey with registered number 167304, whose registered office is at Caversham House, 19 Queen Street, St Helier, Jersey, JE2 4WD (Comply, we, us and our). Comply is the controller of your Personal Data and is registered with the Jersey Office of the Information Commissioner under registration number 101454.
1.2 In this privacy notice, the following definitions apply.
(a) Data Protection Laws means the Jersey Data Law, the Data Protection Authority (Jersey) Law 2018, the EU Data Law where it applies, and any other relevant equivalent legislation, each as amended from time to time.
(b) Data Subject means the person who is the subject of the Personal Data in question.
(c) EU Data Law means the General Data Protection Regulation (EU) 2016/679.
(d) Jersey Data Law means the Data Protection (Jersey) Law 2018.
(e) JOIC means the Jersey Office of the Information Commissioner.
(f) Personal Data means any information that identifies or could identify you and which is about you.
(g) Processing means any operation performed on Personal Data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
(h) Special Category Data means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (when processed to identify an individual uniquely), data concerning health, sex life or sexual orientation, and, in Jersey, criminal records or alleged criminal conduct.
2. About this privacy notice
2.1 We take the protection of your privacy seriously. This notice explains how and why we collect, use, keep and share your Personal Data, your rights in relation to it, and how to raise any concerns.
2.2 This notice applies when you deal with us as a Data Subject, including as a client or customer, an event attendee, speaker or sponsor, or as a director, employee, beneficial owner or other individual connected with a client. As a controller of your Personal Data, we must comply with the Data Protection Laws.
2.3 The JOIC is our lead supervisory authority. Jersey's data protection regime is recognised by the European Commission as providing an adequate level of protection for Personal Data.
2.4 If you have any questions about this notice or the information we hold about you, want to exercise any of your rights, or wish to make a complaint, please contact us at ches@comply.je.
2.5 You also have the right to complain to the JOIC:
(a) online at jerseyoic.org;
(b) by email to enquiries@jerseyoic.org;
(c) by telephone on +44 (0)1534 716530; or
(d) by post to 2nd Floor, 5 Castle Street, St Helier, Jersey, JE2 3BT.
2.6 We may update this notice from time to time. The current version is always available at comply.je/privacy-notice
3. Our reasons for processing
3.1 Under the Data Protection Laws, we can only use your Personal Data if we have a proper reason for doing so, including:
(a) where you have given your consent;
(b) to comply with our legal and regulatory obligations;
(c) to perform a contract with you, or to take steps at your request before entering into a contract;
(d) where it is in the substantial public interest;
(e) to protect your vital interests; or
(f) where it is necessary for our legitimate interests (as described in clause 6) or those of a third party.
3.2 A legitimate interest is where we have a business or commercial reason to use your non-sensitive Personal Data, provided your rights and interests do not override it. When we rely on legitimate interests, we carry out an assessment to balance our interests against yours.
3.3 Where we rely on your consent, you can withdraw it at any time without penalty. This does not affect Processing carried out before you withdrew it.
4. Information we process
4.1 We process Personal Data in accordance with the law and your reasonable expectations. Depending on how we deal with you, this may include:
(a) contact information, including postal address, email addresses, telephone numbers, company details and, where applicable, social media contact details;
(b) identity information, including current and former names, gender, date and place of birth, nationality, passport or similar photo ID and birth certificate;
(c) preference information, including preferred correspondence language;
(d) verification information, including government-issued documents, bank statements and utility bills;
(e) tax information, including domicile, tax identification numbers, tax returns and tax advice;
(f) source of wealth information, including pension plans, property sale documents and loan documents;
(g) financial information, including bank account details, assets held and the basis on which they are held (for example, legal or beneficial ownership);
(h) trust information (where applicable), including settlor details and letters of wishes;
(i) employment information;
(j) criminal records or allegations information, including details of any investigation of you by an official body and any sanctions applying to you;
(k) insolvency or bankruptcy information (where applicable);
(l) debtor information;
(m) connected persons information, including information about family relationships;
(n) politically exposed person information, including political activities and relationships;
(o) information in the public domain;
(p) correspondence between you, your agents or representatives, and us;
(q) training recordings, including images, voices and contributions of participants in training sessions and webinars we record;
(r) event information, including event registrations and attendance, dietary and accessibility requirements, and photographs or video taken at our events;
(s) billing, transaction and payment information; and
(t) technical data, including information about how you use our website, IT, communication and other systems.
4.2 For more information on how we use cookie data, please contact us.
4.3 We collect and use this Personal Data to provide our services to you. If you do not provide the Personal Data we ask for, it may delay or prevent us from providing those services.
5. How we collect your information
5.1 We collect most Personal Data directly from you, in person, by telephone, video call, text message or email, and through our website. We may also collect information:
(a) from publicly accessible sources;
(b) from a third party, including with your consent;
(c) from cookies on our website; and
(d) through our IT systems, for example through automated monitoring of our website and other technical systems, such as our computer networks and connections, communications systems, email and instant messaging systems.
5.2 We may, from time to time, record telephone or video calls. We will tell you at the start of any call we record.
5.3 Where a client asks us to, we may record training sessions or webinars we deliver and make the recording available to that client for its internal training for a limited period, after which the client must delete it. We will tell participants at the start of any session that is being recorded.
6. How we use your information
6.1 We may use your Personal Data in the following ways and for the following reasons.
(a) Preventing and detecting fraud or other unlawful financial activity against you or us.
Why: To minimise fraud or other unlawful financial activity that could damage you or us (legitimate interests; legal obligations).
(b) Identifying and verifying clients, screening for financial and other sanctions or embargoes, and other activities needed to meet our professional, legal and regulatory obligations.
Why: To comply with our legal and regulatory obligations.
(c) Gathering and providing information required by, or relating to, audits, enquiries or investigations by regulatory bodies.
Why: To comply with our legal and regulatory obligations.
(d) Operating IT systems, software and business applications.
Why: To provide agreed services to you safely and efficiently (contract; legitimate interests).
(e) Ensuring security and internet use policies are followed.
Why: To make sure we follow our own internal procedures and deliver the best service to you (legitimate interests).
(f) Protecting the confidentiality of commercially sensitive information.
Why: To protect trade secrets and other commercially valuable information and to comply with our legal and regulatory obligations.
(g) Preventing unauthorised access to, and changes to, our systems.
Why: To prevent and detect criminal activity that could damage you or us, and to comply with our legal and regulatory obligations.
(h) Recording training sessions and webinars at a client's request and making the recording available to that client for a limited period.
Why: To deliver the service the client has asked for (performance of our contract with the client, and our legitimate interests in relation to participants). The client receives a copy of the recording for the Access Period.
(i) Communicating with clients and customers.
Why: To perform our contract with you or take steps at your request before entering into one, to comply with our legal and regulatory obligations, to keep in touch with you about existing services and new services, and to keep our records up to date.
(j) Ensuring safe working practices, staff administration and assessments.
Why: To comply with our legal and regulatory obligations and to work efficiently in line with our internal procedures (legitimate interests).
(k) Marketing our services, and those of selected third parties, to existing and former clients, to people who have expressed an interest in our services, and to people we have not dealt with before.
Why: To promote our business to existing and future clients (legitimate interests or consent, see clause 12).
(l) Enforcing or defending our rights.
Why: To protect our rights and those of people we are responsible for, to liaise with regulatory authorities, and to meet our reporting obligations to government agencies with jurisdiction.
7. Events
7.1 We run events, including the Comply Offsite. This clause explains how we use Personal Data relating to attendees, speakers, sponsors and exhibitors.
7.2 When you register for or attend an event, we use your name, job title, employer and contact details to manage your booking, communicate with you about the event, take payment and run the event. We do this to perform our contract with you.
7.3 If you tell us about dietary or accessibility requirements, we use this only to make appropriate arrangements for you and share it only with the venue or caterers who need it. Because this may reveal information about your health, we will ask for your explicit consent, and we delete it within 30 days after the event.
7.4 We take photographs, video and audio recordings throughout our events and may use them on our website, on social media (including LinkedIn), in printed and digital marketing, in press and media communications and to promote future events. We do this for our legitimate interests in promoting our events and business. Attendees may be identifiable, and we will not show your name alongside any question you submit during the event. Because our events are live, we cannot guarantee that you will not appear in any photographs or recordings. If you would prefer not to be featured, please tell us at registration or on the day and we will make reasonable efforts to avoid featuring you and to remove identifiable images of you on request where practicable.
7.5 If we ask you to take part in an interview, testimonial or other individual promotional content, we will ask for your permission separately.
7.6 Registering for an event does not mean you will automatically receive unrelated marketing from us. Where required, we will ask you separately whether you would like to hear about future events and services, as described in clause 12. You can change your preferences or unsubscribe at any time.
7.7 We will only share your contact details with event sponsors, exhibitors or partners for their own marketing where you have agreed to this, for example by opting in at registration. If you give your details to a sponsor, speaker or another attendee directly, their own privacy terms will apply. We may include your name, job title and organisation in an attendee list or other event materials where we have told you this at registration.
7.8 After the event, we use your email address to send your CPD certificate and may invite you to give feedback. Giving feedback is voluntary.
7.9 For speakers, we use your name, biography, photograph and presentation materials to promote and deliver the event, and may share them with attendees and sponsors.
7.10 The terms and conditions for each event, including the Comply Offsite, set out the booking terms that apply to that event.
8. Special Category Data
8.1 Where we process Special Category Data, we will also make sure we are permitted to do so under the Data Protection Laws, for the following reasons:
(a) to protect your (or someone else's) vital interests where you are physically or legally incapable of giving consent;
(b) to comply with another law;
(c) to prevent unlawful acts, including money laundering, other financial misconduct and the financing of terrorism;
(d) to establish, exercise or defend legal claims; or
(e) where we have your explicit consent, for example for dietary or accessibility requirements you give us for an event (see clause 7).
9. Sharing your information
9.1 Where necessary, we may share your Personal Data with:
(a) third parties who help us run our business, for example administrative and marketing agencies or website hosts;
(b) organisations with whom we co-host events, and event venues, caterers and other suppliers, to the extent they need it to run the event;
(c) event sponsors, exhibitors and partners, but only with your consent (see clause 7);
(d) professional advisers, including lawyers, regulatory specialists and tax advisers;
(e) IT service providers;
(f) our insurers and banks;
(g) intermediaries;
(h) third parties you approve, for example social media sites you choose to link to or third-party payment providers;
(i) government agencies to whom we have a disclosure obligation; and
(j) courts and tribunals which issue an order we are obliged to comply with.
9.2 We only allow our service providers to handle your Personal Data if we are satisfied they take appropriate measures to protect it. We also require them by contract to use your Personal Data only to provide services to us and to you.
9.3 We may also need to:
(a) share Personal Data with external auditors;
(b) disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations; and
(c) share Personal Data with other parties, such as potential buyers of some or all of our business or in a restructuring. We will anonymise the information where possible, and the recipient will be bound by confidentiality obligations.
10. International transfers
10.1 Some of our service providers, such as our email and cloud storage providers, may process Personal Data outside Jersey.
10.2 Where Personal Data is transferred outside Jersey, we will only do so to a jurisdiction recognised as providing an adequate level of protection, such as the UK or a member of the European Economic Area, or where appropriate safeguards are in place as required by the Data Protection Laws, such as standard contractual clauses.
11. How long we keep your information
11.1 We keep your Personal Data while you have a relationship with us or we provide services to you. After that, we keep it for as long as necessary:
(a) to respond to any questions, complaints or claims made by you or on your behalf;
(b) to show that we treated you fairly; and
(c) to keep records required by law.
11.2 Different retention periods may apply to different types of Personal Data. To manage your data efficiently, we may keep all of your Personal Data for the longest period that applies to any item of it. At the end of the relevant period, we will delete or anonymise it.
12. Marketing
12.1 We may use your Personal Data to send you updates about our services, such as offers, events or new services, by email, text message, telephone or post.
12.2 Where we have a legitimate interest in using your Personal Data for marketing, we do not usually need your consent. Where consent is needed, we will ask for it clearly and separately.
12.3 You can opt out of marketing at any time by contacting us at ches@comply.je or by using the unsubscribe link in any marketing email.
12.4 If you ask for more services in future, or if there are changes in the law, regulation or our business structure, we may ask you to confirm or update your marketing preferences.
13. Your rights
13.1 You may have the following rights in relation to your Personal Data, which you can usually exercise free of charge:
(a) access: to be given a copy of your Personal Data;
(b) rectification: to require us to correct any mistakes in your Personal Data;
(c) erasure (also known as the right to be forgotten): to require us to delete your Personal Data in certain situations;
(d) restriction of processing: to require us to restrict the Processing of your Personal Data in certain circumstances;
(e) data portability: to receive Personal Data you have provided to us in a structured, commonly used, machine-readable format, and to have it transferred to another controller, in certain circumstances;
(f) objection:
(i) at any time to your Personal Data being processed for direct marketing (including profiling); and
(ii) in certain other situations, to our continued Processing of your Personal Data, for example Processing carried out for our legitimate interests;
(g) automated decision-making: not to be subject to a decision based solely on automated Processing (including profiling) that produces legal effects concerning you or similarly significantly affects you; and
(h) withdrawal of consent: where we rely on your consent, to withdraw it at any time.
13.2 We will usually respond to your request within four weeks. In some cases, this may be extended by up to a further eight weeks, and we will tell you if so. The clearer and more specific your request, the more quickly we can help.
14. Keeping your information secure
14.1 We use appropriate technical and organisational measures to protect your Personal Data against unauthorised access, loss, misuse or alteration.
14.2 If there is a Personal Data breach, we will notify you and the JOIC promptly where the law requires us to do so.