Last updated: April 2023
Shearman & Sterling LLP (“Shearman & Sterling”, “Firm”, “we” and “us”) is strongly committed to protecting Personal Information.
This Data Privacy Notice (China) (this “Privacy Notice”) shall apply solely when we process Personal Information within the scope of laws related to the protection of Personal Information within the territory of mainland China, including the Personal Information Protection Law (“PIPL”) and relevant laws, regulations, and national standards (“China Data Protection Law”).
Where we operate in jurisdictions outside mainland China or where China Data Protection Law does not apply, descriptions, and in particular the outlined rights and obligations and limitations to processing contained in this Privacy Notice do not necessarily apply, and nothing in this Privacy Notice may be interpreted to establish rights or obligations that go beyond what is required. For additional information about our data practices: please see our main privacy notice.
“Personal Information” refers to information related to an identified or identifiable natural person that is recorded electronically or otherwise, excluding anonymized information.
“Sensitive Personal Information” refers to Personal Information that once leaked or illegally used, may easily cause the infringement to the dignity of the natural person or harm to personal or property security, including but not limited to the information on biometric characteristics, religious beliefs, specially-designated status, medical health, financial accounts, individual location tracking, as well as the Personal Information of minors under the age of 14.
This Privacy Notice describes why and how we collect and use Personal Information and provides information about rights individuals may have in relation to Personal Information. It applies to Personal Information provided to us, both by individuals themselves or by others. We may use Personal Information provided to us for any of the purposes described in this Privacy Notice or as otherwise stated at the point of collection.
Please read this Privacy Notice carefully to understand how we will process your Personal Information. By interacting with us or submitting your Personal Information to us, you acknowledge and accept the terms in this Privacy Notice.
We will only process your Sensitive Personal Information with your consent or as required by applicable laws or regulations. Our processing will not adversely affect your rights or interests. For the Sensitive Personal Information we process, we will take appropriate security measures that correspond to the risk level of such information to prevent unauthorized access to and public disclosure, use, modification, destruction, leakage, or loss of Personal Information.
This Privacy Notice will help you understand the following content:
As a law firm, we regularly receive Personal Information in the course of professional activities. We may collect Personal Information in the following scenarios:
When you or your organization seek legal advice or representation from us, as part of our business intake procedures, we may need to collect the following information from you for the purpose of contacting, identity verification, conflict interest check, background check, AML and sanctions check, client relationship management, and to contract with you or your organization: matter description, description of goods or services to be supplied, contact details of you or your organization (such as your name, phone number, work email and work address), contact detail of your organization's contact person, the job title and role of you or your organization's contact person. If you fail to provide us with the aforementioned information, we may not be able to successfully provide legal services to you.
If you are our client, we may collect the following information for the purpose of providing services or support to you: matter description, contact details for you, your organization or your employees (including name, phone number, work email, office location and work address), the job title and role of the individual client or client's employee and the content of communications with you.
Depending on the legal services we provide, we may collect additional Personal Information from you or your organization. For example, when we provide capital market-related services, we may collect your employee's age, education background, and work experience for due diligence. When we provide litigation and investigation-related services, we may collect your employee's financial information, such as bank account numbers. You are responsible for getting the necessary consent from the individuals whose Personal Information is provided to us.
When you offer or provide services as our vendor, such as providing event-related services or legal research management services, we will collect the following information for the purpose of vendor management and contracting: name, contact detail of the vendor and vendor's contact person (including company address, work address, work email, company address, phone number and Wechat contact).
For additional information about our collection and use of your information when you apply for employment or other roles with the Firm, please see our Candidate Privacy Notice (China).
When you visit our offices, we may collect your name, phone numbers and the purpose of your visit to grant you access. During your visit, we will collect your entrance records such as CCTV footage capturing your images for building security purposes.
If you subscribe to our website to receive marketing communications from Shearman & Sterling, we will collect the following information from you: first name (optional), last name, email, job title (optional), company name (optional), country of residence, and subscription preferences.
If you subscribe to our WeChat official account, we will collect your WeChat user name and portrait. If you fail to provide us with the aforementioned non-optional information, we will not be able to send you the marketing communications from us. You may opt-out at any time.
When you request details about or attend a Firm-sponsored event, we may collect the following information from you: name, email, job title, company name, and name card information, such as telephone and fax number. If you failed to provide us with the aforementioned non-optional information, we will not be able to contact you and send you the event details or invitation.
As permitted by law and regulation, we will process your Personal Information without your consent under the following circumstances:
Notwithstanding the specific purposes set forth above, we may use the Personal Information we collect from you under Applicable Data Protection Law and for the purposes related to the aforementioned processing activities unless you refuse us to process your Personal Information by deleting your Personal Information, withdrawing your consent or other means.
Such information allows us to better understand the visitors to our website, such as where they come from and what contents of our website attract them. We use this information for internal analysis and troubleshooting, and to improve the quality of our website's contents. We also need to keep appropriate logs to record the status of our website in order to comply with the applicable laws and regulations.
Please note that when you disable cookies by changing browser settings or using the "anonymous browsing" feature of the browser, cookies will no longer collect your information. For more information about the cookies that we use in our website, please refer to our Cookie Notice.
We may entrust third parties to process your Personal Information. We will enter into strict confidentiality agreements with such third parties and require them to process Personal Information in accordance with our requirements, this Privacy Notice, and the confidentiality and security measures required by laws and regulations.
If we process your Personal Information, it may be shared among the Shearman & Sterling offices in order to provide services to our clients or for our business operations. View a list of our offices.
We may share Personal Information with third parties in the course of representing our clients, for example (but not limited to) clients, other parties involved in client matters, or those other parties' counsel, courts, government agencies, industry regulators, vendors, service providers, and consulting experts.
We will only disclose your Personal Information to the relevant parties to the extent necessary. As required by Applicable Data Protection Law, we will enter into data processing agreements and confidentiality agreements with the relevant parties, requiring them to process your Personal Information following our instructions, this Privacy Notice and the security measures required by Applicable Data Protection Law.
We may share your Personal Information with third parties in the following circumstances:
In the event of any change, merger, acquisition, reorganization, or liquidation involving the transfer of Personal Information, we will ask the new company or organization holding your Personal Information to continue to process your Personal Information in accordance with this Privacy Notice. If the new company or organization holding your Personal Information needs to use your Personal Information for purposes not stated in this Privacy Notice, the new company or organization will obtain your consent, unless otherwise provided by the applicable laws and regulations.
To the relevant competent law enforcement body, regulatory, government agency, court or other third parties where we believe that such disclosure is to:
(i) comply with an applicable law or regulation; (ii) exercise, establish or defend our legal rights, or
(ii) protect your vital interests or those of any other person.
We will make every reasonable effort to protect the Personal Information you provided, overseen by our dedicated data security team. To prevent accidental and unauthorized access, copying, modification, transmission, deleting, destruction, processing or use of the Personal Information, we have taken and will continue to take appropriate measures to protect your Personal Information based on the risk level of the Personal Information.
Although we have taken reasonable and effective measures as described above and comply with the standards required by the applicable laws and regulations, we still cannot guarantee the security of your Personal Information when you are communicating through insecure means. Therefore, you should take active measures to ensure the security of your Personal Information, such as: regularly changing your email account password and not disclosing your account password and other Personal Information to others.
We have put in place procedures to deal with any suspected Personal Information breach and will notify you and any applicable regulatory authority of a breach where we are legally required to do so.
You understand that the Personal Information protection measures we take only apply to the Personal Information you provide to us. Once you use other websites, services, and access other content resources, we have no ability or obligation to protect any Personal Information you submit on other websites, regardless of whether your access to or browsing of the above websites is based on a link or guide in our website.
We will delete your Personal Information when it is no longer reasonably required for the purposes described above, or, where applicable, if you withdraw your consent, unless we are legally required or otherwise permitted to continue to hold such data. We may retain your Personal Information for an additional period if deletion would require us to overwrite our automated disaster recovery backup systems, or to the extent we deem it necessary to assert or defend legal claims during any relevant retention period, then we will securely retain your Personal Information and not further process such data until deletion is possible.
For the purposes specified in this Privacy Notice, we may transfer your Personal Information to our Firm offices, clients, or other parties involved in client matters or those other parties' counsel, vendors, service providers, and consulting experts service providers located in countries or regions other than China for the purpose of providing service to the client or supporting our business operation.
Specifically, we may provide Personal Information we collected about you among our Firm offices to provide services to our clients or for our business operations. View a list of our offices. We may also use office software such as Office 365, iManage, Elite, New Business Intake, Interaction at the global level to store and process matter-related information and to provide you with client services.
Before transferring your Personal Information outside of China, we will take safeguards, complete necessary legal formalities, and obtain government approvals if necessary under China Data Protection Law. Meanwhile, we will take technical and organizational measures to ensure data security during transmission that are at least comparable to the Personal Information protection offered under China Data Protection Law.
We will make every effort to protect your rights of accessing, correcting, copying, and deleting Personal Information, withdrawing consent as well as other statutory rights.
With the exceptions outlined in Section 6.3, you have the right to request we delete your Personal Information under the following circumstances:
You can submit requests to us regarding your rights to accessing, correcting, copying and deleting Personal Information by contacting us through the contact details in the "How to contact us" section of this Privacy Notice below.
When you interact with us or submit your Personal Information to us, you have consented to our processing of your Personal Information for the purpose set out in this Privacy Notice. You have the right to withdraw your consent for processing for that purpose at any time. To withdraw your consent, please contact us using the contact details in the "How to contact us" section of this Privacy Notice below. Once we have received notification that you have withdrawn your consent, we will no longer process your Personal Information subject to the exceptions addressed in Section 6.3 and, subject to our data retention rule set forth in this Privacy Notice, we will delete or anonymize your Personal Information securely.
We will respond to all requests we receive from individuals who intend to exercise their rights to Personal Information according to China Data Protection Law. Before we respond to a communication or request, we may take certain steps to verify the requestor's identity and the authenticity of a request. Where we have reasonable doubts concerning the identity of the person making the request, or the authenticity of a request, we may request such additional information as we deem necessary to satisfy ourselves of their identity and authenticity of their request. If we cannot satisfactorily verify the identity of a requestor and the authenticity of a request, we will not be able to take any action pursuant to the request.
In order to facilitate this process and to enable us to assist you, when you make a request to us, please specify the type of request you are making, and provide us with your name, e-mail and telephone number, and satisfactory evidence of your identity. We will use your information only to verify your request by attempting to match your information to our internal records.
Under the following circumstances, we will be unable to address your requests:
Other circumstances where entertaining your request will seriously jeopardize the legitimate rights and interests of other individuals or organizations.
There is generally no charge for the exercise of your legal rights. However, if your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may either:
We try to respond to all legitimate requests within 15 working days. If your request is particularly complex, or if you have already made multiple requests, it may take us longer than 15 working days to process your request. In this case, we will notify you and keep you updated.
We may update this Privacy Notice from time to time to reflect changes in legal requirements or our processing practices. Any such changes will be posted on this website, with the date at the top of the Privacy Notice providing the date it was last updated. Changes to this Privacy Notice will be effective upon posting.
If you have any requests, questions or concerns about this Privacy Notice and our use of your Personal Information, you may contact the Data Privacy team via the following contact information:
Address: Director, Data Privacy, Shearman & Sterling, 9 Appold Street, London EC2A 2AP, United Kingdom
Phone number: +44 20 7655 5000
Email address: Data.Privacy@Shearman.com
If you are dissatisfied with our processing of your Personal Information or any other matter, you may file a complaint with the relevant data protection authorities.