Lawful basis of processing
Our Global Data Privacy Statement lists the purposes for which we process your personal information. The lawful basis of processing will depend on these purposes. For majority of our processing operations, we rely on PPG’s legitimate interests, necessity to perform a contract with you, or attending to PPG’s legal obligations. In limited circumstances, we may also ask for your consent to process personal information. We list below the purposes of processing, as related to each lawful basis:
Processing on the basis of our legitimate interest. Our legitimate interests may include: (i) handling and responding to your questions, enquiries and complaints; (ii) understanding your needs as our customer; (iii) customizing your user experience; (iv) measuring effectiveness of communications and Websites and Apps performance; (v) compiling market insights; (v) conducting data analysis, testing and troubleshooting on the Sites.
When you are our active customer we use legitimate interest as a lawful basis to (i) engage in direct marketing by email, post and phone; (ii) provide you with offers, samples, invitations to events, training courses; (iii) provide you with advertisement information which we have a reason to believe you may find interesting based on your previous requests or based on similar products you have bought or expressed your interest before.
Processing on the basis of performance of a contract: we normally process your personal information on the basis of contract performance when we need to take preparatory steps prior to a conclusion of a contract with you or in order to manage our contractual relationship such as sale of our products. Examples include: (i) creating your account, including on the Sites; (ii) managing your orders, including payment;
(iii) process payments and fulfill orders that you place on or through the Websites or Apps; (iv) provide you with customer and technical services.
Processing on the basis of your consent: the typical activities that we would ask your permission for include: (i) direct marketing activities, as described below; (ii) targeted advertising; (iii) adjusting or turning on settings of your mobile phone when using PPG Apps to, for example, turn on your camera or use your geolocation, always to offer you better service.
When you are a prospective client of PPG, we ask you for a permission to (i) engage in direct marketing by email; (ii) provide you with offers, samples, invitations to events, training courses; (iii) provide you with advertisement information that you have expressed your interest in at the moment of granting consent.
Processing on the basis of our legal obligation: we may ask you to provide certain personal information or obtain it from third parties when the law requires us to do so or it is indispensable to attend to our legal obligations. Examples include: (i) maintaining our business records; (ii) preventing fraud; (iii) complying with the requests of public authorities; (iv) complying with export control and sanctions regulations; (v) abiding by health and safety laws and protocols.
Transfers outside of EEA
In general, given the geographical proximity of our business with our customers, we use your personal information within your country or another member state of the European Union. However, as an international company, PPG may transfer your personal information throughout PPG’s worldwide organization or engage third party service providers based in countries outside the European Union. Some of these countries may not be regarded as ensuring an adequate level of protection with regard to the processing of your personal information. In such cases, we do not transfer your personal information unless we have provided appropriate safeguards such as data processing agreements on the basis of standard data protection clauses adopted by the EU Commission (which PPG has implemented for transfers to its group entities in the U.S., for example). You may request a copy of any such safeguards in place concerning the processing of your personal information by contacting us via PPG Privacy Portal.
GDPR provides EEA individuals with specific rights regarding their personal information. More specifically, you have the following rights regarding PPG’s collection, use and sharing of your personal information:
- Right to access: You may require us to provide you with confirmation as to whether we process your personal information and, where that is the case, obtain from us access to your personal information and other details on how we process it.
- Right to rectification: You may require us to correct inaccurate personal information concerning you or complete any such data which is incomplete.
- Right to erasure (“right to be forgotten”): Under certain circumstances, you may obtain from us erasure of your personal information.
- Right to restriction of processing: Under certain circumstances, you may obtain from us restriction of the processing of your personal information.
- Right to data portability: Where our processing of your personal information is based on your consent or on a contract between you and us, you may require us to provide you with your personal information which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit such data to another controller without hindrance from us or, where technically feasible, to have the data transmitted directly from us to another controller.
- Right to object: You may object to our processing of your personal information (i) for direct marketing purposes at any time; or (ii), on grounds relating to your particular situation, where we are performing a task in the public interest or pursuing our legitimate interests or those of a third party.
Where you have given us your consent to process your personal information, you can withdraw your consent at any time and at no cost with effect for the future. If you do, we will stop the respective processing of your personal information based on that consent. However, this may, for example, prevent us from providing you with certain services for which we processed your personal information.
If you would like to exercise any of the above rights, please contact us by submitting a request via PPG Privacy Portal.
In any case and at any time, you may lodge a complaint with the data protection authority.