Processing of personal data in connection with
Establishment of client relationships, client management, and marketing
Clients and potential clients:
• Personal data (non-sensitive), including name, title/position, address, and passport details/driver's license.
• Confidential information, including civil registration numbers (CPR numbers).
Personal data is collected and processed as part of our Know Your Customer (KYC) procedure to provide documentation for mandatory anti-money laundering checks in accordance with the Anti-Money Laundering Act.
We process personal data (non-sensitive) pursuant to Article 6(1)(c) of the GDPR, based on a legal obligation arising from the applicable Anti-Money Laundering Act and the Administration of Justice Act.
We process civil registration numbers (CPR numbers) pursuant to Section 11(2)(1) of the Data Protection Act, cf. Section 11(1)(a) of the Anti-Money Laundering Act.
Personal data is deleted five years after the termination of the client relationship.
We do not disclose your personal data to external parties unless it is necessary and there is a legal basis for doing so. This may include public authorities, private companies or individuals, foundations, associations, etc., depending on the nature of the case. In the event that a lawyer changes workplace and takes ongoing cases to their new employer, documentation obtained in connection with the establishment of the client relationship may be transferred from the former employer. This disclosure is made to ensure compliance with legal obligations, including documentation requirements towards supervisory authorities, to which lawyers and law firms are subject under applicable law.
We entrust information to our data processors (e.g., IT providers).
Impartiality and conflict of interest checks during case onboarding
Clients, potential clients, counterparties, and potential counterparties, etc.:
- Non-sensitive personal data, including name, title/position, address, passport information/driver's license, and relationships in connection with client/case onboarding.
- Confidential information, including civil registration numbers (CPR numbers).
Personal data is collected and processed as part of identifying potential conflicts of interest and impartiality. This check is performed to protect the rights of the data subjects and to ensure that our advice and representation of our clients comply with the requirements of the Administration of Justice Act and the Code of Conduct for the Danish Bar and Law Society.
We process non-sensitive personal data pursuant to Article 6(1)(c) of the GDPR, based on a legal obligation to which we are subject under the Code of Conduct for the Danish Bar and Law Society and the Administration of Justice Act.
We process civil registration numbers (CPR numbers) pursuant to Section 11(2)(1) of the Danish Data Protection Act, in accordance with the Code of Conduct for the Danish Bar and Law Society and the Administration of Justice Act.
Personal data processed in connection with conflict checks is stored for 20 years after the case is archived, unless the case is subject to an exceptionally extended deletion period.
We do not disclose your personal data to external parties unless it is necessary and there is a legal basis for doing so. This may include public authorities, private companies or individuals, foundations, associations, etc., depending on the nature of the matter.
We entrust information to our data processors (e.g., IT providers).
Building and maintaining relationships with existing and potential customers, clients, partners, network members, etc.
Individuals with a relationship to us, including existing and potential customers, clients, partners, network members, etc.
- Personal data (non-sensitive), including name, job title, company/authority, address, phone number, email, preferences, interests, and network connections.
- Special categories of personal data (sensitive), including allergies/intolerances.
Personal data is processed for the purpose of building and maintaining relationships. With this knowledge, we can meet your needs and preferences, ensuring you only receive relevant information, such as event announcements or news.
Your health information is processed to ensure appropriate catering at meetings and participation in events, including courses, networking, training, etc.
We process personal data (non-sensitive) pursuant to Article 6(1)(b) of the GDPR when processing is necessary for the performance of a contract to which the data subject is a party, and Article 6(1)(f) of the GDPR, as we have a legitimate interest in establishing and maintaining client relationships.
We process special categories of personal data pursuant to Article 9(2)(a) of the GDPR, provided you have given your consent to the processing.
Personal data is stored for as long as it is relevant in relation to the existing or potential client relationship, or until any consent is withdrawn.
We do not disclose your personal data to external parties unless it is necessary and there is a legal basis for doing so. This may include public authorities, private companies or individuals, foundations, associations, etc., depending on the nature of the matter.
We entrust information to our data processors (e.g., IT suppliers).
Participation in events, courses, webinars, networks, and subscriptions, etc.
Participants and registrants for our events, etc.:
- Personal data (non-sensitive), including, among other things, name, title, email, and information about the selected event, course, etc.
- Special categories of personal data (sensitive), including, among other things, allergies/intolerances.
- Other information that the data subject chooses to provide to us voluntarily.
Personal data is processed for the purpose of managing participation in events, etc., and for sending relevant material in connection with the specific event.
We process personal data based on Article 6(1)(b) of the GDPR, as the processing is necessary for the implementation of measures taken at the request of the data subject prior to the event.
We process special categories of personal data based on Article 9(2)(a) of the GDPR, provided you have given your consent to the processing.
Personal data is stored for as long as necessary to fulfill the purposes for which it was collected, or until any consent is withdrawn.
Invoices regarding the data subject's participation in events, etc., are deleted five years after the invoice date.
Participant lists may be shared with network members, course participants, event attendees, and external speakers.
We do not disclose your personal data to external parties unless it is necessary and there is a legal basis for doing so. This may include public authorities, private companies or individuals, foundations, associations, etc., depending on the nature of the matter.
We entrust information to our data processors (e.g., IT providers).
Newsletters and requested
marketing
Subscribed recipients of newsletters, etc.:
- Personal data (non-sensitive), including name, job title, company/authority, and email address.
The personal data is processed for marketing purposes in the form of sending newsletters, invitations to events, etc.
If you have consented to us sending you newsletters, information about activities, invitations to events, etc., we process your personal data in accordance with Article 6(1)(a) of the General Data Protection Regulation.
Information necessary to document your consent is processed in accordance with Article 6(1)(c) of the General Data Protection Regulation.
Personal data is stored until consent is withdrawn. However, information regarding the consent is kept for 2 years from the last communication so that we can document compliance with the anti-spam regulations.
We do not disclose your personal data to external parties unless it is necessary and there is a legal basis for doing so. This may include public authorities, private companies or individuals, foundations, associations, etc., depending on the nature of the matter.
We entrust information to our data processors (e.g., IT providers).
Social media
(LinkedIn, Facebook, and
Instagram)
Individuals who interact with our social media pages and posts:
- Non-sensitive personal data, including images, name, job title, and area of expertise.
- Other information that the data subject has made available on their own initiative via the comment section on our posts.
Personal data is processed as part of our communication and marketing activities on social media.
We use Article 6(1)(f) of the GDPR to process personal data (non-sensitive) in connection with our communication and marketing activities on social media, and the legitimate interest we pursue is to make content available on social media for marketing purposes.
Personal data associated with one of our posts will be deleted no later than three years after publication.
Personal data in comments not associated with our posts will be deleted when the data subject removes their comment.
Personal data is disclosed exclusively to the company that facilitates the relevant media:
- LinkedIn: Microsoft Corporation
- Facebook and Instagram: Meta Platforms Inc.
When Meta Platforms Inc. uses personal data collected on our Facebook and Instagram accounts, we and Meta Platforms Inc. may be considered joint controllers. In this regard, we refer to Meta Platforms Inc.’s data policy for further information on Meta Platforms Inc.’s purposes for processing personal data.
We do not disclose your personal data to external parties unless it is necessary and there is a legal basis for doing so. This may include public authorities, private companies or individuals, foundations, associations, etc., depending on the nature of the matter.
We entrust information to our data processors (e.g., IT providers).