PwC NL is committed to protecting personal data. This Privacy Statement describes why and how we collect and use personal data and provides information about individuals’ rights. It applies to personal data provided to us, both by individuals themselves or by others such as companies and institutions we work with, who provide us, in that context with information about their employees or business relationships. We use personal data provided to us for the purposes described in this privacy statement, or as otherwise stated at the point of collection.
This Privacy Statement applies to PwC NL and PwC NL websites as described in the Scope section of this statement.
We process personal data in the following contexts:
Our legal basis for processing personal data varies depending on the specific purpose and context, but generally we rely on one or more of the following:
Please refer to the Personal data use chapter below for more information about the personal data we process, the purposes for which we process this personal data and our legal basis for doing so.
As a data subject, you have several privacy rights including the right of access, the right to rectification and to erasure, the right to object and the right to restrict the processing of your personal data. You also have data portability rights, the right to withdraw your consent at any time, and the right to submit a complaint with the supervisory authority. Please refer to Individuals’ rights and how to exercise them for more information.
For questions or complaints, you can contact our Data Protection Office by emailing nl_dataprotection@pwc.com. Please refer to Contact information for additional contact details.
This Privacy Statement applies exclusively to PwC NL* and the following PwC NL websites:
The PwC network is a worldwide network of independent member firms that operate locally in countries throughout the world. This Privacy Statement does not apply to websites administered by other PwC entities. We recommend visitors to those other websites to carefully read the corresponding privacy statements. For further details, please see Information on our organisation.
Our website may also link to other third-party sites that are not controlled by PwC NL and which do not operate under PwC NL's privacy practices. When you link to third party sites, PwC NL's privacy practices no longer apply. We encourage you to review each third party site's privacy policy before disclosing any personally identifiable information.
If you are an employee of PwC NL, including partners and the supervisory board, our partners and employee privacy policy applies in addition to this Privacy Statement. Please refer to our partners and employee privacy policy available on our intranet for information on why and how personal data is collected and processed in relation to your role with PwC NL.
*As far as they: (1) are a contracting party for the purpose of providing or receiving services, (2) posted a position for which you are applying, or (3) have a role or relationship with you, "PwC NL" (and "we", "us", or "our") refers to PricewaterhouseCoopers B.V. based in Amsterdam, and also to PricewaterhouseCoopers Accountants N.V., PricewaterhouseCoopers Belastingadviseurs N.V., PricewaterhouseCoopers Advisory N.V., PricewaterhouseCoopers Deelnemingen B.V., PricewaterhouseCoopers Compliance Services B.V., PricewaterhouseCoopers Pensions, Actuarial & Insurance Services B.V. and PricewaterhouseCoopers Academy Netherlands VOF.
We process personal data of visitors to our offices. This involves collecting and processing the following categories of personal data:
| Purpose | Description | Categories of personal data | Legal basis |
|---|---|---|---|
| Security and safety | To ensure the security of our premises and the safety of everyone on-site through access control systems, CCTV, and network security measures. | Contact details; time and date of entry/exit; appointment details; CCTV footage. | Legitimate interest. |
| Visitor management | To manage and confirm appointments, identify, and register visitors, coordinate logistical aspects such as parking and facility use, and manage events or meetings. | Contact details; time and date of entry/exit; appointment details; license plate. | Legitimate interest; consent. |
| Communication and support | To contact you in cases of emergency, respond to inquiries, complaints, or disputes, provide necessary information, and facilitate networking opportunities. | Contact details; appointment details. | Legitimate interest; consent. |
| Compliance and reporting | To comply with legal requirements and report any incidents that may occur. | Contact details; time and date of entry/exit; appointment details; CCTV footage. | Legitimate interest. |
We may collect and hold personal data as part of our client engagement and acceptance procedures. As part of our client engagement and acceptance, we carry out searches using publicly available sources (such as internet searches and sanctions lists) to identify politically exposed persons and heightened risk individuals and organisations and check that there are no issues that would prevent us from working with a particular client (such as sanctions, criminal convictions (including in respect of company directors), conduct or other reputational issues).
Our customer due diligence (CDD) check involves collecting and processing the following categories of personal data:
Note that when we perform CDD, we may process sensitive categories of personal data including data about criminal convictions and offences, where legally permitted.
| Purpose | Description | Categories of personal data | Legal basis |
|---|---|---|---|
| Compliance and legal obligations | To comply with legal and regulatory obligations, including anti-money laundering (AML) and counter-terrorism financing (CTF) regulations. | Contact details; job details; identification information; financial details; compliance information. | Legal obligation; legitimate interests. |
| Risk management and quality control | To prevent conflicts of interest, control risks, and assess the quality of our services and operations. | Contact details; job details; identification information; financial details; compliance information. | Legal obligation; legitimate interests. |
| Customer relationship management | To maintain a financial administration and for other essential administrative support services. | Contact details; job details; financial details. | Legal obligation; legitimate interests. |
We process personal data of visitors to our in-scope websites Scope and others who get in touch with us with a question, complaint, comment or feedback. This involves collecting and processing the following categories of personal data:
We ask that you do not provide us with any sensitive data when using our website.
Please note that information you share on public-facing blogs, forums, crowdsourcing or other applications and services implemented on our PwC NL website, may be accessible to other users of these applications and services.
| Purpose | Description | Categories of personal data | Legal basis |
|---|---|---|---|
| Administering and managing our website | To enable the safe access to and navigation of our (careers) websites and monitor website performance, including to confirm and authenticate your identity and prevent unauthorised access to restricted areas of the site or premium content. | Information we generate: IP address, browser type and version, device type and operating system, log files, user preferences and settings, error logs. | Legitimate interest. |
| Marketing and communications | To manage newsletter subscriptions, send (requested) materials, provide (prospective) clients with information that we think will be of interest about us and our services (such as industry updates and insights, other services that may be relevant and invitations to events), and to ask for further information. | Information you provide to us: Client business contact details, inquiry details. | Consent; legitimate interest. |
| Analytics and website improvement | To conduct data analysis and benchmarking to develop our businesses and services and improve the functionality of our websites. | Information we generate: Website usage data, anonymized IP address, browser type and version, device type and operating system, aggregated website visitor data Information you provide to us: User feedback and comments to PwC related social media posts. |
Consent; legitimate interest. |
Given the diversity of the services we provide to individual clients, we process categories of personal information, as appropriate for the services we are providing. Generally, our policy is to collect only the personal information necessary for agreed purposes, and we ask our clients only to share personal information when it is needed for those purposes.
We collect personal data from our clients or from a third party acting on the instructions of the relevant client. When we need to process personal information relating to individuals other than our clients to provide our services, we ask our clients to provide the necessary information to other data subjects concerned, such as family members, regarding its use.
As appropriate for the services we are providing, we collect and process the following categories of personal data:
We may provide a separate privacy statement in connection with certain services provided to those individuals, and where we do so, such privacy statement will apply to our processing of personal information in the performance of those services.
| Purpose | Description | Categories of personal data | Legal basis |
|---|---|---|---|
| Providing the professional services | To provide professional services to our clients. | As appropriate for the professional service we are providing contact details; family details; job details; CRM data; financial data; special categories of data; criminal data. | Consent; fulfilment of an agreement; legal obligation; legitimate interests. |
| Administering, managing and developing our business and services | Develop our businesses and services (such as identifying client needs and improvements in service delivery), to maintain and use IT systems, to conduct surveys (e.g. benchmarking) or quizzes, to host or facilitate the hosting of events, and to administer and manage our website and systems and applications. | Contact details; job details CRM data; financial data. | Consent; fulfilment of an agreement; legitimate interests. |
| Manage relationships | To manage and maintain relationships with (prospective) clients and analyse and evaluate the strength of interactions with contacts via our CRM system, based on aspects including interaction frequency, duration, recentness and response time. | Contact details; job details; CRM data. | Fulfilment of an agreement; legitimate interests; consent. |
| Perform analytics | Where agreed with our clients to conduct analyses to better understand a particular issue, industry or sector, provide insights back to our clients, to improve our business, service delivery and offerings and to develop new PwC technologies. | To the extent that the information that we receive while providing professional services contains personal data, we will de-identify the data prior to using the information for these purposes. | Legitimate interest. |
| Security, quality, and risk management activities | To monitor network and information security, for example by performing automated scans to identify harmful emails like phishing emails, and to manage risks to our business and monitor the quality of our services by detecting, investigating and resolving security threats. We have policies and procedures in place to monitor the quality of our services and manage risks in relation to client engagements. | Contact details and CRM data, including automated scans to identify harmful emails and personal data stored on the relevant client file]. | Fulfilment of an agreement; legal obligation; legitimate interests. |
| Complying with any requirement of law, regulation, or a professional body of which we are a member | To fulfil legal, regulatory and professional obligations as a professional services provider. Specifically, subject to these obligations and as described in the Retention section, we need to keep certain records to demonstrate that our services are provided in compliance with those obligations and those records may contain personal data. | Contact details, CRM data, financial data. | Legal obligation; legitimate interests. |
Our use of suppliers involves collecting and processing the following categories of personal data of our suppliers (including subcontractors and individuals associated with our suppliers and subcontractors):
| Purpose | Description | Categories of personal data | Legal basis |
|---|---|---|---|
| Ordering and receiving services | To receive services from our suppliers. | Business contact details; communications. | Fulfilment of agreement; legitimate interest. |
| Internal management activities | To administer, manage and develop our business and services and maintain and use IT systems. | Business contact details. | Fulfilment of agreement; legal obligation; legitimate interest. |
| Provide professional services to our clients | To deliver professional services to our clients (for example, where our supplier is providing people to work with us as part of a PwC NL team providing professional services to our clients). | Business contact details. | Fulfilment of agreement; legitimate interest. |
| Maintaining contacts | Administering and managing our relationship with suppliers and the relevant individuals. | Business contact details; communications. | Fulfilment of agreement; legitimate interest. |
| Disputes and audits | Handling of disputes and exercising audits. | Business contact details; communications. | Legal obligation; legitimate interest. |
We process personal data in connection with our recruitment activities. This involves the following categories of personal data:
*Note that you do not have to provide a BSN or social security number when you apply for a job.
| Purpose | Description | Categories of personal data | Legal basis |
|---|---|---|---|
| Marketing and communication | To promote career opportunities at PwC NL and communicate with potential candidates. This includes participating in events, marketing activities, and using recruiters to reach out to talent. | Contact details; CV details. | Legitimate interests. |
| Process and manage applications | To identify, attract, evaluate, and hire talent. This includes sourcing candidates from our existing talent pool and other publicly available sources, managing applications and conducting interviews and assessments. | Contact details; CV details; references; interview details; offer details; log-in credentials. | Fulfilment of an agreement; legal obligation; legitimate interests. |
| Background checks | To conduct appropriate (PES) background checks to ensure an individual is eligible to work in the Netherlands and to comply with clearance requirements. | Pre-employment screening information. | Legal obligation; fulfilment of an agreement. |
| Analytics | To conduct statistical analyses and create reports, including for example conducting a demographic analysis of candidates, reports on our recruitment activities, and analysis of candidate sourcing channels. | Contact details. | Consent; legitimate interest. |
We obtain your personal data in various ways:
We will only share personal data with others when we are legally permitted to do so. When we share data with others, we put contractual arrangements and security mechanisms in place as appropriate to protect the data and to comply with our data protection, confidentiality, and security standards.
We are part of a global network of member firms and, like other professional service providers, we use third parties located in other countries to help us run our business. As a result, personal data may be transferred outside the countries where we and our clients are located. This includes countries outside the European Economic Area (EEA). We have taken steps to ensure all personal data is provided with adequate protection and that all transfers of personal data outside the EEA are done lawfully.
We take the protection of all data we hold seriously. That is why we have taken appropriate technical and organizational measures to guarantee a risk-adjusted security level. We adhere to internationally recognised security standards and our information security management system relating to client confidential data is independently certified as complying with the requirements of ISO/IEC 27001:2022. We have a framework of policies, procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.
Where we transfer personal data outside of the EEA to a country not determined by the European Commission as providing an adequate level of protection for personal data, the transfers will be under an agreement which covers the EEA requirements for the transfer of personal data outside the EEA, such as by the European Commission approved standard contractual clauses. If you have any questions about the way in which we transfer your personal data to countries outside the EEA and on which basis, you can contact our Data Protection Office by emailing nl_dataprotection@pwc.com.
We only retain personal data for as long as necessary for the purposes described in chapter Personal data use. We determine our specific retention periods based on the nature of the personal data, the purposes for which we process this data, the data subjects that the personal data relates to, and their reasonable expectations.
For example:
The laws on the protection of personal data give you the following rights about your personal data:
If you have any questions about this Privacy Statement or how and why we process personal data, please contact us at:
We recognise that transparency is an ongoing responsibility, so we keep this Privacy Statement under regular review. If we want to make any substantial changes to the way we process personal data, for example, if we intend to collect new types of personal data or process the data for new purposes, we will give notice in advance where we can, including here on our website.'
This Privacy Statement was last updated in May 2026