How and why does the QFC Regulatory Authority process your personal data?
As a general principle, the Qatar Financial Centre Regulatory Authority (“Regulatory Authority”) only collects and processes personal data for the performance of its regulatory function and statutory tasks assigned to it in accordance with the Qatar Financial Centre Data Protection Regulations.
The collection and processing of personal data varies by function, to see more specific information on how personal data is processed in relation to our activities please see the links below:
International transfers of personal data
The Regulatory Authority uses IT systems outside of the QFC in the European Economic Area to host and back up all data. The QFC Data Protection Office has stated that, at this time, these countries offer an adequate level of protection. The QFC Data Protection Office determines and lists the jurisdictions of adequate protection and can be found here. We rely on the guidance of the Data Protection Office in relation to the jurisdictions that are deemed to offer an adequate level of protection.
If we transfer your personal data outside the QFC to a country that is not considered to offer an adequate level of protection by the Data Protection Office, we strive to ensure your personal data is adequately protected by putting in place appropriate contractual safeguards, as required.
Your choices and rights
You have the right to ask the Regulatory Authority for a copy of your personal data; to correct, delete or restrict the processing of your personal data; and to obtain the personal data you provide in a structured, machine-readable format. In addition, you can object to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet legal requirement or a requirement relating to our regulatory function). Where we have asked for your consent, you may withdraw consent at any time. If you ask to withdraw your consent to the Regulatory Authority processing your data, this will not affect any processing that has already taken place.
Upon receipt of a request, we will take action within 30 days of receiving your request. We may extend the period for 60 days if necessary due to the complexity and number of relevant requests. We will inform you of such an extension and the reasons within 30 days of receiving the initial request.
These rights may be limited, for example if fulfilling your request would adversely affect the rights and legitimate interests of another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep or where complying with your request would be likely to prejudice the proper discharge of the RA’s powers. You will not be subject to decisions that will significantly impact you based solely on automated decision-making (i.e., with no human involvement in the decision).
If you have unresolved concerns and consider that our processing breaches the QFC Data Protection Regulations, you have the right to complain to the QFC Data Protection Office.
The QFC Data Protection Office Resource Centre can be accessed via this link.
The Regulatory Authority has a retention schedule which sets out how long we hold all information, including any personal data used for each of the areas mentioned in this privacy notice.
Updates to this privacy notice
We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal data.
We are the data controller for your personal data. This means that we are responsible for deciding how we hold and use your personal data. We are required under the QFC Data Protection Regulations 2021 to notify you of the information contained in this privacy notice.
If you have questions about this privacy notice or wish to contact us for any reason in relation to our personal data processing, please contact the Data Protection Adviser at email@example.com.