2. DATA PROTECTION – WHAT YOU SHOULD KNOW WHEN USING OUR WEBSITES
How we’re regulated: For UK data protection legislation purposes, Jaguar Land Rover Limited is registered with the Information Commissioner’s Office under registration number ZA020510.
Customer Relationship Centre contact details: If you’d like to get in touch on a website related query, Jaguar Land Rover Customer Relationship Centre contact details are accessible from these web pages:
Queries in relation to Jaguar: https://www.jaguar.com/contact-us/index.html
Queries in relation to Land Rover: https://www.landrover.com/contact-us.html
Queries in relation to any purchases made from the Jaguar store: https://shop.jaguar.com/contact/
Queries in relation to any purchases made from the Land Rover store: https://shop.landrover.com/contact/
More about the JLR Group...
Jaguar Land Rover is part of a group of companies whose parent company is Jaguar Land Rover Automotive plc. You can find out more corporate information about Jaguar Land Rover on our website at: https://www.jaguarlandrover.com/.
Jaguar Land Rover is part of the Tata group. More information about the Tata group and the Tata companies can be found here: http://www.tata.com/aboutus/sub_index/Leadership-with-trust and http://www.tata.com/company/index/Tata-companies
2. WHAT INFORMATION WE COLLECT FROM OUR WEBSITES AND WHAT INFORMATION WE RECEIVE FROM OTHER SOURCES.
Our websites serve primarily as information portals to help you better understand our cars, products and services. We also, however, offer a number of website functions that collect information you provide to us when you ask to be kept informed, to be added to lists, events or experiences, or when you buy goods or book or request services.
The main ways we collect information from our websites:
- When you visit, or use and interact with our websites, for example to take steps to request or use online-available services, where you find out more about an event or experience or where you request any other information;
- When you enter into personalised web areas and use our websites as a way to engage with us, as a place where you can ask for personalised reminders, receive information about your vehicle, and/or request vehicle service or other information to be notified to you;
- When you provide information to or interact with any of Jaguar Land Rover careers pages;
- When you contact us (via contact details made available on our websites), or send us correspondence.
Information may also be received from other sources. For example:
- Vehicle related data from independent third party sources: When you own a JLR vehicle, information connected with you and your vehicle (including the vehicle identification number or VIN) may be shared as is appropriate between our network of retailers, repairers, importers, credit providers and credit hire product providers, and used to inform any personalised web areas you register to receive. The information that is shared will depend on factors like who you have bought your vehicle from and the services that you request from us throughout the period of your vehicle ownership. Please visit Section 4 (Who we share your personal data with) below to find out more. Please also visit our separate InControl terms and privacy policies (here for Jaguar: https://incontrol.jaguar.com and here for Land Rover: https://incontrol.landrover.com) for more information on vehicle data.
- Third party support services: For the performance of our website services and to allow us to maintain appropriate records and to support ongoing queries, we may receive data about you or your website activities from our group companies or third party providers (e.g. to confirm website payments, to track website order deliveries, to support website maintenance). More information on our categories of suppliers is provided at Section 4 (Who we share personal data with) below.
- Device data: Our websites automatically take certain device information in order to optimise your website experience (for example, allowing our website to automatically adapt screen size as appropriate for the device you are using to browse the website). This data also supports our website analytics. More information on automated data collection and cookies can be found in our Cookies policy, available via this link.
- Marketing data: Your contact details, marketing preferences or other information may be shared with us by retailers or other third parties partners, where there is appropriate notice and in compliance with applicable data protection laws. You have the right to ask us not to use your personal data for marketing purposes. Please see your data protection rights at Section 7 (Your data protection rights) below for further information on these.
- Public sources of data: We may use public sources of data, for example, to support website functionality (e.g. to support authenticate or fraud checks), and/or to maintain the accuracy of the data we hold. For example, we may make checks from time to time with the DVLA to check our vehicle owner information remains up to date.
We receive information you provide to us in your use of our websites, for example, when you add information to online forms or to data fields on our websites. We may also receive information from you by other online means, for example, if you comment on our social media pages. This will be the information that is visible to you, and may include your name, occupation, contact information (e.g. email, postal address and phone/mobile number), credit card/payment details, driving licence details, vehicle data and general information you decide to share such as your experience with JLR products and services.
3. HOW WE USE YOUR PERSONAL INFORMATION.
We use personal information to manage and meet service and information requests, to understand service, vehicle and website use, and to make our products and services (including our web services) as effective as possible.
More about the main uses of your personal data and the legal grounds we rely on for these are…
|Activity:||Applicable Legal grounds:|
|Maintaining and supporting website use
Where you use an online service governed by our provided online Terms and Conditions (for example, purchases from the online stores, or entering into prize draws and competitions), we and our permitted third parties will process data in a number of ways that support our website services. For example, this may include the following activities: identity confirmation, any fraud and authentication checks, service delivery, administration of prize draws, competitions, membership offers, surveys and other promotional activities, any applicable payment processes and collections activities, customer support and any ongoing service communications. We may also seek to improve our services, using user experiences to strengthen our internal processes. For example, we let you know when you call us (our customer care numbers are available from our websites) that our calls may be recorded to support training, audit and quality purposes.
|Necessary for contract
Legitimate Interests in running effective website services
Where personal data is required for entering into a contract, we will identify to you where information is mandatory. The consequences of not providing this information may include being unable to proceed with the requested service.
|Managing your requests
We will process data in managing your requests made on or via our websites (e.g. where you request a brochure, sign up to ‘keep me informed’ or add your details into any other website data form or data field). We will also process data in providing and maintaining personalised website experiences.
|Legitimate Interests in running effective website services.|
|Enhancing website experience
Where we pre-fill website data fields to enhance and streamline your online experience.
|Legitimate Interests in enhancing, simplifying and streamlining website experiences.|
|Internal research and development
For internal research, development, analytics, analysis and reporting purposes, e.g. to monitor current vehicle performance, predict trends or performance, develop new functions, products and services, or to evidence compliance with regulatory requirements.
|Legitimate Interests in assessing and improving performance, managing compliance, monitoring trends and developing new products.|
Other marketing activities will happen assessed on the Legitimate Interests ground. e.g. where we tailor marketing communications or send targeted marketing messages via post or social media and other third party platforms; and in providing existing customers with information about similar products and services. In order to improve the services we offer via our websites, we may ask you to participate in research from time to time. It is entirely up to you whether you choose to do so.
We will use profiling and carry out research and analytics activities to inform our marketing strategies, to create a better understanding of our customers and visitors; to support our website advertising, and to better improve the website information, functionality and the services we provide.
Note: Where we collect your personal data with consent, you may withdraw your consent for us to use your information in any of these ways at any time. Please see Withdrawing your consent in Section 7 below for further details. (This right doesn’t effect the lawfulness of processing that was based on that consent before its withdrawal.)
Legitimate Interests for direct marketing purposes
|Records maintenance and general administration
To maintain our records, administer and maintain our websites, support your queries and any other internal operations and administrative purposes (for example, this will include troubleshooting, testing, supporting our audit requirements and in responding to any enquiries you may make, including any data protection rights you raise).
|Legitimate Interests in maintaining appropriate websites, records and service administration|
|Network and information security
To maintain our network and information security in order for us to take steps to protect your information against loss or damage, theft or unauthorised access. And to maintain appropriate server locations (for example, we may work with third parties to support appropriate use of cloud services).
|Legitimate Interests as appropriate for ensuring network and information security|
|Corporate acquisitions and disposals
Any data processed as is necessary in the context of corporate acquisitions or disposals.
|Legitimate business Interests
|Management of legal and regulatory requirements
To manage legal and regulatory requests and requirements, meet or defend legal rights or for the prevention/detection of crime, (including where required to assist HMRC, law enforcement agencies such as the Police, the Driver and Vehicle Licensing Agency (DVLA) or any other public authority or criminal investigation body, or for the safeguarding of national security).
|Legitimate Interests in complying with law and regulation, including responding to regulators
In the event we communicate to you an urgent safety or product recall notices.
We may share your personal data with:
- Those third parties who need to handle it so we can provide to you the products, services you have signed up to or requested, for example, to provide or offer finance or credit, insurance, to provide marketing and advertising support services and for optimised website services.
- With our network of retailers, authorised repairers and where relevant our importers network (together our “retail network”), so as to be able to fulfil requests for goods, services, etc, and for assessment and training, to be able to enhance the quality of the services you obtain when interacting with our Retail Network.
- Third parties in the event we sell or buy any business or assets.
- If we are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation or requests, or in order to enforce these terms or to investigate actual or suspected breaches.
More about JLRs network of Independent Third Parties...
We work with a number of independent third parties to provide services, such as our Retail Network, credit product providers, contract hire products. Personal data may be sent directly to these entities by you (for example if you contact them by phone or email or via their website pages), or we may share personal data with them where appropriate to support with your queries or other service requirements.
Where you use the UK websites to find or make contact with our Retail Network, a credit provider, or a contract hire product provider, these are (unless otherwise stated), independent businesses and not JLR group companies. Any contact you make to them (for example, to call or send an email) and any data you provide to them in use of their websites, will be controlled by them, not by JLR. If you have questions regarding a third party’s (such as a retailer, importer, credit provider, contract hire product provider or repairer's) use of your personal data, we recommend you contact those parties directly.
For information on independent third parties we work with:
- Our Retail Network is generally identifiable from the ‘locate a retailer’ website functionality. They can be searched for by name, location or postcode. A full list of all UK Retailers is accessible by clicking here.
- In the UK, credit is provided by Black Horse Limited trading as Jaguar Financial Services, St William House, Tresillian Terrace, Cardiff CF10 5BH.
For Land Rover:
- Our Retail Network is generally identifiable from the ‘locate a retailer’ website functionality. They can be searched for by name, location or postcode. A full list of all UK Retailers is accessible by clicking here.
- Credit products are provided by Black Horse Limited trading as Land Rover Financial Services, St William House, Tresillian Terrace, Cardiff CF10 5BH.
- Contract Hire products are provided by Lex Autolease Limited trading as Land Rover Contract Hire, Heathside Park, Heathside Park Road, Stockport SK3 0RB.
We use a number of service suppliers to support our business and these service providers may have access to our systems and data in order to provide services to us and on your behalf, for example payment processors, information technology such as hosting service providers, marketing and digital advertising support services, customer services and relationship handling, service and system specialists, website analytics support, online store shipping, delivery and support for events and experiences.
More about JLR Group companies, and how they may provide service support...
As a member of the Tata Group of companies, we can benefit from the large IT infrastructure and expertise that exists within our wider corporate structure. This means that the personal data you provide to us may be accessed by members of our group of companies only as necessary for service and system maintenance and support, aggregate analytics, business continuity, IT and administrative purposes. For example where necessary to support particular website enquiries, or to provide technical support that maintains website functionality.
More about Public bodies, law enforcement and regulators...
From time to time, the police, other law enforcement agencies and regulators can request personal data, for example for the purposes of preventing or detecting crime, or apprehending or prosecuting offenders.
5. INFORMATION ABOUT INTERNATIONAL DATA TRANSFERS.
The Jaguar Land Rover UK websites use servers which are hosted in the EU. However we may share website personal data with suppliers or group companies located outside of the EU where this is necessary for the purposes described above. Where this happens, we apply safeguards to add to the data protections that apply to those data transfers. This includes an assessment of the adequacy of the third country in question, use of European Commission approved model contract terms where appropriate, and assessment of Privacy Shield certification for US located entities where applicable.
More about the adequacy checks JLR puts in place for international data transfers...
Where JLR chooses to share personal data with a third party located outside the EU, the following factors are assessed to support adequate transfer of this data:
- Use of measures like European Commission approved measures to support adequate transfers of personal data. We also have group companies, and use suppliers located in countries that are elsewhere in the world. To manage data protection compliance with these transfers, we will use European Commission approved data transfer mechanisms such as use of model contractual clauses approved by the Commission. We will also assess where applicable where a supplier is able to demonstrate to us they have Binding Corporate Rules. (Binding Corporate Rules is a GDPR – recognised Data Protection mechanism to ensure adequate personal data transfers). We may work with suppliers who are able to demonstrate to us they are Privacy Shield certified.
- To understand the protections required in European Commission approved Model Clauses, a template copy of these is accessible from this location.
- To see a full list of approved Binding Corporate Rules, please click this link.
- A full list of Privacy Shield participants, and their Privacy Shield certification information is available from this website link .
We’ll keep your personal data for as long as we need it to provide the products and services you’ve signed up to. We may also keep it to comply with our legal obligations, respond to queries and resolve any disputes, to meet our legitimate interests and to enforce our rights.
The criteria we use to determine storage periods include the following: Information we have told you about storage periods on our website or in website terms and conditions. We will also use criteria such as applicable contractual provisions that are in force, legal statutory limitation periods, applicable regulatory requirements and industry standards.
7. YOUR DATA PROTECTION RIGHTS.
You have rights in connection with your personal data, including: to withdraw consent where you have given it, to be informed and have access to your personal data, to correct or complete inaccurate data, and in certain circumstances to restrict, request erasure, object to processing, or request portability of your personal data to another organisation.
We try to ensure that we deliver the best levels of customer service. If you do need or want to get in touch with us for any reason regarding your data protection rights, please get in touch using either of the email addresses below, and add into the subject header that it relates to your data protection rights. These Customer Experience Centre email addresses are the appropriate contact details for our Data Protection Officer where queries are data protection related:
If you are not happy and have a data protection related complaint, please contact us direct at this email address: DPOffice@jaguarlandrover.com. If you are not satisfied, you also have the right to complain to the Information Commissioner’s Office.
To learn more about these data protection rights, see below.
More about my data subject rights...
- If you have given us consent to process your personal data, including for electronic marketing communications, you have the right to withdraw that consent at any time. Just use the unsubscribe options presented, for example, these are present in the email marketing communications sent by us.
- You can ask for access to the personal data we hold about you, object to the processing, request that we correct any mistakes, restrict or stop processing or delete it. If you do ask us to delete or stop processing it, we will not always be required to do so. If this is the case, we will explain why.
- In certain circumstances you can ask us to provide you with your personal data in a usable electronic format and transmit it to a third party (right to data portability). This right only applies in certain circumstances. Where it does not apply, we will explain why.
The Information Commissioner’s Office (the ICO) is the supervisory authority that regulates personal data in the UK. You can get in touch with the ICO in any of the following ways:
- By going to their website: www.ico.org.uk
- By giving them a call on 0303 123 1113
- or by writing to them. Their address is: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow SK9 5AF.
9. KEEPING YOUR INFORMATION SECURE
We require all of our services providers to have appropriate measures in place to maintain the security of your information.
Where we have given you (or where you have chosen) a password that enables you to access any personalised area in a JLR website, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted over the internet; any transmission is at your own risk. Your information will be kept in a secure environment protected by a combination of physical and technical measures such as encryption technologies or authentication systems to prevent any loss, misuse, alteration, disclosure, destruction, theft or unauthorised access.
Jaguar Land Rover is responsible for the processing any personal data you provide to us through these websites:
The InControl Websites:
These are websites for which Jaguar Land Rover Limited is also data controller, but they are governed by separate and different website terms and privacy policies.
The British Motor Museum Website:
Independent companies we don’t control: Where you go from our websites to a third party, such as a retailer, repairer, importer, credit product provider, or contract hire product provider these are independent parties and not part of the JLR group. This means JLR will no longer control (and in some cases won’t even see) the data you provide to third parties in these instances.
Websites we don’t control: When you visit the following websites: