Privacy Notice
Last updated: August 2026
This Notice explains how Panterra collects, uses, shares, stores and protects personal data relating to clients, prospective clients, suppliers, experts, government and public-sector contacts, academics, journalists, website visitors, business contacts and other third parties. It replaces Panterra's previous external privacy notice.
1. About this Notice
References in this Notice to "Panterra", "we", "us" and "our" have the meaning given in section 2.
This Notice applies to personal data about individuals outside Panterra's workforce. Personal data concerning employees, contractors and workers is addressed in Panterra's separate Global Workforce Privacy Notice.
Panterra operates internationally. The privacy law that applies to a particular activity may depend on the relevant Panterra entity, where the individual is located, where processing takes place and the nature of the activity. In this Notice, "Applicable Data Protection Law" means the data protection and privacy law applicable to the relevant processing, including, where applicable, the UK GDPR and Data Protection Act 2018, EU GDPR, ADGM Data Protection Regulations 2021, the California Consumer Privacy Act as amended by the CPRA, and other applicable US federal, state or local privacy laws.
Where a local law gives you greater protection than this Notice, the local law will prevail. Sections 14 to 16 contain jurisdiction-specific information that supplements the global provisions.
2. Who is responsible for your personal data
Panterra operates internationally through a group of affiliated companies (the "Panterra Group"). Depending on the circumstances, the controller responsible for your personal data will ordinarily be the Panterra entity with which you or the organisation you represent interacts, or the Panterra entity responsible for the relevant processing activity.
The Panterra Group includes:
- Panterra Holdings Ltd (United Kingdom), company number 11545645;
- Panterra Global Limited (United Kingdom), company number 04454838;
- Project Associates EU SRL trading as Panterra (Belgium), company number 0708.896.190;
- Panterra Holdings Inc. (United States), FEIN 99-1275932;
- Panterra Inc. (United States), FEIN 84-2411515;
- Panterra LLC (United States), FEIN 99-1322639; and
- Panterra Limited (Abu Dhabi Global Market, United Arab Emirates), company number 28298.
In some circumstances, more than one Panterra Group company may process your personal data as a separate controller or, where applicable, as a joint controller. This may occur, for example, where processing is undertaken for group-wide administration, client delivery, business development, compliance, security or other shared purposes.
References in this Notice to "Panterra", "we", "us" or "our" mean the relevant Panterra Group company or companies responsible for the processing in question.
If you would like to know which Panterra entity is responsible for processing your personal data in a particular case, please contact the Data Protection Manager using the details in section 13.
3. Personal data we collect
Depending on your relationship with Panterra and the circumstances, we may collect the following categories of personal data:
| Category | Examples |
|---|---|
| Identity and contact information | Name, title, employer or organisation, role, postal address, email address, telephone number and other business contact details. |
| Professional and biographical information | Career history, qualifications, expertise, memberships, publications, areas of interest, professional profile and publicly available professional information. |
| Communications and relationship information | Emails, correspondence, meeting notes, event attendance, preferences, enquiries, introductions and records of interactions with Panterra. |
| Client, supplier and contractual information | Information relating to engagements, projects, proposals, contracts, instructions, deliverables, supplier relationships and business administration. |
| Financial and transaction information | Billing, payment, bank or transaction information where relevant to a client, supplier or other business relationship. |
| Website, device and technical information | IP address, device and browser information, website usage, logs, cookie or similar technology information and security data, subject to applicable law and our Cookie Notice. |
| Marketing and preference information | Communications preferences, event interests, subscription preferences and records of marketing engagement. |
| Due diligence, legal and compliance information | Sanctions, conflicts, regulatory, fraud-prevention, litigation, complaints and other compliance information where lawful and relevant. |
| Public-source information | Information from public registers, government sources, websites, media, professional networks, publications and other lawfully accessible sources. |
| Sensitive or special category information | Panterra does not ordinarily seek to collect or process sensitive or special category personal information about individuals covered by this Notice. We ask that you do not provide such information unless it is necessary for a particular purpose and Panterra has requested it or otherwise agreed to receive it. |
4. How we collect personal data
We may collect personal data:
- directly from you, including through correspondence, meetings, events, forms, enquiries or contractual dealings;
- from your employer, organisation, colleagues or representatives;
- from Panterra clients, prospective clients, introducers, suppliers and business partners;
- from public registers, government bodies, regulators, public websites, media, professional networks, publications and other publicly available sources;
- from professional advisers, research or data providers and due-diligence providers where lawful;
- from other Panterra group companies; and
- automatically when you use our websites or digital services, including through cookies, logs and similar technologies as described in our Cookie Notice.
Where we obtain personal data from someone other than you, we will provide any additional information required by Applicable Data Protection Law, subject to applicable exemptions.
5. How and why we use personal data
Panterra uses personal data only where it has an appropriate legal basis or other lawful authority under Applicable Data Protection Law. Depending on the jurisdiction and circumstances, this may include performance of or steps relating to a contract, compliance with legal obligations, legitimate interests that are not overridden by your rights, protection of vital interests, performance of tasks permitted by law, recognised legitimate interests under UK law where applicable, or consent where consent is appropriate and valid.
| Purpose | What we do | Typical basis / authority where applicable |
|---|---|---|
| Client and project delivery | Provide advisory, communications and other services; manage instructions, projects, stakeholders, research and deliverables. | Contract; legitimate interests; legal obligation where applicable. |
| Relationship management | Communicate with clients, prospective clients, suppliers, experts, officials, academics, journalists and other professional contacts. | Legitimate interests; contract where applicable. |
| Business development and proposals | Prepare proposals and credentials; identify opportunities; maintain professional contact information and relationships. | Legitimate interests; consent where required. |
| Events and professional communications | Invite relevant contacts to events and communicate about Panterra, clients, public and economic policy, areas of professional interest, organisations and individuals. | Legitimate interests; consent where required by marketing/e-privacy law. |
| Supplier and business administration | Administer suppliers, contracts, payments, finance, records and operational functions. | Contract; legitimate interests; legal obligation. |
| Legal, regulatory and compliance | Comply with law, regulation, sanctions and court requirements; prevent fraud; conduct due diligence; establish, exercise or defend legal claims. | Legal obligation; legitimate interests; recognised legitimate interests or other statutory authority where applicable. |
| Security and business continuity | Protect people, premises, systems and information; investigate incidents; maintain backups and business continuity. | Legitimate interests; legal obligation; recognised legitimate interests where applicable. |
| Website operation and analytics | Operate, secure and improve our websites and understand usage, subject to cookie and e-privacy requirements. | Legitimate interests; consent or statutory cookie exemption where applicable. |
| Corporate transactions | Evaluate or implement a merger, acquisition, financing, restructuring, investment or sale of business/assets. | Legitimate interests; legal obligation where applicable. |
Where we rely on legitimate interests, those interests may include delivering and developing our services, maintaining professional relationships, managing Panterra's business, communicating with relevant stakeholders, ensuring security, preventing fraud, protecting legal rights and administering the Panterra group. We consider whether those interests are overridden by the rights and interests of affected individuals.
6. Marketing, events and professional communications
Panterra may use business contact information to send relevant professional communications, event invitations and information about Panterra, our services or matters connected with your professional interests where permitted by Applicable Data Protection Law and applicable electronic marketing rules.
You may opt out of marketing communications at any time by contacting datamanager@panterra.global. An opt-out from marketing will not prevent Panterra from sending service, contractual, legal or other non-marketing communications where appropriate.
7. Sharing personal data
Panterra may share personal data where necessary and lawful with:
- other Panterra group companies for client delivery, group management, finance, legal, compliance, IT, security, business development and operational purposes;
- clients and prospective clients where necessary for the relevant engagement, proposal, communication or legitimate business purpose;
- suppliers and service providers, including cloud, IT, communications, CRM, event, research, data, payment, accounting and security providers;
- professional advisers, auditors, insurers and consultants;
- journalists, media organisations, public policy or academic researchers, experts, associates and other relevant stakeholders where appropriate to the services Panterra provides;
- government departments, regulators, courts, law enforcement and other public authorities where required or permitted by law; and
- prospective purchasers, investors, lenders and advisers in connection with a corporate transaction, financing, restructuring or due-diligence exercise.
Where a service provider processes personal data on Panterra's behalf, Panterra requires appropriate contractual, confidentiality, security and data protection obligations. We do not permit processors to use personal data for unrelated purposes except where independently permitted or required by law.
Panterra does not sell personal data or share it for cross-context behavioural advertising. If this practice changes in a jurisdiction that provides an opt-out right, Panterra will provide the required notice and choice before doing so.
8. International transfers
Panterra operates internationally and uses global service providers. Personal data may therefore be transferred to, stored in or accessed from countries other than the country in which you are located. Those countries may have different data protection laws.
Where Applicable Data Protection Law restricts international transfers, Panterra will use an approved transfer mechanism or other lawful safeguard. Depending on the originating jurisdiction, this may include an adequacy decision or designation, EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, ADGM Standard Contractual Clauses or another legally recognised safeguard. Panterra may rely on a statutory derogation where appropriate.
You may contact the Data Protection Manager for further information about safeguards relevant to your personal data, subject to lawful confidentiality restrictions.
9. Security
Panterra uses appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include access controls, secure configuration, encryption, monitoring, backups, incident response, vendor due diligence, confidentiality obligations and staff training.
Access to personal data is limited to people who need it for legitimate business or legal purposes. Staff and service providers are required to handle personal data in accordance with applicable confidentiality, information security and data protection requirements.
10. Retention and deletion
Panterra retains personal data only for as long as reasonably necessary for the purposes for which it was collected, including to satisfy legal, regulatory, tax, accounting, contractual, security and claims-management requirements. Retention periods vary according to the category of information and applicable law.
| Category | Indicative retention approach |
|---|---|
| Contract and client/supplier records | Normally up to 7 years after the relevant relationship or contract ends, unless a different period is required or justified. |
| Tax, accounting and transaction records | For the period required by applicable tax and accounting law, commonly 6 to 8 years depending on jurisdiction. |
| General professional contact and marketing information | Normally while the relationship remains active and for up to 3 years after the last meaningful interaction, subject to suppression records and applicable law. |
| Event records | For a period reasonably necessary to administer the event and related professional relationship, subject to legal or business requirements. |
| Website and security logs | For a period proportionate to security, analytics, audit and operational needs, subject to applicable law and cookie settings. |
| Legal, compliance and due-diligence records | For the period necessary to meet legal/regulatory obligations and applicable limitation periods. |
Panterra may retain records longer where reasonably necessary for litigation, investigations, regulatory enquiries, legal holds or the establishment, exercise or defence of legal claims. When data is no longer required, Panterra will delete, anonymise or securely dispose of it in accordance with its retention procedures.
11. Your privacy rights
Your rights depend on the law applicable to the relevant processing. Subject to statutory conditions and exceptions, you may have rights to:
- be informed about how your personal data is used;
- request access to your personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion or erasure of personal data;
- request restriction of processing;
- object to processing, including processing based on legitimate interests and direct marketing;
- receive or transfer certain personal data in a portable format;
- withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing;
- exercise any opt-out, limitation or similar privacy rights provided by local law, where applicable;
- appeal certain decisions on privacy rights requests where applicable; and
- make a complaint to the competent data protection authority or regulator.
Panterra will not discriminate or retaliate against you for exercising a privacy right protected by law. Some rights do not apply in every jurisdiction or to every processing activity, and Panterra may need to verify your identity before responding.
12. Cookies and website technologies
Panterra's website uses cookies for purposes including website functionality, security and, where applicable, analytics. For information about the technologies we use, their purposes, applicable retention periods and the choices available to you, please refer to the Cookie Policy on our website (www.panterra.global).
13. Contacting Panterra and complaints
Questions, privacy rights requests and concerns about the handling of personal data should be directed to:
Where Applicable Data Protection Law gives you a right to complain to a regulator, you may contact the authority competent for your location or the relevant Panterra entity. The jurisdiction-specific sections below identify key regulators. Panterra encourages you to contact the Data Protection Manager first so that we have an opportunity to address your concern.
Where Panterra is required to notify a personal data breach, it will notify the competent regulator and affected individuals in accordance with the applicable legal thresholds and time limits.
14. United Kingdom and European Economic Area supplement
Where the UK GDPR or EU GDPR applies, this section supplements the global Notice.
14.1. Controller and lawful bases
The relevant Panterra entity is the controller for the processing for which it determines the purposes and means. Other Panterra group companies may be separate or joint controllers for group-level processing. Panterra will rely on one or more lawful bases under applicable UK or EEA data protection law, which may include performance of a contract or steps before entering into a contract, compliance with a legal obligation, legitimate interests, vital interests, performance of a task in the public interest or exercise of official authority where applicable, recognised legitimate interests under UK law where applicable, and consent in limited circumstances.
Where legitimate interests are relied on, the interests may include client delivery, professional relationship management, business administration and development, direct marketing where permitted, intra-group administration, security, fraud prevention and protecting Panterra's legal rights. Under UK law, recognised legitimate interests may apply to specified processing permitted by the UK GDPR as amended by the Data (Use and Access) Act 2025.
14.2. Special category and criminal offence data — exceptional processing
Panterra does not ordinarily seek to collect or process special category personal data about individuals covered by this Notice. If such processing becomes necessary in a particular case, Panterra will do so only where permitted by applicable UK or EEA data protection law, will identify an applicable Article 9 condition and any additional national-law condition, and will provide any additional information required by law. Criminal offence data will be processed only where an Article 10 basis and any required national-law condition are satisfied.
14.3. International transfers
Restricted transfers from the UK or EEA will use an applicable adequacy decision or appropriate safeguard, which may include EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with any required risk assessment or supplementary measures.
14.4. Regulatory complaints
In the United Kingdom, you may complain to the Information Commissioner. In the EEA, you may complain to the supervisory authority in the country where you live, work or consider an infringement has occurred.
15. ADGM / United Arab Emirates supplement
Where Panterra Limited (ADGM company number 28298) processes personal data within the scope of the ADGM Data Protection Regulations 2021 ("ADGM DPR"), this section supplements the global Notice.
15.1. Controller and lawful bases
Panterra Limited is the controller for processing for which it determines the purposes and means. Panterra will process personal data only where an available legal basis under the ADGM DPR applies. Depending on the circumstances, this may include processing necessary for the performance of a contract or to take steps at your request before entering into a contract, compliance with a legal obligation, pursuit of Panterra's legitimate interests or those of a third party where those interests are not overridden by your interests or fundamental rights, protection of vital interests, or consent where consent is appropriate and valid. Where applicable, processing may also be carried out where necessary for a task in the interests of ADGM or in connection with the exercise of functions or powers conferred by ADGM law on an ADGM authority.
15.2. Sensitive personal data — exceptional processing
Panterra does not ordinarily seek to collect or process Sensitive Personal Data about individuals covered by this Notice. If such processing becomes necessary in a particular case, Panterra will do so only where permitted by the ADGM DPR, will identify any additional condition required by the ADGM DPR, apply appropriate safeguards and provide any additional information required by law.
15.3. Individual rights
Subject to the ADGM DPR, individuals may have rights including information, access, rectification, erasure, restriction, portability, objection and rights relating to automated decision-making. Requests may be subject to statutory conditions or restrictions.
15.4. International transfers
Where personal data is transferred from ADGM to a recipient outside ADGM, Panterra will use an available transfer mechanism under the ADGM DPR, such as transfer to a jurisdiction designated as adequate by the ADGM Commissioner of Data Protection, ADGM Standard Contractual Clauses or another recognised safeguard or derogation.
15.5. Regulatory complaints
Where the ADGM DPR applies, you may raise a concern with the ADGM Office of Data Protection / Commissioner of Data Protection. Panterra encourages you to contact the Data Protection Manager first so that we have an opportunity to address the issue.
16. United States and California supplement
United States privacy rights vary by state and by the type of information involved. The global Notice applies to individuals in the United States together with the additional provisions below where applicable.
16.1. General United States privacy
Panterra collects, uses and discloses personal information for the business purposes described in this Notice and will comply with applicable federal, state and local laws governing privacy, electronic communications, security breach notification and other applicable privacy requirements.
16.2. California
If you are a California resident and Panterra is a "business" subject to the California Consumer Privacy Act ("CCPA") with respect to your personal information, this Notice is intended to provide the disclosures required by the CCPA, including a notice at collection to the extent permitted by law. The categories of personal information collected, sources, purposes, recipients and retention approach are described in sections 3 to 10 above.
Depending on the circumstances and statutory exceptions, California residents may have rights to know/access, delete, correct, opt out of sale or sharing, and be free from discrimination for exercising CCPA rights. Panterra does not sell personal information or share it for cross-context behavioural advertising. Panterra does not ordinarily seek to collect or process sensitive personal information about individuals covered by this Notice. If that changes and California law provides a right to limit the relevant use or disclosure, Panterra will provide the required notice and mechanism.
To exercise a California privacy right, contact datamanager@panterra.global. Panterra may verify your identity and will recognise authorised agents where required by the CCPA. Requests are subject to applicable exceptions and response periods.
16.3. Other US states
State privacy laws differ in their scope and exemptions. Where a state law applies to personal information processed by Panterra and grants additional rights, Panterra will honour those rights and provide any additional notice or choice required by law.
17. Changes to this Notice
Panterra may amend this Notice to reflect changes in law, technology, business practices or our processing activities. Where a change materially affects how personal data is used, Panterra will provide appropriate notice before the change takes effect where required by law.