Milliman Personal Data Privacy Policy- Milliman Saudi Arabia LLC
Last updated September 2024
Where Milliman is Acting as a Data Controller
Milliman, Inc. and its affiliates (“Milliman” or “we”) take data privacy very seriously. This Privacy Policy sets out the principles governing the way in which Milliman Saudi Arabia LLC located in Riyadh, uses and protects Personal Data that individuals share with us (“Personal Data”), hereafter “you”. Milliman is committed to handling Personal Data in accordance with this Privacy Policy, the Personal Data Protection Law (“PDPL”) and other data privacy legislation, as applicable.
Collection of Data
Aggregate Data
Like many companies, Milliman monitors the use of its websites by collecting aggregate data. No Personal Data is collected in this process. Typically, Milliman collects data about the number of visitors to: (i) the website; (ii) each web page; and (iii) the originating domain name of the visitor's Internet Service Provider. This data is used to improve the usability, performance and effectiveness of Milliman’s website.
Processing of Personal Data
The Personal Data Milliman Saudi Arabia LLC collects varies depending upon the nature of the services provided and our interactions with you. All processing (i.e., use) of your Personal Data is justified by a "lawful basis" for processing. In most cases, processing will be justified on the basis that:
- the processing is necessary for the performance of a contract to which you are a party, or to take steps (at your request) to enter into a contract (e.g., where you request certain services as an individual client, or where we help advise your employer or service provider on fulfilling an obligation to you under a contract).
- the processing is necessary for us to comply with a relevant legal obligation (e.g., where we are required to collect certain information about our clients for tax or accounting purposes, where we are required to make disclosures to courts or regulators or confirm background checks for anti-money laundering and terrorist financing purposes); or
- the processing is in our legitimate interests, subject to due consideration for your interests and fundamental rights (this is the basis we rely upon for the majority of our processing activities in connection with the provision of our services and also for the purposes of most client on-boarding, administration and relationship management activities).
No automated decision-making is undertaken based on the Personal Data collected from you.
In all instances, where the basis for processing your Personal Data is based on consent, you may withdraw your consent at any time.
Affiliates and Authorized Third-Party Agents
Some Personal Data may be shared between Milliman Saudi Arabia LLC and Milliman entities located in the U.S. and/or India, for the purposes of the centralization of Milliman’s General Corporate Services, focused on IT-maintenance and security.
For such IT-maintenance and security services, Milliman may share Personal Data with authorized third-party agents or contractors that perform services for Milliman, located in and outside of Saudi Arabia. If Milliman shares Personal Data with a third party, Milliman requires that those third parties agree to process Personal Data based on Milliman’s instructions and in compliance with this Privacy Policy.
Milliman, Inc. and Milliman Saudi Arabia LLC are joint controllers with respect to the processing of Personal Data described in this section. This means that Milliman, Inc. and Milliman Saudia Arabia LLC are both responsible for the compliance with the PDPL and other applicable data privacy legislation.
In all cases, any transfers of Personal Data out of Saudi Arabia are subject to appropriate safeguards and authorizations that are compliant with the PDPL and other applicable regulations.
Other Disclosures
Milliman Saudi Arabia LLC may also disclose Personal Data and other related information in response to subpoenas, court orders, or other lawful requests by public authorities, and to meet national security or law enforcement requirements. Milliman Saudi Arabia LLC may collect and share Personal Data to investigate or to take action regarding illegal activities, suspected fraud, violations of Milliman's Terms of Use, or as otherwise required by law or regulation.
Security
Milliman Saudi Arabia LLC stores Personal Data on a secure server that is password protected and shielded from unauthorized access by a firewall. Milliman Saudi Arabia LLC has in place security policies that are intended to ensure the security and integrity of all Personal Data. Milliman Saudi Arabia LLC has appropriate technical and organisational measures in place to protect against unauthorized or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data held or processed by Milliman. If Milliman Saudi Arabia LLC forwards Personal Data to any third party, it will require that those third parties have appropriate technical and organisational measures in place to comply with this Privacy Policy and applicable data privacy laws.
Data Retention
Milliman Saudi Arabia LLC retains Personal Data only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or as directed by law. It will delete your Personal Data once the purpose of the collection and processing has been fulfilled and the adequate duration for documentation and backup storage of such Personal Data has lapsed. If you have unsubscribed from receiving marketing information from us, we will continue to maintain your Personal Data for any other purpose for which we still have legal grounds for processing (such as for the purposes of complying with a legal obligation or when the processing is necessary for a legitimate interest). In certain cases, if no other legal grounds exist, we will maintain limited Personal Data (such as your email address) about you on record, so to ensure that such marketing communications are no longer sent to you in the future.
Children
Milliman’s websites, products, and services are not directed to children, and Milliman does not knowingly collect Personal Data from children. If a parent or legal guardian becomes aware that his or her child has provided Milliman with Personal Data without their consent, the parent or legal guardian should fill out the applicable form available under the section “Rights”, and Milliman will take steps to delete any such Personal Data.
Third-party Links
This website may contain links to websites hosted and operated by companies other than us (“Third-Party Websites”) to which you can export (all or part of) your Personal Data.
We do not disclose your Personal Data to these Third-Party Websites without your consent. Note that any information you disclose to Third Party Websites is no longer under our control and no longer subject to this Privacy Policy.
You should review the privacy policy practices of any such Third-Party Website to understand how that Third-Party Website collects and uses your Personal Data. We are not responsible for the content or performance of these Third-Party Websites. We are in no way responsible or liable for the manner in which a Third-Party Website treats any Personal Data that you choose to provide to such a Third-Party Website and use of Third-Party Websites is strictly at your own risk.
Policy Updates
Milliman may change the terms of this Privacy Policy from time to time. Milliman therefore asks all persons concerned to check it occasionally to ensure that they are aware of the most recent version.
Rights
You have a number of rights under the PDPL (article 4) and its implementing regulations in relation to your Personal Data, namely:
- the right to information: you have the right to be informed about the legal basis, the purpose of the collection of your Personal Data and the additional information legally required (e.g., details of the Controller, the retention of the Personal Data or the mechanism to withdraw consent).
- the right of access: you have the right to obtain from us confirmation as to whether or not Personal Data concerning you is being processed, and, where that is the case, access to (including by obtaining a copy of) such Personal Data and the manner in which, and the purposes for which we process your Personal Data, so that you can verify its accuracy and the lawfulness of the processing.
- the right to correction, completion or update: you may ask us to correct inaccurate Personal Data concerning you and may ask us to update or amend any incomplete Personal Data completed. You can do this by providing a supplementary statement.
- the right to erasure: you may ask us to delete your Personal Data delay where: (a) your Personal Data is no longer necessary for the purpose for which it was collected/processed; (b) you wish to withdraw your consent to processing (except where we have another legal ground for processing that we may rely on); (c) you object to the processing of your Personal Data and we have no overriding legitimate grounds to continue to process it; or (d) where your Personal Data has been unlawfully processed.
- the right to restrict the processing of your Personal Data: you may ask us to restrict the processing of your Personal Data where the accuracy of such Personal Data is contested by you (for such period as will enable us to verify the accuracy of your Personal Data).
You can exercise any of your rights as stated above, by contacting Milliman at [email protected].
Milliman welcomes feedback and questions on this Privacy Policy. If for any reason you wish to contact us, please send an email at the above-mentioned address. Complaints will be resolved internally in accordance with Milliman’s complaints procedures.