GDPR Compliance

At Malone & Co., protecting personal data is an important part of how we work. We are committed to handling personal data responsibly, transparently and securely, in accordance with applicable data protection law.

This page provides an overview of our approach to data protection and the rights available to individuals. More detailed information about how and why we process personal data is available in our Privacy Notice.

Our data protection responsibilities

Malone & Co. processes personal data in accordance with the General Data Protection Regulation, the Data Protection Act 2018 and other applicable Irish and European data protection legislation.

Depending on the services being provided, one or more Malone & Co. entities may act as the data controller responsible for determining how and why personal data is processed. In certain circumstances, we may also process personal data on behalf of a client.

The relevant Malone & Co. entity and its role will depend on the nature of the engagement and the services being provided.

What is personal data?

Personal data is any information relating to an identified or identifiable individual.

This may include a person’s name, contact details, identification information, financial or tax information, payroll or employment information, online identifiers, correspondence and other information connected with the services we provide.

Some information is considered particularly sensitive under data protection law. This includes certain health information, biometric data and information revealing racial or ethnic origin, religious beliefs or trade union membership. We only process this type of information where there is an appropriate legal basis and suitable safeguards are in place.

How we use personal data

We may process personal data where necessary to:

  • provide accountancy, audit, tax, advisory, payroll and related professional services;
  • manage our relationship and communicate with clients;
  • meet legal, regulatory and professional obligations;
  • complete client onboarding, identification and compliance checks;
  • manage billing, administration and business records;
  • maintain the security of our systems, premises and services;
  • respond to enquiries and requests;
  • recruit employees and manage employment relationships;
  • send relevant business communications where permitted by law; and
  • establish, exercise or defend legal claims.

 

The lawful basis we rely upon will depend on the purpose and circumstances of the processing. This may include performance of a contract, compliance with a legal obligation, our legitimate interests, consent or another basis permitted by law.

How we protect personal data

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures are reviewed and updated where appropriate, taking account of the nature of the information, the risks associated with the processing and developments in technology.

Where third-party service providers process personal data on our behalf, we take appropriate steps to assess those providers and put suitable contractual and security arrangements in place.

Security cannot be guaranteed absolutely, but we work to ensure that the safeguards applied are appropriate to the risks involved.

Sharing personal data

We may share personal data with third parties where this is necessary for the services we provide, to operate our business, to meet a legal or regulatory obligation or for another lawful purpose.

Depending on the circumstances, these third parties may include:

  • professional advisers and specialist service providers;
  • technology, hosting and software providers;
  • banks and payment-service providers;
  • Revenue, the Companies Registration Office and other public authorities;
  • regulatory and professional bodies;
  • law-enforcement authorities, where required by law; and
  • other parties authorised by the individual or our client.

We do not disclose personal data to third parties unless there is an appropriate legal basis for doing so.

International transfers

Some service providers may process or store personal data outside the European Economic Area.

Where personal data is transferred internationally, we take appropriate steps to ensure that the transfer is carried out in accordance with data protection law. This may include relying on an adequacy decision, approved contractual protections or another lawful transfer mechanism.

This paragraph must be verified against your actual suppliers before publication.

How long we keep personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, regulatory, contractual and professional obligations.

Retention periods may vary depending on the type of information, the nature of the services provided and any relevant legal or regulatory requirements.

When personal data is no longer required, it is securely deleted, destroyed or anonymised in accordance with our retention procedures.

Your data protection rights

Subject to applicable conditions and exemptions, individuals may have the right to:

  • request access to their personal data;
  • request the correction of inaccurate or incomplete information;
  • request the deletion of personal data;
  • request that processing be restricted;
  • object to certain processing;
  • receive certain personal data in a structured, commonly used and machine-readable format;
  • withdraw consent at any time where processing is based on consent; and
  • raise concerns about how their personal data is being used.

 

Where automated decision-making or profiling has legal or similarly significant effects, individuals may also have rights relating to that processing. Malone & Co. should only retain this sentence if such processing exists or the firm wants to cover the position generally.

These rights are not absolute and may be limited in certain circumstances. For example, we may need to retain information to comply with a legal or regulatory obligation or to establish, exercise or defend legal claims.

Making a data protection request

To exercise a data protection right or ask a question about how we use personal data, please contact:

Email: info@maloneaccountants.ie
Post: Landscape House, Baldonnell Business Park, Dublin 22, D22 P3K7, Ireland
Telephone: +353 (0)1 4580911

Please use a dedicated privacy or data-protection email address here if Malone & Co. has one.

We may need to request additional information to confirm a person’s identity before responding. We will respond without undue delay and normally within one month, although this period may be extended where a request is particularly complex or where multiple requests have been made.

Complaints

If you have concerns about how we process your personal data, we encourage you to contact us first so that we can try to resolve the matter.

You also have the right to make a complaint to the Data Protection Commission:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland

Website: www.dataprotection.ie
Telephone: +353 1 765 0100

The DPC is Ireland’s supervisory authority for GDPR and has regulatory functions under the Data Protection Act 2018 and the ePrivacy Regulations.

Updates to this page

We may update this page from time to time to reflect changes in our practices, services or legal obligations.

Last updated: September 2026