Skip to main content
main content, press tab to continue

Data Protection Notice

PRIVACY NOTICE FOR CLIENTS

This privacy notice describes how Willis Towers Watson in Mauritius collects and processes personal data when we provide transactional broking and insurance advisory services (“Services”) to our clients.

Willis Towers Watson operates worldwide through subsidiary and affiliate companies. In Mauritius this means Willis Towers Watson (Mauritius) Limited.

Insurance involves the use and disclosure of personal data by various insurance market participants such as intermediaries, insurers and reinsurers. You should read this Privacy Notice for specific information regarding how we process personal data in relation to the Services.

In providing the Services, we may be required to process personal data of individuals named in an insurance policy, or individuals that are beneficiaries of, or have made claims under, an insurance policy, or individuals who are involved in an incident giving rise to an insurance claim. This can include children, their legal guardians or caregivers. We also process personal data of individuals who are employees, contractors and representatives of our clients. This privacy notice applies to any individual whose personal data we process in the course of providing the Services (each a "data subject" or "you").

  1. SCOPE OF THIS PRIVACY NOTICE

    This privacy notice applies when we collect your personal data in the course of offering or administering our Services, and it applies to all personal data we collect or process about you in relation to this Service.

  2. CROSS-BORDER TRANSFER

    Willis Towers Watson is a global organisation operating in more than 140 countries and our business activities are global in nature. As such we sometimes transfer personal data to countries located outside of the country of origin. The laws applicable to the country where the data is being received may not be equivalent to that in your location. However, we always take steps to ensure any transfer of information is carefully managed to protect your privacy rights. In particular:

    • For transfers between Willis Towers Watson Group companies: We have put in place an intra group data transfer agreement to ensure that transfers of personal data within our Group receive a consistent and adequate level of protection, similar to that applicable under the Data Protection Act 2017, wherever it is transferred.
    • For transfers to third parties outside of the Willis Towers Watson Group of Companies: We will only transfer personal data to parties located outside Mauritius, where the foreign jurisdiction to which the personal data is transferred has implemented data protection legislation at least equivalent to the data protection standards and provisions required under the Data Protection Act 2017. in accordance with applicable data protection law.

    Please see the Contact & Comments section below for details on how you can contact us to get further information on the third countries to which personal data will be transferred and further information relating to the safeguards we have in place in relation to international transfers of personal data.

  3. PERSONAL DATA

    In this section we describe the types of personal data we collect in providing the Services, what we use it for and what our lawful basis is for doing so under applicable data protection legislation.

    • PERSONAL DATA WE COLLECT

      “personal data” is information that identifies you as an individual or relates to an identifiable individual.

      We may collect your personal data in the following ways:

      • Our client or third party service providers (such as insurers) may provide your personal data to us. When a client or third party service provider provides us with personal data about you, we ask that the client provides a copy of this privacy notice to you before doing so.
      • You may provide your personal data directly to us if you are our client or if you are involved in a claim that we are handling for a client.
      • We may collect your personal data from publicly available sources such as information available on social media platforms, information about your registered property or assets and information about claims and convictions on public records.

      The personal data we may collect about you from our clients, third party service providers or directly from you, will depend on the type of Service we are providing and the relationship between us, or between you and our client. You do not have to provide personal data requested by us nor do you have to allow us to handle your personal data. A failure to provide this personal data will mean we are unable to provide our Services, which could affect your ability to receive benefits to which you may be entitled.

      Personal data we collect may include:

      • name and contact information;
      • demographic information (such as gender, age, date of birth, marital status, nationality, education/work histories, academic/professional qualifications, employment details, hobbies, family composition, and dependents);
      • personal identification documentation and related information such as passport numbers, Mauritian ID number and employee identification numbers;
      • financial and payment data such as bank account numbers and transaction information;
      • information related to the provision of the Services, such as policy information, claims information, and information relating to incidents giving rise to claims and related losses;
      • information about your property and assets;
      • statements made by or about you;
      • records of communications and CCTV footage; and
      • human resources data, such as job title and role; benefits and compensation information; dependent/beneficiary information; educational, academic and professional qualifications information; emergency contact information; and performance management information and criminal records.

      Some of the categories of information that we collect are special categories of personal data ("sensitive personal data"). These include your health records (such as your medical history and reports on medical diagnoses, injuries and treatment); information about your personal characteristics and circumstances of a sensitive nature such as your racial or ethnic origin, sex life, mental and physical health and genetic information; and criminal records.

    • HOW WE MAY USE YOUR PERSONAL DATA

      We use your personal data:

      • to provide the Services and fulfill our contractual obligations to clients;
      • to conduct data analysis;
      • for fraud monitoring and prevention;
      • to help develop new services and to enhance, improve or modify our Services;
      • to operate and expand our business activities;
      • to carry out background checks and conduct due diligence;
      • to perform administrative activities in connection with our Services;
      • to exercise, defend or protect our legal rights or the rights of our clients or third parties; and
      • to comply with legal and professional obligations and to cooperate with regulatory bodies.

      The way we analyse personal data for the purposes of risk assessment, fraud prevention and detection, and to report to our clients as part of the Services may involve profiling, which means that we may process your personal data using software that is able to evaluate your personal aspects and predict risks or outcomes.

      We may also aggregate or anonymise information about you. Aggregated or anonymised data is not capable of being used to identify individuals and is not treated as personal data under this privacy notice.

    • LEGAL BASES FOR PROCESSING PERSONAL DATA

      We must have a legal basis to process your personal data in accordance with applicable data protection legislation. This will be for at least one of the following purposes:

      • where it is necessary to enter into a contract with us / in order to perform the Services to you;
      • where it is necessary to comply with our legal obligations such as due diligence and reporting obligations, for example know-your-customer checks to prevent money laundering and fraudulent activities;
      • where you have provided your consent, for example if you have agreed to receive marketing communications from us. You may withdraw your consent at any time by contacting us using the details at the end of this privacy notice;
      • where it is necessary for our legitimate interests, or those of a third party, for example to ensure that the Services we provide are appropriate our clients' requirements, to improve our Services, manage our risks, maintain accurate transaction records, and manage our business in an efficient way. These circumstances shall only apply where such legitimate interests are not overridden by your interests or fundamental rights and freedoms.

      We only process sensitive personal data in limited circumstances:

      • where applicable under national data protection laws the processing is necessary for our insurance purposes (i.e. for advising, arranging, underwriting or administering an insurance contract or handling claims);
      • where we have your explicit consent, (in which case our client will obtain your explicit consent to collect and use the data for the purposes described in this privacy notice). You may withdraw your consent at any time by contacting us using the details at the end of this privacy notice; or
      • to establish, exercise or defend legal claims.
  4. DISCLOSURE OF YOUR PERSONAL DATA

    We share your personal data with third parties under the following circumstances:

    • to any Willis Towers Watson group company for the uses and purposes set out above;
    • to our clients, intermediaries, advisers and business partners for the purposes of fulfilling our contractual obligations to clients, for example to deliver our Services and to arrange insurance products for clients;
    • to third party service providers including entities providing customer service, email delivery, marketing service providers, IT service providers, auditing and other services;
    • if we are obliged to disclose your personal data under applicable law or regulation, which may include laws outside your country of residence; and
    • in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).

    We request those external service providers to implement and apply security safeguards to ensure the privacy and security of your personal data.

  5. SECURITY AND RETENTION

    Willis Towers Watson maintains appropriate technical and organizational security measures to protect the security of your data against loss, misuse, unauthorized access, disclosure or alteration. These measures are aimed at ensuring the ongoing integrity and confidentiality of Personal data. We evaluate these measures on a regular basis to ensure the security of the processing.

    We will retain your personal data for as long as is necessary for the provision of Services to our clients. When we no longer need your personal data in connection with the Services, we will then retain your personal data for a period of time that reasonably allows us to comply with our regulatory obligations and to commence or defend legal claims. We may retain aggregated or anonymised data (which is not treated as personal data under this privacy notice) for longer.

  6. CHOICES AND ACCESS

    If you would like to access or request the deletion of your personal data or request a copy of personal data about you, please contact us using the details set out in the ‘Contact and Comments’ section below.

    You also have a right to lodge a complaint to the Data Protection Office if you have any concerns about how we are processing your personal data. We ask that you please attempt to resolve any issue with us first, although you have a right to contact the regulator, the Data Protection Commissioner at any time in writing at either dpo@govmu.org or 5th Floor, SICOM Tower, Wall Street, Ebene, Republic of Mauritius.

  7. CHANGES TO OUR PRIVACY NOTICE

    You may request a copy of this privacy notice from us using the contact details set out below.

    We may modify or update this privacy notice from time to time by notifying or providing a revised version to our clients. Where changes to this privacy notice will have a fundamental impact on the nature of the processing or otherwise have a substantial impact on you, we will ask that our clients give you sufficient advance notice of these changes so that you have the opportunity to exercise your rights (e.g. to object to the processing).

  8. CONTACT & COMMENTS

    If you have any questions or comments regarding this privacy notice or would like to exercise your rights as a data subject, please contact our Global Privacy Office, at privacy@willistowerswatson.com or alternatively, our data protection officer for Willis Towers Watson (Mauritius) Limited, The Data Privacy Officer, Willis Towers Watson (Mauritius) Limited at WTW-MU.compliance@willistowerswatson.com 3rd Floor, UDL House, United Docks Business Park, Caudan, Port Louis, Mauritius.

Contact us