Find out how and why we use your personal data, and how this applies in different aspects of our work.
Our privacy notice informs you of what to expect when the Financial Conduct Authority (FCA) collects information about individuals (which we will call ‘personal data’ in this privacy notice). The FCA is the controller responsible for the processing of your personal data.
To help you understand how we use personal data across the FCA, in this privacy notice we explain core activities that we undertake and how we may use the personal data that we collect to carry out these activities. We also provide information about your rights and how to contact us if you have any questions.
The FCA may at times process personal data as a joint controller (such as, under section 166 of FSMA, where we make joint decisions around processing personal data with Skilled Persons or with the Prudential Regulation Authority (PRA)) or as a separate controller (where we share personal data) with other authorities (such as the PRA).
In most cases, individuals can still exercise their rights in relation to the personal data we process as set out below. Where we will allocate responsibilities between the controllers and we will, if necessary, notify or redirect individuals to other authority or controller, in relation to exercising their individual rights.
To learn more about our use of personal data in different aspects of our work, please use the below links:
- our use of cookies
- personal data used when you contact us
- personal data and handling complaints about us
- personal data and authorisation
- personal data and enforcement
- personal data and market oversight
- personal data and supervision
- personal data and the Financial Services Register services
- personal data and surveys, consultations and market research
- personal data and communicating FCA news and events
- our whistleblowers page explains how we handle information provided by whistleblowers
- to learn how we handle personal data for job applications, read our Recruitment Privacy notice
- if we feature a film on our website that includes footage that has been filmed in a public place, we make sure that the footage only captures people in the background and that they are not identifiable. For all other forms of video, we obtain express permission from everyone who appears in our films which includes people participating in FCA research, vox pop interviews, conferences and webinars.
Independent investigations and reviews
Independent investigations and reviews consider the FCA’s actions, policies and approach during the conduct and discharge of our regulatory responsibilities. These investigations and reviews are often undertaken by appointed individuals, independent of the FCA. These can be conducted as a result of a direction from HM Treasury under section 73 or 77 of the Financial Services Act 2012 or commissioned on the FCA’s own initiative. HM Treasury also has powers to arrange independent inquiries. We set out to be as open and accountable as possible and further information can be found on our transparency pages.
Where it is appropriate to do so, we may share personal data as part of these investigations with any appointed independent reviewer and professional advisors. This personal data may originate from public sources as well as information we have collected in the discharge of our other functions, such as complaints handling and the supervision of regulated firms and individuals. When the independent investigation or review has been completed, we may also publish part or all of that report, which may contain personal data related to certain individuals. Where the report has been produced as a result of a direction by HM Treasury under the Financial Services Act, the FCA will provide the report (which may include personal data) to HM Treasury. HM Treasury will publish the report. Such personal data may include names, references to employment positions held, actions taken by and communications with such individuals.
For the independent investigation into the regulation by the FCA of London Capital & Finance Plc, HM Treasury and the FCA have determined that – for the purpose of providing the report to HM Treasury – they are joint controllers of any personal data contained in the report, and that (amongst other things) the FCA is responsible for complying with requests from data subjects (including subject access requests). A Protocol has been agreed for these purposes.
We process this personal data under Article 6(1)(e) of the UK GDPR (it is necessary for the performance of a task carried out in the public interest) and Section 8(c) of the DPA 2018. In the case of reports commissioned on the FCA’s own initiative, the FCA publishes the report using its guidance power in section 139A FSMA. Where the report is commissioned as a result of a direction by HM Treasury under the Financial Services Act, the FCA is under an obligation to provide a report to HM Treasury under section 79 of that Act.
To the extent that we use any special categories of personal data, we do so under Article 9(2)(g) of the UK GDPR (it is necessary for reasons of substantial public interest) and Section 10(3) of the DPA 2018, in that it meets a condition in Part 2 of Schedule 1 of the DPA 2018 and we have an appropriate policy document covering this processing.
International transfers of personal data
Where the processing of personal data requires a transfer to other countries outside the UK (to the EU and outside the European Economic Area 'EEA'), we will ensure that necessary safeguarding and protections are in place as set out by the UK GDPR and guidance issued by the Information Commissioner’s Office, such as checking the applicable adequacy regulations and implementing robust contractual and security safeguards with third-party providers.
Data retention
Our retention policy sets out how long we hold all information, including any personal data used for each of the areas mentioned in this privacy notice.
Your rights
Under the DPA 2018 and the UK GDPR, you have rights as an individual which you can exercise in relation to the personal data we hold about you. For example, you can exercise your right to:
- request access to, and deletion or correction of, information about you
- object to the way in which we use information about you
- request that your personal data be transferred to another organisation
- complain to the Information Commissioner’s Office if you are unhappy about the way we use information about you
Individual rights request form
If you wish to find out what personal data, if any, we hold about you or if you wish to exercise any of your other privacy rights, you can contact our Information Disclosure Team. To enable us to process your request as quickly as possible, we will need you to provide us with some information about yourself. You may find it helpful to complete our individual rights request form.
If we hold information about you
If we do hold information about you we will:
- give you a description of it
- tell you why we are holding it
- tell you who it could be or has been disclosed to
- tell you how long we intend to keep the information
- tell you where we obtained the information (if not from you directly)
- tell you if any significant automated decisions (those made by a computer and with no human intervention) have been made about you by us
- let you have a copy of the information in an intelligible form
If you notice any mistakes in the information that we hold about you, you can ask us to correct those mistakes. You can also ask us to stop holding or using information about you, which we will do unless we have genuine and lawful reasons for continuing to hold or use it.
As a public authority, and a regulator who exercises functions of a public nature or in the public interest, we are entitled to rely on certain exemptions set out in the DPA 2018 which may have an impact on any rights request that you may make to us. If this is the case, we will clearly explain what the exemption is, why it applies and what impact it may have on your rights request. Also, if we are processing personal data for a law enforcement purpose, we may withhold information from you if we believe that doing so is necessary to avoid prejudicing the detection and investigation of criminal offences.
Find out more about your privacy rights
If you are interested in learning more about your privacy rights, you can find more information on the ICO website.
How to contact us
This privacy notice covers all the main ways that we use the various types of personal data we may hold about you, to make sure that we are as transparent as possible and to avoid using your information in a way that would surprise you.
If you feel that we have missed anything that you would like to know, or you have any particular questions about our privacy policy, you can email us or write to: Information Disclosure Team, Financial Conduct Authority, 12 Endeavour Square, London, E20 1JN.
When you contact us and / or when we contact you
We use personal data to fulfil statutory functions and other duties. This may include recorded phone and video calls, written notes, and digital copies. Depending upon our statutory and operational requirements, we may be required to keep written/digital notes and recordings to maintain an accurate record of information to support our work and aid our decision-making; these will be retained in accordance with our retention schedule. Please note that recorded phone and video calls, written/digital notes, and any other data processed by the FCA may also be processed by third party data processors performing services for the FCA under contract.
Our Data Protection Officer
As a public authority we are required to appoint a Data Protection Officer (DPO) who oversees our internal data protection compliance, informs and advises us on our data protection obligations, advises us on our data protection impact assessment process and acts as our contact point with the Information Commissioner.
Please email our team if you would like to contact our DPO.
Glossary of terms used in this privacy notice
DPA 2018 |
The Data Protection Act 2018 |
UK GDPR | The General Data Protection Act Regulation as it applies in the UK |
ICO | The Information Commissioner’s Office |
LED | The Law Enforcement Directive (EU) 2016/680 |
Personal data | When we refer to personal data we mean any information about a living identifiable individual who can be directly or indirectly identified from that information. |
Pseudonymise |
The process of distinguishing individuals in a dataset by using a unique identifier which does not reveal their “real world” identity. |
Anonymise | The process that does not itself identify any individual and that is unlikely to allow any individual to be identified through its combination with other data. |
Special categories of data | The special categories of data are specifically listed in the UK GDPR. They include race, ethnicity, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health information, or information about a person’s sex life or sexual orientation. Previously referred to as 'sensitive personal data' |
Changes to this privacy notice
We keep our privacy notice under regular review. See 'last updated' at the top of the page for the date of the latest update.