Website Privacy Statement and Notice of Collection of Personal Data

Version 4:00
Last updated: June 2026

1. Introduction

NTT DATA, Inc. and its subsidiaries (‘NTT DATA’, ‘us’, ‘our’ and ‘we’), understand the importance of ensuring that we collect, use, store, disclose, share, and dispose of and otherwise handle (collectively ‘Process’ or ‘Processing’) information about you (‘Personal Data’, including ‘Personal Information’ or ‘Personally Identifiable Information’ as it may be defined under applicable data protection laws and regulations) in a transparent, fair, secure, and lawful way.

This Website Privacy Statement and Notice of collection of Personal Data (‘Privacy Statement’) describes what Personal Data relating to you we hold, how we Process it, and your choices and rights in relation to your Personal Data.

The entity responsible for the Processing of your Personal Data will depend on your location and your interaction with us. A list of NTT DATA companies acting as controllers, including their contact details, is available under the NTT DATA Companies section.

This Privacy Statement applies to our Processing of your Personal Data in our interactions with you through our websites, online portals, e-stores, social media sites, and any other site or web or mobile application that references or links to this Privacy Statement (‘Sites’). It also applies to the Processing of Personal Data collected from you in our in-person interactions or through our third parties.

Additional information on our privacy practices with respect to recruitment, certain products, services and solutions, may be provided in specific privacy statements, privacy fact sheets, and/or other notices provided to you. To the extent that a specific statement, fact sheet, or notice differs from this Privacy Statement, the specific statement, fact sheet or notice will take precedence.

This Privacy Statement is incorporated into, and part of, our Terms of Use that govern the use of our Sites.

The categories of individuals covered by this Privacy Statement may vary depending on applicable local laws and the nature of the engagement.

If you have any questions about how we Process your Personal Data or would like to lodge a complaint, you can find our contact details under How to contact us section of this Privacy Statement.

2. Purpose and Legal Basis for Processing your Personal Data

We Process Personal Data for the purposes set out below and under the corresponding legal bases. Depending on your location, the nature of your interaction with us, and the applicable law, the legal basis for Processing may differ.

Where required by applicable law, we rely on your consent for specific Processing activities (for example, marketing communications, cookies, and similar technologies). In other circumstances, we may rely on our legitimate interests were permitted by law, provided that such interests are not overridden by your rights and freedoms.

Where we rely on legitimate interests, we carry out a balancing assessment to ensure that your rights are protected. You may object to such Processing in certain circumstances. A summary of the relevant Legitimate Interest Assessment (LIA) is available on request.

Purpose

Legal Basis

To provide access to our Sites, products, services and solutions, and fulfil your request

  • provide you with access to our Sites (e.g. browsing website pages, accessing portals, downloading white papers)
  • Process your orders and provide products, services and solutions (e.g. responding to How to contact us section or service inquiries)
  • respond to your inquiries and fulfil requests (e.g. chatbot queries, webform submissions)

To manage contractual and pre-contractual relationships

  • fulfil contractual obligations (e.g. delivering services or follow-up on inquiries)
  • manage the relationship with you as a client or prospect (e.g. account engagement)
  • send administrative communications (e.g. confirmations, service updates)
Performance of a contract
Where Processing is necessary to provide requested products, services, solutions, access to our Sites, or to take steps at your request prior to entering a contract.

To comply with legal and regulatory obligations and manage formal Processes

  • comply with applicable laws (e.g. data protection, regulatory reporting)
  • respond to privacy requests (e.g. access, deletion, correction requests submitted via webform)

To support legal and regulatory activity

  • defend legal claims or disputes
  • investigate breaches of the Terms of Use or Privacy Statement

Compliance with legal obligations

Where Processing is necessary to comply with applicable laws, regulations, legal Processes, and regulatory requirements.

To send marketing communications and manage your preferences

  • send newsletters, campaigns, and marketing emails (e.g. product updates, thought leadership)
  • provide information about services and solutions relevant to your organisation
  • enable subscription to mailing lists and newsletters

To personalise your experience and interactions

  • customise website content based on behaviour and preferences
  • manage cookie and marketing preferences via preference centres

To support participation in events and engagement activities

  • register you for events, webinars, and seminars
  • manage attendance and communications relating to events

Consent, where required by applicable law

Where laws require prior consent (for example for electronic marketing communications, cookies, or similar technologies), we will rely on your consent.

You may withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.

Legitimate interests, where permitted by applicable law

To promote our products, services, and solutions to relevant business contacts and enhance your experience, provided that such interests are not overridden by your rights and freedoms.

Where we rely on legitimate interests, you have the right to object to such Processing in certain circumstances. In particular, you may object where:

  • your Personal Data is Processed for direct marketing purposes (including profiling related to marketing), in which case we will stop Processing your Personal Data for such purpose

A summary of the relevant Legitimate Interest Assessment (LIA) is available on request.

To operate, administer and manage our business activities

(To ensure the efficient administration, operation, and continuity of our business activities, including managing relationships with customers, prospects, and business partners), e.g.

  • perform administrative functions (e.g. customer relationship management, support operations)
  • internal reporting (e.g. pipeline reporting, engagement tracking)
  • manage relationships with clients and prospects outside of a strict contract context
  • send operational communications (e.g. service announcements, updates)

To improve our products, services, solutions and business operations

(To enhance and develop our products, services, and solutions, and to optimise our business operations to better meet customer and market needs), e.g.

  • improve service offerings based on usage insights
  • evaluate demand for solutions (e.g. analysing downloads of content or service interest)

To obtain feedback and conduct research and surveys

(To understand customer satisfaction, preferences, and market trends in order to improve our offerings and inform business decision-making), e.g.

  • To run client satisfaction surveys (e.g. post-engagement or periodic surveys)
  • conduct market research questionnaires

To manage and maintain accurate records

(To maintain accurate, up-to-date, and reliable business and contact records to support effective communication and operational integrity), e.g.

  • update and maintain contact details (e.g. correcting outdated business contact information and professional data, such as name, business email address, job title, and company details)

To analyse and improve website performance and usage

(To monitor, analyse, and improve the performance, functionality, and your experience of our websites and digital platforms), e.g.

  • assess website performance (e.g. page views, navigation paths)
  • analyse how you interact with content (e.g. time spent, clicks)
  • compile usage statistics to improve website functionality

To support marketing analytics, contact acquisition, and business development (where permitted)

(To support business development and growth by identifying relevant business contacts, assessing engagement and interest, and delivering targeted and appropriate communications), e.g.

  • enrich contact data using providers such as business intelligence or enrichment services
  • obtain business contact information and professional data (such as name, business email address, job title, and company details) from third-party sources
  • assess relevance of services to organisations (e.g. account-based marketing insights, intent data)
  • prioritise outreach based on engagement signals

To obtain Personal Data from group companies, business partners, and third-party providers

(To enable coordinated business operations and maintain accurate and relevant business and professional information through the responsible use of data obtained from group companies, partners, and third-party providers), e.g.

  • receive data from NTT DATA affiliates and subsidiaries (e.g. shared client engagement)
  • obtain contact data from business partners in joint marketing activities
  • use public databases and list enhancement services to verify contact details
  • use data enrichment and intent providers to enhance business contact profiles

To protect our business, systems, and stakeholders

(To protect our organisation, systems, people, and partners by ensuring network and information security, protecting information and digital assets, preventing fraud and misuse, enforcing our legal rights, and identifying and mitigating data security risks through monitoring and classification of data within our corporate systems), e.g.

  • detect and prevent fraud or misuse (e.g. suspicious activity monitoring)
  • secure websites and systems (e.g. cybersecurity monitoring, threat detection)
  • identify, discover, and classify data stored in our corporate systems (e.g. scanning repositories and databases to understand data location and sensitivity)
  • monitor and analyse data repositories to detect security risks, unauthorised access, data exposures, or non-compliance with internal policies
  • support the management of security incidents and investigations, including identifying affected data
  • enforce internal IT usage, data protection, and information security policies
  • enforce legal rights and protect business interest

Legitimate interests

Where Processing is necessary for our legitimate interests or those of a third party, provided these interests are not overridden by your rights and freedoms.

You may object to such Processing in certain circumstances, e.g.

  • you have grounds relating to your particular situation which make the Processing inappropriate or disproportionate; or
  • the Processing is not aligned with your reasonable expectations, including where it involves profiling, tracking, or the use of data obtained from third-party sources.

Where you object to Processing based on legitimate interests, we will consider your request and will stop Processing your Personal Data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or where we need to continue Processing for the establishment, exercise, or defence of legal claims.

A summary of the relevant Legitimate Interest Assessment (LIA) is available on request.

3. Categories of Personal Data we Process about you

Personal Data is any information that either directly or indirectly identifies, relates to, describes, or is capable of being associated with, or could reasonably be linked to you. We collect and Process Personal Data in a manner that is relevant, limited to what is necessary, and proportionate to the purposes described in this Privacy Statement.

You can choose not to provide Personal Data to us in certain circumstances. However, if your Personal Data is necessary for the purposes as set out in this Privacy Statement, we may be unable to provide the relevant service, perform the requested activity, or otherwise fulfil the purpose described in this Privacy Statement.

We also collect Personal Data from other sources, as follows:

  • Our subsidiaries, affiliates and other NTT DATA companies: We may collect information about you from our subsidiaries and affiliated entities.
  • Our business partners: we collect information about you from our business partners with whom we offer co-branded products, services and solutions or engage in joint marketing activities.
  • Public databases or list enhancement services: we obtain information about you from public databases and list enhancement services. For example, we may use a service provider to verify mailing addresses. In some instances, our external service provider may perform mailing activities on our behalf, and we do not obtain the updated address information.
  • NTT DATA third party providers: where you have provided your contact data to a data service provider and agreed to your data being shared and Processed with other parties.
  • Data enrichment and business intelligence providers: We may obtain or supplement your Personal Data through commercial data enrichment, business intelligence and contact verification services. This may include business contact details (such as name, business email address, phone number), professional role information, company information and similar business-relevant data points used to keep our records accurate and to ensure that the communications we send you are relevant to your professional context.
  • Intent and engagement data providers: We may obtain information about the professional research interests and engagement signals of organisations and the individuals associated with them from third-party providers of account-based marketing and intent data. This information is used to assess the likely relevance of our products and services to the organisation you represent and to prioritise our outreach accordingly.
  • Internal systems and repositories: We may Process Personal Data that is already held within our shared corporate systems, including files, databases, and repositories, in order to identify, classify, and secure data as part of our information security and compliance activities. This may include metadata (such as file names, locations, or access rights) and, in limited circumstances, Personal Data contained within such systems, files, databases and repositories.

3.1. Personal Data that we collect

We collect Personal Data directly from you, automatically about you as you use our Sites and other sources, as described in this Privacy Statement.

The type of Personal Data that we collect about you varies based on our interactions with you.

Personal Data that we collect directly from you

The Personal Data we collect directly from you will typically relate to your professional or business role and contact details, depending on how you interact with us.

We collect Personal Data directly from you in the following circumstances:

  • When you use or register with our Sites, we will collect information about your use of the Site and any information that you submit through that Site.
  • When you post or comment on our social media pages, we may collect information about you from your post or comment. We typically Process this information to respond to your inquiry. In limited circumstances, we may associate this information with an existing record where necessary to respond to your request, manage an ongoing interaction or relationship with you, or for security and compliance purposes.
  • When you download white papers, reports, or other collateral, we may collect business contact information and professional data (such as name, business email address, job title, and company details).
  • When you subscribe to our mailing lists or newsletters, we may collect business contact information and professional data (such as name, business email address, job title, and company details).
  • When you request information from us by completing our contact us form or engaging with any of our chat bots, we may collect your name, contact information, job title, industry, location, inquiry information and any other information that you voluntarily share. This may include additional details you provide in free text fields. We may also obtain your feedback about our products, services and solutions when you respond to our surveys.
  • When you submit a privacy request or exercise your data protection rights, we may collect Personal Data necessary to Process and verify your request, including identifying information and any supporting information you choose to provide.
  • When you register for or attend our events, workshops, webinars or seminars, we may collect your name, contact details (such as phone numbers and email address), the company you work for, contact preferences, additional information as may be noted in our event forms such as meal preferences or accessibility requirements We may also collect video and/or audio recordings of the event and any chat submissions or other submissions made by you during the event.

Personal Data that we automatically collect

We, and our service providers, including analytics and advertising partners, automatically collect the following information about your use of our Sites through cookies, web beacons, and other technologies including:

  • Your domain name.
  • Your browser type and operating system.
  • Web pages you view.
  • Links you click.
  • Language preferences.
  • Marketing preferences.
  • Tracking and targeting preferences.
  • Your IP address.
  • The length of time you visit or use our Sites; and the referring URL, or the webpage that led you to our Sites.
  • We may also collect your approximate location through collection of your IP address.
  • This information is used to operate, maintain, analyse, and improve our Sites, to understand your behaviour, and, where permitted, to support personalisation and marketing activities.
  • We may also generate or infer information about your interests, preferences, or engagement with our content based on your interactions with our Sites and communications, as well as information obtained from third-party providers. This may include insights used to understand how you engage with our content and, where permitted, to improve our services, personalise your experiences, and support marketing and business development activities.
  • Typically, we do not combine this information with other Personal Data that directly identifies you, unless necessary for the purposes described in this Privacy Statement, such as improving our services, personalizing your experience, or supporting business and marketing activities were permitted by applicable law.
  • Personal Data we collect from other sources

    The Personal Data we collect from other sources primarily consists of business contact information and professional data (such as name, business email address, job title, and company details) about individuals.

    We also collect Personal Data from other sources, as follows:

    • Our subsidiaries, affiliates and other NTT DATA companies: We may collect information about you from our subsidiaries and affiliated entities.
    • Our business partners: we collect information about you from our business partners with whom we offer co-branded products, services and solutions or engage in joint marketing activities
    • Public databases or list enhancement services: we obtain information about you from public databases and list enhancement services. For example, we may use a service provider to verify mailing addresses. In some instances, our external service provider may perform mailing activities on our behalf, and we do not obtain the updated address information.
    • NTT DATA third party providers: where you have provided your contact data to a data service provider and agreed to your data being shared and Processed with other parties.
    • Data enrichment and business intelligence providers: We may obtain or supplement your Personal Data through commercial data enrichment, business intelligence and contact verification services. This may include business contact details (such as name, business email address, phone number), professional role information, company information and similar business-relevant data points used to keep our records accurate and to ensure that the communications we send you are relevant to your professional context.
    • Intent and engagement data providers: We may obtain information about the professional research interests and engagement signals of organisations and the individuals associated with them from third-party providers of account-based marketing and intent data. This information is used to assess the likely relevance of our products and services to the organisation you represent and to prioritise our outreach accordingly.
    • Internal systems and repositories: We may Process Personal Data that is already held within our shared corporate systems, including files, databases, and repositories, in order to identify, classify, and secure data as part of our information security and compliance activities. This may include metadata (such as file names, locations, or access rights) and, in limited circumstances, Personal Data contained within such systems, files, databases and repositories.

    3.2. Special Categories or Sensitive Personal Data

    Special categories or sensitive Personal Data includes information relating to your race, gender, sexual orientation, ethnicity, religion, political opinions or beliefs, membership of a trade union or political affiliation, physical or mental health information, information related to criminal convictions or offences, identification information, such as proof of identity, nationality, immigration status, passport, and work permits, veteran or military status, information obtained from background checks, disability (‘Sensitive Personal Data”).

    We ask that you do not send or provide this information to us unless it is necessary for your interactions with us. We do not collect or Process Sensitive Personal Data for the purpose of inferring characteristics about you. We also do not actively collect sensitive Personal Data as part of our Site interactions, except where such data is necessary for the purposes described in this Privacy Statement.

    However, in limited circumstances, Sensitive Personal Data may be Processed where you choose to provide such information to us, for example through contact forms, event registrations, surveys, or when submitting a data subject request, including where additional information is required to verify your identity or support your request.

    In addition, Sensitive Personal Data may be Processed on an incidental basis where such data is included within information already held in our systems and is Processed as part of our information security, data protection, or compliance activities. In such cases, access to this data is restricted and appropriate safeguards are applied to protect it.

    We do not use Sensitive Personal Data for marketing, profiling, or automated decision-making purposes.

    Note: You can choose not to provide Personal Data to us in certain circumstances. However, if your Personal Data is necessary to provide our services, manage our relationship with you or administer your contract with us, we may be unable to provide this service without it.

    3.3. Children’s Personal Data

    We do not knowingly collect information about children without appropriate parental or guardian consent. If you believe that we may have collected Personal Data about an individual who is under the applicable age of consent in your country without proper consent, you can find our contact details under How to contact us section of this Privacy Statement.

    4. Disclosing your Personal Data

    We may disclose your Personal Data for the purposes set out in this Privacy Statement and as otherwise permitted or required by applicable law. Where appropriate, we limit disclosure to the minimum amount of Personal Data reasonably necessary and proportionate for the relevant purpose.

    We may disclose your Personal Data to the following categories of recipients:

    • Our subsidiaries, affiliates and NTT companies: NTT DATA is part of the NTT, Inc Group and has subsidiaries and affiliates worldwide. We may disclose information about you with our subsidiaries, affiliates and other NTT, Inc Group companies for the purposes of operating our business, including coordinating activities, maintaining accurate and up-to-date business contact and professional information, analysing and improving our products, services and solutions, and securing our systems.
      • This may include disclosing Personal Data to support client and prospect engagement, account management, and business development activities.
      • Where such Processing involves marketing communications, we rely on consent where required by applicable law, or otherwise on our legitimate interests where permitted, subject to appropriate safeguards and your right to object as described in the “Your privacy rights” section.
      • Where your Personal Data is shared with NTT DATA and other NTT, Inc Group companies (including subsidiaries and affiliates) for marketing purposes, the receiving entities will Process your Personal Data in their capacity as controllers for the relevant Processing activity. Such Processing may be based on legitimate interests, or on consent where required, depending on the nature of the activity. You have the right to object to Processing based on legitimate interests, as described in the “Your privacy rights” section below.
    • Authorized personnel and advisors: We may disclose information about you with authorized NTT DATA personnel, agents and professional advisors of NTT DATA including legal advisors, auditors, and consultants to NTT DATA, where required.
    • NTT DATA third party providers: We may disclose information about you with NTT DATA third party providers where we have sub-contracted out parts of our products, services and solutions; where we engage third party applications, services or products; or where we engage third parties or use third party systems as part of NTT DATA internal business processes. Examples include Processing of orders and credit card transactions, hosting websites, hosting seminar registration, assisting with sales-related efforts or post-sales support, and providing customer support, providing analytics, statistics, digital marketing, advertising and personalisation services, and information security services used to identify, classify, and secure data within our systems.
    • Our business partners: We may disclose information about you with our business partners with whom we jointly offer our products, services and solutions or with whom we run co-branded marketing activities, events or content programmes. Disclosing Personal Data with partners is limited to the categories of partners and the purposes disclosed to you at the point of collection, including where you have indicated your agreement when completing a form, registering for an event or downloading a gated asset or where otherwise permitted by applicable law.

    We also may disclose Personal Data in the following circumstances:

    • When you consent to the disclosure of your Personal Data.
    • In connection with the agreed terms of contract for the service provided.
    • In connection with, any joint venture, merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or to another company and to our advisors and the advisors of the other company in such transactions.
    • To protect the rights, property or safety of NTT DATA, its business partners, you, or others, or as otherwise required by applicable law.
    • To respond to a request for information by a competent authority in accordance with, or required by any applicable law, regulation or legal process; or where necessary to comply with judicial proceedings, court orders or government orders.
    • In aggregated, anonymized, and/or de-identified form that cannot reasonably be used to identify you.
    • For other legal reasons.

    Any service providers or other parties with whom we disclose Personal Data are contractually required to implement appropriate physical, administrative and technical safeguards to protect Personal Data and are not permitted to Process Personal Data for any purpose other than the purpose for which they are provided with or given access to Personal Data by us. Where we disclose Personal Data to independent controllers, they are responsible for their own Processing in accordance with applicable law and any disclosures provided to you.

    For the purposes of this Privacy Statement, we use the term “disclose” broadly to describe the sharing of Personal Data with third parties. In some jurisdictions, certain types of disclosure may be referred to as “sharing” or “sale” of Personal Data under applicable law. The terminology used below reflects these legal distinctions where relevant.

    Personal Data sold or shared

    We may share limited business contact information and professional data (such as name, business email address, job title, and company details) with our business partners as part of joint marketing, solution delivery, or co-branded initiatives. This may include sharing data for purposes such as lead generation, event participation, or content syndication.

    In some jurisdictions, certain disclosure or advertising related activities may be classified as “sale”, “sharing” or ‘targeted advertising’ of Personal Data under applicable law. Where applicable, you may exercise your right to opt out, which can be exercised via by unsubscribing on our website or via the additional methods described under How to contact us section of this Privacy Statement.

    5. International Data Transfers

    NTT DATA operates globally, and your Personal Data may be transferred between entities within NTT DATA, and other NTT, Inc Group companies and to authorized third party providers located in various countries in connection with the purposes described in this Privacy Statement.

    Where Personal Data is transferred across borders, including to countries that may not provide an equivalent level of data protection, we ensure that such transfers are carried out in accordance with applicable data protection laws and are subject to appropriate safeguards or valid transfer mechanisms recognized under those laws.

    The specific transfer mechanism applied will depend on the jurisdictions involved and the applicable legal requirements governing the transfer. These may include adequacy decisions, standard contractual clauses, or other approved safeguards, together with additional technical, organizational, and contractual measures were required to provide an appropriate level of protection.

    You may obtain further information about these safeguards, including a copy where relevant, by contacting us using the details in the How to contact us section.

    Whenever we undertake an international data transfer, we take steps to ensure that Personal Data is transferred securely and is only accessed by authorized parties in a business or professional context where necessary for the purposes described in this Privacy Statement.

    6. Security of your Personal Data

    We are committed to protecting your Personal Data from accidental or unlawful destruction, loss, or alteration, and unauthorized access or disclosure by using a combination of physical, administrative and technical safeguards and contractually requiring our third parties to whom we disclose your Personal Data to do the same.

    We use specialized tools and technologies to monitor, identify, classify, and secure data within our corporate systems, databases and repositories in order to protect our information and digital assets and to identify and mitigate potential security risks, unauthorized access, data exposures, and non-compliance with internal policies. Please note that we cannot guarantee 100% security of your Personal Data, and we recommend that you take reasonable steps to protect your Personal Data. (for example, by not sharing your passwords, choosing strong passwords, and taking other appropriate security measures).

    7. Retaining your Personal Data

    We will retain your Personal Data for as long as is reasonably necessary and proportionate to fulfil the purpose for which it was collected, Processed, or for another disclosed purpose, unless a longer retention period is required to comply with legal obligations, resolve disputes, protect our assets, or enforce our rights. The specific retention period will depend on the type of Personal Data and the nature of the relationship you have with us. We retain Personal Data for as long as you have an active relationship with us, or otherwise for a reasonable period thereafter in accordance with our business needs and applicable law.

    The criteria we Process to determine retention periods include whether:

    • we are under a legal, contractual or other obligation to keep your Personal Data, or as part of an investigation or for litigation purposes;
    • Personal Data is needed to maintain accurate business and financial records;
    • there are automated means (if any) to enable you to access and delete your Personal Data at any time;
    • Personal Data is sensitive Personal Data, in which event we will generally retain this for a shorter period of time;
    • you have consented to us retaining your Personal Data for a longer retention period, in which case, we will retain your Personal Data in line with your consent
    • where Personal Data is contained in backups and/or archived copies it may not be immediately deleted but will be retained and protected in accordance with applicable data protection laws until it is overwritten or securely deleted in the normal course of operations. In some instances, we may anonymize your information in accordance with our policies and may keep those anonymized records for longer periods.

    8. Automated decision-making and Artificial Intelligence (AI)

    Automated decision-making

    Automated decision-making refers to Processing that uses algorithms, artificial intelligence or related technologies to generate outputs, recommendations, alerts, or decisions, which in some cases may be made without meaningful human intervention.

    In the context of our Sites and marketing activities, we primarily use automated Processing to support profiling and personalization, rather than to make decisions that produce legal or similarly significant effects concerning you. We may use automated decision-making and profiling technologies to enhance your experience on our Sites. These technologies Process Personal Data to make decisions or facilitate human decision-making. This includes:

    • Tailoring content and recommendations based on your behaviour and preferences;
    • Targeting advertisements and promotions to specific user segments;
    • Understanding your interactions to predict future behaviour and preferences;
    • Analysing your engagement to improve website functionality and content

    These activities may involve the use of inferred or derived data based on your interactions with our Sites and communications, as described in this Privacy Statement. We do not use automated decision-making to make decisions about you that produce legal or similarly significant effects. Where required by applicable law, we will ensure appropriate safeguards are in place, including the ability to request human intervention or object to such Processing.

    Artificial intelligence (AI)

    We may use automated systems, analytics tools, artificial intelligence (AI), machine learning models, robotic Process automation, or similar technologies (‘collectively referred to as AI’) for purposes such as:

    • operating chatbots and virtual assistants that respond to your inquiries;
    • generating suggested replies, summaries, recaps and insights from our communications with you (for example, in emails, chats, calls and meetings);
    • translating or transcribing communications in real time;
    • supporting our marketing operations, including content personalisation and the prioritisation of relevant communications;
    • supporting our internal business operations, including analytics, security monitoring and Process automation.

    We will make it transparent to you whenever you are interacting with an AI technology, such as a chatbot or AI-generated response. Where we record or transcribe a call, meeting or similar interaction (including through speech-to-text technology), we will inform you in advance and, where required by applicable law, obtain your consent.

    We will use your Personal Data in AI technologies in accordance with applicable law, our internal governance Processes and appropriate disclosures where required. Our use of AI technologies is governed by NTT DATA's responsible AI principles, which prioritise transparency, fairness, accountability and data privacy. Where the use of AI involves automated decision-making that produces legal or similarly significant effects concerning you, the provisions set out in the 'Automated decision-making' section above will apply. For more information on how we use AI within NTT DATA, please visit Artificial Intelligence Transparency Statement | NTT DATA. If you encounter harmful, unsafe, or incorrect AI behavior, please contact us at AIGovernance@nttdata.com.

    9. Your privacy rights

    Data protection laws and regulations, in certain countries, provide you with specific rights in relation to your Personal Data. We are committed to upholding the following privacy rights: Right to be informed / know: you have a right to know what Personal Data, including the types of sensitive Personal Data, we have about you, what we do with it, where we get it from, who we disclose it to and share it with, how long we keep it and why we need it.

    Right of access: you have the right to access your Personal Data and obtain a copy of your Personal Data from us.

    • Right to correct: you have the right to update inaccurate and/or incomplete Personal Data about you. We will review all information provided by you to us, to determine whether the information is inaccurate. We reserve the right to delete the information instead of correcting if such deletion does not impact you or you consent to the deletion of your Personal Data.
    • Right to delete: you have the right to have your Personal Data erased, deleted or destroyed (i.e. right to be forgotten).
    • Right to data portability: you have the right to move, copy or transfer your Personal Data in a safe and secure way and Process it for your own purposes.
    • Right to withdraw consent: you have the right to withdraw consent at any time regarding the Processing of your Personal Data (where applicable) or in relation to direct marketing activities.
    • Right to restrict Processing: you have the right to limit the way we Process your Personal Data.
    • Right to object: you have the right to stop or prevent us from Processing your Personal Data. In particular, you can object to our Processing of your Personal Data for direct marketing or the sale, sharing, or use of your Personal Data for targeted advertising where applicable.
    • Right to challenge automated decisions: you have the right to query and review decisions made about you using purely automated means (i.e. without human involvement or intervention).
    • Right to complain: you have the right to make a complaint or raise a concern about how we Process your Personal Data. Complaints may be made directly to us or a relevant data protection authority.
    • Right to non-discrimination: you have the right not to be discriminated against for exercising your privacy rights.

    You may submit a request to enforce your rights at any time by contacting us through the How to contact us section of this Privacy Statement. NTT DATA is committed to upholding your privacy rights and treats all requests to uphold or enforce your rights confidentially.

    When you submit a request to us, you must provide sufficient information to allow us to verify that you are the person about whom the Personal Data relates. This information must contain sufficient detail to allow us to properly understand, evaluate and respond to your request. If we cannot verify your identity, we will not be able to respond to your request.

    Once we receive your request, we will begin the Process to verify that you are the person that is the subject of the request. This may include matching identifying information provided by you with the information we have about you in our records. Where permitted under applicable law, we may charge you a reasonable fee to access your Personal Data; however, we will advise you of any fee in advance.

    We respond to privacy rights requests and complaints within 30 days or within the timeframes required by applicable law. We will retain correspondence, documents and information related to any requests or complaints for a period of 24 months or as required by any applicable laws and regulations.

    In some situations, we may not be required to enforce these rights under applicable law and where exceptions may apply. We may also have a legitimate business interest to decline a request to action your rights. These exceptions to your rights may include our right to maintain Personal Data for business purposes and solely internal processes reasonably aligned to your expectations, as well as to comply with any legal obligations, including maintaining proper records, or maintaining privilege or confidentiality of certain records, as well as to establish, exercise or defend legal claims, in compliance with applicable laws and regulations. We will inform you of our decision to deny or grant your request and of any other action we have taken to respond to your request and enforce your rights, as required by applicable law.

    10. Authorized agent information

    You may designate an authorized agent to make a request on your behalf. When your authorized agent makes a request related to your Personal Data, we will require the agent to provide written permission from you. We may also require that you verify your own identity directly with us at the time such a request is made. You or your authorized agent may contact us with requests, complaints, or questions regarding these rights by contacting us in accordance with the How to contact us section.

    11. Manage your marketing consent preferences

    In some instances, you may provide NTT DATA with consent to Process your Personal Data such as where you have opted into receiving direct marketing communications from us. You can change your consent preference at any time and manage your communication preferences by unsubscribing on our website or via the How to contact us section.

    If you opt-out of receiving marketing related communications from us, we may still send you administrative messages or other required communications as part of your ongoing use of our products, services and solutions, which you are unable to opt-out of.

    12. Cookies and similar technologies

    When you access our Sites, we and our service providers may use cookies (small text files containing a unique identification number which are placed on your PC, laptop, tablet or mobile phone) and similar technologies including scripts, embedded web links, web beacons, Local Shared Objects (flash cookies) and Local Storage (HTML 5).

    Please refer to our Cookies Statement (available on our Sites) for more information on:

    • What cookies are
    • How we use cookies and similar technologies
    • How third parties we partner with may use cookies and similar technologies
    • Your choices regarding acceptance of cookies and similar technologies

    You can manage your cookie preferences at any time through the cookie preferences centre available on our Sites.

    13. Links to third party websites and applications

    Our Sites may provide links to the websites and/or applications of other parties. You may further interact with us through third party applications, owned and operated by the company you work for or other third parties such as LinkedIn, Microsoft Teams, Facebook, X (formerly Twitter), and other social media sites or applications.

    We are not responsible for and make no representations or warranties in relation to the security, privacy practices and content of these third-party websites and applications. Please ensure that you read the applicable privacy and cookie policies before sharing Personal Data on these websites and applications. Your use of such websites and applications is subject to the terms and conditions and privacy practices of those third parties.

    Where you interact with third-party websites, applications, or services, those third parties may independently collect and Process Personal Data about you in accordance with their own privacy policies.

    You may also interact with us through social media plug-ins by ‘liking’, reposting, or sharing information related to NTT DATA. Social media plug-ins are operated by the social network themselves (such as Facebook, LinkedIn, Twitter, Google+, etc.) and are subject to the terms of use, and privacy and cookies policies of the respective social network. Please ensure that you are familiar with these.

    14. Updates to our Privacy Statement

    We may update this Privacy Statement at any time for any reason. If we do, we will update the “Last Updated” information at the top of this Privacy Statement and will notify you of such changes by posting the revised statement on this page.

    We encourage you to regularly review this Privacy Statement to stay informed about our privacy practices and whenever you submit Personal Data to us.

    15. Other Privacy Statements

    We may provide additional or supplementary privacy statements, notices, or disclosures to you in connection with specific products, services, solutions, or interactions with us.

    Where a specific privacy statement or notice is provided to you, it will apply to the relevant interaction and will take precedence over this Privacy Statement to the extent of any inconsistency.

    16. How to contact us

    If you have any questions about how we Process your Personal Data, have a privacy concern, or wish to make a request or complaint relating to your Personal Data, you may contact us through the following ways:

    If you would like to reach out to our Data Protection Officers directly, please consult our DPO directory or contact our global Data Privacy team at privacyoffice@nttdata.com.