Privacy Policy

This notice was last updated on 29 June 2026 to reflect the DIFC Laws Amendment Law No. 1 of 2025 (effective 8 July 2025).

1. Who We Are


MNA Risk Management Ltd (“MNA“, “we“, “us“, or “our“) is the data controller in respect of personal data collected through this website and in the course of providing our services.

Data Controller Details

  • Legal name: MNA Risk Management Ltd
  • Registered in: England & Wales
  • UK office: One Canada Square, London E14 5AB
  • DIFC office: DIFC Gate District, Dubai, UAE
  • DFSA regulated: Authorised firm within the Dubai International Financial Centre (DIFC)

Data Protection Officer

We have appointed a Data Protection Officer (DPO) as required by the DIFC Data Protection Law No. 5 of 2020.

 

2. Scope of This Notice


This Privacy and Cookie Notice applies to personal data collected through our website (www.mnarisk.com) and in the course of MNA’s provision of professional advisory services. It should be read alongside our full Data Protection Policy, available on request from our DPO.

This notice covers data processing subject to:

  • the DIFC Data Protection Law No. 5 of 2020 (as amended by DIFC Laws Amendment Law No. 1 of 2025, effective 8 July 2025) and the DIFC Data Protection Regulations 2020 (updated September 2023) — governing our DIFC operations; and
  • the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 — governing our UK operations.

The DIFC Data Protection Law applies to MNA as a controller incorporated in the DIFC, regardless of where personal data is processed.

 

3. Personal Data We Collect


When you visit our website

  • Technical data: IP address, browser type and version, device type, operating system, referring URL, and pages visited.
  • Usage data: time spent on pages, click paths, and interaction data.
  • Contact form submissions: name, email address, company name, telephone number, and any message you provide.
  • Cookie data: as described in Section 9 below.

When you engage with us professionally

  • Contact and identity details: name, professional title, business email, telephone, and business address.
  • KYC / AML information: identity verification documents, beneficial ownership information, and related regulatory documentation required under applicable AML obligations.
  • Engagement information: correspondence, meeting notes, instructions, and information provided during the course of an engagement.
  • Professional background: career history and areas of expertise relevant to the advisory relationship.

Special categories of personal data

We do not collect special categories of personal data (such as health, racial or ethnic origin, or political opinion) through our website. In exceptional engagement contexts where such data is relevant, we collect it only with explicit consent or under another lawful basis and with enhanced safeguards.

 

4. How We Use Your Personal Data


  • Responding to enquiries and providing information about our services.
  • Providing professional advisory, assurance, compliance, and financial services to clients.
  • Client onboarding, including KYC/AML verification as required by the DFSA and applicable law.
  • Managing our ongoing client relationships and communications.
  • Complying with legal and regulatory obligations, including reporting to the DFSA, FCA, DIFC Commissioner of Data Protection, and other competent authorities.
  • Sending relevant professional content, insights, and marketing communications to existing clients and professional contacts (you can opt out at any time).
  • Operating, improving, and securing our website and digital services.
  • Analytics and statistical analysis (using anonymised or aggregated data where possible).
  • Fraud prevention, security, and risk management.

 

5. Lawful Bases for Processing


We always process personal data on a recognised lawful basis. The bases we rely on are:

  • Contract performance — where processing is necessary to perform or prepare to perform a contract with you.
  • Legal obligation — where processing is required to comply with AML, regulatory, or other legal requirements.
  • Legitimate interests — where processing is necessary for MNA’s legitimate business interests (such as business development, fraud prevention, and improving our services), provided these are not overridden by your interests or rights.
  • Consent — where we have obtained your clear, specific consent, for example for non-essential cookies or certain marketing communications. You may withdraw consent at any time without detriment.

 

6. Who We Share Your Data With


We do not sell your personal data. We may share it with:

  • Trusted service providers acting as data processors on our behalf (cloud hosting, IT services, payroll, insurance) under data processing agreements.
  • Professional advisers including lawyers, auditors, and accountants, subject to confidentiality obligations.
  • Regulatory and law enforcement authorities, including the DFSA, FCA, DIFC Commissioner of Data Protection, UK ICO, and other competent bodies, where required by law or regulation.
  • Courts and dispute resolution bodies, where necessary for legal proceedings.
  • Other parties with your consent or as otherwise required or permitted by law.

 

7. International Transfers of Personal Data


MNA operates from offices in the DIFC (Dubai) and London. Your personal data may be transferred between these locations and to other countries where our clients, service providers, or regulators are based.

When transferring personal data internationally, we use appropriate safeguards, which may include:

  • transfers to countries with an adequacy determination from the DIFC Commissioner or UK Government;
  • DIFC Standard Contractual Clauses (under Article 27(2)(c) of the DIFC DP Law); or
  • UK International Data Transfer Agreements (UK IDTAs).

Further information on transfer safeguards is available from our DPO on request.

 

8. How Long Do We Keep Your Data


We retain personal data only for as long as necessary for the purposes described in this notice, or as required by applicable law and regulatory obligations. Key retention periods include:

  • Client and engagement records: 6 years from the end of the engagement.
  • AML / KYC records: 6 years from the end of the client relationship, as required by DFSA and DIFC AML rules.
  • Marketing contact data: until you object, or 3 years of inactivity — whichever is earlier.
  • Website and cookie data: as set out in Section 9 below.

On expiry of the applicable retention period, personal data is securely deleted or anonymised.

 

9. Cookies and Tracking Technologies


Our website uses cookies and similar technologies. A cookie is a small text file placed on your device when you visit a website. We use cookies to make our website work, to understand how visitors use it, and — with your consent — to provide a more personalised experience.

In accordance with the DIFC Data Protection Regulations 2020 (updated September 2023) and applicable UK law, we obtain your consent before placing non-essential cookies. You can manage your preferences at any time using the cookie settings link in our banner or site footer.

Types of cookies we use

Cookie Type Purpose Duration Consent Required?
Essential Necessary for the website to function. These enable core functionality such as security, navigation, and accessibility. They cannot be disabled. Session / up to 12 months No — strictly necessary
Analytics Help us understand how visitors interact with our website by collecting anonymous usage data — pages visited, time spent, error encounters. We use this to improve the site. Up to 24 months Yes — opt-in required
Preferences Remember your preferences and settings (such as language, region, and cookie choices) to improve your experience on return visits. Up to 12 months Yes — opt-in required

We do not currently use third-party advertising or behavioural tracking cookies. If this changes, we will update this notice and seek your consent before placing any such cookies.

Managing cookies: You can withdraw consent or manage your cookie preferences at any time by clicking the Cookie Settings link in our site footer. You can also manage cookies through your browser settings — please note that disabling essential cookies may affect the functionality of this website.

 

10. Your Data Subject Rights


Under the DIFC Data Protection Law No. 5 of 2020 (as amended) and the UK GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, please contact our DPO at a.chen@mnarisk.com. We will respond within 30 days (extendable by 60 days in complex cases).

Right to be Informed
To receive clear information about how your personal data is used — fulfilled by this notice.
Right of Access
To receive a copy of the personal data we hold about you (a Subject Access Request).
Right to Rectification
To have inaccurate or incomplete personal data corrected or completed.
Right to Erasure
To have your personal data deleted where it is no longer necessary, subject to legal retention obligations.
Right to Restriction
To limit how we process your data in certain circumstances, for example while accuracy is contested.
Right to Portability
To receive your personal data in a structured, machine-readable format to transfer to another controller.
Right to Object
To object to processing based on legitimate interests or direct marketing — direct marketing objections are always honoured immediately.
Right to Complain
To lodge a complaint with the DIFC Commissioner of Data Protection or the UK ICO, and (under the July 2025 amendments) to bring a direct claim in the DIFC Courts.

No fee is charged to exercise these rights unless requests are manifestly unfounded, excessive, or repetitive. We may request proof of identity before processing your request.

 

11. Security


We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These include access controls, encryption, secure cloud hosting, staff training, and regular security testing. Notwithstanding these measures, no system is entirely secure, and we cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, as required by the DIFC DP Law and UK GDPR.

 

12. Contact, Supervisory Authorities & Complaints


Contact our Data Protection Officer

For any questions about this notice, to exercise your data subject rights, or to raise a data protection concern:

  • Email: a.chen@mnarisk.com
  • Post (Dubai): Alexandra Chen — DPO, MNA Risk Management Ltd, DIFC Gate District, Dubai, UAE
  • Post (London): Alexandra Chen — DPO, MNA Risk Management Ltd, One Canada Square, London E14 5AB

DIFC Commissioner of Data Protection

If you are dissatisfied with our response, or wish to raise a concern directly with the supervisory authority for our DIFC operations, you may contact the DIFC Commissioner of Data Protection. You also have the right, following the DIFC Laws Amendment Law No. 1 of 2025 (effective 8 July 2025), to bring a direct civil claim in the DIFC Courts without first filing a regulatory complaint.

UK Information Commissioner’s Office (ICO)

For matters relating to our UK operations, you may contact the UK ICO:

  • Website: ico.org.uk
  • Telephone: 0303 123 1113

Changes to this Notice

We may update this Privacy and Cookie Notice from time to time to reflect changes in law, our practices, or our business. The current version and its effective date are always displayed at the top of this page. Where changes are material, we will notify you by email (if we hold your email address) or by a prominent notice on our website.

x

x

MNA Risk & Technology Advisory provides independent technology audit and assurance to regulated and high-growth organisations. We combine deep IT and cyber expertise with audit discipline — giving boards confidence that technology risk is understood and controlled. learn more…

Contact us

Unit RT-208, Level 1 Gate Avenue – South Zone, Dubai International Financial Centre, UAE.

Call us: +971 55618 4721

Mon – Sat: 8.00am – 18.00pm