Privacy Policy
This Policy explains how we Process Personal Data. This Policy may be amended or updated from time to time, so please check it regularly for updates.
This Policy is issued by each of the Controller entities listed in Section (Q) below (together, “GLG”, “we”, “us” and “our”) and is addressed to individuals outside our organisation with whom we interact, including our Network Members, customers, visitors to our Sites, users of our Apps, other users of our services (including artificial intelligence (“AI”) services), personnel of corporate customers and vendors, applicants for employment, and visitors to our premises (together, “you”). Defined terms used in this Policy are explained in Section (S) below.
This Policy may be amended or updated from time to time to reflect changes in our practices with respect to the Processing of Personal Data, or changes in applicable law. We encourage you to read this Policy carefully, and to regularly check this page to review any changes we might make in accordance with the terms of this Policy.
This Policy was last updated on 4 August, 2026.
We collect or obtain Personal Data: when those data are provided to us (e.g., where you contact us); in the course of our relationship with you (e.g., if you’re a client, a candidate, or apply to be a Network Member); when you make Personal Data (e.g., via social or business networking sites); when you download, install, or use any of our Apps; when you visit our Sites; when you register to use any of our Sites, Apps, or services; or when you interact with any third party content or advertising on a Site or in an App. We may also receive Personal Data about you from third parties (e.g., law enforcement authorities).
We Process the following categories of Personal Data about you:
- Data provided to us: We obtain Personal Data when those data are provided to us (e.g., where you contact us via email or telephone, or by any other means; when you interact with any of our AI tools; when you provide us with your business card; or when you submit a job application).
- Relationship data: We may collect or obtain your Personal Data in the ordinary course of our relationshipwith you (e.g., we provide a service to you or to your employer, or you visitour offices).
- Network Member data: We may collect or obtain your Personal Data if you apply to become a Network Member.
- Collaborations: We obtain Personal Data when you collaborate with us in research or in an advisory/consultancy capacity.
- AI-generated data: Personal Data created by artificial intelligence and similar technologies (including large language models and machine learning) used by usor our Processors.
- Data you make public: We collect or obtain Personal Data that you manifestly choose to make public, including via social media (e.g., we may collect information from your social media or business networking profile(s), if you make a public post about us).
- App data: We collect or obtain Personal Data when you download or use any of our Apps.
- Site data: We collect or obtain Personal Data when you visit any of our Sites or use any features or resources available on or through a Site.
- Registration: We collect or obtain Personal Data when you use, or register to use, any of our Sites, Apps, or services
- Third party information: We may collect or obtain your Personal Data from third parties who provide it to us (e.g., credit reference agencies; law enforcement authorities; etc.). A Network Member’s current employer or another third party may notify GLG that restrictions should be placed on that Network Member’s participation in the GLG Network, where the Network Member owes confidentiality, non-compete, restricted-list or other professional duties to that party. GLG will comply with restrictions notified by an authorised representative of the relevant employer or third party to the extent required by applicable law or best practice, and reserves the right to apply such restrictions on a case-by-case basis. GLG may also contact employers or third parties to verify factual information provided by a Network Member or to confirm consents or approvals required for participation in specific Engagements.
- Background screening and compliance checks: Where you are a Network Member orprospective Network Member, we may conduct or commission background screening to verify your identity, check sanctions and regulatory watchlists, screen for adverse media and, where required by applicable law or our compliance policies, perform criminal record checks.
- AI-assisted Expert matching and profile summarisation: We may use artificial intelligence tools to analyse and summarise your biographical information and professional background for the purpose ofidentifying Engagements within your field of expertise and presenting suitable matches to Clients
- GLG Library and content publication: Where you participate in an interview, panel discussion or consultation to be recorded or transcribed for publication on the GLG Library, we will seek your separate, express written consent before publishing your name, biographical information, or any recording or transcript of your contributions.
- Background check data: Where you are a Network Member or prospective Network Member, we may receive Personal Data about you from third-partybackground screening providers, including identity verification results, sanctions and watchlist screening outcomes, adverse media reports and, where required by applicable law or our compliance policies, criminal record checkinformation.
We may create Personal Data about you (e.g., records of your interactions with us).
We also create Personal Data about you in certain circumstances, such as records of your interactions with us, our clients, or our Network Members. We may also combine Personal Data from any of our Sites, Apps, or services, including where those data are collected from different devices or sources.
We Process: your personal details (e.g., your name, biographical information; and demographic data); your contact details (e.g., your address); your professional details (e.g., your CV); records of surveys or testing in which you have participated; demographic data (e.g., your age); visitor logs for our premises; records of your consents; payment details (e.g., your billing address); information about our Sites and Apps (e.g., the type of device you are using); details of your employer (where relevant); information about your interactions with our content or advertising; cookie data; security information; and any views or opinions you provide to us.
We Process the following categories of Personal Data about you:
- Personal details: given name(s); preferred name; photograph; and biographical information.
- Demographic information: gender; date of birth / age; nationality; salutation; title; and language preferences.
- Network Member data: With respect to Network Members (in addition to any other applicable category set out in this Notice), we also collect wireless device addresses (including text message addresses), payment information, professional biography, and other profiling information pertaining to your experience and expertise.
- Contact details: correspondence address; telephone number; email address; details of Personal Assistants, where applicable; messenger app details; online messaging details; social media details; and details of your public business networking profile(s) or online biographies.
- Correspondence: records and copies of your correspondence if you contact us.
- Professional details: your CV; records of your expertise; professional history; practising details and qualification details; information about your experience; participation in meetings, seminars, advisory boards and conferences; information about your professional relationship with other individuals or institutions; language abilities; and other professional skills.
- Visitor logs: records of visits to our premises.
- Consent records: records of any consents you have given, together with the date and time, means of consent, and any related information (e.g., the subject matter of the consent).
- Purchase details: records of purchases and prices.
- Payment details: invoice records; payment records; billing address; payment method; bank account number or credit card number; cardholder or accountholder name; card or account security details; card ‘valid from’ date; card expiry date; BACS details; SWIFT details; IBAN details; payment amount; payment date; and records of cheques.
- Data relating to our Sites and Apps: device type; operating system; browser type; browser settings; IP address; language settings; dates and times of connecting to a Site; App usage statistics; App settings; dates and times of connecting to an App; location data; and other technical communications information (some of which may constitute Personal Data); registration details; username; password; security login details; usage data; aggregate statistical information; internet service provider (ISP) details; referring and exit pages; and clickstream data.
- Employer details: where you interact with us in your capacity as an employee of a third party; and the name, address, telephone number and email address of your employer, to the extent relevant.
- Content and advertising data: records of your interactions with our online advertising and content, records of advertising and content displayed on pages or App screens displayed to you, and any interaction you may have had with such content or advertising (e.g., mouse hover, mouse clicks, any forms you complete in whole or in part) and any touchscreen interactions.
- Cookie data: we collect information via cookies and similar technologies. Please see our Cookie Policy for more details.
- Security information: your password(s); login attempt details; security settings; and other security-related information.
- Views and opinions: responses to surveys, responses to testing, any views and opinions that you choose to send to us or publicly post about us on social media platforms.
- MCP Connector technical data: API authentication tokens or client credentials; query payloads and response metadata; session identifiers; request timestamps and IP addresses; error logs generated through the Connector interface. This data is generated when a Client organisation integrates with GLG’s services via the MCP Connector.
- Background screening data: identity verification results; sanctions and watchlist screening outcomes; adverse media reports; and, where required by applicable law or our compliance policies, criminal record information obtained from third-party background check providers.
- Engagement content: recordings and transcripts of interviews, panel discussions or consultations in which you participate, where you have provided separate express consent to recording and to publication on the GLG Library.
We do not seek to collect or otherwise Process Sensitive Personal Data. Where we need to Process Sensitive Personal Data for a legitimate purpose, we do so in accordance with applicable law.
We do not seek to collect or otherwise Process Sensitive Personal Data in the ordinary course of our business. Where it becomes necessary to Process your Sensitive Personal Data for any reason, we rely on one of the following legal bases:
- Compliance with applicable law: We may Process your Sensitive Personal Data where the Processing is required or permitted by applicable law (e.g., to comply with our diversity reporting obligations);
- Detection and prevention of crime: We may Process your Sensitive Personal Data where the Processing is necessary for the detection or prevention of crime (e.g., the prevention of fraud);
- Establishment, exercise or defence of legal claims: We may Process your Sensitive Personal Data where the Processing is necessary for the establishment, exercise or defence of legal claims; or
- Consent: We may Process your Sensitive Personal Data where we have, in accordance with applicable law, obtained your express consent prior to Processing your Sensitive Personal Data (this legal basis is only used in relation to Processing that is entirely voluntary – it is not used for Processing that is necessary or obligatory in any way).
If you provide Sensitive Personal Data to us, you must ensure that it is lawful for you to disclose such data to us, and you must ensure a valid legal basis applies to the Processing of those Sensitive Personal Data.
We Process Personal Data for the following purposes: providing our Sites, Apps, and services to you; compliance checks; operating our business; operating our AI tools and AI services; communicating with you; managing our IT systems; health and safety; financial management; conducting surveys; ensuring the security of our premises and systems; conducting investigations where necessary; compliance with applicable law; improving our Sites, Apps, and services; fraud prevention; establishment, exercise and defence of legal claims; and recruitment and job applications.
The purposes for which we Process the categories of Personal Data identified in Section (D) above, subject to applicable law, and the legal bases on which we perform such Processing, are as follows:
| Purpose of Processing | Categories of Personal Data | Legal basis for Processing |
|---|---|---|
| Provision of Sites, Apps, and services: providing our Sites, Apps, or services; providing promotional items upon request; and communicating with you in relation to those Sites, Apps, or services. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Purchase details; Payment details; Data relating to our Sites and Apps; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract that you have entered into with us, or to take steps prior to entering into a contract with us; or We have a legitimate interest in carrying out the Processing for the purpose of providing our Sites, Apps, or services; or We have obtained your prior consent to the Processing. |
| Compliance checks: fulfilling our regulatory compliance obligations; ‘Know Your Client’ checks; confirming and verifying your identity; use of credit reference agencies; and screening against sanctions lists and other legal restrictions. | Personal details; Contact details; Network Member data; Correspondence; Professional details; Consent records; Payment details; Employer details; Security information | The Processing is necessary for compliance with a legal obligation; or The Processing is necessary in connection with any contract that you have entered into with us; or We have a legitimate interest in carrying out the Processing; or We have obtained your prior consent to the Processing. |
| Operating our business: operating and managing our Sites, our Apps, and our services; providing content to you; displaying advertising and other information to you; communicating and interacting with you; and notifying you of changes to any of our Sites, our Apps, or our services. | Personal details; Contact details; Network Member data; Correspondence; Consent records; Payment details; Data relating to our Sites and Apps; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract that you have entered into with us; or We have a legitimate interest in carrying out the Processing; or We have obtained your prior consent to the Processing. |
| GLG MCP Connector Services: Providing the GLG MCP Connector service; authenticating Client organisations and their authorised end-users; routing queries; logging API requests for security monitoring, misuse detection, and billing reconciliation; generating and delivering expert network data in response to Connector queries; monitoring Connector performance; and enforcing applicable terms of service. | Personal details; Contact details; Network Member data; Correspondence; Consent records; Payment details; Data relating to our Sites and Apps; Content and advertising data; Cookie data; Security information; Views and opinions; MCP Connector technical data; Background screening data; Engagement content | The Processing is necessary in connection with any contract that you have entered into with us; or We have a legitimate interest in carrying out the Processing for the purpose of providing the GLG MCP Connector service; or We have obtained your prior consent to the Processing. |
| Operating our AI tools and AI services: using AI tools and services to manage workforce monitoring, interviews and evaluations, exams, and assessments, subject to human review where appropriate. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Purchase details; Payment details; Data relating to our Sites and Apps; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract that you have entered into with us; or We have a legitimate interest in carrying out the Processing for the purpose of operating our AI tools and AI services; or We have obtained your prior consent to the Processing. |
| Planning: organisational planning; succession planning; making changes to the nature and scope of our operations; mergers, acquisitions, dissolutions, demergers, liquidations, asset sales, divestitures, reorganisations and similar corporate structuring arrangements. | Personal details; Contact details; Network Member data; Professional details; Demographic information; Data relating to our Sites and Apps; Employer details; Content and advertising data; Views and opinions | We have a legitimate interest in carrying out the Processing for the purpose of planning the future operation of our business. |
| Communications and marketing: communicating with you via any means to provide news items and other information in which you may be interested; personalising our Sites, products and services for you; maintaining and updating your contact information; and obtaining your prior, opt-in consent where required. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Data relating to our Sites and Apps; Content and advertising data; Cookie data; Views and opinions | The Processing is necessary in connection with any contract that you have entered into with us; or We have a legitimate interest in carrying out the Processing for the purpose of contacting you; or We have obtained your prior consent to the Processing. |
| Management of IT systems: management and operation of our communications, IT and security systems; and audits (including security audits) and monitoring of such systems. | Personal details; Contact details; Network Member data; Professional details; Demographic information; Consent records; Payment details; Data relating to our Sites and Apps; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in carrying out the Processing for the purpose of managing and maintaining our communications and IT systems. |
| Health and safety: health and safety assessments and record keeping; providing a safe and secure environment at our premises; and compliance with related legal obligations. | Personal details; Contact details; Correspondence; Visitor logs | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in carrying out the Processing for the purpose of ensuring a safe environment at our premises; or The Processing is necessary to protect the vital interests of any individual. |
| Financial management: sales; finance; corporate audit; and vendor management. | Personal details; Contact details; Network Member data; Payment details | We have a legitimate interest in carrying out the Processing for the purpose of managing and operating the financial affairs of our business; or We have obtained your prior consent to the Processing. |
| Surveys: engaging with you for the purposes of obtaining your views on our Sites, our Apps, or our services. | Personal details; Contact details; Network Member data; Correspondence; Consent records; Views and opinions | We have a legitimate interest in carrying out the Processing for the purpose of conducting surveys, satisfaction reports and market research; or We have obtained your prior consent to the Processing. |
| Security: physical security of our premises (including records of visits to our premises); CCTV recordings; and electronic security (including login records and access details). | Personal details; Contact details; Network Member data; Visitor logs | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in carrying out the Processing for the purpose of ensuring the physical and electronic security of our business and our premises. |
| Investigations: detecting, investigating and preventing breaches of policy, and criminal offences, in accordance with applicable law. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in carrying out the Processing for the purpose of detecting, and protecting against, breaches of our policies and applicable laws. |
| Legal compliance: compliance with our legal and regulatory obligations under applicable law. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in carrying out the Processing for the purpose of compliance with regulatory requirements or guidance. |
| Improving our Sites, Apps, and services: identifying issues with our Sites, our Apps, or our services; planning improvements; and creating new Sites, Apps, or services. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Data relating to our Sites and Apps; Content and advertising data; Views and opinions | We have a legitimate interest in carrying out the Processing for the purpose of improving our Sites, our Apps, or our services; or We have obtained your prior consent to the Processing. |
| Fraud prevention: Detecting, preventing and investigating fraud. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in carrying out the Processing for the purpose of detecting, and protecting against, fraud. |
| Training of artificial intelligence: Training and developing artificial intelligence and similar technologies (including large language models and machine learning). | Personal details; Contact details; Network Member data; Professional details; Identification documents; Demographic information; Consent records; Bank details; Financial information; Data relating to our Sites; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract that you have entered into with us; or We have a legitimate interest in carrying out the Processing for the purpose of training and developing artificial intelligence; or We have obtained your prior consent to the Processing. |
| Establishment, exercise and defence of legal claims: management of legal claims; establishment of facts and claims; exercise and defence of legal rights and claims, including formal legal proceedings. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest; or The Processing is necessary for the establishment, exercise or defence of legal claims. |
| Recruitment and job applications: recruitment activities; advertising of positions; interview activities; analysis of suitability for the relevant position; records of hiring decisions; offer details; and acceptance details. | Personal details; Contact details; Correspondence; Professional details; Demographic information; Visitor logs; Consent records; Data relating to our Sites and Apps; Employer details; Content and advertising data; Views and opinions | The Processing is necessary for compliance with a legal obligation (especially in respect of applicable employment law); or We have a legitimate interest in carrying out the Processing for the purpose of recruitment activities; or We have obtained your prior consent to the Processing (e.g., where this is necessary for the purposes of criminal records checks). |
The purposes for which we Process the categories of Personal Data identified in Section (D) above, subject to applicable law, and the legal bases on which we perform such Processing, are as follows:
| Purpose of Processing | Categories of Personal Data | Legal basis for Processing |
|---|---|---|
| Provision of Sites, Apps, and services: providing our Sites, Apps, or services; providing promotional items upon request; and communicating with you in relation to those Sites, Apps, or services. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Purchase details; Payment details; Data relating to our Sites and Apps; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract that you have entered into with us, or to take steps prior to entering into a contract with us; or We have a legitimate interest in carrying out the Processing; or We have obtained your prior consent to the Processing. |
| Compliance checks: fulfilling our regulatory compliance obligations; ‘Know Your Client’ checks; confirming and verifying your identity; and screening against sanctions lists. | Personal details; Contact details; Network Member data; Correspondence; Professional details; Consent records; Payment details; Employer details; Security information | The Processing is necessary for compliance with a legal obligation; or The Processing is necessary in connection with any contract; or We have a legitimate interest; or We have obtained your prior consent. |
| Operating our business: operating and managing our Sites, our Apps, and our services; providing content to you; and notifying you of changes. | Personal details; Contact details; Network Member data; Correspondence; Consent records; Payment details; Data relating to our Sites and Apps; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract; or We have a legitimate interest; or We have obtained your prior consent. |
| GLG MCP Connector Services: Providing the GLG MCP Connector service; authenticating Client organisations; routing queries; logging API requests; generating and delivering expert network data; and monitoring Connector performance. | Personal details; Contact details; Network Member data; Correspondence; Consent records; Payment details; Data relating to our Sites and Apps; Content and advertising data; Cookie data; Security information; Views and opinions; MCP Connector technical data; Background screening data; Engagement content | The Processing is necessary in connection with any contract; or We have a legitimate interest in providing the GLG MCP Connector service; or We have obtained your prior consent. |
| Operating our AI tools and AI services: using AI tools and services to manage workforce monitoring, interviews and evaluations, exams, and assessments, subject to human review where appropriate. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Purchase details; Payment details; Data relating to our Sites and Apps; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract; or We have a legitimate interest in operating our AI tools; or We have obtained your prior consent. |
| Planning: organisational planning; succession planning; mergers, acquisitions, dissolutions, demergers, liquidations, asset sales, divestitures, reorganisations and similar corporate structuring arrangements. | Personal details; Contact details; Network Member data; Professional details; Demographic information; Data relating to our Sites and Apps; Employer details; Content and advertising data; Views and opinions | We have a legitimate interest in carrying out the Processing for the purpose of planning the future operation of our business. |
| Communications and marketing: communicating with you via any means to provide news items and other information in which you may be interested; personalising our Sites, products and services; maintaining and updating your contact information. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Data relating to our Sites and Apps; Content and advertising data; Cookie data; Views and opinions | The Processing is necessary in connection with any contract; or We have a legitimate interest in contacting you; or We have obtained your prior consent. |
| Management of IT systems: management and operation of our communications, IT and security systems; and audits and monitoring of such systems. | Personal details; Contact details; Network Member data; Professional details; Demographic information; Consent records; Payment details; Data relating to our Sites and Apps; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in managing and maintaining our IT systems. |
| Health and safety: health and safety assessments and record keeping; providing a safe and secure environment at our premises; and compliance with related legal obligations. | Personal details; Contact details; Correspondence; Visitor logs | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in ensuring a safe environment; or The Processing is necessary to protect the vital interests of any individual. |
| Financial management: sales; finance; corporate audit; and vendor management. | Personal details; Contact details; Network Member data; Payment details | We have a legitimate interest in managing and operating the financial affairs of our business; or We have obtained your prior consent. |
| Surveys: engaging with you for the purposes of obtaining your views on our Sites, our Apps, or our services. | Personal details; Contact details; Network Member data; Correspondence; Consent records; Views and opinions | We have a legitimate interest in conducting surveys, satisfaction reports and market research; or We have obtained your prior consent. |
| Security: physical security of our premises (including records of visits to our premises); CCTV recordings; and electronic security (including login records and access details). | Personal details; Contact details; Network Member data; Visitor logs | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in ensuring the physical and electronic security of our business and our premises. |
| Investigations: detecting, investigating and preventing breaches of policy, and criminal offences, in accordance with applicable law. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in detecting, and protecting against, breaches of our policies and applicable laws. |
| Legal compliance: compliance with our legal and regulatory obligations under applicable law. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in compliance with regulatory requirements or guidance. |
| Improving our Sites, Apps, and services: identifying issues with our Sites, our Apps, or our services; planning improvements; and creating new Sites, Apps, or services. | Personal details; Contact details; Network Member data; Correspondence; Demographic information; Consent records; Data relating to our Sites and Apps; Content and advertising data; Views and opinions | We have a legitimate interest in improving our Sites, our Apps, or our services; or We have obtained your prior consent. |
| Fraud prevention: Detecting, preventing and investigating fraud. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest in detecting, and protecting against, fraud. |
| Training of artificial intelligence: Training and developing artificial intelligence and similar technologies (including large language models and machine learning). | Personal details; Contact details; Network Member data; Professional details; Identification documents; Demographic information; Consent records; Bank details; Financial information; Data relating to our Sites; Employer details; Content and advertising data; Cookie data; Security information; Views and opinions | The Processing is necessary in connection with any contract; or We have a legitimate interest in training and developing artificial intelligence; or We have obtained your prior consent. |
| Establishment, exercise and defence of legal claims: management of legal claims; establishment of facts and claims; exercise and defence of legal rights and claims, including formal legal proceedings. | Each category of Personal Data identified in Section (D) above, to the extent necessary. | The Processing is necessary for compliance with a legal obligation; or We have a legitimate interest; or The Processing is necessary for the establishment, exercise or defence of legal claims. |
| Recruitment and job applications: recruitment activities; advertising of positions; interview activities; analysis of suitability for the relevant position; records of hiring decisions; offer details; and acceptance details. | Personal details; Contact details; Correspondence; Professional details; Demographic information; Visitor logs; Consent records; Data relating to our Sites and Apps; Employer details; Content and advertising data; Views and opinions | The Processing is necessary for compliance with a legal obligation (especially in respect of applicable employment law); or We have a legitimate interest in carrying out the Processing for the purpose of recruitment activities; or We have obtained your prior consent (e.g., where this is necessary for the purposes of criminal records checks). |
We disclose Personal Data to: legal and regulatory authorities; our external advisors; our Processors; any party as necessary in connection with legal proceedings; any party as necessary for investigating, detecting or preventing criminal offences; any purchaser of our business; and any third party providers of advertising, plugins or content used on our Sites or our Apps.
We disclose Personal Data to other entities within the GLG group, for legitimate business purposes and the operation of our Sites, Apps, or services to you, in accordance with applicable law. In addition, we disclose Personal Data to:
- you and, where appropriate, your appointed representatives;
- accountants, auditors, consultants, lawyers and other outside professional advisors to GLG, subject to binding contractual obligations of confidentiality;
- third party Processors (such as payment services providers; survey partners, marketing outreach providers, cloud service providers, etc.), located anywhere in the world, subject to the requirements noted below in this Section (G);
- any relevant party, regulatory body, governmental authority, law enforcement agency or court, to the extent necessary for the establishment, exercise or defence of legal claims or compliance with applicable law;
- any relevant party, regulatory body, governmental authority, law enforcement agency or court, for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties;
- any relevant party if we believe disclosure is necessary and appropriate to prevent physical, financial, or other harm, injury, or loss;
- any relevant third party acquirer(s) or successor(s) in title, in the event that we sell or transfer all or any relevant portion of our business or assets (including in the event of a reorganization, dissolution or liquidation); and
- any relevant third party provider, where our Sites or our Apps use third party advertising, plugins or content. If you choose to interact with any such advertising, plugins or content, your Personal Data may be shared with the relevant third party provider. We recommend that you review that third party’s privacy policy before interacting with its advertising, plugins or content.
Where a Client accesses GLG services via the GLG MCP Connector, relevant technical log data (including API request metadata, session identifiers and error logs) may be disclosed to: (i) the Client organisation that operates the Connector integration, to enable billing reconciliation and usage reporting; (ii) GLG’s hosting and infrastructure sub-processors, solely to operate and maintain the Connector; and (iii) security and monitoring service providers engaged by GLG to detect and prevent misuse of the Connector. GLG will not disclose query content or expert data retrieved through the Connector to parties other than the requesting Client, except as required by law.
If we engage a third-party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to: (i) only Process the Personal Data in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of the Personal Data; together with any additional requirements under applicable law.
Additionally, if you are a Network Member:
- We may disclose your information to Clients, to whom we have certain confidentiality obligations which may prevent us from disclosing their identity;
- We may disclose your information to third parties, such as current and former employers and companies that you have provided services to or contracted with, for the purpose of confirming any consents or approvals that you may need to participate in the GLG Network or in specific project(s);
- To providers with whom we have partnered to facilitate surveys, compliance checks, and screenings;
- Our Clients (to the extent required by law, or by the relevant Client’s compliance policies) may disclose information about projects in which you were involved, for example your name and the amount you were paid on the project.
Personal Data are subject to automated decision-making and Profiling.
We Process Personal Data for the purposes of automated decision-making and Profiling, which is carried out for the following purposes:
| Profiling activity | Logic of the Profiling activity | Consequences for you |
|---|---|---|
| We may use AI tools for the purpose of identifying Engagements within your field of expertise and presenting suitable matches to Clients. | This Profiling activity is based on an AI analysis of your biographical information and professional background, matched to relevant information regarding our Clients. | This Profiling activity may affect which Engagements are presented to you, and whether you are selected for a particular Engagement. |
We transfer Personal Data to recipients in other countries. Where we transfer Personal Data from the UK or the EEA to a recipient outside the UK or the EEA (as applicable) that is not in an Adequate Jurisdiction, we do so on the basis of Standard Contractual Clauses or the UK equivalent (i.e., the UK addendum to the Standard Contractual Clauses).
Because of the international nature of our business, we transfer Personal Data within the GLG group, and to third parties as noted in Section (G) above, in connection with the purposes set out in this Policy. For this reason, we transfer Personal Data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located.
If an exemption or derogation applies (e.g., where a transfer is necessary to establish, exercise or defend a legal claim) we may rely on that exemption or derogation, as appropriate. Where no exemption or derogation applies, and we transfer your Personal Data from the UK or the EEA to recipients located outside the UK or the EEA (as applicable) who are not in Adequate Jurisdictions, we do so on the basis of Standard Contractual Clauses or the UK equivalent (i.e., the UK addendum to the Standard Contractual Clauses). You are entitled to request a copy of our Standard Contractual Clauses or the UK equivalent (i.e., the UK addendum to the Standard Contractual Clauses) using the contact details provided in Section (P) below.
If you are located outside of the United States, you should be aware that the Personal Data you provide to us is being transmitted to us and Processed in the United States, and will be protected subject to this privacy policy and United States laws, which may not be as protective as the laws in your country. Please note that when you transfer any Personal Data directly to any GLG entity established outside the UK or the EEA (as applicable), we are not responsible for that transfer of your Personal Data. We will nevertheless Process your Personal Data, from the point at which we receive those data, in accordance with the provisions of this Policy.
We take every reasonable step to ensure that your Personal Data are kept accurate and up-to-date and are erased or rectified if we become aware of inaccuracies.
We take every reasonable step to ensure that:
- your Personal Data that we Process are accurate and, where necessary, kept up-to-date; and
- any of your Personal Data that we Process that are inaccurate (having regard to the purposes for which they are Processed) are erased or rectified without delay.
From time to time we may ask you to confirm the accuracy of your Personal Data.
We take every reasonable step to limit the volume of your Personal Data that we Process to what is necessary.
We take every reasonable step to ensure that your Personal Data that we Process are limited to the Personal Data reasonably necessary in connection with the purposes set out in this Policy.
We take every reasonable step to ensure that your Personal Data are only retained for as long as they are needed in connection with a lawful purpose.
We take every reasonable step to ensure that your Personal Data are only Processed for the minimum period necessary for the purposes set out in this Notice. The criteria for determining the duration for which we will retain your Personal Data are as follows:
we will retain copies of your Personal Data in a form that permits identification only for as long as:
- we maintain an ongoing relationship with you (e.g., where you are a user of our services, are a Network Member (or have applied to become one), or you are lawfully included in our mailing list and have not unsubscribed);
- should you cease being a Network Member, six (6) years from your most recent interaction with any GLG client; or
- your Personal Data are necessary in connection with the lawful purposes set out in this Notice, for which we have a valid legal basis (e.g., where we have a legitimate interest in processing your data for the purposes of operating our business and fulfilling our obligations under a contract),
plus:
(2) the duration of:
(a) any applicable limitation period under applicable law (i.e., any period during which any person could bring a legal claim against us in connection with your Personal Data, or to which your Personal Data may be relevant); and
(b) an additional two (2) month period following the end of such applicable limitation period (so that, if a person bring a claim at the end of the limitation period, we are still afforded a reasonable amount of time in which to identify any Personal Data that are relevant to that claim),
and:
(3) in addition, if any relevant legal claims are brought, we may continue to Process your Personal Data for such additional periods as are necessary in connection with that claim.
During the periods noted in paragraphs (2)(a) and (2)(b) above, we will restrict our Processing of your Personal Data to storage of, and maintaining the security of, those data, except to the extent that those data need to be reviewed in connection with any legal claim, or any obligation under applicable law.
Once the periods in paragraphs (1), (2) and (3) above, each to the extent applicable, have concluded, we will either:
- permanently delete or destroy the relevant Personal Data; or
- anonymize the relevant Personal Data.
Subject to applicable law, you may have a number of rights, including: the right not to provide your Personal Data to us; the right of access to your Personal Data; the right to request rectification of inaccuracies; the right to request the erasure, or restriction of Processing, of your Personal Data; the right to object to the Processing of your Personal Data; the right to have your Personal Data transferred to another Controller; the right to withdraw consent; and the right to lodge complaints with Data Protection Authorities. In some cases it will be necessary to provide evidence of your identity before we can give effect to these rights.
Subject to applicable law, you may have the following rights regarding the Processing of your Relevant Personal Data:
- the right not to provide your Personal Data to us (however, please note that we will be unable to provide you with the full benefit of our Sites, Apps, or services, if you do not provide us with your Personal Data – e.g., we might not be able to process your requests without the necessary details);
- the right to request access to, or copies of, your Relevant Personal Data, together with information regarding the nature, Processing and disclosure of those Relevant Personal Data;
- the right to request rectification of any inaccuracies in your Relevant Personal Data;
- the right to object to the Processing of your Relevant Personal Data;
- the right to request, on legitimate grounds:
- erasure of your Relevant Personal Data; or
- restriction of Processing of your Relevant Personal Data;
- the right to have certain Relevant Personal Data transferred to another Controller, in a structured, commonly used and machine-readable format, to the extent applicable;
- where we Process your Relevant Personal Data on the basis of your consent, the right to withdraw that consent (noting that such withdrawal does not affect the lawfulness of any Processing performed prior to the date on which we receive notice of such withdrawal, and does not prevent the Processing of your Personal Data in reliance upon any other available legal bases); and
- the right to lodge complaints regarding the Processing of your Relevant Personal Data with a Data Protection Authority (i.e., in relation to the UK, the Information Commissioner’s Office (https://ico.org.uk/) or in relation to the EU, the Data Protection Authority for EU Member State in which you live, or in which you work, or in which the alleged infringement occurred (see the list here: https://edpb.europa.eu/about-edpb/about-edpb/members_en)).
Subject to applicable law, you may also have the following additional rights regarding the Processing of your Relevant Personal Data:
the right to object, on grounds relating to your particular situation, to the Processing of your Relevant Personal Data by us or on our behalf, where such processing is based on Articles 6(1)(e) (public interest) or 6(1)(f) (legitimate interests) of the GDPR / UK GDPR; and
the right to object to the Processing of your Relevant Personal Data by us or on our behalf for direct marketing purposes.
This does not affect your statutory rights.
To exercise one or more of these rights, or to ask a question about these rights or any other provision of this Policy, or about our Processing of your Personal Data, please use the contact details provided in Section (P) below. Please note that:
- in some cases it will be necessary to provide evidence of your identity before we can give effect to these rights; and
- where your request requires the establishment of additional facts (e.g., a determination of whether any Processing is non-compliant with applicable law) we will investigate your request reasonably promptly, before deciding what action to take.
Where the GDPR applies, we will respond within one calendar month of receipt of a verifiable request, extendable by a further two months for complex requests.
Our Terms of Use govern all use of our Sites.
All use of our Sites, or our services is subject to our Terms of Use. We recommend that you review our Terms of Use regularly, in order to review any changes we might make from time to time.
We Process Personal Data to contact you with information regarding Sites, Apps, or services that may be of interest to you. You may unsubscribe for free at any time.
When you visit a Site we may place Cookies onto your device, or read Cookies already on your device, subject always to obtaining your consent, where required, in accordance with applicable law. We use Cookies to record information about your device, your browser and, in some cases, your preferences and browsing habits. We may Process your Personal Data through Cookies and similar technologies, in accordance with our Cookie Policy. We Process Personal Data to contact you via email, telephone, direct mail or other communication formats to provide you with information regarding Sites, Apps, or services that may be of interest to you. We also Process Personal Data for the purposes of displaying content tailored to your use of our Sites, Apps, or services. If we provide Sites, Apps, or services to you, we may send or display information to you regarding our Sites, Apps, or services, upcoming promotions and other information that may be of interest to you, including by using the contact details that you have provided to us, or any other appropriate means, subject always to obtaining your prior opt-in consent to the extent required under applicable law.
You may unsubscribe from our promotional email list at any time by simply clicking on the unsubscribe link included in every promotional email we send. After you unsubscribe, we will not send you further promotional emails, but we may continue to contact you to the extent necessary for the purposes of any Sites, Apps, or services you have requested.
There are several GLG entities that act as Controllers for the purposes of this Policy.
For the purposes of this Policy, the relevant Controllers are:
| Controller entity | Contact details |
|---|---|
| Gerson Lehrman Group, Inc.® | See below. |
| Gerson Lehrman Group Limited | See below. |
| Gerson Lehrman Group (Ireland) Limited | See below. |
Each Controller established outside the EEA or UK has appointed a representative for the purposes of Article 27 of the GDPR / UK GDPR.
Each of the controllers established outside the EEA and listed in Section (P) above has appointed Laurence Herman, 60 East 42nd Street, 3rd Floor, New York, NY 10165 to be its representative for the purposes of Article 27 of the GDPR.
Each of the controllers established outside the UK and listed in Section (Q) above has appointed Siun McMahon, Gerson Lehrman Group (Ireland) Limited, Third Floor, Block C Bloodstone Building, Riverside IV, Sir John Rogerson’s Quay, Dublin 2, Ireland to be its representative for the purposes of Article 27 of the UK GDPR.
You may contact us via post, telephone, fax, email or via our online Contact Us form.
If you have any comments, questions or concerns about any of the information in this Notice, or any other issues relating to the Processing of Personal Data carried out by us, or on our behalf, please contact:
Legal Department
Gerson Lehrman Group, Inc.
60 East 42nd Street
3rd Floor
New York
NY 10165
Phone: (212) 984-8500
Fax: (212) 984-2485
Email: privacy@glg.it
Defined terms used in this Policy are explained in this Section.
- “App” means any application made available by us (including where we make such applications available via third party stores or marketplaces, or by any other means).
- “Adequate Jurisdiction” means a jurisdiction that has been formally designated by the European Commission as providing an adequate level of protection for Personal Data.
- “Cookie” means a small file that is placed on your device when you visit a website (including our Sites). In this Policy, a reference to a “Cookie” includes analogous technologies such as web beacons and clear GIFs.
- “Controller” means the entity that decides how and why Personal Data are Processed. In many jurisdictions, the Controller has primary responsibility for complying with applicable data protection laws.
- “Data Protection Authority” means an independent public authority that is legally tasked with overseeing compliance with applicable data protection laws.
- “EEA” means the European Economic Area.
- “GDPR” means the General Data Protection Regulation (EU) 2016/679.
- “GLG MCP Connector” means the application programming interface product offered by GLG that enables Client organisations and their authorised AI-assisted systems to query GLG’s expert network data, content and services programmatically in accordance with a separate Connector agreement.
- “Network Member” means any person who has executed a version of the GLG Terms & Conditions of Network Membership and not had their membership discontinued (either by GLG or at their request).
- “Personal Data” means information that is about any individual, or from which any individual is directly or indirectly identifiable, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.
- “Process”, “Processing” or “Processed” means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- “Processor” means any person or entity that Processes Personal Data on behalf of the Controller (other than employees of the Controller).
- “Profiling” means any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
- “Relevant Personal Data” means Personal Data in respect of which we are the Controller.
- “Sensitive Personal Data” means Personal Data about race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, biometric data, physical or mental health, sexual life, any actual or alleged criminal offences or penalties, national identification number, or any other information deemed to be sensitive under applicable law.
- “Standard Contractual Clauses” means template transfer clauses adopted by the European Commission or adopted by a Data Protection Authority and approved by the European Commission.
- “Site” means any website operated, or maintained, by us or on our behalf.
- “UK GDPR” has the meaning given in s.3(10) of the Data Protection Act 2018.
PRIVACY NOTICE FOR CALIFORNIA RESIDENTS
This Privacy Notice for California Residents (“CCPA Notice”) supplements, and should be read in conjunction with, the information contained in our Privacy Notice above and applies solely to all visitors, users, and others who reside in the State of California (”consumers” or “you”). GLG adopts this notice to comply with the California Consumer Privacy Act of 2018 (“CCPA”) and any terms defined in the CCPA have the same meaning when used in this CCPA Notice.
This CCPA Notice does not apply to employment-related personal information collected from California-based employees, job applicants, contractors, or similar individuals.
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“personal information”). Personal information does not include:
Publicly available information from government records.
Deidentified or aggregated consumer information.
Information excluded from the CCPA’s scope, like:
health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the California Confidentiality of Medical Information Act (“CMIA”) or clinical trial data; and
personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (“FCRA”), the Gramm-Leach-Bliley Act (“GLBA”) or California Financial Information Privacy Act (“FIPA”), and the Driver’s Privacy Protection Act of 1994.
In particular, we have collected the following categories of personal information from consumers within the last twelve (12) months:
Identifiers
A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
A name, signature, Social Security number, address, telephone number, passport number, driver’s license or state identification card number, employment, employment history, and bank account number. Some personal information included in this category may overlap with other categories.
Commercial Information
Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Internet or other similar network activity
Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.
Professional or employment-related information.
Current or past job history or performance evaluations.
In addition to all the stated uses of Personal Data set forth in Paragraph (G) of the Privacy Notice above, we may use or disclose your personal information for any purpose described to you when collecting your personal information or as otherwise set forth in the CCPA.
We may disclose your personal information to a third party for a business purpose. In the preceding twelve (12) months, we have disclosed the following categories of personal information for a business purpose:
- Identifiers.
- California Customer Records personal information categories.
- Commercial Information.
- Professional or employment-related information.
The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past twelve (12) months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
- If we sold or disclosed your personal information for a business purpose, two separate lists disclosing:
- sales, identifying the personal information categories that each category of recipient purchased; and
- disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.
We do not provide these access and data portability rights for B2B personal information.
Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request your personal information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us, such as future field campaigns or product safety issues.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
We do not provide these deletion rights for B2B personal information.
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described above, please submit a verifiable consumer request to us by either:
- Calling us at toll free at 866-230-4843
- Emailing us at privacy@glg.it
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative, which may include:
- Your name
- Email Address
- Additional information depending upon the type of request and the sensitivity of the information.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.
We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time, we will inform you of the reason and extension period in writing.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
- However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt in consent, which you may revoke at any time.
CHINA PRIVACY NOTICE
GLG also complies with specific requirements stipulated by the Personal Information Protection Law of the People’s Republic of China (“PIPL”), and other relevant Chinese rules and regulations.
Under PIPL, “personal data” is all kinds of information, whether recorded in electronic or another format, that relates to an identified or identifiable natural person, excluding anonymized information; “sensitive personal data” refers to personal data that, if leaked or if used illegally, is likely to cause harm to a natural person’s personal dignity or endanger their personal safety or the safety of their property, as well as the personal data of minors under the age of 14.
We collect and process personal data, including sensitive personal data (but only that of our employees and Network Members) only for specified, explicit and reasonable purposes and to the extent directly relevant to the purposes of processing. We will process your personal data (including sensitive personal data) in a way that has the least impact on your personal rights and interests (for example, grant access to personal data to necessary personnel only, use encryption technologies during transmission and storage of sensitive personal data when necessary). Our collection of personal data is described in Section B (Collection of Personal Data) and Section O (Cookies and Similar Technologies) of the Privacy Policy.
The personal data collected and processed by us is outlined in the below paragraphs, and the personal data that might constitute sensitive personal data is underlined in the following paragraphs. We will process sensitive personal data only if strict protection measures are put in place and there is sufficient necessity to justify the processing. It is necessary for us to process your sensitive personal data in order to perform the specific Services you request from us and for other specific purposes described in this China Privacy Notice.
- Personal details: given name(s); preferred name; and photograph (if provided).
- Demographic information: date of birth; salutation; title; and language preferences.
- Network Member data: With respect to Network Members (in addition to any other applicable category set out in this Notice), we also collect wireless device addresses (including text message addresses), payment information, professional biography, and other profiling information pertaining to your experience and expertise.
- Contact details: address; telephone number; email address; and details of your public business networking profile(s) or online biographies.
- Consent records: records of any consents you may have given, together with the date and time, means of consent and any related information (e.g., the subject matter of the consent).
- Payment details: invoice records; payment records; billing address; payment method; bank account number; BACS details; SWIFT details; IBAN details; payment amount; and payment date.
- Data relating to our Sites: device type; operating system; browser type; browser settings; IP address; language settings; dates and times of connecting to a Site; username; password; security login details; usage data; aggregate statistical information; internet service provider (ISP) details; referring and exit pages; and clickstream data.
- Employer details: where you interact with us in your capacity as an employee, the name, address, telephone number and email address of your employer, to the extent relevant.
In addition to all the stated uses of Personal Data set forth in Paragraph G of the Privacy Notice above (Purposes for which we may Process your Personal Data), we may use or disclose your personal data for any purpose described to you when collecting your personal data or as otherwise set forth in the PIPL.
Pursuant to PIPL, we may process personal data if one of the following options applies:
- Relevant data subject has given prior consent to processing of their personal data for one or more specific purposes;
- Processing of personal data is necessary to conclude or perform a contract to which the data subject is party;
- Processing is necessary for compliance with any statutory duties or legal obligations;
- Processing is necessary in order to, in an emergency, protect the lives, health or property of natural persons;
- The personal data has been made public by the data subject concerned or has otherwise been lawfully made public, the processing is done pursuant to the PIPL and the extent of the processing is reasonable; or
- Processing is done in other circumstances provided for in applicable laws or administrative regulations.
GLG’s information systems are owned and maintained by Gerson Lehrman Group, Inc. in the United States, and are utilized by all of its subsidiaries and affiliates, including Gerson Lehrman Group (Shanghai) Co., Ltd. A full list of GLG Inc.’s subsidiaries and affiliates can be found here: glg.com/about/contact-locations.
We will take necessary measures required by laws including obtaining your separate consent, entering into standard contractual clauses with the overseas recipient to stipulate the rights and obligations between us, and will ensure that the foreign receiving party provides adequate protection for your personal information under applicable laws.
To the extent required by applicable law, we will, before sharing your personal data with such recipient, notify you of the name and contact details of the recipients, the purposes and means of processing and provision of your personal data, and the types of personal data to be provided and shared, and obtain your consent to the sharing of your personal data.
In any case, we will only share and transfer your personal data for specific and definite purposes pursuant to the principles of lawfulness, fairness, necessity and good faith, and only share and transfer the personal data to the extent necessary for the specific purposes you are informed of. If we share your personal data with the foregoing recipients, we may use encryption, anonymization and other means as necessary and appropriate to ensure your personal data security. Before sharing or transferring your personal data, we will follow and adopt the applicable process and requirements required by the applicable law in respect of transfer of your personal data.
The foregoing data recipients will use the personal data to the extent necessary for the specific purposes you are informed of and store the personal data for the minimum length of time required to fulfil the purposes, or as prescribed by the applicable law.
The PIPL provides certain rights to China data subjects. These include rights of: knowing about and deciding on the processing of your personal data; access to and making copy of your personal data; correction and supplement of inaccurate or incomplete personal data; portability; withdrawal of consent with future effect; deletion; and requesting explanations of the rules governing the processing of your personal data. This section provides more information about those rights and how a China data subject can exercise these rights under the PIPL.
For GLG to fulfill any request related to your personal data, you must provide sufficient information for us to reasonably verify that you are the data subject from whom we collected the personal data. The information you send for us to verify your identity will be used for this purpose only. If we are unable to verify your identity or if we suspect fraudulent activity, we may decline to comply with your request.
We will make commercially reasonable efforts to identify your personal data that we collect, process, store, disclose and otherwise use and to respond to your requests. In addition, we will not honor your requests to the extent that doing so would infringe upon our or any other person or party’s rights or conflict with applicable law. If we deny your request, we will explain the reasons in our response.
RIGHT TO ACCESS
- China data subjects have a right to access and obtain a copy of their personal data.
- You can exercise your right to access your personal data by contacting GLG via the means provided in Section R (Contact Details) of the Privacy Policy.
RIGHT TO DELETION
- Subject to the following conditions, China data subjects have the right to request deletion of their personal data when:
- the processing purpose has been achieved or is unachievable or the personal data is no longer necessary to achieve the processing purpose;
- we have ceased to offer the products or services or the retention period has expired;
- the data subject has withdrawn their consent;
- we have processed personal data in violation of a law or administrative regulation or in breach of the Privacy Policy and this China Privacy Notice; and
- other circumstances provided for in laws or administrative regulations.
- If the retention period provided for in laws or administrative regulations has not yet expired or the personal data would be technically difficult to delete, we will cease the processing except for storage and the taking of necessary security protection measures.
- You can exercise your right to deletion of your personal data by contacting GLG via the means provided in Section R (Contact Details) of the Privacy Policy.
OTHER RIGHTS
- You can exercise your other privacy rights, including your right of knowing about and deciding on the processing of your personal data, correction and supplement of inaccurate or incomplete personal data, portability, withdrawal of consent with future effect and requesting explanations of the rules governing the processing of your personal data by contacting GLG at the information provided in Section R (Contact Details) of the Privacy Policy.
We reserve the right to change this China Privacy Notice from time to time. Changes shall be notified to you and become effective on the date they are posted. If required by applicable law, we will obtain your consent in respect of such changes.
If you have any questions about this China Privacy Notice, our global privacy standards, or our handling of personal data, please contact us at privacy@glgroup.com.






