Information about the processing of personal data

Last updated April 2023

This information text describes the processing of personal data for:

  • Users of our websites and digital channels, e.g. our social media pages.
  • A designated contact or representative of a customer, supplier or partner of ours.
  • A third party who is in contact with, or otherwise communicates with us or is affected by our personal data processing in general and is not covered by the categories above, e.g. if you own or live in a property affected by our work.

“Personal data” means information that can directly or indirectly identify you as an individual, e.g. your name or IP address.

Who is the data controller for the processing of your personal data?

The NCC company providing the website you are visiting is normally the personal data controller for such processing of personal data in accordance with this information text.

The NCC company with which your company has a business relationship is normally responsible for managing data in our business portals within the framework of contract management and procurement.

Each NCC company is responsible for Know Your Customer checks, user account management in our business portals, and for reporting violations of NCC’s policies and guidelines, as well as for fulfilling its own legal obligations and for establishing and asserting legal claims.

From which sources do we collect personal data?

We collect personal data from:

  • You. We collect the personal data that you provide to us, e.g. in connection with the use of our websites and other digital channels or when you contact us.
  • Employees. We may collect personal data about you from employees who provide your personal data to us, e.g. in connection with communication or when the employee voluntarily submits your data to us or in connection with the receipt of whistleblowing reports.
  • Partners. We may collect your personal data from business partners, e.g. in connection with carrying out an event or other activity together with said business partners. When conducting Know Your Customer (KYC) checks on senior executives of customers and suppliers, data may also be collected from independent companies that assist us with such surveys. We may also obtain information from credit reference agencies.
  • Social networking platforms. If you visit our social media channels, we will collect the personal data that you provide to us via these channels, e.g. to answer any questions you ask or to communicate about us, our business, or our services and offers.
  • Group companies. The companies within the NCC Group work collaboratively and therefore share information with each other, e.g. when communicating about the management of customer and supplier relationships.
  • Third parties. We may also collect personal data about you from third parties who provide your personal data to us, e.g. in connection with communication or an event or other activity, or in connection with the receipt of whistleblowing reports.
  • Public data sources. We may collect personal data about you from public sources, such as government agencies and public records, e.g. corporate engagement in order to manage orders and manage the relationship with the firm or organization to which you belong.

Which personal data do we collect?

The personal data we collect depends on how you interact with us. We only collect the personal data that we need, mainly within the following categories of personal data:

  • Identity data. Data that makes it possible to identify you, e.g. your name and, where appropriate, your personal identity number or equivalent.
  • Contact details. Information that makes it possible to contact you, e.g. address, email address and telephone number.
  • User-generated data. Information about your activity on and use of our websites and digital channels, e.g. clicks and visits to the website, and otherwise your behavior on our websites and in our digital channels.
  • Order details. Information about ordered goods or services, e.g. the goods or service, price and delivery or assignment period.
  • Billing data. This may include terms of payment, cost center, or reference number, number of hours, staff involved.
  • Profile data. Data relating to your profile, e.g. your title, name and address of the firm or organization to which you belong, and department.
  • Image and sound material. Information such as a still or moving image of you or a recording of your voice, e.g. photography, video or audio recording.
  • Communication. Content of communication with us, e.g. content of emails or responses you provide when you e.g. participate in a survey or provide feedback and comments.
  • Technical data. Technical details of the device you use when visiting our website or digital channels, e.g. type of device, version of browser and operating system.

If necessary in order to fulfill the purpose of the processing of personal data, in some cases we may also collect and process other types of personal data.

How do we protect your personal data?

We take measures to ensure that the personal data we process is always protected and that our processing is carried out in accordance with applicable data protection rules, as well as our internal guidelines and procedures. Information security and ensuring the appropriate protection of personal data are of the utmost importance to us. We strive to implement security measures in accordance with the ISO 27000 international standard, in order to determine the appropriate level of protection for data, and to prevent and detect disclosure of personal data to unauthorized parties.

Which recipients do we share your personal data with?

Below we describe which recipients we share your personal data with. The recipients with whom we share your personal data will depend on how you interact with us. Unless stated otherwise below, the recipient is responsible for their own processing of your personal data.

Service providers

In order to process personal data, we share personal data with service providers that we have hired. These service providers provide e.g. IT services. When the service providers process personal data on our behalf and in accordance with our instructions, they are data processors for us and we are responsible for the processing of your personal data. Service providers may not use your personal data for their own purposes and they are required by law and contractual obligations with us to protect your data.

Group companies

The companies in the Group work collaboratively and therefore share information with each other. To the extent that Group companies process personal data on our behalf and in accordance with our instructions, e.g. to manage the assignment, they are data processors for us and we are responsible for their processing of your personal data.

Intended purpose

Personal data

Legal basis
Communication between employees and third parties
  • Remuneration data
  • Billing data
  • Identity data
  • Communication
  • Contact details

Legitimate interest. The processing is necessary in order to satisfy our legitimate interest in the communication between employees and third parties.

Managing and meeting legal requirements

Only the categories of personal data that are necessary for managing and meeting the legal requirement on a case-by-case basis.

Legitimate interest. The processing is necessary in order to satisfy our legitimate interest in managing and meeting legal requirements.

Investigative and security reasons
  • Image and sound material
    Identity data
  • Incident data
  • Communication
  • Contact details
  • Billing data
  • Remuneration data
  • Log data
  • Profile data

Legitimate interest. The processing is necessary in order to fulfill our legitimate interest in processing personal data for investigative and security reasons. In the event that NCC processes data about criminal offenses (in accordance with Article 10 of the GDPR), such processing will take place in order to satisfy NCC’s legitimate interest in establishing, asserting or defending legal claims.

Managing whistleblowing reports
  • Identity data
  • Communication
  • Contact details
  • Profile data
  • Remuneration data
  • Billing data

Legitimate interest. The processing is necessary in order to fulfill our legitimate interest in processing personal data in order to manage whistleblowing reports.

Other categories of recipients

NCC may also disclose personal data to recipients outside the NCC Group such as:

Recipient

Intended purpose

Legal basis
Courts, mediators and representatives In order to establish, assert and defend legal claims

In order to satisfy our and your legitimate interest in having disputes settled by competent authorities.

Suppliers, customers
and partners

Managing our relationship with suppliers, customers and partners

To satisfy our legitimate interest in managing our relationship with suppliers, customers and partners.

Authorities and trade union organizations

To comply with legal obligations

To fulfill legal obligations (e.g. in the areas of taxation and labor law).

Business customers

To provide aggregated data regarding workplace accidents and near-accidents

To satisfy our legitimate interest in preventing workplace accidents and near-accidents.

Insurance companies

Establishing, asserting and defending legal claims

To satisfy our legitimate interest in establishing, asserting and defending legal claims.

Potential buyers

Implementing any divestment of all or parts of our business

In order to satisfy our legitimate interest in implementing any divestment.

Credit reference agencies and companies that perform background checks

Conducting credit checks in preparation for the customer/supplier relationship on legal entities, as well as background checks.

To satisfy our legitimate interest in conducting credit checks in preparation for the customer/supplier relationship with legal entities, as well as background checks.

Furthermore, NCC may disclose personal data to third parties such as IT suppliers, communication agencies and others who provide services who process personal data in accordance with NCC’s instructions and assignments.

Where do we process and store the personal data?

We always strive to store personal data within the EU. In some cases, your personal data is shared with recipients outside the EU/EEA, e.g. service providers hired by us.

To ensure that personal data is protected, we ensure that appropriate safeguards are in place with all service providers who process your personal data outside the EU/EEA, in light of the legislation of the recipient country. We normally enter into data transfer contracts that contain so-called standard contractual clauses for the transfer of personal data.

If you would like more information about the countries outside the EU/EEA to which we transfer your personal data, and the safeguards we have put in place to protect your personal data, please contact us.

How long do we store your personal data?

NCC retains your personal data for as long as necessary in order to fulfill the purposes set out in this information text, unless a longer retention period is required or permitted by local law to which NCC is subject. We use the following criteria to determine the retention period:

  • As long as we have an ongoing relationship with you (either as an individual or in your role as an employee of a firm hired by NCC);
  • as long as required by legal obligations to which NCC is subject (such as fiscal and accounting obligations);
  • as long as appropriate in light of our legal position (such as applicable provisions in statutes of limitations); and
  • as long as necessary for other legitimate business reasons (e.g. follow-up on supplier relationships and documentation of the business).