Financial Services

Employee Privacy Policy

MG Financial Services is committed to protecting the privacy and security of personal information relating to our employees, members and contractors. This policy explains what data we collect, why we collect it, how we use it, how long we keep it, and the rights you have under UK data protection law. We act as a Data Controller for our employee data.

How to contact us

If you have any questions about how we use your information, or want to exercise your rights over your information, you can contact us at:

Email: privacy@mgfinancialservices.uk

What information do we collect and process about you, what do we do with it and why?

When you work for us

In the process of working for us, we will collect and process personal information we need to meet our contractual, legal and regulatory obligations. Based on our legitimate interest we may use may IT providers, consultancy or other third parties to help meet these commitments. We keep employment data inline with our regulatory requirements this is typically 6 years after employment.

Employee data may include the following types of personal data:

Identity & Contact Data – name, address, email, phone number, date of birth, gender, marital status, emergency contact details.

Employment & HR Data – job title, department, employment history, right‑to‑work documentation, performance reviews, training records, disciplinary and grievance information, attendance, leave, sickness records.

Financial & Payroll Data – bank details, salary, bonuses, pension contributions, tax, NI, payroll deductions.

Regulatory & Compliance Data – FCA‑related fitness and propriety information, credit checks (where role‑appropriate), anti‑money‑laundering (AML) compliance data, records required for SMCR roles.

IT & Security Data - system login records, device identifiers, email and system usage logs,

Special Category Data (Processed Only When Necessary) - health information (e.g., sickness notes, occupational health reports), diversity and equal‑opportunity monitoring data.

Criminal disclosures - some senior and technical roles may require criminal records checks for financial crime and anti-fraud purposes.

Sharing your data

As part of our regulatory obligations we may share your data with public authorities such as the HMRC and the FCA. Based on legitimate interest we may also share your data with background-check providers, pension providers, insurers and payroll providers.

International Transfers

If any service providers store data outside the UK, we ensure appropriate safeguards such as UK GDPRapproved Standard Contractual Clauses are in place.

How do we look after your data?

We have strict contracts with anyone with whom we share information to ensure they take appropriate care of your data, in line with relevant data protection legislation including but not limited to the General Data Protection Regulation 2016, the UK Data Protection Act 2018 (supplemented by the Data Usage and Access Act 2025).

We take the security of your data very seriously. We ensure we have various security measures including but not limited to: encrypted systems, secure servers, access controls, staff training, supplier vetting, policies aligned with FCA expectations.

Your rights

Your personal data belongs to you. We use it to provide our products and services, comply with our legal obligations, and improve the way we work.

Transparency

You have the right to understand what personal data we hold about you, how and where we use it, how long we keep it, and who we share it with. This information is set out in the details of our data processing below.

Access

You have the right to request a copy of the personal data we hold about you. We may ask you to confirm your identity before releasing your data. If you need the information for a particular reason, please let us know, as this may help us respond more effectively. Please note that no one can force you to request a copy of your personal data, and no one should ask you to share it with them.

Correction

You have the right to ask us to correct your personal data if you believe it is incomplete or inaccurate. We may ask you to confirm your identity and provide evidence to support the changes you request.

Erasure and the right to be forgotten

You have the right to ask us to delete your personal data where we no longer need it. In some cases, we may need to keep certain information to meet our obligations to you, comply with the law, or protect your interests and ours.

Review of automated decision-making

You have the right to request human review of decisions made about you solely by automated means. We do not make any pure automated decisions without human review.

Restriction of processing

In certain circumstances, you have the right to ask us to stop processing your personal data. These circumstances include where:

* you dispute the accuracy of the information we hold about you, while we verify it;

* we no longer need the personal data and would normally delete it, but you want us to keep it without otherwise processing it, for example because you may need it for a legal claim; or

* you believe that processing your data may cause you substantial harm or distress and that our processing is not justified under the law.

Data portability

In some circumstances, you have the right to ask us to transfer your personal data directly to another service provider. This can only be done where it is technically possible for both us and the other service provider. We, and they, will let you know if this is possible.

Withdrawal of consent

In some cases, we will ask for your consent to process your personal data. Where we rely on your consent, you have the right to withdraw it at any time. If you do so, we will stop the relevant processing. We will explain the consequences of withdrawing consent when we ask for it and again if you ask to withdraw it.

Further information and complaints

If you would like to know more about our processing of your data or would like to exercise any of your rights, or make a complaint, you can email us at privacy@mgfinancialservices.uk

Complaints will be acknowledged as soon as possible and in no longer than 30 days. We will without undue delay take appropriate steps to respond, make appropriate enquires and keep you informed of progress and the result of the complaint.

You also have the right to make a complaint to the Information Commissioner’s Office – the supervisory authority that handles data protection law in the UK. You can contact them at:

https://ico.org.uk/make-a-complaint/

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Email: icocasework@ico.org.uk

Telephone: 0303 123 1113

Information
Contact

+44 20 8129 1756

© 2026. All rights reserved.

Your home or property may be repossessed if you do not keep up with repayments on your mortgage.

MG Financial Services is a trading name of MG Financial Services (PVT) Limited which is an appointed representative of MG Financial Services (PVT) Limited which are authorised and regulated by the Financial Conduct Authority. Our FCA number is 1053411. MG Financial Services (PVT) Limited Companies House number is 12541157.