Official Compliance RecordVersion 3.2 • Effective Jan 2025
Contact Advisory Team

Privacy Policy & Data Protection Notice

Henrietta Lescalier Risk Advisory operates structured advisory services across the UK and Middle East. This document outlines our commitment to transparency, lawful processing, and technical security under UK GDPR and DIFC Data Protection standards.

Dual Jurisdiction Alignment

Governed under UK GDPR, Data Protection Act 2018, and DIFC Law No. 5.

Institutional Encryption

AES-256 data protection at rest and TLS 1.3 transit security protocols.

Defensible Governance

Structured audit trails, minimal retention periods, and rapid DSAR processing.

1. Data Controller Information

Clause 1.0

Identification of the joint data controller entities across UK and UAE operations.

Henrietta Lescalier Risk Advisory operates as an online business consultancy specializing in risk, regulation, and compliance across the United Kingdom and the Middle East. For the purposes of applicable data protection legislation, Henrietta Lescalier Risk Advisory acts as the Data Controller responsible for determining the means and purposes of personal data processing. Our operations span central advisory offices in the City of London (UK) and regional compliance desks within the Dubai International Financial Centre (DIFC, Dubai, UAE).

2. Lawful Basis for Processing

Clause 2.0

Statutory compliance under UK GDPR, Data Protection Act 2018, and DIFC Data Protection Law No. 5 of 2020.

We process personal data strictly in accordance with recognized international data protection frameworks, including the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018, and DIFC Data Protection Law No. 5 of 2020. Our lawful bases comprise: (a) Performance of Contract: executing consultancy and regulatory audit agreements; (b) Legal Obligation: satisfying anti-money laundering (AML), customer due diligence, and financial regulatory filings; (c) Legitimate Interests: assessing corporate risk exposures, client onboarding, and maintaining advisory platform security; and (d) Consent: for specific opt-in advisory publications and direct communication requests.

UK Framework
UK GDPR & Data Protection Act 2018 under ICO regulatory authority.
Middle East (DIFC)
DIFC Data Protection Law No. 5 of 2020 via DIFC Commissioner.

3. Categories of Personal Data Collected

Clause 3.0

Specific personal, business identity, and engagement records maintained.

In providing our risk and compliance consultancy services, we collect: (1) Identity and Contact Data: Full name, business email, corporate phone number, professional title, and company address; (2) Advisory & Corporate Engagement Data: Compliance documentation, regulatory correspondence, supervisory questionnaire responses, and risk governance records; (3) Technical & Communication Data: Consultation booking details, secure form submissions, IP addresses, and digital interaction records.

4. How We Use Your Information

Clause 4.0

Systematic utilization for advisory fulfillment, regulatory verification, and client liaison.

Your data is utilized strictly to: (i) deliver bespoke risk management, compliance reviews, and licensing advisory engagements; (ii) process consultations, inquiries, and contractual engagements requested through our digital channels; (iii) fulfill statutory reporting and oversight requirements stipulated by relevant financial supervisory bodies; and (iv) enhance our diagnostic toolsets and maintain data governance integrity.

5. International Data Transfers

Clause 5.0

Cross-border data protection mechanisms between the UK, DIFC, and international hubs.

Because our consulting services operate cross-border between the United Kingdom and the Middle East (specifically the UAE / DIFC), personal data may be accessed across these jurisdictions. We implement strict safeguards ensuring equivalent levels of protection, including the UK International Data Transfer Addendum, European Commission Standard Contractual Clauses (SCCs), and DIFC Commissioner of Data Protection approved cross-border transfer agreements.

6. Data Retention & Technical Security

Clause 6.0

Encryption standards, access controls, and defensible audit retention timelines.

We implement institutional-grade technical and organizational measures, including TLS 1.3 encryption in transit, AES-256 encryption at rest, role-based access restrictions, and immutable audit logs. In accordance with professional standards for financial advisory firms, client engagement records are retained for a minimum statutory period of seven (7) years following the conclusion of the advisory engagement, after which they are securely scrubbed or permanently anonymized.

7. Your Data Subject Rights

Clause 7.0

Enforceable individual rights under UK and DIFC privacy statutes.

Under UK GDPR and DIFC Data Protection Law, you retain distinct statutory rights, including: the Right of Access (to obtain copies of personal records held); the Right to Rectification (to correct incomplete or inaccurate data); the Right to Erasure ('Right to be Forgotten'); the Right to Restriction of Processing; the Right to Object to processing under legitimate interests; and the Right to Data Portability. Exercising these rights requires formal identity verification to preserve confidentiality.

8. Contact, Supervisory Authority & Complaints

Clause 8.0

Official contact details for data protection officers and supervisory escalation channels.

For questions regarding this Privacy Policy, or to submit a formal Data Subject Access Request (DSAR), please contact our Data Protection Team at [email protected]. If you believe your data has been handled inconsistently with applicable laws, you retain the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or the DIFC Commissioner of Data Protection.

Need Clarification on Our Regulatory Posture?

Our risk advisory practice conducts continuous compliance reviews to ensure absolute alignment with evolving UK PRA/FCA requirements and DIFC DFSA supervisory guidelines. Reach out directly for compliance assessments or specific data transfer agreements.