Safeguarding and Security Privacy Notice
The date this privacy notice was last revised was 20 December 2024.
Privacy notice
This notice explains how Westfield Europe Limited (referred to in this notice as we, us or our) collects and uses personal information in our shopping centres for security and safeguarding purposes. Security relates to the prevention and detection of alleged or actual criminal activity. Safeguarding refers to the collection of personal information on accidents and incidents within our centres. The notice also covers the processing of personal data on exclusion orders.
This notice covers the following:
How do we collect personal information?
What information do we collect?
How do we use your information?
What is the legal basis that permits us to use your information?
What happens if you do not provide information that we request?
How do we share your personal information?
How do we keep your personal information secure?
When do we transfer your personal information overseas?
For how long do we keep your personal information?
Your rights in relation to your personal information
The Table at the end of this notice provides an overview of the personal information that we collect, the purposes for which we use that data, the legal basis which permits us to use your personal information and the rights that you have in relation to your personal information.
Contact details
Our contact details are as follows:
Address: UK Data Protection Team, 4th Floor, 1 Ariel Way, London, W12 7SL and/or dpo@urw.com
We have appointed a Data Protection Officer (DPO) who has responsibility for advising us on our data protection obligations. You can contact the DPO c/o the above address or by using the above email.
What is personal information?
Personal information is any information that tells us something about you. This could include information such as your name, contact details, images captured on Closed Circuit Television Video (CCTV), Body Worn Video (BWV), photographs and pertinent information on accident/injuries and alleged or actual incidents or criminal activity within our centres. This could include health and medical related information.
How do we collect personal information?
We collect personal information about you from various sources including but not limited to:
What personal information do we collect?
We collect the following categories of personal information:
How do we use your personal information?
We use your personal information for the following purposes:
What is the legal basis that permits us to use your personal information?
Under data protection legislation we are only permitted to use your personal information if we have a legal basis for doing so. We rely on the following legal bases to use your personal information for security and safeguarding purposes where:
The Table at the end of this notice provides more detail about the personal information that we use, the legal basis that we rely on in each case and your rights.
What happens if you do not provide personal information that we request?
Where we are legally obliged to collect personal information the provision of this information will be mandatory.
For alleged or actual criminal activity, personal information may be collected by the Police where refused to be provided to us.
Failure to provide personal information which you later rely upon in preparing or making a legal claim could result in your claim being dismissed and/or unsuccessful.
How do we share your personal information?
We may share personal information in the following ways:
How do we keep your personal information secure?
At Westfield we take the security of all the personal information we hold very seriously. We are committed to protecting your personal information and implement appropriate technical security measures to protect it. We adhere to all required security standards and our centres and corporate networks are independently tested on an annual basis. We have a framework of policies, procedures along with internal user training in place covering data protection, confidentiality and cyber security. Security controls are regularly tested for the appropriateness of the measures we have in place to keep the data we hold secure.
When do we transfer your personal information overseas?
When data is transferred to countries outside of the UK and the European Economic Area those countries may not offer an equivalent level of protection for personal information to the laws in the UK. Where this is the case we will ensure that appropriate safeguards are put in place to protect your personal information.
The countries to which your personal information is transferred and the safeguards in place are detailed below:
France: Safeguarding information is accessible by Unibail Management Management S.A.S. , a member of the URW Group in France. Access to this personal information is strictly limited and is for monitoring and risk management purposes. The legal mechanism for the transfer of this data is Model Contractual Clauses approved by the European Commission.
For how long do we keep your personal information?
Personal injury records (including BWV footage)
Adults: 10 years.
Minors: 21 years.
Records relating to damage to property: 6 years.
CCTV recording
Standard retention of CCTV footage is 31 days.
Footage of personal injury: Adults for 4 years; Minors for 4 years after 16th birthday.
Footage of property damage: 7 years.
ANPR recording
30 days unless required by judicial agencies
Accessinformation
6 months from the end of job request
Exclusions orders and retail crime prevention partnerships
If you are reported by a scheme Member for participating in any threat or damage to any Member’s property, staff or customers, your name and facial image may be shared among Members for 12 months; it will be retained for a further 12 months by Westfield Europe Limited.
If during the 12 months you are reported for another such incident your name and facial image will be circulated among Members for 24 months from the date of the second report. Any further report during this 24-month period will result in the extension of this period by a further 24 months from the date of such report. If no further report is submitted by a Member during that period, your data will be withdrawn from Members; it will be retained for a further 12 months in our database.
Exceptions to stated retention periods
We may need to retain records or CCTV footage beyond these stated retention periods, for example where a law enforcement body or regulatory body such as the Health and Safety Executive are investigating a crime or incident, or in preparation for or in the defence of legal claims.
Your rights in relation to your personal information
You may have a number of rights in relation to your personal information, these include the right to:
o if we are continuing to process personal information beyond the period when it is necessary to do so for the purpose for which it was originally collected;
o if we are relying on consent as the legal basis for processing your personal information and you withdraw consent;
o if we are relying on legitimate interest as the legal basis for processing your personal information and you object to this processing and there is no overriding compelling ground which enables us to continue with the processing;
o if the personal information has been processed unlawfully (i.e. in breach of the requirements of the data protection legislation); or
o if it is necessary to delete the personal information to comply with a legal obligation;
o personal information is inaccurate;
o our processing of your personal information is unlawful;
o where we no longer need the personal information but you require us to keep it to enable you to establish, exercise or defend a legal claim; or
o where you have raised an objection to our use of your personal information;
Please be aware that the right to receive personal data through a data subject access request does not extend to the personal data of third parties. This means that you will not have the right to access personal data of another individual, such as their vehicle registration number or images captured by CCTV, through such a request.
If you would like to exercise any of your rights or find out more, please contact our Data Protection Officer using the contact details provided above. The Table at the end of this notice provides more detail about the personal information that we use, the legal basis that we rely on in each case and your rights.
Complaints
If you have any complaints about the way we use your personal information please contact our UK Data Protection Team who will try to resolve the issue. If we cannot resolve your complaint, you have the right to complain to the data protection authority. In the United Kingdom this is the Information Commissioner’s Office (ICO). Westfield Europe Limited is registered with the ICO with registration number Z5539526.
Table: lawful bases for how we use your personal information
Purpose |
Data used |
Legal basis |
Which rights apply?* |
Accident and injury records or damage to personal property. |
Personal contact details, date of birth, information on injury and accident or damages to personal property. May contain health related/medical information. |
We are legally obliged to collect information on accidents and injuries. We may need to retain information to assist in the preparation for or defence of a legal claim. |
The generally applicable rights plus the right to object. The right to erasure will not apply to personal data being held for statutory purposes. |
Information on alleged or actual criminal conduct or incidents |
Information about alleged or actual criminal convictions and offences committed, including exclusion orders. Personal contact details, gender, photograph, information on alleged criminal activity. May include CCTV and Body Worn Video footage as part of the record.
|
For reasons of public interest, our legitimate interests and for the preventing or detecting of unlawful acts. |
The generally applicable rights plus the right to object. |
Crime prevention |
We may have security measures and operations in place to maintain security and prevent criminal activity, including CCTV, Body Worn Video, and Automatic Number Plate Recognition. This may also where necessary include covert surveillance, and may be in coordination with law enforcement authorities. The data used will be dependent upon the activity being investigated or crime being prevented.
We may also conduct social media monitoring to check publicly available information for references to Westfield and potential security concerns. |
Public interest, legitimate interest and for the prevention or detection of unlawful acts. It is in our interests as well as the interests of our centre visitors to ensure that crime is prevented.
|
The generally applicable rights plus the right to object. |
To deal with legal disputes |
Personal contact details, information on alleged or actual incidents, CCTV and Body Worn Video and Automatic Number Plate Recognition footage/information.
|
Legitimate interests and to prepare for and defend legal claims. |
The generally applicable rights plus the right to object. |
Granting access to non-public areas of the centres and/or wider estate. |
Name, employer, contact details, signatures. Name and signatures of briefing records for employees and non-employees Professional qualifications Description of task or responsibilities carried out by individual workers (data collected directly from employer) |
We are legally obliged to collect information. We may need to retain information to assist in the preparation for or defence of a legal claim. |
The generally applicable rights plus the right to object. The right to erasure will not apply to personal data being held for statutory purposes. |