This document describes how Arrow Global Limited (‘we, us, our, Arrow’) use and share personal data (also called ‘Account data’) they receive from you or other sources. This fully replaces all previous Privacy Notices.
May 2023 (Version 5.0)
1. WHO IS ARROW GLOBAL LIMITED?
Arrow is a leading European credit management services provider focusing on loan purchases and specialist asset management. We purchase customer accounts from a range of businesses.
We operate as the regulated entity in the UK for a number of other companies. Where the account is owned by any party in the below list, it is operated by us under this Privacy Notice:
- Arrow Global Limited
- AGL Fleetwood Limited
- Arrow Global Accounts Management Limited
- Arrow Global Europe Limited
- Arrow Global Investment (Holdings) Limited
- Arrow Global Portugal Investments
- Arrow Global Receivables Management Limited
Please be aware if you are an Erudio Student Loans customer, you will have a separate Privacy Notice for this data, which can be found at http://www.erudiostudentloans.co.uk/tools/privacy-policy.htm
2. WHAT DO WE USE PERSONAL DATA FOR?
Customer and Account Information Accuracy
We maintain information, including personal data, for the purposes of managing accounts where we are the owner, or on behalf of that owner. This could include activities designed to support:
- Ensuring our customer and account information is accurate. This involves regular data quality reporting, investigating data inaccuracies and making corrections should they arise;
- Arrears Management;
- Processing statutory documents, including Statements, Notice of Sums in Arrears and Notices of Default.
Tracing and debt recovery
We use data from Credit Reference Agencies (CRAs) and other 3rd party data providers to trace people who are not responding using known contact details.
An example of a tracing activity could be when a customer moves home without informing us of their new address. We may then use the data we obtain from CRAs and other 3rd party data providers to identify the customer’s new address and contact details. We then use our analytics capability to help find missing individuals through updated addresses and contact details.
We report the status of the accounts we own, as well as any updates to a customers confirmed contact details, to the CRA. The CRAs combine this data with that from other lenders to build a credit profile of an individual which in turn may be used to help inform future lending decisions.
Statistical analysis, analytics and profiling
Personal data can be used to create scorecards, models and variables in connection with the assessment of credit, fraud, risk or to verify identities. It can also be used to monitor and predict market trends, to allow use by Arrow for refining recovery and trace strategies, and for analysis such as loss and revenue forecasting.
We carry out certain processing activities internally which support databases effectiveness and efficiencies. For example:
- Data loading: this is where data is supplied to us and is checked for integrity, validity, consistency, quality and age to help make sure it is fit for purpose. These checks pick up things like irregular dates of birth, names, addresses, account start and default dates, and gaps in status history.
- Data matching: this is where data supplied to us is matched to existing databases to help make sure it’s assigned to the right person, even when there are discrepancies e.g. spelling mistakes or different versions of a person’s name. We use the personal data people give lenders together with data from other sources to create and confirm identities, which they use to underpin the services they provide.
- Data linking: this is where we compile data into its databases and we create links between different pieces of data. For example, people who appear financially associated with each other may be linked together, and addresses where someone has previously lived can be linked to each other and to that person’s current address.
- Systems and product testing: this is where data is used to help support the development and testing of new products and technologies.
Uses as required by or permitted by law
Your personal data will also be used for other purposes where required by law, such as where we are obliged to provide data to the law enforcement agencies.
3. WHAT ARE OUR LEGAL GROUNDS FOR HANDLING PERSONAL DATA?
We use the following grounds for handling personal data:
- Legitimate interests;
- Compliance with a legal obligation;
- Fulfilment of a contract;
The below outlines the activities we undertake in relation to your data, the appropriate legal grounds for processing as well as an explanation of what our legitimate interests are when this is our reason for processing.
|Interest||Reason(s) for Processing||Explanation|
|Managing your account||– Legitimate interests
– Compliance with a legal obligation
|We have an obligation to appropriately manage your account in line with any credit agreement.|
|Recovery of funds owed||– Legitimate interests
– Compliance with a legal obligation
|Our business is primarily the recovery of funds owed by individuals in the consumer credit market. As such, our customers typically have overdue funds that we are seeking to be repaid, either actively or by awaiting a change to customers’ personal circumstances. This explicitly requires us to understand our customers and their circumstances in order to conduct ourselves in an appropriate way.|
|Account status reporting – Credit Reference Agencies||– Legitimate interests||We share personal data about our customers, their circumstances where applicable, and their financial history with the CRAs.|
|Complying with and supporting compliance with legal and regulatory requirements||– Legitimate interests
– Compliance with a legal obligation
– Fulfilment of a contract
|We must comply with various legal and regulatory requirements and help other organisations comply with their own legal and regulatory obligations.|
|Maintenance of data for use in defending legal actions||– Legitimate interests||We need to be able to investigate and respond to customer claims and to provide appropriate disclosure in the event of proceedings being issued. This requires it to maintain information for a period after its original legitimate purpose has expired. This is subject to the retention of personal information, described below.|
|Training and Quality||– Legitimate interests
– Compliance with a legal obligation
|To ensure the good quality of the service we provide, customer data is used while training staff and reviewing the quality and output of ourselves and our partners.|
|Customer service and market research||– Legitimate interests
– Compliance with a legal obligation
|To ensure the good quality of the service we provide, customer data is used for communication purposes; and where necessary for market research purposes.|
Our use of this personal data is subject to an extensive framework of safeguards that help make sure that people’s rights are protected. These include the information given to people about how their personal data will be used and how they can exercise their rights to obtain their personal data, have it corrected or restricted, object to it being processed, and complain if they are dissatisfied.
Additionally, Arrow will look for your consent to process personal information in relation to your health. This will only be in circumstances where you choose to share this information with us to help us understand your circumstances and appropriately manage your account. This will be used for no other purposes than managing your account and for training and quality purposes.
4. WHAT KINDS OF PERSONAL DATA DO WE USE, AND WHERE DO WE GET IT FROM?
We obtain and use information from different sources, so we often hold different information and personal data about each customer. All information we hold about our customers falls into the below categories:
|Key Customer Identifiers||We hold personal data that can be used to identify people; this includes:
– Name, including Title, Forename and Surname.
– Address, including current and previous addresses, if these are marked as no longer resident. Additionally, we will hold address confirmed as inaccurate to prevent these being reused.
– Contact details, including telephone and email information, past and present. Additionally, we will hold contact details marked as inaccurate to prevent these being reused.
|This personal data is included with all the other data sources. For example, names, addresses and dates of birth are attached to financial account data, so it can be matched and associated with all the other data Arrow holds about the relevant person.
Data is first obtained from the lender of the debt prior to our acquisition.
Data is also provided by customers directly in the daily interactions with ourselves or our agents.
Data about UK postal addresses is also obtained from sources like Royal Mail.
We also obtain copies of the Edited Electoral Register containing the names and addresses of registered voters from local authorities across the UK in accordance with specific legislation. We also have access to public data sources on people and businesses, including from the Insolvency Service, Companies House, the CRAs and commercial business directories.
|Customer Circumstances||We hold personal data relating to individual’s circumstances including mental and physical health, financial status (including hardship) and difficulties relating to communication. The purpose of this information is to ensure all circumstances are taken into account when managing your account(s).||This information will be obtained from:
1. You, the customer, during an interaction directly with Arrow
2. A 3rd party you have authorised to work on your behalf, or
3. You, the customer, directly during an interaction with an agency working on our behalf.We do not actively obtain data from external sources relating to customer circumstances.We will always obtain customer consent before recording information relating to personal circumstances such as health, financial status or communication requirements.
|Financial data||We receive information that includes personal data from credit accounts and other financial accounts that people hold with other organisations. This includes data about bank accounts, credit card accounts, mortgage accounts and other agreements that involve credit agreements such as utilities and communications contracts (including mobile and internet).
The collected data includes the date the account was opened, the amount of debt outstanding (if any), any credit limits and the repayment history on the account, including late and missing payments.
We may also receive data about financial accounts like current accounts, credit cards or loans and may receive payment information that businesses hold from the organisations who maintain other accounts belonging to you. We also use external data services from the CRAs to validate customers’ stated income.
|Banks, building societies, lenders and other financial services providers supply data including personal data about people’s financial accounts and repayments to CRAs.
Other credit providers, such as hire purchase companies, utilities companies, mobile phone networks, retail and mail order, and insurance companies also provide this data when they agree credit facilities with their customers to the CRAs.
These are then provided to us with regards to our customers, to assist us in our legitimate purposes.
|Court judgments, decrees and administration orders||We obtain data about court judgments that have been issued. This may include, for example, the name of the court, the nature of the judgment, how much money was owed, and whether the judgment has been satisfied. Additionally, we may receive information about enforcement taken, such as Charging Orders on properties held by customers.||Judgments and some other decrees and orders are made publicly available through statutory public registers. These are maintained by Registry Trust Limited, which also supplies the data on the registers to the CRAs, and in turn Arrow.
Charging Order information may also be provided by the Land Registry.
|Bankruptcies, Individual Voluntary Arrangement (IVAs), debt relief orders and similar events||We obtain data about insolvency related events that happen to our customers and may also obtain this type of data about businesses. This includes data about bankruptcies, IVAs and debt relief orders, and in Scotland it includes sequestrations, trust deeds and debt arrangement schemes. This data includes the start and end dates of the relevant insolvency or arrangement.||We obtain this data from our customers, their representative (Insolvency Practitioner), The Insolvency Service, and the CRAs.|
|Search footprints||We have access to credit application information where a financial institution uses a CRA to make enquiries about a particular person, the CRA keeps a record of that enquiry which appears on the person’s credit file.
This includes the name of the application, the date, and the reason they gave for making the enquiry.
Additionally, it may include such information as contact details, address information, income and employment situation of the applicant when they applied for the credit.
|CRAs generate search footprints when enquiries are made about a particular person by other lenders.
The lender making the enquiry provides some of the data in the footprint (such as the reason for the enquiry).
We in turn obtain this information from the CRAs.
|Scores and ratings||We will use the data they receive to produce scores and ratings including potential affordability, risk, fraud and identity checks, screening, collections, litigation and insolvency scores about our customers.||We produce their scores and ratings using the data available to them detailed in this section only.
This is sometimes supplemented by CRAs’ own scores.
|Public interest data||We receive data from commercial sources which includes lists of politically exposed persons (PEPs) and sanctions data; this is to ensure we meet our regulatory requirements.||We receive this data from reputable commercial sources as agreed from time to time.|
|Other derived data||We produce other kinds of data ourselves to manage our databases efficiently and ensure that all the relevant data about a person is on the correct credit file.
Address links: when we detect that a person seems to have moved to a different residence, it may create and store a link between the old and new address.
Flags and triggers: through analysis of other data, we can add indicators to a customer’s account file. These aim to summarise particular aspects of a person’s financial situation. For example, a Potential Insolvency flag protects those who may be insolvent, and invites additional checks as a defence against further fraud risk.
|Arrow generates this data from the data sources available to them.|
5. WHO DO WE SHARE PERSONAL DATA WITH?
This section describes the types of recipient we share data with and our process for ensuring it is an appropriate organisation. In some cases, some organisations have the ability to compel us, by law, to disclose certain data for certain purposes.
Members of the credit reference agency data sharing network
We share information with CRAs as part of our obligation to ensure appropriate lending for consumers and help ensure the health of the UK financial services industry. Each organisation that shares financial data with the CRAs is also entitled to receive similar kinds of financial data contributed by other organisations. These organisations are typically banks, building societies, and other lenders, as well as other credit providers like utilities companies and mobile phone networks. In the UK we use the following CRAs:
|Credit reference agency||Contact details|
|TransUnion||Post: One Park Lane, Leeds, West Yorkshire, LS3 1EP
Web Address: https://www.transunion.co.uk
Phone: 0113 388 4300
|Equifax Limited||Post: Equifax Ltd, Customer Service Centre PO Box 10036, Leicester, LE3 4FS
Phone: 0333 321 4043 or 0800 014 2955
|Experian Limited||Post: Experian, PO BOX 9000, Nottingham, NG80 7WF
Web Address: https://www.experian.co.uk
Phone: 0344 481 0800 or 0800 013 8888
We may entrust your account for management by one of our Partner companies, who will operate as our agent. We will communicate with you at the time should this outsourcing take place.
Information Technology Processors
We will use other organisations to perform tasks on their own behalf (for example, IT service providers and call centre technology providers) to assist us with running our business. These providers will always act as our agents, should we instruct them to contact you.
If proceedings are issued against you or enforcement activity is taken, we will provide information to the relevant Court service.
If you have chosen to make payments via Debit or Credit Card, Arrow will provide relevant information to payment processing companies to facilitate the transaction.
People are entitled to obtain copies of the personal data the Arrow holds about them. You can find out how to do this in Section 10 below.
Legal and Regulatory
Any law enforcement agency, regulator, court, government authority or other third party where we believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights or the rights of any third party.
We may share data with any organisation who holds an interest, whether legal or beneficial in nature, who may act as an individual or joint data controller. They may process the data for the purposes of management of your account. Should you wish to obtain further information about it, you can contact us using the methods outlined in section 10 of this notice.
6. WHERE IS PERSONAL DATA STORED AND SENT?
As a result of Brexit, the UK stopped being treated as part of the European Union and the European Economic Area (“EEA”) and, as a result, your personal data will be protected by UK privacy laws from that date. Looking after your data is very important to us, and Brexit will not change that.
We will only share personal data with others outside the UK where:
- the EU Commission or UK government (as relevant) has decided that the relevant country has adequate protective rules in relation to data protection in place (an “adequacy decision”);
- we have entered into the relevant “standard contractual clauses” with the recipient of your personal data (these are a set of obligations about how your data is protected and used; or
- we can rely on another basis under the law such as that we have to share the personal data because this is necessary for the purpose of a court case, investigation or to protect our legal rights.
7. FOR HOW LONG IS PERSONAL DATA RETAINED?
In general, we will retain all information held about our customers for as long as they continue to have an active account with us. This will include for as long as funds are owed to us.
Once the account is closed and no funds are owed, we will continue to retain all data for a period typically of six years from closure. The criteria used to determine the storage period will include the legal limitation of liability period, agreed contractual provisions, applicable regulatory requirements and industry standards.
Exceptions to this standard six-year approach are detailed below:
In the rare situations where customers’ accounts have some form of overpayment, the data is kept for as long as the account remains in credit and for six years from the date these monies are re-payed to the customer.
Voice recordings of telephone conversations with customers will be held for three years after the call has taken place.
We will hold archived data in both physical and digital formats for business continuity purposes. Where data is retained in archives for longer than the periods described above, it will not be accessible to unauthorised staff and in the case of digital backups data is encrypted. We will take steps to ensure that, if such archives are required to be accessed, we will have all personal information no longer required removed.
8. WHAT RIGHTS DO I HAVE UNDER DATA PROTECTION REGULATION?
|Right to be informed||You have the right to be informed about how we collect and use your personal data. This has been described within this Privacy Notice.||All|
|Rights related to automated decision making||You have rights in relation to any automated decision-making and/or profiling that has legal or similarly significant effects on you.||9|
|Right of access||You have the right to access your personal data and supplementary information held by us.||10|
|Right to data portability||In certain circumstances, you have the right to obtain and reuse your personal data for your own purposes across different services.||10|
|Right of rectification||You have the right to have inaccurate personal data rectified, or completed if it is incomplete.||11|
|Right to object||You have the right to object to the processing of your personal data.||12|
|Right of erasure||In certain circumstances, you have the right to request the deletion or removal of personal data where there is no compelling reason for its continued processing.||12|
|Right to restrict processing||In certain circumstances, you have the right to request us to ‘block’ or suppress processing of personal data.||13|
If you wish to exercise any of these rights, you can contact us at DPO@arrowglobal.net.
9. HOW DOES ARROW MAKE DECISIONS ABOUT ME (“RIGHTS RELATED TO AUTOMATED DECISION MAKING”)?
Scores and ratings
We use the data we hold on the accounts we own along with data from the CRAs and other 3rd party data providers to produce various scores such as risk, fraud, affordability, collection, litigation and/or insolvency scores to profile accounts and customers. The following factors are likely to impact these scores:
- How long the person has lived at their address;
- The number and type of credit agreements and how they use those credit products;
- Whether the person has been late making payments;
- Whether the person has had any court judgments made against them;
- Whether the person has been bankrupt or had an IVA or other form of debt-related arrangement.
These scores will inform appropriate actions to manage customers’ accounts with us and ensure appropriate steps are taken with respect to personal circumstances. An example would be where we use the insolvency scores and data to place an account with a specialist insolvency practitioner.
Where automated decisions are made with regards to account treatment or placement, customers have the right to appeal.
10. WHAT CAN I DO IF I WANT TO SEE THE PERSONAL DATA HELD ABOUT ME (“RIGHT OF ACCESS”)? DO I HAVE A ‘PORTABILITY RIGHT’ IN CONNECTION WITH MY ARROW DATA (“RIGHT TO DATA PORTABILITY”)?
You have the right to ask us what data we hold about you. This is known as a Subject Access Request (SAR). You have a right to find out what personal data we hold about you. You can do this by emailing your request to DPO@arrowglobal.net
11. WHAT CAN I DO IF MY PERSONAL DATA IS WRONG (“RIGHT TO RECTIFICATION”)?
When we receive personal data, we perform a number of checks on it to try and detect any defects or mistakes. Ultimately though, we rely on our suppliers and our customers to provide accurate data to us.
If you think that any personal data we hold about you is wrong or incomplete, you have the right to request this is updated.
If our data does turn out to be incorrect, we will update our records accordingly. If we still believe our data is correct after completing our checks, we will continue to hold and keep it – although you can ask us to add a note to your file indicating that you disagree or providing an explanation of the circumstances. Additionally, we will need to keep a copy of the incorrect record but solely for auditing purposes.
If you’d like to request an update of your data, you should contact us at DPO@arrowglobal.net.
12.CAN I OBJECT TO THE USE OF MY PERSONAL DATA (“RIGHT TO OBJECT”) AND HAVE IT DELETED (“RIGHT TO ERASURE”)?
You have the right to object to our use of your personal information, or to ask us to delete, remove, or stop using your personal information if there is no need for us to keep it. This is known as the ‘right to object’ and ‘right to erasure’, or the ‘right to be forgotten’.
Section 4 of this notice details what information we process, and why we need this information within our organisation in relation to the activities we undertake. This is why your right to object doesn’t automatically lead to deletion of your information, but we will deal with every request we receive and if we can’t delete your information we shall inform you and explain why we cannot.
13. CAN I RESTRICT WHAT YOU DO WITH MY PERSONAL DATA (“RIGHT TO RESTRICT PROCESSING”)?
In some circumstances, you can ask us to restrict how we use your personal data. This is not an absolute right, and your personal data may still be processed where certain grounds exist. These grounds include:
- With your consent;
- For the establishment, exercise, or defence of legal claims;
- For the protection of the rights of another natural or legal person;
- For reasons of important public interest.
Only one of these grounds needs to be demonstrated to continue data processing. We will consider and respond to requests we receive, including assessing the applicability of these exemptions.
Please note that given the importance of complete and accurate records, for purposes outlined above, it will usually be appropriate to continue processing data. In particular, to ensure appropriate management of your account.
14. WHO CAN I COMPLAIN TO IF I’M UNHAPPY ABOUT THE USE OF MY PERSONAL DATA?
In the first instance, our data protection officer can be contacted by emailing DPO@arrowglobal.net or by writing to us at 12 Booth Street, Manchester, M2 4AW.
If you are unhappy with how we have investigated your complaint, you have the right to refer your concerns to the Information Commissioner’s Office (or ICO), the body that regulates the handling of personal data in the UK. You can contact them by:
- Phone on 0303 123 1113
- Writing to them at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF
- Going to their website at www.ico.org.uk