At Malone & Co., protecting personal data is an important part of how we work. We are committed to handling personal data responsibly, transparently and securely, in accordance with applicable data protection law.
This page provides an overview of our approach to data protection and the rights available to individuals. More detailed information about how and why we process personal data is available in our Privacy Notice.
Malone & Co. processes personal data in accordance with the General Data Protection Regulation, the Data Protection Act 2018 and other applicable Irish and European data protection legislation.
Depending on the services being provided, one or more Malone & Co. entities may act as the data controller responsible for determining how and why personal data is processed. In certain circumstances, we may also process personal data on behalf of a client.
The relevant Malone & Co. entity and its role will depend on the nature of the engagement and the services being provided.
Personal data is any information relating to an identified or identifiable individual.
This may include a person’s name, contact details, identification information, financial or tax information, payroll or employment information, online identifiers, correspondence and other information connected with the services we provide.
Some information is considered particularly sensitive under data protection law. This includes certain health information, biometric data and information revealing racial or ethnic origin, religious beliefs or trade union membership. We only process this type of information where there is an appropriate legal basis and suitable safeguards are in place.
We may process personal data where necessary to:
The lawful basis we rely upon will depend on the purpose and circumstances of the processing. This may include performance of a contract, compliance with a legal obligation, our legitimate interests, consent or another basis permitted by law.
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures are reviewed and updated where appropriate, taking account of the nature of the information, the risks associated with the processing and developments in technology.
Where third-party service providers process personal data on our behalf, we take appropriate steps to assess those providers and put suitable contractual and security arrangements in place.
Security cannot be guaranteed absolutely, but we work to ensure that the safeguards applied are appropriate to the risks involved.
We may share personal data with third parties where this is necessary for the services we provide, to operate our business, to meet a legal or regulatory obligation or for another lawful purpose.
Depending on the circumstances, these third parties may include:
We do not disclose personal data to third parties unless there is an appropriate legal basis for doing so.
Some service providers may process or store personal data outside the European Economic Area.
Where personal data is transferred internationally, we take appropriate steps to ensure that the transfer is carried out in accordance with data protection law. This may include relying on an adequacy decision, approved contractual protections or another lawful transfer mechanism.
This paragraph must be verified against your actual suppliers before publication.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, regulatory, contractual and professional obligations.
Retention periods may vary depending on the type of information, the nature of the services provided and any relevant legal or regulatory requirements.
When personal data is no longer required, it is securely deleted, destroyed or anonymised in accordance with our retention procedures.
Subject to applicable conditions and exemptions, individuals may have the right to:
Where automated decision-making or profiling has legal or similarly significant effects, individuals may also have rights relating to that processing. Malone & Co. should only retain this sentence if such processing exists or the firm wants to cover the position generally.
These rights are not absolute and may be limited in certain circumstances. For example, we may need to retain information to comply with a legal or regulatory obligation or to establish, exercise or defend legal claims.
To exercise a data protection right or ask a question about how we use personal data, please contact:
Email: info@maloneaccountants.ie
Post: Landscape House, Baldonnell Business Park, Dublin 22, D22 P3K7, Ireland
Telephone: +353 (0)1 4580911
Please use a dedicated privacy or data-protection email address here if Malone & Co. has one.
We may need to request additional information to confirm a person’s identity before responding. We will respond without undue delay and normally within one month, although this period may be extended where a request is particularly complex or where multiple requests have been made.
If you have concerns about how we process your personal data, we encourage you to contact us first so that we can try to resolve the matter.
You also have the right to make a complaint to the Data Protection Commission:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland
Website: www.dataprotection.ie
Telephone: +353 1 765 0100
The DPC is Ireland’s supervisory authority for GDPR and has regulatory functions under the Data Protection Act 2018 and the ePrivacy Regulations.
We may update this page from time to time to reflect changes in our practices, services or legal obligations.
Last updated: September 2026