Privacy Policy
How we collect, use, and protect your personal data.
Last updated: August 20, 2026
Introduction
PwC is strongly committed to protecting personal data. This privacy statement describes why and how we collect and use personal data and provides information about individuals' rights. It applies to personal data provided to us, both by individuals themselves or by others. We may use personal data provided to us for any of the purposes described in this privacy statement or as otherwise stated at the point of collection.
"PwC" (and "we", "us", or "our") refers to any PricewaterhouseCoopers member firm in the Middle East that: (1) is a contracting party for the purposes of providing or receiving services, (2) posted a position for which you are applying, or (3) you have a role or relationship with. Each member firm in the PwC network is a separate legal entity and a separate controller for personal data. Personal data is any information relating to an identified or identifiable living person. When "you" or "your" are used in this statement, we are referring to the relevant individual who is the subject of the personal data. PwC processes personal data for numerous purposes, and the means of collection, lawful basis of processing, use, disclosure, and retention periods for each purpose may differ.
When collecting and using personal data, our policy is to be transparent about why and how we process personal data. To find out more about our specific processing activities, please go to the relevant sections of this statement.
Security
We take the security of all the data we hold very seriously. The Network Information Security Policy Framework for the PwC network is aligned and compatible with financial services industry recognised security frameworks (e.g. ISO27002:2013) and best practices. An annual review of alignment and these processes is conducted as part of the governance procedure.
We have a framework of policies, procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data that we hold secure.
Collection of personal data
PwC will collect personal data in connection with the application as described below.
1. Account / entity registration
Account registration and onboarding information, including:
- The End Beneficiary's legal name
- Trade licence number
- Registered address
- Contact details
- TRN/VAT/tax registration number
- Bank account details linked to the trade license
- Details of the initial Authorized User
2. KYC / individuals
Compliance and onboarding information, including:
- Beneficial ownership details
- Full name
- Nationality
- Date of birth
- Passport and Emirates ID details/copies
- Documents and declarations required for acceptance, AML, sanctions, independence, conflicts, fraud prevention and risk assessment purposes
Use of personal data
Personal data relating to business contacts may be used for the following purposes:
Account and Service Administration
To register and maintain the End Beneficiary's account, verify eligibility, manage Authorized Users, process orders, activate access to Products and Associated Support, issue invoices, and administer payments.
Compliance and Risk Assessment
To conduct acceptance, compliance, AML, sanctions, independence, conflicts, fraud prevention and risk assessments, respond to requests for further information, and determine whether registration, access, processing or service delivery may proceed.
Our legal grounds for processing your personal data
Your local law may require us to set out in this privacy statement the legal grounds on which we rely in order to process your personal information. In such cases, we rely on one or more of the following processing conditions:
- Our legitimate interests in the effective delivery of information and services to you and in the effective and lawful operation of our businesses and the legitimate interests of our clients in receiving professional services from us as part of running their organisation (provided these do not interfere with your rights);
- To satisfy any requirement of law, regulation or professional body of which we are a member (for example, for some of our services, we have a legal obligation to provide the service in a certain way);
- To perform our obligations under a contractual arrangement with you.
When and how we share personal data and locations of processing
We will only share personal data with others when we are legally permitted to do so. When we share data with others, we put contractual arrangements and security mechanisms in place as appropriate to protect the data and to comply with our data protection, confidentiality and security standards.
We are part of a global network of firms and in common with other professional service providers, we use third parties located in other countries to help us run our business. As a result, personal data may be transferred outside the countries where we and our clients are located. This includes countries that do not have laws that provide specific protection for personal data. We have taken steps to ensure all personal data is provided with adequate protection and that all transfers of personal data outside a specific jurisdiction are done lawfully. Where we transfer personal data outside a jurisdiction to a country not determined as providing an adequate level of protection for personal data, the transfers will be under an agreement which covers the relevant data protection requirements for the transfer of personal data outside the jurisdiction.
Personal data held by us may be transferred to:
Other PwC member firms
We may share personal data with other PwC member firms where necessary for administrative purposes and to provide professional services to our clients (e.g. when providing services involving advice from PwC member firms in different territories). We store personal data on our or other PwC member firm servers around the world such as the EU, Singapore and the USA. IT support and services are provided by PwC member firms in different territories.
Third party organisations that provide applications/functionality, data processing or IT services to us
We are part of a global network of firms and in common with other professional service providers, we use third parties to help us run our business and these third parties may be located in other countries.
Auditors, insurers and professional advisers
We may share personal data with our auditors and professional advisors such as lawyers.
Law enforcement or other government and regulatory agencies or to other third parties as required by, and in accordance with, applicable law or regulation
Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, to establish, exercise or defend legal rights. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.
Third party organisations that provide applications/functionality, data processing or IT services to us
We share personal data processed in connection with the application as follows:
| Name | Address | Role | Processing responsibilities |
|---|---|---|---|
| Magnati / Network International | P.O. Box 2923, Dubai, United Arab Emirates | Payment gateway provider | Providing a PCI-DSS compliant hosted checkout / payment gateway to enable SME clients to pay online by card for tax services, starting with UAE Corporate Tax services. Card payment entry and processing will be handled on the payment provider's hosted environment. PwC systems will not store, process, or transmit raw cardholder data; the platform will retain only permitted payment references, transaction metadata and payment status information required for payment confirmation, service activation, reconciliation and support. |
| LexisNexis | Arjaan Office Tower, Office 404 to 407, P O Box 503246, Dubai, UAE | KYC, sanctions and adverse media screening provider | Providing screening and due diligence functionality to support onboarding, KYC, AML, sanctions, politically exposed person and adverse media checks in connection with the application. Personal data may be shared with LexisNexis for the purpose of carrying out these checks and returning screening results required for compliance, risk assessment and service eligibility decisions. |
Further details about other processors (such as IT service providers) used by PwC and locations of processing are captured on the ME Firm's privacy statement. Where the locations of processing are outside of a jurisdiction that imposes restrictions over transferring personal data (such as EEA, UK, DIFC, ADGM, Bahrain, Oman, KSA, Qatar and QFC), we have the approved standard contractual clauses in place to provide appropriate safeguards for personal data transferred outside to jurisdictions that do not provide an adequate level of protection for personal data.
Data retention
We will retain your personal data for as long as is considered necessary for the purpose(s) for which it was collected (including as required by applicable law or regulation). Our baseline retention period is 5-10 years.
Personal data may be held for longer periods where extended retention periods are required by law or regulation and in order to establish, exercise or defend our legal rights.
Cookies
For more details, please refer to the Cookies Policy.
Changes to this privacy statement
We recognise that transparency is an ongoing responsibility, so we will keep this privacy statement under regular review. This privacy statement was last updated on August 20, 2026.
Data controller and contact information
We are generally controllers for the personal data we process. If you have any questions about this privacy statement or how and why we process personal data, please contact us at: mer_me_data_protection_management@pwc.com
Individuals' rights and how to exercise them
Some local laws and regulations in the ME grant Individuals certain rights over their personal data and controllers are responsible for fulfilling these rights. Individuals' rights may include:
- Right of access to personal data
- Right to rectification of personal data
- Right to erasure of personal data / right to be forgotten
- Right to restrict processing of personal data
- Right to object to processing of personal data
- Right to data portability
- Right to withdraw consent at any time (where processing is based on consent)
- Right to lodge a complaint with a supervisory authority
Contact us
For any enquiries, or if you wish to exercise a legal right in relation to your personal data, or complain about our use of personal data, please send an email to mer_me_data_protection_management@pwc.com or submit a request.