Skip to Main Content

Log In

Select Business Area

Search

Privacy Notice

Last Updated Date: July 10, 2026

United Kingdom and European Union (UK & EU) Privacy Notice

This Privacy Notice applies to personal data collected and processed by the European Wilmington Trust entities listed below in Section 7 for the purposes described in this document.

The terms “Wilmington Trust,” “we,” “us” or “our” in this Privacy Notice refers to the Controllers identified in Section 7.

This Privacy Notice explains what types of personal data we collect, how we use it, and the rights you have under applicable laws, including the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and the United Kingdom General Data Protection Regulation (“UK GDPR”).

This Privacy Notice may be amended or updated from time to time to reflect changes in our Personal Data processing activities, or changes in applicable law. When a change is made, we will post the updated version of this Privacy Notice to the Wilmington Trust website (Click Here). All changes will become effective as of the Last Updated Date indicated on this Privacy Notice. We encourage you to regularly check the website to review any changes that we make.

Please also refer to the following Privacy Policy and Notices for specific information relating to the following:

Section 1: Categories of Data Collected

We collect certain categories of Personal Data about you:

  • Personal Details: name, address (including country of residence and country of citizenship or nationality), date of birth, government issued identification number, passport identification information (including passport photo and number) and other Know Your Customer (KYC) information including utility bills and bank account statements.
  • Financial Details: percentage stake of beneficial ownership in financial vehicles, net worth, assets, liabilities, and annual income, and source of wealth.
  • Contact Details: company role, business address, business phone number, and business email address.

We collect Personal Data directly from you or your company representative. We also obtain Personal Data about you from third-party sources, but only where: 1. you have consented to us obtaining such Personal Data; 2. we have checked that these third parties have your consent to disclose such Personal Data; or 3. the third parties are otherwise legally permitted or required to disclose your Personal Data to us. We do not collect Special Categories of Personal Data for the processing purposes set forth in this Privacy Notice.

Section 2: Purposes of the Processing and Legal Basis for the Processing

We process your personal data for the purposes and legal reasons explained in this section.
 

1.      Processing of information is necessary for compliance with a legal obligation.

  • We process your Personal Data as necessary for compliance with our legal and regulatory obligations including applicable anti-terrorism and anti-money laundering laws and regulations as described in the next paragraph.
  • When we onboard you as a client, and regularly throughout our relationship, we process your Personal Data to comply with anti-terrorism and anti-money laundering laws and regulations. We will use your Personal Data to verify your identity in accordance with ‘Know Your Customer’ requirements and for screening against law enforcement agency sanctions lists. During these processes, the information provided to us is compared against information contained in databases maintained by third parties (including governmental authorities). We also check your information against publicly available sources. Through this process, we may find new details about you and combine them with the information you or your company representative provided.
  • We process your Personal Data as necessary for detecting, investigating, preventing, and reporting any actual or suspected violations of laws and regulations.
  • Failure to provide this information will prevent us from conducting business with you or your company.

 

2.      Processing of information is necessary for our legitimate interests considering your fundamental rights and freedoms.

We process your Personal Data based on our legitimate interests, provided these do not override your rights or freedoms. This includes:

  • Audits and Risk Management: When not already covered under legal obligations, we use your Personal Data to conduct audits and manage business risks, including security risks.
  • Legal Proceedings: We process your Personal Data if necessary for legal actions involving you or your company.
  • Business Communications: Where allowed by law, we may use your business contact details to communicate about your existing relationship or future opportunities. This can include newsletters, event invitations, or service updates. You can opt out of these emails by following the instructions in each message.
  • Protecting Your Rights: We take steps to ensure our processing is necessary and proportionate, and we give you the right to opt out or object as explained in Section 6.

 

3.      Processing of information for other purposes.

  • We use your personal information only for the purposes described in this Privacy Notice or those explained when we collect it. If we need to use it for other purposes allowed by law, we’ll make sure these purposes are compatible with what we’ve told you. Where the law requires, we’ll ask for your consent before any further processing.

Section 3: Disclosure of Personal Data

In accordance with applicable law, we may disclose your Personal Data to the following categories of recipients as identified below.

Group Companies and Affiliates which includes our related companies located in the United States, United Kingdom, and the European Economic Area (EEA).

Competent law enforcement body, governmental agency, court and judicial bodies which includes national and local government agencies, regulatory bodies, law enforcement agencies and courts where we believe disclosure is necessary (i) as a matter of applicable law or regulation; (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person.

Third Parties which includes Processors, service providers, auditors, attorneys, and other professional advisors that may be in countries outside of the United Kingdom or European Economic Area (EEA). These parties provide data processing services or handle your Personal Data for the purposes described in this Privacy Notice or explained when we collect it. Refer to Section 4 for more information on transfer of Personal Data outside of the United Kingdom or European Economic Area. Third Parties are subject to contractual obligations to only process the Personal Data in accordance with our instruction, and to use measures to protect the confidentiality and security of your Personal Data.

Actual or potential buyer (and its agents and advisors) in the event that we wish to sell or transfer all or any of our business or assets, we may disclose your Personal Data with the potential acquirer(s) (and its agents and advisers) provided we inform the buyer it must use your Personal Data only for the purposes disclosed in this Privacy Notice.

Any other person with your consent to the disclosure.

Section 4: Transfers of Personal Data outside of the United Kingdom or European Economic Area

As outlined in Section 3, to deliver our services and comply with applicable laws, we may transfer your personal data to jurisdictions outside the United Kingdom or the European Economic Area (EEA), including the United States. When such transfers occur, we implement appropriate safeguards to ensure that your personal data remains protected in accordance with this Privacy Notice.

When we share your personal data within our group, we make sure it stays protected. If the data comes from the EEA, we rely on the EU’s Standard Contractual Clauses, which require all group companies to follow EU data protection rules. If the data comes from the UK, we rely on the UK’s International Data Transfer Agreement or the UK Addendum to those clauses to meet UK data protection standards.

For transfers to third-party service providers and partners, we apply similar safeguards, including contractual commitments and, where applicable, adherence to approved data transfer frameworks.

Contact us if you would like more information.

Section 5: Data Retention

We retain your Personal Data for the duration of your client relationship with us. After the relationship ends, we will keep your data only for as long as necessary to fulfill the purposes outlined in this Privacy Notice and no longer than permitted by applicable laws and regulations. Specifically, we retain:

(i) Know Your Customer (KYC) information for a period of ten (10) years following termination of the client relationship.

(ii) Client transaction documents for a period of seven (7) years following termination of the client relationship.

(iii) Contact details of prospective clients for marketing purposes for a period of up to 2 years, even if no account relationship is established.

Section 6: Your Legal Rights

Depending on the laws that apply to you, you may have the following rights regarding your personal data:

  • Access – You can request a copy of the Personal Data we hold about you.
  • Correction – You can ask us to fix any inaccurate or incomplete Personal Data.
  • Deletion – You can ask us to delete your Personal Data.
  • Restriction – You can ask us to limit how we process and use your Personal Data.
  • Objection – You can object to us using your Personal Data for certain purposes.
  • Data Portability – You can ask us to transfer your Personal Data to another organization.
  • Complaints – You can file a complaint with a Data Protection Authority (DPA) (Find contact details for DPAs in the EEA here.)

We respond to all requests and complaints in line with applicable data protection laws. To make a request or submit a complaint, please use the contact details below.

Section 7: Controllers and Contact Details

This Privacy Notice is issued by the entities listed below, who are responsible for handling your personal data (“Controllers”). If you have any questions or concerns about how we manage your data, please contact our designated representative using the details provided below.

Name of Controller

  • Wilmington Trust SP Services (London) Limited
  • Wilmington Trust (London) Limited
  • Wilmington Trust SP Services (Dublin) Limited
  • Wilmington Trust SP Services (Frankfurt) GmbH
  • Wilmington Trust S.A.S
  • Wilmington Trust (Milano) S.r.l.

Controller Contact Information

Section 8: Defined Terms

Personal Data

  • Any information that can be used to identify an individual, directly or indirectly.

Processing

  • Operations, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Controller

  • The person or entity that determines the purposes and means of Processing Personal Data.

Processor

  • Any person or entity that Processes Personal Data on behalf of the Controller.

Special Categories of Personal Data

  • Race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sexual life, or sexual orientation data.

Section 9: Updates to this Privacy Notice

We may update this Privacy Notice occasionally to reflect changing legal, technical, or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws.