Last updated 24 May 2018
GE Capital Aviation Services (“GECAS”) is committed to protecting the privacy of those who provide us their Personal Data and we have updated the terms of our Privacy Policy as it relates to the information which we process for the purposes set out below.
This notice (“Notice”) describes how GECAS will: (i) handle and protect Personal Data for the purposes of compliance with the General Data Protection Regulation (“GDPR”) (EU) 2016/679 and, (ii) comply with financial crime compliance (“FCC”) law and regulation, including for anti-money laundering ("AML") and counter terrorism financing ("CTF") purposes. This Personal Data may be part of Know Your Customer ("KYC ") due diligence required for onboarding a customer, or as part of due diligence undertaken for onboarding a new supplier or third-party business partner.
For the purposes of this Notice, “Personal Data” includes any information relating to an identified or identifiable natural person who can be directly or indirectly identified in particular by reference to an identifier, that you provide, or which we obtain. For further information about the ways in which we protect your Personal Data please visit our Privacy Policy at www.ge.com/privacy.
By providing us with Personal Data you confirm that: (i) you have reviewed this Notice and agree to its processing as explained herein; and (ii) you have the necessary authority to share the Personal Data of others, such as directors, officers, beneficial owners, or other natural persons.
Where the provision of an individual’s Personal Data is necessary for GECAS to fulfil its legal or compliance obligations and such information is not provided, this may impact GECAS’s ability to enter a business relationship with you or a relevant party.
Click on one of the sections below to find more information:
Collection and Processing
In addition to collecting Personal Data directly from you, we may collect Personal Data from third parties, such as credit reference agencies or publicly available sources, as required or permitted by local law. The legal basis for us processing your Personal Data will typically be one of the following: for the performance of an agreement or contract with you or a relevant party; to fulfil our legitimate business interests or comply with our legal obligations; or based on your consent. We will only use your Personal Data as described in this Notice to:
-
• comply with our obligations under AML, CTF and other FCC laws, which include:
-
- to identify and verify identity;
-
- to detect and prevent criminal activity;
-
- to screen and monitor against watchlists including sanctions;
-
-
• manage and service accounts to enable us to perform our contract with you or a relevant party;
-
• trace and recover debts to address our legitimate interests;
-
• to manage complaints to meet our contractual obligations with our customers or other third parties; and
-
• complete financial risk modeling to assess and manage various risks in our portfolio.
Personal Data Sharing
We may share Personal Data with other entities within the GE Group (being the General Electric Company and its wholly and majority-owned and/or serviced entities) or with third parties who all perform FCC services on our behalf and with law enforcement authorities and governmental entities, connected to criminal investigations or to establish, exercise, or defend our legal rights. In the event all, or some, of our business (or its assets) is sold, we may transfer Personal Data to any successor entities or parties. Wherever we share Personal Data we will exercise measures to safeguard it and ensure it is only processed as strictly necessary to fulfill a contractual task or legal obligation.
Data Transfers
Only where we have to do so in the performance of the contract or where you specifically request us to do so, we may transfer or process Personal Data worldwide. Where no satisfactory data protection laws exist in the country to which we are transferring the Personal Data, we will put equivalent contractual safeguards in place to protect it.
We have also entered Binding Corporate Rules which govern our data handling practices: www.ge.com/bcr. For further information on these safeguards please contact us at the address at the end of this Notice.
Protection and Retention of Personal Data
We maintain administrative, technical, and physical safeguards, consistent with legal requirements where the Personal Data is obtained, to protect the integrity, confidentiality, security, and availability of Personal Data. Personal Data is retained only for as long as it is needed to fulfil the purpose for which it was obtained in accordance with the principle of data minimization under GDPR and subject to additional legal retention requirements.
Your Rights